Zurück zur CVE-Übersicht
CVE-2023-46850
CRITICAL(9.8)CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk Signal Score25/100 — MITTEL
- CVSS 9.8 — Kritisch
EPSS-Score
2%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
9.8
Technische Schwere
Beschreibung
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Referenzen
- https://community.openvpn.net/openvpn/wiki/CVE-2023-46850
- https://openvpn.net/security-advisory/access-server-security-update-cve-2023-468...
- https://community.openvpn.net/openvpn/wiki/CVE-2023-46850
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproje...
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproje...
- https://openvpn.net/security-advisory/access-server-security-update-cve-2023-468...
- https://www.debian.org/security/2023/dsa-5555