CVE-2017-7521

Description

From CVE.org

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extract_x509_extension().

Statement

This issue does not affect Red Hat Enterprise Linux 5, 6 and 7 as OpenVPN is not included in any of Red Hat's supported products.

Acknowledgements

Red Hat would like to thank the OpenVPN project for reporting this issue. Upstream acknowledges Guido Vranken as the original reporter.

Frequently Asked Questions

Want to get errata notifications? Sign up here.