CVE-2017-7479 PUBLISHED

OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.

EPSS 0.37% · 58.7th percentile

Risk Scores

EPSS Score
0.37%
58.7th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSopenvpn0, 2.3.2-4ubuntu1, 2.3.2-5ubuntu1
Ubuntu:16.04:LTSopenvpn0, 2.3.7-1ubuntu1, 2.3.7-2ubuntu1

Timeline

References

Open in Interactive Console →