What the vulnerability does

01Description

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.

Key dates

02Disclosure timeline

July 8, 2024 CVE published
August 23, 2024 Record updated