OpenVPN 2.6.23 Released: 7 Security Fixes Close Windows Injection and Crash Bugs

Published by

OpenVPN 2.6.23 has been released as a security patch, addressing seven vulnerabilities, five of which are specific to Windows systems. The vulnerabilities include command injection, buffer overflows, and a cross-platform pre-authentication crash that could allow an unauthenticated peer to cause a client to crash. All fixes were backported from the master branch, enabling existing 2.6.x users to update without a major version change. Users are urged to upgrade promptly to mitigate risks, especially those operating on Windows, and should maintain clean host paths to avoid potential security issues



OpenVPN 2.6.23 Released: 7 Security Fixes Close Windows Injection and Crash Bugs

OpenVPN 2.6.23 dropped today as a pure security patch, sealing seven vulnerabilities, with no new features in the mix. Five of the seven flaws are Windows-specific, covering command injection through cmd.exe, binary planting of netsh.exe, a local denial-of-service, a DHCP buffer overflow, and config-directory traversal. The release also closes a cross-platform pre-authentication crash that lets an unauthenticated peer force a client segfault. All fixes were backported from master, so existing 2.6.x users can patch without a major upgrade.

OpenVPN 2.6.23 Released: 7 Security Fixes Close Windows Injection and Crash Bugs @ Linux Compatible