Bugzilla – Bug 1220612
VUL-0: CVE-2023-6247: openvpn: null pointer when PKCS7 is invalid
Last modified: 2024-02-29 08:47:18 UTC
The PKCS#7 parser in OpenVPN 3 Core Library versions through 3.8.3 did not properly validate the parsed data, which would result in the application crashing. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-6247 https://www.cve.org/CVERecord?id=CVE-2023-6247 https://community.openvpn.net/openvpn/wiki/CVE-2023-6247
pkcs7 is not supported in openvpn 2. None of the codestream is affected. Closing