OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-05-15 11:29
Updated : 2017-08-15 18:29
NVD link : CVE-2017-7478
Mitre link : CVE-2017-7478
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
openvpn
- openvpn