Описание
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
A flaw was found in OpenVPN. An incorrect buffer size calculation within the Windows Interactive Service allows local authenticated users to trigger memory corruption or disclose sensitive information. This vulnerability can be exploited by providing specially crafted inputs.
Отчет
Important: This vulnerability affects the Windows Interactive Service component of OpenVPN, allowing local authenticated users to cause memory corruption or information disclosure. Red Hat's OpenVPN packages, available in Community Projects like Fedora and EPEL, are Linux-based and do not include the vulnerable Windows-specific service, thus are not directly impacted by this flaw.
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
An incorrect buffer size calculation in the Windows Interactive Servic ...
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
7.5 High
CVSS3