CVE-2018-9336
Summary
| CVE | CVE-2018-9336 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-01 18:29:00 UTC |
| Updated | 2018-06-13 14:27:00 UTC |
| Description | openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Release OpenVPN v2.4.6 release · OpenVPN/openvpn · GitHub |
CONFIRM |
github.com |
Release Notes, Third Party Advisory |
| The Slackware Linux Project: Slackware Security Advisories |
SLACKWARE |
www.slackware.com |
Mailing List, Third Party Advisory |
| ChangesInOpenvpn24 – OpenVPN Community |
CONFIRM |
community.openvpn.net |
Release Notes, Vendor Advisory |
| [R1] OpenVPN Windows Service Double Free - Research Advisory | Tenable® |
MISC |
www.tenable.com |
Exploit, Third Party Advisory |
| Fix potential double-free() in Interactive Service (CVE-2018-9336) · OpenVPN/openvpn@1394192 · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500503 Alpine Linux Security Update for Open Virtual Private Network (OpenVPN)
- 500571 Alpine Linux Security Update for Open Virtual Private Network (OpenVPN)
- 500770 Alpine Linux Security Update for openvpn
- 501170 Alpine Linux Security Update for openvpn
- 504260 Alpine Linux Security Update for openvpn