openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.
2018-05-01T18:29:00.697
2024-11-21T04:15:21.590
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openvpn | openvpn | < 2.4.6 | Yes |
| Operating System | slackware | slackware_linux | 13.0 | Yes |
| Operating System | slackware | slackware_linux | 13.1 | Yes |
| Operating System | slackware | slackware_linux | 13.37 | Yes |
| Operating System | slackware | slackware_linux | 14.0 | Yes |
| Operating System | slackware | slackware_linux | 14.1 | Yes |