Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-9336

Опубликовано: 01 мая 2018
Источник: debian
EPSS Низкий

Описание

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openvpnnot-affectedpackage

Примечания

  • https://github.com/OpenVPN/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b

EPSS

Процентиль: 26%
0.00087
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
nvd
около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

suse-cvrf
почти 7 лет назад

Security update for openvpn

suse-cvrf
почти 7 лет назад

Security update for openvpn

CVSS3: 7.8
github
около 3 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

EPSS

Процентиль: 26%
0.00087
Низкий