CVE-2017-12166: Out of Bounds Write in Key-Method 1
OpenVPN versions 2.4.4 and 2.3.18 resolve an out-of-bounds write vulnerability discovered by Guido Vranken.
This vulnerability is only exposed when key-method 1 is explicitly selected in the config or on the command line. This option is available solely for backward compatibility with OpenVPN 1.x and has not been the default since the release of OpenVPN 2.0 in 2005. It will be completely removed in OpenVPN 2.5.
Commit Message
Fix bounds check in read_key() The bounds check in read_key() was performed after using the value, instead of before. If 'key-method 1' is used, this allowed an attacker to send a malformed packet to trigger a stack buffer overflow. Fix this by moving the input validation to before the writes. Note that 'key-method 1' has been replaced by 'key method 2' as the default in OpenVPN 2.0 (released on 2005-04-17), and explicitly deprecated in 2.4 and marked for removal in 2.5. This should limit the amount of users impacted by this issue. CVE: 2017-12166 Signed-off-by: Steffan Karger <steffan.karger@fox-it.com> Acked-by: Gert Doering <gert@greenie.muc.de> Acked-by: David Sommerseth <davids@openvpn.net> Message-Id: <80690690-67ac-3320-1891-9fecedc6a1fa@fox-it.com> URL: https://www.mail-archive.com/search?l=mid&q=80690690-67ac-3320-1891-9fecedc6a1fa@fox-it.com Signed-off-by: David Sommerseth <davids@openvpn.net>
Mail Thread Reporting the Vulnerability
OpenVPN-devel mailing list thread
Fixes in Tree
Master Branch
- commit 3b1a61e9fb27213c46f76312f4065816bee8ed01
Release/2.4 Branch
- commit c7e259160b28e94e4ea7f0ef767f8134283af255
Release/2.3 Branch
- commit fce34375295151f548a26c2d0eb30141e427c81a
Release/2.2 Branch
- commit a9f5c744d6b09f2495ca48d2c926efd3a4b981e6
Release/2.1 Branch
- commit c560f95e7038daa3a1b5a08b69b85fb68d4eeef3
