Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-openvpn | Aug 22, 2024 | Nov 11, 2023 | |
| Debian | debian-upgrade-openvpn | Nov 20, 2023 | Nov 11, 2023 | |
| Freebsd | freebsd-upgrade-package-openvpnfreebsd-upgrade-package-openvpn-devel | Nov 16, 2023 | Nov 15, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-net-vpn-openvpn | Sep 23, 2024 | Nov 11, 2023 | |
| Ubuntu | ubuntu-upgrade-openvpn | Nov 17, 2023 | Nov 11, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub