Commit 7c7ee3

2025-02-27 10:29:54 Samuli Seppänen: Switch to non-AI version
Security Announcements/TapWindows6BufferOverflowVulnerability.md ..
@@ 1,3 1,3 @@
- There was a buffer overflow vulnerability in tap-windows6 version 9.21.1, in `adapter.c`, where the code was failing to check the size of a registry string read by `NdisReadConfiguration` before copying it to a fixed length buffer. The vulnerability could potentially allow arbitrary code execution in the kernel context of a signed driver, however it requires local Admin privileges to exploit. Further details are available in the [reporter's GitHub repository](https://github.com/Rootkitsmm/OpenVpn-Pool-Overflow/blob/master/README.md).
+ There was a buffer overflow vulnerability in tap-windows6 version 9.21.1, in adapter.c, where the code was failing to check the size of a registry string read by !NdisReadConfiguration before copying it to a fixed length buffer. The vulnerability could potentially allow arbitrary code execution in the kernel context of a signed driver, however it requires local Admin privileges to exploit. Further details are available in the [reporter's GitHub repository](https://github.com/Rootkitsmm/OpenVpn-Pool-Overflow/blob/master/README.md).
- This problem has been fixed in tap-windows6 version 9.21.2, which is bundled with `openvpn-install-2.3.10-I604` and later. The I00x installers do not have this vulnerability, because they bundle the old NDIS 5-based tap-windows driver. The source code for the fix is [available on GitHub](https://github.com/mattock/tap-windows6/commit/6b05a00fb85903f0d26cb3a21bb70b1f814003d5).
\ No newline at end of file
+ This problem has been fixed in tap-windows6 version 9.21.2, which is bundled with openvpn-install-2.3.10-I604 and later. The I00x installers do not have this vulnerability, because they bundle the old NDIS 5-based tap-windows driver. The source code for the fix is [available](https://github.com/mattock/tap-windows6/commit/6b05a00fb85903f0d26cb3a21bb70b1f814003d5) on !GitHub.
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9