mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
72 lines
2.4 KiB
JSON
72 lines
2.4 KiB
JSON
{
|
|
"id": "CVE-2024-1305",
|
|
"sourceIdentifier": "security@openvpn.net",
|
|
"published": "2024-07-08T18:15:07.150",
|
|
"lastModified": "2024-11-21T08:50:16.840",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "tap-windows6 driver version 9.26 and earlier does not properly \ncheck the size data of incomming write operations which an attacker can \nuse to overflow memory buffers, resulting in a bug check and potentially\n arbitrary code execution in kernel space"
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "La versi\u00f3n 9.26 y anteriores del controlador tap-windows6 no verifica correctamente los datos de tama\u00f1o de las operaciones de escritura entrantes que un atacante puede usar para desbordar los b\u00fafers de memoria, lo que resulta en una verificaci\u00f3n de errores y la ejecuci\u00f3n de c\u00f3digo potencialmente arbitrario en el espacio del kernel."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"baseScore": 9.8,
|
|
"baseSeverity": "CRITICAL",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "HIGH"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 5.9
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "security@openvpn.net",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-190"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-1305",
|
|
"source": "security@openvpn.net"
|
|
},
|
|
{
|
|
"url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html",
|
|
"source": "security@openvpn.net"
|
|
},
|
|
{
|
|
"url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-1305",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
},
|
|
{
|
|
"url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html",
|
|
"source": "af854a3a-2127-422b-91ae-364da2661108"
|
|
}
|
|
]
|
|
} |