Blame
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 1 | # Introduction |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 3 | In !May/June 2017 Guido Vranken threw a fuzzer at OpenVPN 2.4.2. In the process he found several vulnerabilities and reported them to the OpenVPN project. The OpenVPN Git branches were patches as follows: |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 5 | * master: 7 patches |
| 6 | * release/2.4: 7 patches |
|||
| 7 | * release/2.3: 5 patches (no mbedtls patches) |
|||
| 8 | * release/2.2: 1 patch (only the NTLM patch) |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 9 | |
| 10 | The first releases to have these fixes are OpenVPN 2.4.3 and 2.3.17. These releases also include a bunch of fixes not related to Guido's findings. |
|||
| 11 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 12 | **PLEASE NOTE** We have noticed that the Cloudflare front have been serving out the wrong contents for several users. See [this page](/release-packages-2.4.3-2.3.17) for more information. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 13 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 14 | # Vulnerabilities |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 15 | |
| 16 | ## Remotely-triggerable ASSERT() on malformed IPv6 packet |
|||
| 17 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 18 | This vulnerability is of serious nature: it can be used to remotely shutdown an openvpn server or client if IPv6 and --mssfix are enabled and the IPv6 networks used inside the VPN are known. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 19 | |
| 20 | This issue was found by Guido Vranken and has been assigned CVE-2017-7508. It has been fixed in commit "Fix remotely-triggerable ASSERT() on malformed IPv6 packet": |
|||
| 21 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 22 | * master: c3f47077a7 |
| 23 | * release/2.4: ed28cde3d8 |
|||
| 24 | * release/2.3: fc61d1bda1 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 25 | |
| 26 | ## Pre-authentication remote crash/information disclosure for clients |
|||
| 27 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 28 | If clients use a HTTP proxy with NTLM authentication (i.e. "--http-proxy <server> <port> [<authfile>|'auto'|'auto-nct'] ntlm2"), |
| 29 | a man-in-the-middle attacker between the client and the proxy can cause the client to crash or disclose at most 96 bytes of stack memory. The disclosed stack memory is likely to contain the proxy password. |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 30 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 31 | If the proxy password is not reused, this is unlikely to compromise the security of the OpenVPN tunnel itself. Clients who do not use the --http-proxy option with ntlm2 authentication are not affected. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 32 | |
| 33 | This issue has been assigned CVE-2017-7520. It has been fixed in commit "Prevent two kinds of stack buffer OOB reads and a crash for invalid input data": |
|||
| 34 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 35 | * master: 7718c8984f |
| 36 | * release/2.4: 043fe32787 |
|||
| 37 | * release/2.3: f38a4a1059 |
|||
| 38 | * release/2.2: 4bec9d25d5 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 39 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 40 | ## Potential double-free in --x509-alt-username |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 41 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 42 | OpenVPN did not check the return value of ASN1_STRING_to_UTF8() in extract_x509_extension(). Ignoring such a failure could result in buf being free'd twice. An error in ASN1_STRING_to_UTF8() can be caused remotely if the peer can make the local process run out of memory. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 43 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 44 | The problem can only be triggered for configurations that use the --x509-alt-username option with an x509 extension (i.e. the option parameter starts with "ext:"). Extensive testing by Guido Vranken gives confidence that this function is very unlikely to fail in real-world usage (using subjectAltName or issuerAltName extensions) for other reasons than memory exhaustion. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 45 | |
| 46 | This issue was found by Guido Vranken and has been assigned CVE-2017-7521. It has been fixed in commit "Fix potential double-free in --x509-alt-username (CVE-2017-7521)": |
|||
| 47 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 48 | * master: cb4e35ece4 |
| 49 | * release/2.4: 0400840671 |
|||
| 50 | * release/2.3: 1dde0cd6e5 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 51 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 52 | ## Remote-triggerable memory leaks |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 53 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 54 | Several of our OpenSSL-specific certificate-parsing code paths did not always clear all allocated memory. Since a client can cause a few bytes of memory to be leaked for each connection attempt, a client can cause a server to run out of memory and thereby kill the server. That makes this a (quite inefficient) DoS attack. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 55 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 56 | In particular when using the --x509-alt-username option on openssl builds with an extension (argument prefixed with "ext:", e.g. "ext:subjectAltName"), the code would not free all allocated memory. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 57 | |
| 58 | This issue was found by Guido Vranken and has been assigned CVE-2017-7521. It has been fixed in commit "Fix remote-triggerable memory leaks (CVE-2017-7521)": |
|||
| 59 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 60 | * master: 2d032c7fcd |
| 61 | * release/2.4: 2341f71619 |
|||
| 62 | * release/2.3: 84e1775961 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 63 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 64 | ## Post-authentication remote DoS when using the --x509-track option |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 65 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 66 | asn1_buf_to_c_string() returned a literal string if the input ASN.1 string contained a NUL character, while the caller expects a mutable string. The caller will attempt to change this string, which allows a client to crash a server by sending a certificate with an embedded NUL character. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 67 | |
| 68 | The other way around is not interesting, as servers are allowed to stop a client by design. |
|||
| 69 | ||||
| 70 | Impact analysis: |
|||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 71 | * applies to mbedtls builds only |
| 72 | * introduced in 2.4 (so 2.3 is not affected) |
|||
| 73 | * can only be exploited if the --x509-track option is used |
|||
| 74 | * requires the CA to sign a certificate with an embedded NUL in the |
|||
| 75 | certificate subject |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 76 | |
| 77 | This issue was found by Guido Vranken and has been assigned CVE-2017-7522. It has been fixed in commit "mbedtls: fix --x509-track post-authentication remote DoS (CVE-2017-7522)": |
|||
| 78 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 79 | * master: 426392940c |
| 80 | * release/2.4: 67edada0be |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 81 | |
| 82 | ## Null-pointer dereference in establish_http_proxy_passthru() |
|||
| 83 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 84 | Client could crashes if the peer did not specify the 'realm' and/or 'nonce' values. These pointers are dereferenced in DigestCalcHA1() and DigestCalcResponse(); hence, if not set, a null-pointer dereference would occur. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 85 | |
| 86 | This problem has been fixed in commit "Fix a null-pointer dereference in establish_http_proxy_passthru()": |
|||
| 87 | ||||
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 88 | * master: 14865773ad |
| 89 | * release/2.4: bf547b8ac7 |
|||
| 90 | * release/2.3: 479b6d13d8 |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 91 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 92 | # Issues with little to no practical security impact |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 93 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 94 | Many of the findings were such that they don't have a practical security impact. Nevertheless they are bugs and were fixed in the following Git commits: |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 95 | |
| 84c021 | Samuli Seppänen | 2025-02-27 10:36:58 | 96 | * Restrict --x509-alt-username extension types |
| 97 | * Fix potential 1-byte overread in TCP option parsing |
|||
| 98 | * Fix mbedtls fingerprint calculation |
|||
| 99 | * openssl: fix overflow check for long --tls-cipher option |
|||
| 100 | * Ensure option array p[] is always NULL-terminated |
|||
| 101 | * Pass correct buffer size to GetModuleFileNameW() (Quarkslabs finding 5.6) |
