GCVE-VVD-MAGEIA-2017-152
Advisory Published
Vulnetix · Advisory published June 1, 2017
It was discovered that OpenVPN improperly triggered an assert when
receiving an oversized control packet in some situations. A remote
attacker could use this to cause a denial of service (server or client
crash) (CVE-2017-7478).
It was discovered that OpenVPN improperly triggered an assert when packet
ids rolled over. An authenticated remote attacker could use this to cause
a denial of service (application crash) (CVE-2017-7479).