Описание
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 2.7.3-1ubuntu2 |
| esm-infra-legacy/trusty | needs-triage | |
| esm-infra-legacy/xenial | needs-triage | |
| esm-infra/bionic | needs-triage | |
| esm-infra/focal | needs-triage | |
| esm-infra/xenial | ignored | end of ESM support, was needs-triage |
| jammy | released | 2.5.11-0ubuntu0.22.04.3 |
| noble | released | 2.6.19-0ubuntu0.24.04.2 |
| questing | released | 2.6.19-0ubuntu0.25.10.2 |
| resolute | released | 2.7.0-1ubuntu1.1 |
Показывать по
EPSS
Связанные уязвимости
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.
Improper validation of packet length during tls-crypt-v2 key extractio ...
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.
Уязвимость функции tls_crypt_v2_extract_client_key() программного обеспечения OpenVPN, позволяющая нарушителю вызвать отказ в обслуживании
EPSS