CVE-2005-2531
published 2005-08-24CVE-2005-2531: OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails…
PriorityP423medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.97%
78.1th percentile
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvpn | < openvpn 2.0.2-1 (bookworm) | openvpn 2.0.2-1 (bookworm) |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
| openvpn | openvpn | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h572-qc5h-fc64: OpenVPN before 2
ghsa_unreviewed·2022-05-01
CVE-2005-2531 [MEDIUM] GHSA-h572-qc5h-fc64: OpenVPN before 2
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
OSV
CVE-2005-2531: OpenVPN before 2
osv·2005-08-24·CVSS 5.0
CVE-2005-2531 [MEDIUM] CVE-2005-2531: OpenVPN before 2
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
Debian
CVE-2005-2531: openvpn - OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication,...
vendor_debian·2005·CVSS 5.0
CVE-2005-2531 [MEDIUM] CVE-2005-2531: openvpn - OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication,...
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.
Scope: local
bookworm: resolved (fixed in 2.0.2-1)
bullseye: resolved (fixed in 2.0.2-1)
forky: resolved (fixed in 2.0.2-1)
sid: resolved (fixed in 2.0.2-1)
trixie: resolved (fixed in 2.0.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://openvpn.net/changelog.htmlhttp://secunia.com/advisories/16463http://secunia.com/advisories/17103http://www.debian.org/security/2005/dsa-851http://www.mandriva.com/security/advisories?name=MDKSA-2005:145http://www.novell.com/linux/security/advisories/2005_20_sr.htmlhttp://www.securityfocus.com/bid/14605http://openvpn.net/changelog.htmlhttp://secunia.com/advisories/16463http://secunia.com/advisories/17103http://www.debian.org/security/2005/dsa-851http://www.mandriva.com/security/advisories?name=MDKSA-2005:145http://www.novell.com/linux/security/advisories/2005_20_sr.htmlhttp://www.securityfocus.com/bid/14605
2005-08-24
Published