Описание
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server
| Релиз | Статус | Примечание |
|---|---|---|
| devel | pending | 2.7.5-1ubuntu2 |
| esm-infra-legacy/trusty | not-affected | see notes |
| esm-infra-legacy/xenial | not-affected | see notes |
| esm-infra/bionic | not-affected | see notes |
| esm-infra/focal | not-affected | see notes |
| jammy | not-affected | see notes |
| noble | released | 2.6.19-0ubuntu0.24.04.3 |
| questing | ignored | end of life, was needs-triage |
| resolute | released | 2.7.0-1ubuntu1.2 |
| upstream | released | 2.7.5-1 |
Показывать по
EPSS
7.5 High
CVSS3
Связанные уязвимости
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allo ...
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server
EPSS
7.5 High
CVSS3