OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "2.3.14"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.4.1"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.0-alpha2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.0-beta1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.0-beta2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.0-rc1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.0-rc2"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-7479.json"