CNNVD-202512-002 Information

CNNVD ID

CNNVD-202512-002

CVE-2025-12106

  • CNNVD Published: 2025-12-01

Description (Chinese)

OpenVPN是美国OpenVPN公司的一个用于创建虚拟专用网络(VPN)加密通道的软件包,它使用OpenSSL库来加密数据与控制信息,并允许创建的VPN使用公开密钥、电子证书或者用户名/密码来进行身份验证。 OpenVPN 2.7_alpha1至2.7_rc1版本存在安全漏洞,该漏洞源于参数验证不足,可能导致堆缓冲区越界读取。

Description (English)

OpenVPN is a software package for the creation of a virtual private network (VPN) encryption channel at OpenVPN, United States, which uses the OpenSSL library to encrypt data and control information and allows the created VPN to use public keys, electronic certificates or username/cipher for identification. OpenVPN 2.7 alpha1 to 2.7 rc1 contains a security loophole, which stems from a lack of proof of parameters, which may lead to cross-border reading of stacked buffer zones.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

OpenVPN

Published

2025-12-01

Last Modified

2026-02-24

References

https://community.openvpn.net/Security%20Announcements/CVE-2025-12106 https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00152.html https://access.redhat.com/security/cve/cve-2025-12106

Patch

https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00152.html

Share on: