CVE-2023-46850
11.11.2023, 01:15
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| openvpn | openvpn | 2.6.0 ≤ 𝑥 ≤ 2.6.6 |
| openvpn | openvpn_access_server | 2.11.0 ≤ 𝑥 ≤ 2.11.3 |
| openvpn | openvpn_access_server | 2.12.0 ≤ 𝑥 < 2.12.2 |
| debian | debian_linux | 12.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| openvpn |
| ||||||||||||
| openvpn-auth-pam-plugin |
| ||||||||||||
| openvpn-dco |
| ||||||||||||
| openvpn-dco-devel |
| ||||||||||||
| openvpn-devel |
|
Common Weakness Enumeration
References