VDB

ALPINE-CVE-2017-7478

ALPINE-CVE-2017-7478 PUBLISHED CVSS 7.5 HIGH

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.6openvpn2.0.9-r1, 2.0.9-r2, 2.1.1-r1
Alpine:v3.5openvpn0, 2.0.9-r0, 2.0.9-r1

Timeline

  • May 15, 2017 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jun 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›