← Voltar para CVEs
CVE-2005-2531
N/ADescricao
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado8/24/2005
Ultima modificacao4/16/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
openvpn:openvpn
Referencias
http://openvpn.net/changelog.html(cve@mitre.org)
http://secunia.com/advisories/16463(cve@mitre.org)
http://secunia.com/advisories/17103(cve@mitre.org)
http://www.debian.org/security/2005/dsa-851(cve@mitre.org)
http://www.securityfocus.com/bid/14605(cve@mitre.org)
http://openvpn.net/changelog.html(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/16463(af854a3a-2127-422b-91ae-364da2661108)
http://secunia.com/advisories/17103(af854a3a-2127-422b-91ae-364da2661108)
http://www.debian.org/security/2005/dsa-851(af854a3a-2127-422b-91ae-364da2661108)
http://www.mandriva.com/security/advisories?name=MDKSA-2005:145(af854a3a-2127-422b-91ae-364da2661108)
http://www.novell.com/linux/security/advisories/2005_20_sr.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/14605(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.