CVE-2017-7479: Medium severity OpenVPN OpenVPN vulnerability
Published May 15, 2017
·Updated
OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
Affected Software
8 affected components
OpenVPN OpenVPN<=2.3.14
OpenVPN OpenVPN=2.4.0
OpenVPN OpenVPN=2.4.0-alpha2
OpenVPN OpenVPN=2.4.0-beta1
OpenVPN OpenVPN=2.4.0-beta2
OpenVPN OpenVPN=2.4.0-rc1
OpenVPN OpenVPN=2.4.0-rc2
OpenVPN OpenVPN=2.4.1
Event History
May 15, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7479?
CVE-2017-7479 has been classified as a Denial of Service vulnerability.
2
How do I fix CVE-2017-7479?
To fix CVE-2017-7479, upgrade OpenVPN to version 2.3.15 or later, or 2.4.2 or later.
3
Who is affected by CVE-2017-7479?
CVE-2017-7479 affects OpenVPN versions prior to 2.3.15 and versions before 2.4.2.
4
What type of attack does CVE-2017-7479 enable?
CVE-2017-7479 allows authenticated attackers to cause a Denial of Service on the OpenVPN server.
5
What happens when the packet-ID counter rolls over in CVE-2017-7479?
When the packet-ID counter rolls over in CVE-2017-7479, it leads to a reachable assertion that can crash the server.