CVE-2017-7478

Description

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.599

Associated Vulnerability

VulnerabilityOS Platform
Upgrade openvpn 2.4.1 to latest versionWindows
virtual private network software (USN-3284-1) openvpn_2.4.0-4ubuntu1.2_i386.debLinux
virtual private network software (USN-3284-1) openvpn_2.4.0-4ubuntu1.2_amd64.debLinux
SUSE-SU-2017:2838-1(SUSE Linux Enterprise Server 11-SP4 ) openvpn-2.0.9-143.47.3.1.x86_64.rpmLinux
SUSE-SU-2017:2838-1(SUSE Linux Enterprise Server 11-SP4 ) openvpn-auth-pam-plugin-2.0.9-143.47.3.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234