CVE-2023-46849 Information

Description

Using the –fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash leading to a denial of service.

Reference

https://community.openvpn.net/openvpn/wiki/CVE-2023-46849 https://openvpn.net/security-advisory/access-server-security-update-cve-2023-46849-cve-2023-46850/

Share on: