OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
| Software | From | Fixed in |
|---|---|---|
| openvpn / openvpn | 2.4.0 | 2.4.0.x |
| openvpn / openvpn | 2.4.0-beta1 | 2.4.0-beta1.x |
| openvpn / openvpn | 2.3.12 | 2.3.12.x |
| openvpn / openvpn | 2.4.0-rc1 | 2.4.0-rc1.x |
| openvpn / openvpn | 2.4.0-beta2 | 2.4.0-beta2.x |
| openvpn / openvpn | 2.4.0-alpha2 | 2.4.0-alpha2.x |
| openvpn / openvpn | 2.3.14 | 2.3.14.x |
| openvpn / openvpn | 2.4.1 | 2.4.1.x |
| openvpn / openvpn | 2.3.13 | 2.3.13.x |
| openvpn / openvpn | 2.4.0-rc2 | 2.4.0-rc2.x |