An integer underflow vulnerability exists in the vpnserver OvsProcessData functionality of SoftEther VPN 5.01.9674 and 5.02. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2023-1737 | third party advisory exploit |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1737 |