CVE-2023-46849: Divide by Zero
Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46849?
CVE-2023-46849 is a vulnerability in OpenVPN version 2.6.0 to 2.6.6 that allows an attacker to trigger a divide by zero behavior, leading to a denial of service.
How does CVE-2023-46849 impact OpenVPN?
CVE-2023-46849 can cause an application crash in OpenVPN, resulting in a denial of service.
Which versions of OpenVPN are affected by CVE-2023-46849?
OpenVPN versions 2.6.0 to 2.6.6 are affected by CVE-2023-46849.
How can an attacker exploit CVE-2023-46849?
An attacker can exploit CVE-2023-46849 by using the --fragment option in certain configuration setups.
How can I mitigate the CVE-2023-46849 vulnerability?
To mitigate the CVE-2023-46849 vulnerability, update OpenVPN to version 2.6.7 or apply the appropriate security patches as recommended by your software provider.