CVE-2017-7520
27.06.2017, 13:29
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-middle attacker.Enginsight
Vendor | Product | Version |
---|---|---|
openvpn | openvpn | 𝑥 ≤ 2.3.16 |
openvpn | openvpn | 2.4.0 |
openvpn | openvpn | 2.4.0:alpha2 |
openvpn | openvpn | 2.4.0:beta1 |
openvpn | openvpn | 2.4.0:beta2 |
openvpn | openvpn | 2.4.0:rc1 |
openvpn | openvpn | 2.4.0:rc2 |
openvpn | openvpn | 2.4.1 |
openvpn | openvpn | 2.4.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-125 - Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.
References