A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2004949 | issue tracking third party advisory |
https://www.oracle.com/security-alerts/cpujul2022.html | third party advisory patch |
https://citizenlab.ca/2024/07/vulnerabilities-in-vpns-paper-presented-at-the-privacy-enhancing-technologies-symposium-2024/ | |
https://security.netapp.com/advisory/ntap-20250328-0004/ |