Remote Denial-of-Service Vulnerability in OpenVPN Products
CVE-2017-7521

5.9MEDIUM

What is CVE-2017-7521?

Versions of OpenVPN prior to 2.4.3 and 2.3.17 are susceptible to a remote denial-of-service attack stemming from memory leaks and issues related to double-free errors in the extract_x509_extension() function. An attacker can exploit this vulnerability, leading to memory exhaustion, which can disrupt service availability.

Affected Version(s)

OpenVPN before 2.4.3

OpenVPN before 2.3.17

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.