Описание
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.7.5-1ubuntu2 |
| esm-infra-legacy/trusty | not-affected | code not present |
| esm-infra-legacy/xenial | not-affected | code not present |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| jammy | not-affected | code not present |
| noble | released | 2.6.19-0ubuntu0.24.04.3 |
| questing | ignored | end of life, was needs-triage |
| resolute | released | 2.7.0-1ubuntu1.2 |
| upstream | released | 2.7.5-1 |
Показывать по
EPSS
8.1 High
CVSS3
Связанные уязвимости
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 thr ...
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
Уязвимость функции check_session_buf_not_used() механизма tls-crypt-v2 программного обеспечения OpenVPN, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, вызвать отказ в обслуживании или выполнить произвольный код
EPSS
8.1 High
CVSS3