{"id":"CLSA-2025-1744727573","summary":"Fix CVE(s): CVE-2024-5594","details":"    * SECURITY UPDATE: Improper PUSH_REPLY sanitization allows attackers\n      to inject arbitrary data into third-party executables\n      - debian/patches/CVE-2024-5594.patch: Properly handle null bytes\n        and invalid characters in control\n      - CVE-2024-5594","modified":"2026-06-04T09:46:40.012402877Z","published":"2025-04-15T14:32:58Z","upstream":["CVE-2024-5594"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu16-els/CLSA-2025-1744727573.html"}],"affected":[{"package":{"name":"openvpn","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/openvpn?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.3.10-1ubuntu2.2+tuxcare.els3"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2025-1744727573.json"}}],"schema_version":"1.7.5"}