CVE-2023-6247: PKCS!#7 Parser in OpenVPN 3 Core Library Can Result in NULL-Dereference

The PKCS!#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing.

This issue has been resolved in OpenVPN 3 Core Library version 3.8.4.

Note

The code paths related to this issue are never used for OpenVPN connections. The affected code is only used in some of the AWS API support functionality present in the library.

References

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9