Описание
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
| Релиз | Статус | Примечание |
|---|---|---|
| devel | pending | 2.7.5-1ubuntu2 |
| esm-infra-legacy/trusty | needs-triage | |
| esm-infra-legacy/xenial | needs-triage | |
| esm-infra/bionic | needs-triage | |
| esm-infra/focal | needs-triage | |
| jammy | released | 2.5.11-0ubuntu0.22.04.4 |
| noble | released | 2.6.19-0ubuntu0.24.04.3 |
| questing | ignored | end of life, was needs-triage |
| resolute | released | 2.7.0-1ubuntu1.2 |
| upstream | released | 2.7.5-1 |
Показывать по
EPSS
8.1 High
CVSS3
Связанные уязвимости
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 throug ...
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
EPSS
8.1 High
CVSS3