9.8
CVSSv3

CVE-2023-46850

Published: 11/11/2023 Updated: 29/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openvpn openvpn

openvpn openvpn access server

debian debian linux 12.0

fedoraproject fedora 39

Vendor Advisories

Debian Bug report logs - #1055805 openvpn: CVE-2023-46849 CVE-2023-46850 Package: src:openvpn; Maintainer for src:openvpn is Bernhard Schmidt <berni@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 11 Nov 2023 20:30:01 UTC Severity: grave Tags: security, upstream Found in version openvpn ...
Two vulnerabilities were discovered in openvpn, a virtual private network application which could result in memory disclosure or denial of service The oldstable distribution (bullseye) is not affected For the stable distribution (bookworm), these problems have been fixed in version 263-1+deb12u2 We recommend that you upgrade your openvpn packa ...