Blame
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 1 | # OpenSSL vulnerability - Heartbleed |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 3 | A vulnerability in OpenSSL, nicknamed Heartbleed, was published in April 2014 (ref1). OpenVPN uses OpenSSL as its crypto library by default and thus is affected too. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| 5 | ## What does this mean? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 6 | An attacker can trick OpenSSL into returning a part of your program memory. That memory contains your session keys (the keys used to encrypt your data), and usually your master secret key too. If your OpenVPN is or has been vulnerable to heartbleed you should consider your keys, and the traffic over the VPN tunnel, compromised. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 7 | |
| 8 | ## Am I affected too? |
|||
| 9 | Your OpenVPN is affected when your OpenVPN is linked against OpenSSL, versions 1.0.1 through 1.0.1f. |
|||
| 10 | ||||
| 11 | ## Has OpenVPN been successfully exploited? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 12 | |
| 13 | This is very likely. On 16th April 2014 [a mail](http://thread.gmane.org/gmane.network.openvpn.user/34784) was sent to openvpn-user list by Fredrik Strömberg, who claimed the following: |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 14 | |
| 15 | ``` |
|||
| 16 | We have successfully extracted private key material multiple times |
|||
| 17 | from an OpenVPN server by exploiting the Heartbleed Bug. The material |
|||
| 18 | we found was sufficient for us to recreate the private key and |
|||
| 19 | impersonate the server. |
|||
| 20 | ||||
| 21 | --- snip --- |
|||
| 22 | ||||
| 23 | ... you should assume that other teams with more nefarious purposes |
|||
| 24 | have already created weaponized exploits for OpenVPN. Just to be |
|||
| 25 | clear, we don't intend to use this exploit ourselves. We merely |
|||
| 26 | developed it to examine the practical impact on OpenVPN as part of |
|||
| 27 | our incident investigation. |
|||
| 28 | ``` |
|||
| 29 | ||||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 30 | More details in the [http://thread.gmane.org/gmane.network.openvpn.user/34784 email thread]. The exploit has not yet been tested by anyone within the OpenVPN project, but we have to assume it is capable of doing what Fredrik claims. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 31 | |
| 32 | ## How do I fix this? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 33 | |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 34 | 1. Update your OpenSSL library |
| 35 | 2. Revoke your old private keys |
|||
| 36 | 3. Generate new private keys |
|||
| 37 | 4. Create certificates for the new private keys |
|||
| 38 | ||||
| 39 | ## Is this for clients or servers? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 40 | |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 41 | Both. Replace the keys for each peer that was active while linked against a vulnerable OpenSSL. |
| 42 | ||||
| 43 | ## Are Android clients affected too? |
|||
| 44 | ||||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 45 | Android shipped OpenSSL 1.0.1 as of 4.1, but disable heartbeats since 4.1.2. That means only Android 4.1(.0) and 4.1.1 are vulnerable. There are app available to check your own device like [Heartbleed Detector](https://play.google.com/store/apps/details?id=com.lookout.heartbleeddetector). |
| 46 | ||||
| 47 | OpenVPN for Android 0.6.17 and later use an embedded not vulnerable OpenSSL library. OpenVPN Connect uses PolarSSL and is not vulnerable either. This however still leaves all other apps/services on the device vulnerable. |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 48 | |
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 49 | ## What about Tunnelblick for MacOS X |
| 50 | ||||
| 51 | Old versions for Tunnelblick are affected, but fixed versions [have been released](https://code.google.com/p/tunnelblick/wiki/News). |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 52 | |
| 53 | ## What about Windows clients? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 54 | |
| 55 | All [http://openvpn.net/index.php/download/community-downloads.html official OpenVPN Windows client installers] are shipped with OpenSSL. However, only installer versions *2.3-rc2-I001* through *2.3.2-I003* ship a vulnerable version. Installer version *2.3.2-I004* fixes this vulnerability by bundling OpenSSL 1.0.1g. The fixed version can be downloaded from [http://openvpn.net/index.php/open-source/downloads.html here]. |
|||
| 56 | ||||
| 57 | If you want to verify whether the version of OpenSSL in your OpenVPN installation is vulnerable, go to *C:\Program Files\OpenVPN\bin* using Windows Explorer, right-click on *libeay32.dll*, click properties and check what *Details -> Product Version* says. |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 58 | |
| 59 | ## Is Access Server affected? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 60 | |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 61 | Short answer: yes. |
| 62 | ||||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 63 | All Access Server users are advised to [upgrade immediately](https://openvpn.net/index.php/access-server/overview.html) to Access Server 2.0.7. If you would like to patch the OpenSSL libraries for older versions of Access Server please [download the libs](http://swupdate.openvpn.org/hb/) for your distro and copy them into /usr/local/openvpn_as/lib. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 64 | |
| 65 | For more information have a look at the OpenVPN Technologies' [official announcement](http://openvpn.net/index.php/access-server/heartbleed.html). |
|||
| 66 | ||||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 67 | ## Are OpenVPN Connect clients affected |
| 68 | ||||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 69 | It depends: |
| 70 | ||||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 71 | * The iOS and Android versions use PolarSSL and are not vulnerable |
| 72 | * Windows and MacOS X versions use OpenSSL and old client versions are vulnerable |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 73 | |
| 74 | Access Server 2.0.7 includes OpenVPN Connect clients that have been fixed. If you have installed Access Server 2.0.6 and for whatever reason can't upgrade to 2.0.7 you should get updated clients from [here](http://swupdate.openvpn.org/hb/Clients). |
|||
| 75 | ||||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 76 | For more information have a look at the OpenVPN Technologies' [official announcement](http://openvpn.net/index.php/access-server/heartbleed.html). |
| 77 | ||||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 78 | ## Are PolarSSL builds affected too? |
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 79 | No. See ref 2. |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 80 | |
| 81 | ## Do TLS-auth keys protect my setup? |
|||
| 792107 | Samuli Seppänen | 2025-02-27 10:40:58 | 82 | To some extent. You are strongly encouraged to use TLS-auth keys. In this scenario an attacker can not attack openvpn instances without the TLS-auth key. With a large user base, you should however consider the possibility of one (or more) of the OpenVPN instances being compromised. Such a compromised instance could attack other instances (including the server). |
| 83 | ||||
| 84 | ||||
| 85 | ![1] http://heartbleed.com/ |
|||
| 86 | ||||
| 87 | ![2] https://polarssl.org/tech-updates/security-advisories/polarssl-security-advisory-2014-01 |
