PT-2017-17785 · Openvpn+3 · Openvpn+3

Guido Vranken

·

Published

2017-06-21

·

Updated

2024-06-15

·

CVE-2017-7521

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.4.3 OpenVPN versions prior to 2.3.17
Description The issue is related to remote denial-of-service due to memory exhaustion. This is caused by memory leaks and a double-free issue in the extract x509 extension() function.
Recommendations For versions prior to 2.4.3, update to version 2.4.3 or later. For versions prior to 2.3.17, update to version 2.3.17 or later.

Fix

DoS

Missing Release of Resource after Effective Lifetime

Double Free

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1766
CVE-2017-7521
DSA-3900-1
MGASA-2017-0224
OPENSUSE-SU-2017_1680-1
OPENSUSE-SU-2024:11128-1
SUSE-SU-2017:1635-1
SUSE-SU-2017:1718-1
USN-3339-1

Affected Products

Alt Linux
Openvpn
Suse
Ubuntu