Using the –fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
The product divides a value by zero.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openvpn | Openvpn | 2.6.0 (including) | 2.6.6 (including) |
Openvpn_access_server | Openvpn | 2.11.0 (including) | 2.11.3 (including) |
Openvpn_access_server | Openvpn | 2.12.0 (including) | 2.12.0 (including) |
Openvpn_access_server | Openvpn | 2.12.1 (including) | 2.12.1 (including) |
Openvpn | Ubuntu | bionic | * |
Openvpn | Ubuntu | lunar | * |
Openvpn | Ubuntu | mantic | * |
Openvpn | Ubuntu | trusty | * |
Openvpn | Ubuntu | upstream | * |
Openvpn | Ubuntu | xenial | * |