Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2023-11-11 01:15
Updated : 2023-11-29 03:15
NVD link : CVE-2023-46849
Mitre link : CVE-2023-46849
CVE.ORG link : CVE-2023-46849
JSON object : View
Products Affected
openvpn
- openvpn
- openvpn_access_server
debian
- debian_linux
fedoraproject
- fedora
CWE
CWE-369
Divide By Zero