Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who can control the challenge/response password field to pass a string with more than 14 colons into this field and cause a buffer overflow.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 04 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-125 |
Fri, 25 Oct 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-121 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-04T17:54:47.731Z
Reserved: 2024-03-11T00:00:00.000Z
Link: CVE-2024-28820
Updated: 2024-08-02T00:56:58.128Z
Status : Awaiting Analysis
Published: 2024-06-27T16:15:10.950
Modified: 2024-11-21T09:06:59.737
Link: CVE-2024-28820
No data.
OpenCVE Enrichment
No data.
Weaknesses