Commit 686563

2025-02-27 10:05:08 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2023-46850.md ..
@@ 1,7 1,7 @@
# CVE-2023-46850: Incorrect use of send buffer can cause memory to be sent to peer
- OpenVPN 2.6 from version 2.6.0 up to and including 2.6.6 incorrectly uses a send buffer after it has been freed in some circumstances. This error causes some freed memory to be sent to the peer. All configurations using TLS (i.e., not using `--secret`) are affected by this issue.
+ OpenVPN 2.6 from v2.6.0 up to and including v.2.6.6 incorrectly use a send buffer after it has been free()d in some circumstances, causing some free()d memory to be sent to the peer. All configurations using TLS (e.g. not using --secret) are affected by this issue.
This issue is resolved in OpenVPN 2.6.7.
- **MITRE entry**: [CVE-2023-46850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46850)
\ No newline at end of file
+ MITRE entry: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46850
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9