Blame
| 4d0c88 | Samuli Seppänen | 2025-02-27 10:07:23 | 1 | # CVE-2023-6247: PKCS!#7 parser in OpenVPN 3 Core Library can result in NULL-dereference |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| 3 | The PKCS!#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing. |
|||
| 4 | ||||
| 4d0c88 | Samuli Seppänen | 2025-02-27 10:07:23 | 5 | This is resolved in OpenVPN 3 Core Library version 3.8.4. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 6 | |
| 4d0c88 | Samuli Seppänen | 2025-02-27 10:07:23 | 7 | ### Note |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 8 | |
| 4d0c88 | Samuli Seppänen | 2025-02-27 10:07:23 | 9 | The code paths this issue is related to is never used for OpenVPN connections. The related code is only used in some of the AWS API support functionality present in the library. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 10 | |
| 4d0c88 | Samuli Seppänen | 2025-02-27 10:07:23 | 11 | ### References |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 12 | |
| 4d0c88 | Samuli Seppänen | 2025-02-27 10:07:23 | 13 | * MITRE CVE Record: https://www.cve.org/CVERecord?id=CVE-2023-6247 |
| 14 | * OpenVPN 3 Core commit: https://github.com/OpenVPN/openvpn3/commit/afdfe1bb3f4c54e8794 |
|||
| 15 | * Reported by: Bahaa Naamneh |
