OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openvpn | Openvpn | * | 2.3.16 (including) |
Openvpn | Openvpn | 2.4.0 (including) | 2.4.0 (including) |
Openvpn | Openvpn | 2.4.0-alpha2 (including) | 2.4.0-alpha2 (including) |
Openvpn | Openvpn | 2.4.0-beta1 (including) | 2.4.0-beta1 (including) |
Openvpn | Openvpn | 2.4.0-beta2 (including) | 2.4.0-beta2 (including) |
Openvpn | Openvpn | 2.4.0-rc1 (including) | 2.4.0-rc1 (including) |
Openvpn | Openvpn | 2.4.0-rc2 (including) | 2.4.0-rc2 (including) |
Openvpn | Openvpn | 2.4.1 (including) | 2.4.1 (including) |
Openvpn | Openvpn | 2.4.2 (including) | 2.4.2 (including) |
Openvpn | Ubuntu | upstream | * |