Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-28820
HistoryJun 27, 2024 - 12:00 a.m.

CVE-2024-28820

2024-06-2700:00:00
ubuntu.com
ubuntu.com
2
openvpn
buffer overflow
extract_openvpn_cr
ldap
2.0.4
bug

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in
openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4
allows attackers with a valid LDAP username and who can control the
challenge/response password field to pass a string with more than 14 colons
into this field and cause a buffer overflow.

Bugs

6.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

7.7 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

Related for UB:CVE-2024-28820