Описание
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
A flaw was found in OpenVPN. An incomplete guard allows remote authenticated peers to trigger a use-after-free vulnerability during TLS (Transport Layer Security) session promotion. This can lead to a denial of service, making the service unavailable, or memory leakage, which could potentially expose sensitive information.
Отчет
Moderate: This flaw in OpenVPN allows a remote authenticated peer to trigger a use-after-free during TLS session promotion, leading to a denial of service or memory leakage. The high attack complexity and requirement for prior authentication limit the immediate risk, but successful exploitation could disrupt VPN services or expose sensitive information.
Ссылки на источники
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 thr ...
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
Уязвимость функции check_session_buf_not_used() механизма tls-crypt-v2 программного обеспечения OpenVPN, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, вызвать отказ в обслуживании или выполнить произвольный код
5.9 Medium
CVSS3