PT-2017-12376 · Openvpn+3 · Openvpn+3

Published

2017-10-03

·

Updated

2025-03-11

·

CVE-2017-12166

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.3.18 OpenVPN versions 2.4.x prior to 2.4.4
Description The issue is related to a buffer overflow vulnerability that can occur when key-method 1 is used, potentially leading to code execution.
Recommendations For OpenVPN versions prior to 2.3.18, update to version 2.3.18 or later. For OpenVPN versions 2.4.x prior to 2.4.4, update to version 2.4.4 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2662
CVE-2017-12166
DLA-2992-1
MGASA-2017-0372
OPENSUSE-SU-2017_2892-1
OPENSUSE-SU-2024:11128-1
SUSE-SU-2017:2838-1
SUSE-SU-2017:2839-1
SUSE-SU-2017:3177-1
SUSE-SU-2017_2839-1
SUSE-SU-2017_3177-1
USN-7340-1

Affected Products

Alt Linux
Openvpn
Suse
Ubuntu