Blame

84c021 Samuli Seppänen 2025-02-27 10:36:58 1
# Introduction 
c4f02d Samuli Seppänen 2025-01-29 08:37:37 2
84c021 Samuli Seppänen 2025-02-27 10:36:58 3
In !May/June 2017 Guido Vranken threw a fuzzer at OpenVPN 2.4.2. In the process he found several vulnerabilities and reported them to the OpenVPN project. The OpenVPN Git branches were patches as follows:
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
84c021 Samuli Seppänen 2025-02-27 10:36:58 5
* master: 7 patches
6
* release/2.4: 7 patches
7
* release/2.3: 5 patches (no mbedtls patches)
8
* release/2.2: 1 patch (only the NTLM patch)
c4f02d Samuli Seppänen 2025-01-29 08:37:37 9
10
The first releases to have these fixes are OpenVPN 2.4.3 and 2.3.17. These releases also include a bunch of fixes not related to Guido's findings.
11
84c021 Samuli Seppänen 2025-02-27 10:36:58 12
**PLEASE NOTE** We have noticed that the Cloudflare front have been serving out the wrong contents for several users. See [this page](/release-packages-2.4.3-2.3.17) for more information.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 13
84c021 Samuli Seppänen 2025-02-27 10:36:58 14
# Vulnerabilities
c4f02d Samuli Seppänen 2025-01-29 08:37:37 15
16
## Remotely-triggerable ASSERT() on malformed IPv6 packet
17
84c021 Samuli Seppänen 2025-02-27 10:36:58 18
This vulnerability is of serious nature: it can be used to remotely shutdown an openvpn server or client if IPv6 and --mssfix are enabled and the IPv6 networks used inside the VPN are known.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 19
20
This issue was found by Guido Vranken and has been assigned CVE-2017-7508. It has been fixed in commit "Fix remotely-triggerable ASSERT() on malformed IPv6 packet":
21
84c021 Samuli Seppänen 2025-02-27 10:36:58 22
* master: c3f47077a7
23
* release/2.4: ed28cde3d8
24
* release/2.3: fc61d1bda1
c4f02d Samuli Seppänen 2025-01-29 08:37:37 25
26
## Pre-authentication remote crash/information disclosure for clients
27
84c021 Samuli Seppänen 2025-02-27 10:36:58 28
If clients use a HTTP proxy with NTLM authentication (i.e. "--http-proxy <server> <port> [<authfile>|'auto'|'auto-nct'] ntlm2"),
29
a man-in-the-middle attacker between the client and the proxy can cause the client to crash or disclose at most 96 bytes of stack memory. The disclosed stack memory is likely to contain the proxy password.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 30
84c021 Samuli Seppänen 2025-02-27 10:36:58 31
If the proxy password is not reused, this is unlikely to compromise the security of the OpenVPN tunnel itself. Clients who do not use the --http-proxy option with ntlm2 authentication are not affected.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 32
33
This issue has been assigned CVE-2017-7520. It has been fixed in commit "Prevent two kinds of stack buffer OOB reads and a crash for invalid input data":
34
84c021 Samuli Seppänen 2025-02-27 10:36:58 35
* master: 7718c8984f
36
* release/2.4: 043fe32787
37
* release/2.3: f38a4a1059
38
* release/2.2: 4bec9d25d5
c4f02d Samuli Seppänen 2025-01-29 08:37:37 39
84c021 Samuli Seppänen 2025-02-27 10:36:58 40
## Potential double-free in --x509-alt-username
c4f02d Samuli Seppänen 2025-01-29 08:37:37 41
84c021 Samuli Seppänen 2025-02-27 10:36:58 42
OpenVPN did not check the return value of ASN1_STRING_to_UTF8() in extract_x509_extension(). Ignoring such a failure could result in buf being free'd twice. An error in ASN1_STRING_to_UTF8() can be caused remotely if the peer can make the local process run out of memory.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 43
84c021 Samuli Seppänen 2025-02-27 10:36:58 44
The problem can only be triggered for configurations that use the --x509-alt-username option with an x509 extension (i.e. the option parameter starts with "ext:"). Extensive testing by Guido Vranken gives confidence that this function is very unlikely to fail in real-world usage (using subjectAltName or issuerAltName extensions) for other reasons than memory exhaustion.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 45
46
This issue was found by Guido Vranken and has been assigned CVE-2017-7521. It has been fixed in commit "Fix potential double-free in --x509-alt-username (CVE-2017-7521)":
