Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2017-7522

Published: 27 June 2017

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.

Notes

AuthorNote
mdeslaur
introduced in 2.4
in Debian/Ubuntu, package is built with openssl

Priority

Medium

CVSS 3 base score: 6.5

Status

Package Release Status
openvpn
Launchpad, Ubuntu, Debian
precise Not vulnerable

trusty Not vulnerable
(2.3.2-7ubuntu3.1)
upstream
Released (2.4.3, 2.3.17)
xenial Not vulnerable
(2.3.10-1ubuntu2)
yakkety Not vulnerable
(2.3.11-1ubuntu2)
zesty Not vulnerable
(code not compiled)
Patches:
upstream: https://github.com/OpenVPN/openvpn/commit/426392940c
upstream: https://github.com/OpenVPN/openvpn/commit/67edada0be (2.4)