# CVE-2017-12166: Out of Bounds Write in Key-Method 1
+
# CVE-2017-12166: out of bounds write in key-method 1
-
OpenVPN versions 2.4.4 and 2.3.18 resolve an out-of-bounds write vulnerability discovered by Guido Vranken.
+
OpenVPN 2.4.4 and 2.3.18 resolve an out-of-bounds write vulnerability, that was discovered by Guide Vranken.
-
This vulnerability is only exposed when `key-method 1` is explicitly selected in the config or on the command line. This option is available solely for backward compatibility with OpenVPN 1.x and has not been the default since the release of OpenVPN 2.0 in 2005. It will be completely removed in OpenVPN 2.5.
+
This vulnerability is only exposed when explicitly selecting `key-method 1` in the config (or on the command line). This option is only available for backward compatibility with OpenVPN 1.x, and has no longer been the default since the release of OpenVPN 2.0 in 2005. It will be removed all together in OpenVPN 2.5.
-
## Commit Message
+
Commit message:
```
Fix bounds check in read_key()
-
The bounds check in read_key() was performed after using the value,
-
instead of before. If 'key-method 1' is used, this allowed an attacker to send a
+
The bounds check in read_key() was performed after using the value, instead
+
of before. If 'key-method 1' is used, this allowed an attacker to send a
malformed packet to trigger a stack buffer overflow.
Fix this by moving the input validation to before the writes.
@@ 29,23 29,12 @@
Signed-off-by: David Sommerseth <davids@openvpn.net>
```
-
## Mail Thread Reporting the Vulnerability
+
[Mail thread reporting the vulnerability](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg15492.html)
-
[OpenVPN-devel mailing list thread](https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg15492.html)