OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
Created openvpn tracking bugs for this issue: Affects: epel-all [bug 1952936] Affects: fedora-all [bug 1952935]
External References: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=987380
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.