2025-02-27 10:16:07Samuli Seppänen:
Switch to non-AI version
Security Announcements/CVE-2024-27459.md ..
@@ 1,14 1,12 @@
# CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation
-
**File:** `interactive.c`
+
interactive.c: Fix potential stack overflow issue
-
**Issue:** Fix potential stack overflow issue
-
-
When reading a message from the pipe, we first peek at the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow.
+
When reading message from the pipe, we first peek the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow.
To address this, we terminate the misbehaving process if the peeked message size exceeds the maximum allowable size.