7.5
CVSSv3

CVE-2023-46849

Published: 11/11/2023 Updated: 29/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an malicious user to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openvpn openvpn

openvpn openvpn access server

openvpn openvpn access server 2.12.1

openvpn openvpn access server 2.12.0

debian debian linux 12.0

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1055805 openvpn: CVE-2023-46849 CVE-2023-46850 Package: src:openvpn; Maintainer for src:openvpn is Bernhard Schmidt <berni@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 11 Nov 2023 20:30:01 UTC Severity: grave Tags: security, upstream Found in version openvpn ...
Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in memory disclosure or denial of service The oldstable distribution (bullseye) is not affected For the stable distribution (bookworm), these problems have been fixed in version 263-1+deb12u2 We recommend that you upgrade your openvpn packa ...