CVE-2020-36382 only version 2.6x affected?

Business solution to host your own OpenVPN server with web management interface and bundled clients.
Post Reply
dier884ldWSEkq
OpenVpn Newbie
Posts: 1
Joined: Sat Nov 11, 2023 11:11 am

CVE-2020-36382 only version 2.6x affected?

Post by dier884ldWSEkq » Sat Nov 11, 2023 11:13 am

There is a vulnerability CVE-2020-36382. In the comment is written that version 2.6.x to 2.6.6 are affected. What about version 2.5.1 which is the default installation on debian linux. Is this version also affected?

I cannot find a way to update openVPN on debian to 2.6.x

User avatar
openvpn_inc
OpenVPN Inc.
Posts: 1333
Joined: Tue Feb 16, 2021 10:41 am

Re: CVE-2020-36382 only version 2.6x affected?

Post by openvpn_inc » Tue Nov 14, 2023 11:34 am

Hello,

It's only 2.6.x to 2.6.6 affected. So yeah, that means 2.5.1 is not affected.

Kind regards,
Johan
Image OpenVPN Inc.
Answers provided by OpenVPN Inc. staff members here are provided on a voluntary best-effort basis, and no rights can be claimed on the basis of answers posted in this public forum. If you wish to get official support from OpenVPN Inc. please use the official support ticket system: https://openvpn.net/support

Post Reply