Описание
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
A flaw was found in OpenVPN when using the tap-windows6 driver. A remote attacker could exploit this vulnerability by sending specially crafted DOMAIN-SEARCH entries. This could lead to an out-of-bounds write, potentially causing information disclosure or a denial of service.
Отчет
This Low impact vulnerability in OpenVPN affects Windows installations utilizing the tap-windows6 driver. Red Hat products are not directly impacted as they do not deploy OpenVPN with this specific Windows driver.
Дополнительная информация
Статус:
4.2 Medium
CVSS3
Связанные уязвимости
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver a ...
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
4.2 Medium
CVSS3