Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-46849.json"
[
{
"events": [
{
"introduced": "2.11.0"
},
{
"last_affected": "2.11.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.12.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.12.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "12.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "39"
}
]
}
]