Commit 7cc93a

2025-02-27 10:19:11 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2024-5198.md ..
@@ 1,14 1,8 @@
- # CVE-2024-5198: OpenVPN ovpn-dco for Windows Version 1.1.1 Vulnerability
+ # CVE-2024-5198: OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
- OpenVPN ovpn-dco for Windows version 1.1.1 is vulnerable to a security issue where an unprivileged local attacker can send I/O control messages with invalid data to the driver. This results in a NULL pointer dereference, leading to a system halt.
+ Affected versions: ovpn-dco Windows driver 1.1.1, OpenVPN 2.6.10-I002 Windows client (older and newer versions of the driver and Windows client are not affected)
- **Affected versions:**
- - ovpn-dco Windows driver 1.1.1
- - OpenVPN 2.6.10-I002 Windows client
-
- Note: Only the specified versions are affected. Older and newer versions of the driver and Windows client are not affected.
-
- ## References
- - GitHub PR: [https://github.com/OpenVPN/ovpn-dco-win/pull/70](https://github.com/OpenVPN/ovpn-dco-win/pull/70)
- - CVE record: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5198](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5198)
- - Reported-By: Lukas Jokubauskas <lukas.jokubauskas@nordsec.com>
\ No newline at end of file
+ ### References
+ * GitHub PR: https://github.com/OpenVPN/ovpn-dco-win/pull/70
+ * CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5198
+ * Reported-By: Lukas Jokubauskas <lukas.jokubauskas@nordsec.com>
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9