47
84c021 Samuli Seppänen 2025-02-27 10:36:58 48
* master: cb4e35ece4
49
* release/2.4: 0400840671
50
* release/2.3: 1dde0cd6e5
c4f02d Samuli Seppänen 2025-01-29 08:37:37 51
84c021 Samuli Seppänen 2025-02-27 10:36:58 52
## Remote-triggerable memory leaks
c4f02d Samuli Seppänen 2025-01-29 08:37:37 53
84c021 Samuli Seppänen 2025-02-27 10:36:58 54
Several of our OpenSSL-specific certificate-parsing code paths did not always clear all allocated memory. Since a client can cause a few bytes of memory to be leaked for each connection attempt, a client can cause a server to run out of memory and thereby kill the server. That makes this a (quite inefficient) DoS attack.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 55
84c021 Samuli Seppänen 2025-02-27 10:36:58 56
In particular when using the --x509-alt-username option on openssl builds with an extension (argument prefixed with "ext:", e.g. "ext:subjectAltName"), the code would not free all allocated memory.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 57
58
This issue was found by Guido Vranken and has been assigned CVE-2017-7521. It has been fixed in commit "Fix remote-triggerable memory leaks (CVE-2017-7521)":
59
84c021 Samuli Seppänen 2025-02-27 10:36:58 60
* master: 2d032c7fcd
61
* release/2.4: 2341f71619
62
* release/2.3: 84e1775961
c4f02d Samuli Seppänen 2025-01-29 08:37:37 63
84c021 Samuli Seppänen 2025-02-27 10:36:58 64
## Post-authentication remote DoS when using the --x509-track option
c4f02d Samuli Seppänen 2025-01-29 08:37:37 65
84c021 Samuli Seppänen 2025-02-27 10:36:58 66
asn1_buf_to_c_string() returned a literal string if the input ASN.1 string contained a NUL character, while the caller expects a mutable string. The caller will attempt to change this string, which allows a client to crash a server by sending a certificate with an embedded NUL character.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 67
68
The other way around is not interesting, as servers are allowed to stop a client by design.
69
70
Impact analysis:
84c021 Samuli Seppänen 2025-02-27 10:36:58 71
* applies to mbedtls builds only
72
* introduced in 2.4 (so 2.3 is not affected)
73
* can only be exploited if the --x509-track option is used
74
* requires the CA to sign a certificate with an embedded NUL in the
75
certificate subject
c4f02d Samuli Seppänen 2025-01-29 08:37:37 76
77
This issue was found by Guido Vranken and has been assigned CVE-2017-7522. It has been fixed in commit "mbedtls: fix --x509-track post-authentication remote DoS (CVE-2017-7522)":
78
84c021 Samuli Seppänen 2025-02-27 10:36:58 79
* master: 426392940c
80
* release/2.4: 67edada0be
c4f02d Samuli Seppänen 2025-01-29 08:37:37 81
82
## Null-pointer dereference in establish_http_proxy_passthru()
83
84c021 Samuli Seppänen 2025-02-27 10:36:58 84
Client could crashes if the peer did not specify the 'realm' and/or 'nonce' values. These pointers are dereferenced in DigestCalcHA1() and DigestCalcResponse(); hence, if not set, a null-pointer dereference would occur.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 85
86
This problem has been fixed in commit "Fix a null-pointer dereference in establish_http_proxy_passthru()":
87
84c021 Samuli Seppänen 2025-02-27 10:36:58 88
* master: 14865773ad
89
* release/2.4: bf547b8ac7
90
* release/2.3: 479b6d13d8
c4f02d Samuli Seppänen 2025-01-29 08:37:37 91
84c021 Samuli Seppänen 2025-02-27 10:36:58 92
# Issues with little to no practical security impact
c4f02d Samuli Seppänen 2025-01-29 08:37:37 93
84c021 Samuli Seppänen 2025-02-27 10:36:58 94
Many of the findings were such that they don't have a practical security impact. Nevertheless they are bugs and were fixed in the following Git commits:
c4f02d Samuli Seppänen 2025-01-29 08:37:37 95
84c021 Samuli Seppänen 2025-02-27 10:36:58 96
* Restrict --x509-alt-username extension types
97
* Fix potential 1-byte overread in TCP option parsing
98
* Fix mbedtls fingerprint calculation
99
* openssl: fix overflow check for long --tls-cipher option
100
* Ensure option array p[] is always NULL-terminated
101
* Pass correct buffer size to GetModuleFileNameW() (Quarkslabs finding 5.6)