Blame
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 1 | # CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation |
| 2 | ||||
| 966a34 | Samuli Seppänen | 2025-02-27 10:16:07 | 3 | interactive.c: Fix potential stack overflow issue |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| 966a34 | Samuli Seppänen | 2025-02-27 10:16:07 | 5 | When reading message from the pipe, we first peek the pipe to get the size of the message waiting to be read and then read the message. A compromised OpenVPN process could send an excessively large message, which would result in a stack-allocated message buffer overflow. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 6 | |
| 7 | To address this, we terminate the misbehaving process if the peeked message size exceeds the maximum allowable size. |
|||
| 8 | ||||
| 966a34 | Samuli Seppänen | 2025-02-27 10:16:07 | 9 | ### References |
| 10 | * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html |
|||
| bc9e4a | novaflash | 2025-07-02 16:29:49 | 11 | * CVE record: https://www.cve.org/CVERecord?id=CVE-2024-27459 |
| 966a34 | Samuli Seppänen | 2025-02-27 10:16:07 | 12 | * Reported by: Vladimir Tokarev <vtokarev@microsoft.com> |
