There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2024-5594:
(needs triaging)
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.
- CVE-2024-28882:
(needs triaging)
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
You can find information about how to handle these issues in the security team's documentation.