Commit 4d0c88

2025-02-27 10:07:23 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2023-6247.md ..
@@ 1,15 1,15 @@
- # CVE-2023-6247: PKCS!#7 Parser in OpenVPN 3 Core Library Can Result in NULL-Dereference
+ # CVE-2023-6247: PKCS!#7 parser in OpenVPN 3 Core Library can result in NULL-dereference
The PKCS!#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.
- This issue has been resolved in OpenVPN 3 Core Library version 3.8.4.
+ This is resolved in OpenVPN 3 Core Library version 3.8.4.
- ## Note
+ ### Note
- The code paths related to this issue are never used for OpenVPN connections. The affected code is only used in some of the AWS API support functionality present in the library.
+ The code paths this issue is related to is never used for OpenVPN connections. The related code is only used in some of the AWS API support functionality present in the library.
- ## References
+ ### References
- - MITRE CVE Record: [https://www.cve.org/CVERecord?id=CVE-2023-6247](https://www.cve.org/CVERecord?id=CVE-2023-6247)
- - OpenVPN 3 Core commit: [https://github.com/OpenVPN/openvpn3/commit/afdfe1bb3f4c54e8794](https://github.com/OpenVPN/openvpn3/commit/afdfe1bb3f4c54e8794)
- - Reported by: Bahaa Naamneh
\ No newline at end of file
+ * MITRE CVE Record: https://www.cve.org/CVERecord?id=CVE-2023-6247
+ * OpenVPN 3 Core commit: https://github.com/OpenVPN/openvpn3/commit/afdfe1bb3f4c54e8794
+ * Reported by: Bahaa Naamneh
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9