Commit 29a2a7

2025-07-02 16:23:00 novaflash: -/-
Security Announcements/CVE-2018-7544.md ..
@@ 1,6 1,6 @@
# [DRAFT] CVE-2018-7544: DISPUTED: Remote Information Disclosure and Denial Of Service
- Jose Antonio Pérez Piedra discovered a way to interfere with a running OpenVPN instance via the management interface, and reported this as a security issue to the OpenVPN developers. They disagreed with the assessment and classified as a (non-default) configuration problem. Jose disagreed with that and proceeded to get a CVE ID allocated ([CVE-2018-7544](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7544)).
+ Jose Antonio Pérez Piedra discovered a way to interfere with a running OpenVPN instance via the management interface, and reported this as a security issue to the OpenVPN developers. They disagreed with the assessment and classified as a (non-default) configuration problem. Jose disagreed with that and proceeded to get a CVE ID allocated ([CVE-2018-7544](https://www.cve.org/CVERecord?id=CVE-2018-7544)).
Since the existence of a CVE will create insecurity and confusion for OpenVPN users, this page tries to clarify what this is about, why it is not seen as a security issue and why no code changes will be made to disallow the configuration variant in question.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9