CVE-2017-7522: Null Pointer Dereference
Published Jun 27, 2017
·Updated
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with an embedded NULL character.
Affected Software
9 affected components
OpenVPN OpenVPN<=2.3.16
OpenVPN OpenVPN=2.4.0
OpenVPN OpenVPN=2.4.0-alpha2
OpenVPN OpenVPN=2.4.0-beta1
OpenVPN OpenVPN=2.4.0-beta2
OpenVPN OpenVPN=2.4.0-rc1
OpenVPN OpenVPN=2.4.0-rc2
OpenVPN OpenVPN=2.4.1
OpenVPN OpenVPN=2.4.2
Event History
Jun 27, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7522?
CVE-2017-7522 is classified as a denial-of-service vulnerability affecting older versions of OpenVPN.
2
How do I fix CVE-2017-7522?
To fix CVE-2017-7522, upgrade OpenVPN to version 2.4.3 or later.
3
Which versions of OpenVPN are affected by CVE-2017-7522?
CVE-2017-7522 affects OpenVPN versions prior to 2.4.3 and 2.3.17.
4
Can CVE-2017-7522 be exploited remotely?
Yes, CVE-2017-7522 can be exploited by an authenticated remote attacker.
5
What type of attack is possible with CVE-2017-7522?
CVE-2017-7522 allows for denial-of-service attacks by sending specially crafted certificates.