CVE-2017-7478

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openvpn:openvpn:2.3.12:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.3.13:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.3.14:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:*:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:beta1:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:rc1:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.0:rc2:*:*:*:*:*:*
cpe:2.3:a:openvpn:openvpn:2.4.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-05-15 18:29

Updated : 2023-12-10 12:01


NVD link : CVE-2017-7478

Mitre link : CVE-2017-7478

CVE.ORG link : CVE-2017-7478


JSON object : View

Products Affected

openvpn

  • openvpn
CWE
CWE-20

Improper Input Validation

CWE-617

Reachable Assertion