Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
| Software | From | Fixed in |
|---|---|---|
| openvpn / openvpn | 2.6.0 | 2.6.16 |
| openvpn / openvpn | 2.7-alpha1 | 2.7-alpha1.x |
| openvpn / openvpn | 2.7-alpha2 | 2.7-alpha2.x |
| openvpn / openvpn | 2.7-alpha3 | 2.7-alpha3.x |
| openvpn / openvpn | 2.7-beta1 | 2.7-beta1.x |
| openvpn / openvpn | 2.7-beta2 | 2.7-beta2.x |
| openvpn / openvpn | 2.7-beta3 | 2.7-beta3.x |
| openvpn / openvpn | 2.7-rc1 | 2.7-rc1.x |