OpenVPN read_key Stack Based Buffer Overflow (CVE-2017-12166)

A stack-based buffer overflow vulnerability exists in OpenVPN. The vulnerability is due to a lack of bounds check on the length of key and HMAC lengths provided by the client. A remote, unauthenticated attacker can exploit this vulnerability by sending a crafted P_CONTROL_V1 message to a target server.

from Check Point Update Services Advisories http://ift.tt/2hpd2Xl

No comments:

Post a Comment

Hackers Use LinkedIn Messages to Spread RAT Malware Through DLL Sideloading

Cybersecurity researchers have uncovered a new phishing campaign that exploits social media private messages to propagate malicious payloads...