CVE-2005-3409

UnknownEPSS 2.50%

Last modified

CVE-2005-3409 is a vulnerability of currently unknown severity. OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.. EPSS estimates a 2.50% chance of exploitation in the next 30 days.

Description

OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.

Metrics

EPSS Probability
2.50%

82.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
OpenvpnOpenvpn2.0
OpenvpnOpenvpn2.0.1_rc1
OpenvpnOpenvpn2.0.1_rc2
OpenvpnOpenvpn2.0.1_rc3
OpenvpnOpenvpn2.0.1_rc4
OpenvpnOpenvpn2.0.1_rc5
OpenvpnOpenvpn2.0.1_rc6
OpenvpnOpenvpn2.0.1_rc7
OpenvpnOpenvpn2.0.2_rc1
OpenvpnOpenvpn2.0.3_rc1
OpenvpnOpenvpn2.0_beta1
OpenvpnOpenvpn2.0_beta2
OpenvpnOpenvpn2.0_beta3
OpenvpnOpenvpn2.0_beta4
OpenvpnOpenvpn2.0_beta5
OpenvpnOpenvpn2.0_beta6
OpenvpnOpenvpn2.0_beta7
OpenvpnOpenvpn2.0_beta8
OpenvpnOpenvpn2.0_beta9
OpenvpnOpenvpn2.0_beta10
OpenvpnOpenvpn2.0_beta11
OpenvpnOpenvpn2.0_beta12
OpenvpnOpenvpn2.0_beta13
OpenvpnOpenvpn2.0_beta15
OpenvpnOpenvpn2.0_beta16
OpenvpnOpenvpn2.0_beta17
OpenvpnOpenvpn2.0_beta18
OpenvpnOpenvpn2.0_beta19
OpenvpnOpenvpn2.0_beta20
OpenvpnOpenvpn2.0_beta28
OpenvpnOpenvpn2.0_rc1
OpenvpnOpenvpn2.0_rc2
OpenvpnOpenvpn2.0_rc3
OpenvpnOpenvpn2.0_rc4
OpenvpnOpenvpn2.0_rc5
OpenvpnOpenvpn2.0_rc6
OpenvpnOpenvpn2.0_rc7
OpenvpnOpenvpn2.0_rc8
OpenvpnOpenvpn2.0_rc9
OpenvpnOpenvpn2.0_rc10
OpenvpnOpenvpn2.0_rc11
OpenvpnOpenvpn2.0_rc12
OpenvpnOpenvpn2.0_rc13
OpenvpnOpenvpn2.0_rc14
OpenvpnOpenvpn2.0_rc15
OpenvpnOpenvpn2.0_rc16
OpenvpnOpenvpn2.0_rc17
OpenvpnOpenvpn2.0_rc18
OpenvpnOpenvpn2.0_rc19
OpenvpnOpenvpn2.0_rc20

Showing 50 of 78 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2005-3409?
OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.
How severe is CVE-2005-3409?
Severity scoring for CVE-2005-3409 is pending analysis. The EPSS model estimates a 2.50% probability of exploitation in the next 30 days.
How do I fix CVE-2005-3409?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2005-3409?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST