OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-08-23 21:00
Updated : 2008-09-05 13:52
NVD link : CVE-2005-2532
Mitre link : CVE-2005-2532
JSON object : View
CWE
Products Affected
openvpn
- openvpn