OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://community.openvpn.net/openvpn/wiki/VulnerabilitiesFixedInOpenVPN243 | vendor advisory |
http://www.securitytracker.com/id/1038768 | vdb entry |
http://www.securityfocus.com/bid/99230 | vdb entry third party advisory |
http://www.debian.org/security/2017/dsa-3900 | vendor advisory |