wiki:CVE-2023-46849

Version 1 (modified by novaflash, 10 months ago) (diff)

--

CVE-2023-46849: Use of --fragment option can lead to a division by zero error which can be fatal

OpenVPN 2.6 from v2.6.0 up to and including v.2.6.6 incorrectly restore "--fragment" configuration in some circumstances. This can lead to a division by zero error. On platforms where division by zero is fatal, this will cause OpenVPN to crash.

This issue is resolved in OpenVPN 2.6.7.

MITRE entry: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46849