Lucene search

K
freebsdFreeBSD3DE49331-0DEC-422C-93E5-E4719E9869C5
HistoryNov 01, 2005 - 12:00 a.m.

openvpn -- potential denial-of-service on servers in TCP mode

2005-11-0100:00:00
vuxml.freebsd.org
15

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.093

Percentile

94.7%

James Yonan reports:

If the TCP server accept() call returns an error status, the
resulting exception handler may attempt to indirect through a NULL
pointer, causing a segfault. Affects all OpenVPN 2.0 versions.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchopenvpn= 2.0UNKNOWN
FreeBSDanynoarchopenvpn< 2.0.4UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.093

Percentile

94.7%