Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p34-3252-9gh9

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

EPSS

Процентиль: 26%
0.00087
Низкий

7.8 High

CVSS3

Дефекты

CWE-415

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
nvd
около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

CVSS3: 7.8
debian
около 7 лет назад

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x ...

suse-cvrf
почти 7 лет назад

Security update for openvpn

suse-cvrf
почти 7 лет назад

Security update for openvpn

EPSS

Процентиль: 26%
0.00087
Низкий

7.8 High

CVSS3

Дефекты

CWE-415