CVE-2005-2532 (CNNVD-200508-273)
中文标题:
OpenVPN 多个拒绝服务漏洞
英文标题:
OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decryp...
漏洞描述
中文描述:
OpenVPN是美国OpenVPN公司的一个用于创建虚拟专用网络(VPN)加密通道的软件包,它使用OpenSSL库来加密数据与控制信息,并允许创建的VPN使用公开密钥、电子证书或者用户名/密码来进行身份验证。 OpenVPN中存在多个拒绝服务漏洞,具体如下: 如果到服务器的客户端连接证书认证失败的话,就无法刷新OpenSSL错误队列,导致服务器上另一个无关的客户端例程看到错误并响应该错误,这样无关的客户端就会断开连接。(CAN-2005-2531) 如果无法在服务器上解密客户端发送的报文的话,就无法刷新OpenSSL错误队列,导致服务器上另一个无关的客户端例程看到错误并响应该错误,这样无关的客户端就会断开连接。(CAN-2005-2532) 理论上"dev tap"以太网桥接模式中的恶意客户端可以用看起来好像来自很多不同MAC地址的报文充斥服务器,导致OpenVPN进程在扩展其内部路由表时耗尽系统虚拟内存。(CAN-2005-2533) 如果服务器中没有启用--duplicate-cn,则在两个或多个客户端机器同时通过TCP使用相同的客户端证书试图连接到服务器时,竞争条件会导致服务器"Assertion failed at mtcp.c:411"崩溃。(CAN-2005-2534)
英文描述:
OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| openvpn | openvpn | 2.0 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc1 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc1:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc2 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc2:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc3 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc3:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc4 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc4:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc5 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc5:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc6 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc6:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0.1_rc7 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0.1_rc7:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta1 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta1:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta2 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta2:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta3 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta3:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta4 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta4:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta5 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta5:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta6 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta6:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta7 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta7:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta8 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta8:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta9 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta9:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta10 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta10:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta11 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta11:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta12 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta12:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta13 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta13:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta15 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta15:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta16 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta16:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta17 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta17:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta18 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta18:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta19 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta19:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta20 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta20:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_beta28 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_beta28:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc1 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc1:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc2 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc2:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc3 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc3:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc4 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc4:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc5 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc5:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc6 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc6:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc7 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc7:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc8 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc8:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc9 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc9:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc10 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc10:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc11 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc11:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc12 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc12:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc13 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc13:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc14 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc14:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc15 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc15:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc16 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc16:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc17 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc17:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc18 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc18:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc19 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc19:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc20 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc20:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_rc21 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_rc21:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test1 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test1:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test2 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test2:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test3 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test3:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test5 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test5:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test6 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test6:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test7 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test7:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test8 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test8:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test9 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test9:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test10 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test10:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test11 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test11:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test12 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test12:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test14 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test14:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test15 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test15:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test16 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test16:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test17 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test17:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test18 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test18:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test19 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test19:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test20 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test20:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test21 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test21:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test22 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test22:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test23 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test23:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test24 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test24:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test26 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test26:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test27 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test27:*:*:*:*:*:*:*
|
| openvpn | openvpn | 2.0_test29 | - | - |
cpe:2.3:a:openvpn:openvpn:2.0_test29:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:L/Au:N/C:N/I:N/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2005-2532 |
2025-11-11 15:17:35 | 2025-11-11 07:32:27 |
| NVD | nvd_CVE-2005-2532 |
2025-11-11 14:51:19 | 2025-11-11 07:41:13 |
| CNNVD | cnnvd_CNNVD-200508-273 |
2025-11-11 15:08:48 | 2025-11-11 07:49:00 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200508-273
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 5.0
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:N/I:N/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 74
- data_sources: ['cve'] -> ['cve', 'nvd']