Commit 966a34

2025-02-27 10:16:07 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2024-27459.md ..
@@ 1,14 1,12 @@
# CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation
- **File:** `interactive.c`
+ interactive.c: Fix potential stack overflow issue
- **Issue:** Fix potential stack overflow issue
-
- When reading a message from the pipe, we first peek at the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow.
+ When reading message from the pipe, we first peek the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow.
To address this, we terminate the misbehaving process if the peeked message size exceeds the maximum allowable size.
- ## References
- - Release notes: [OpenVPN Users Mailing List](https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html)
- - CVE record: [CVE-2024-27459](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459)
- - Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
\ No newline at end of file
+ ### References
+ * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html
+ * CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27459
+ * Reported by: Vladimir Tokarev <​vtokarev@microsoft.com>
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9