VDB

ALPINE-CVE-2024-5594

ALPINE-CVE-2024-5594 PUBLISHED CVSS 9.100000381469727 CRITICAL

OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.23openvpn2.3.3-r0, 2.3.4-r0, 2.3.5-r0
Alpine:v3.22openvpn2.5.5-r0, 2.2.2-r0, 2.2.0-r2
Alpine:v3.18openvpn2.6.1-r0, 0, 2.0.9-r0
Alpine:v3.21openvpn2.2.2-r0, 2.3.0-r0, 2.3.1-r0
Alpine:v3.19openvpn2.6.8-r0, 0, 2.0.9-r0
Alpine:v3.17openvpn2.3.2-r0, 2.5.8-r0, 2.5.7-r0
Alpine:v3.20openvpn2.4.5-r0, 2.4.5-r1, 2.4.6-r0

Timeline

  • Jan 6, 2025 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›