CVE-2017-12166: Out of Bounds Write in Key-Method 1

OpenVPN versions 2.4.4 and 2.3.18 resolve an out-of-bounds write vulnerability discovered by Guido Vranken.

This vulnerability is only exposed when key-method 1 is explicitly selected in the config or on the command line. This option is available solely for backward compatibility with OpenVPN 1.x and has not been the default since the release of OpenVPN 2.0 in 2005. It will be completely removed in OpenVPN 2.5.

Commit Message

Fix bounds check in read_key()

The bounds check in read_key() was performed after using the value,
instead of before. If 'key-method 1' is used, this allowed an attacker to send a
malformed packet to trigger a stack buffer overflow.

Fix this by moving the input validation to before the writes.

Note that 'key-method 1' has been replaced by 'key method 2' as the default
in OpenVPN 2.0 (released on 2005-04-17), and explicitly deprecated in 2.4
and marked for removal in 2.5. This should limit the amount of users
impacted by this issue.

CVE: 2017-12166
Signed-off-by: Steffan Karger <steffan.karger@fox-it.com>
Acked-by: Gert Doering <gert@greenie.muc.de>
Acked-by: David Sommerseth <davids@openvpn.net>
Message-Id: <80690690-67ac-3320-1891-9fecedc6a1fa@fox-it.com>
URL: https://www.mail-archive.com/search?l=mid&q=80690690-67ac-3320-1891-9fecedc6a1fa@fox-it.com
Signed-off-by: David Sommerseth <davids@openvpn.net>

Mail Thread Reporting the Vulnerability

OpenVPN-devel mailing list thread

Fixes in Tree

  • Master Branch

    • commit 3b1a61e9fb27213c46f76312f4065816bee8ed01
  • Release/2.4 Branch

    • commit c7e259160b28e94e4ea7f0ef767f8134283af255
  • Release/2.3 Branch

    • commit fce34375295151f548a26c2d0eb30141e427c81a
  • Release/2.2 Branch

    • commit a9f5c744d6b09f2495ca48d2c926efd3a4b981e6
  • Release/2.1 Branch

    • commit c560f95e7038daa3a1b5a08b69b85fb68d4eeef3
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9