CVE-2005-2533: Low severity OpenVPN OpenVPN vulnerability
OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2533?
CVE-2005-2533 has a severity rating that indicates it can lead to denial of service due to memory exhaustion from a packet flood.
How do I fix CVE-2005-2533?
To fix CVE-2005-2533, upgrade to OpenVPN version 2.0.1 or later as this addresses the vulnerability.
What versions of OpenVPN are affected by CVE-2005-2533?
OpenVPN versions prior to 2.0.1, including all 2.0.x pre-release versions, are affected by CVE-2005-2533.
What does CVE-2005-2533 exploit?
CVE-2005-2533 exploits OpenVPN's Ethernet bridging mode by allowing remote authenticated clients to flood it with packets containing spoofed MAC addresses.
What are the consequences of CVE-2005-2533?
The consequences of CVE-2005-2533 include potential service disruption and denial of access due to memory exhaustion.