PT-2023-8897 · Openvpn+3 · Openvpn+3

Published

2023-11-10

·

Updated

2024-08-14

·

CVE-2023-46850

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions 2.6.0 through 2.6.6
Description The issue is related to a use after free condition in OpenVPN, which may lead to undefined behavior, leaking memory buffers, or remote execution when sending network buffers to a remote peer. This could potentially allow a remote attacker to cause a denial of service.
Recommendations For OpenVPN versions 2.6.0 through 2.6.6, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2023-7171
ALT-PU-2024-10859
ALT-PU-2024-10885
BDU:2024-02574
CVE-2023-46850
DSA-5555-1
OPENSUSE-SU-2024:13429-1
USN-6484-1

Affected Products

Alt Linux
Openvpn
Red Os
Ubuntu