OpenVPN — свободная реализация технологии виртуальной частной сети (VPN) с открытым исходным кодом для создания зашифрованных каналoв типа точка-точка или сервер-клиенты между компьютерами.
Релизный цикл, информация об уязвимостях
График релизов
Количество 189
CVE-2018-7544
A cross-protocol scripting issue was discovered in the management inte ...
CVE-2018-7544
A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning
SUSE-SU-2017:3177-1
Security update for openvpn-openssl1
openSUSE-SU-2017:2892-1
Security update for openvpn
SUSE-SU-2017:2839-1
Security update for openvpn
CVE-2017-12166
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
CVE-2017-12166
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to ...
CVE-2017-12166
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
CVE-2017-7522
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
CVE-2017-7522
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to deni ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-7544 A cross-protocol scripting issue was discovered in the management inte ... | CVSS3: 9.1 | 0% Низкий | больше 7 лет назад | |
CVE-2018-7544 A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning | CVSS3: 9.1 | 0% Низкий | больше 7 лет назад | |
SUSE-SU-2017:3177-1 Security update for openvpn-openssl1 | 5% Низкий | почти 8 лет назад | ||
openSUSE-SU-2017:2892-1 Security update for openvpn | 5% Низкий | около 8 лет назад | ||
SUSE-SU-2017:2839-1 Security update for openvpn | 5% Низкий | около 8 лет назад | ||
CVE-2017-12166 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution. | CVSS3: 9.8 | 5% Низкий | около 8 лет назад | |
CVE-2017-12166 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to ... | CVSS3: 9.8 | 5% Низкий | около 8 лет назад | |
CVE-2017-12166 OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution. | CVSS3: 9.8 | 5% Низкий | около 8 лет назад | |
CVE-2017-7522 OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character. | CVSS3: 6.5 | 1% Низкий | больше 8 лет назад | |
CVE-2017-7522 OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to deni ... | CVSS3: 6.5 | 1% Низкий | больше 8 лет назад |
Уязвимостей на страницу