MGASA-2016-0010

Source
https://advisories.mageia.org/MGASA-2016-0010.html
Import Source
https://advisories.mageia.org/MGASA-2016-0010.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0010
Published
2016-01-12T09:13:53Z
Modified
2026-04-16T04:27:54.780660Z
Summary
Updated openvpn packages fix security vulnerability
Details

OpenVPN versions before 2.3.9 contain an out of bounds read error in resolveremote() in the file socket.c. With both IPv4 and IPv6 connections, OpenVPN will read a struct sockaddrin6, but in the IPv4 case the data structure is smaller than in the IPv6 case.

The openvpn package has been updated to version 2.3.9, fixing this issue and several other bugs. See the upstream Changelog for details.

References
Credits

Affected packages

Mageia:5 / openvpn

Package

Name
openvpn
Purl
pkg:rpm/mageia/openvpn?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3.9-1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2016-0010.json"