The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
2024-07-08T11:15:10.303
2024-11-21T09:04:39.057
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openvpn | openvpn | < 2.5.10 | Yes |
Application | openvpn | openvpn | < 2.6.10 | Yes |