OpenVPN Client Remote Format String Vulnerability
BID:15239
Info
OpenVPN Client Remote Format String Vulnerability
| Bugtraq ID: | 15239 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2005 12:00AM |
| Updated: | Oct 31 2005 12:00AM |
| Credit: | Discovery is credited to vade79 <[email protected]>. |
| Vulnerable: |
S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 OpenVPN OpenVPN 2.0.2 OpenVPN OpenVPN 2.0.1 OpenVPN OpenVPN 2.0 beta11 OpenVPN OpenVPN 2.0 OpenPKG OpenPKG 2.5 OpenPKG OpenPKG 2.4 OpenPKG OpenPKG 2.3 OpenPKG OpenPKG Current Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 3.0 Gentoo Linux |
| Not Vulnerable: |
OpenVPN OpenVPN 2.0.4 |
Discussion
OpenVPN Client Remote Format String Vulnerability
OpenVPN is reported prone to a remote format string vulnerability.
A malicious server can send specially crafted command options such as 'dhcp-option' including format specifiers to a client to trigger this vulnerability.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution. This can result in unauthorized remote access.
This issue affects OpenVPN 2.0.x versions. OpenVPN running on Windows is not vulnerable to this issue.
OpenVPN is reported prone to a remote format string vulnerability.
A malicious server can send specially crafted command options such as 'dhcp-option' including format specifiers to a client to trigger this vulnerability.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution. This can result in unauthorized remote access.
This issue affects OpenVPN 2.0.x versions. OpenVPN running on Windows is not vulnerable to this issue.
Exploit / POC
OpenVPN Client Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenVPN Client Remote Format String Vulnerability
Solution:
OpenVPN 2.0.4 is available to address this issue.
OpenPKG advisory OpenPKG-SA-2005.023 is available to address this issue. Please see the referenced advisory for more information.
SUSE has released advisory SUSE-SR:2005:025 to address this, and other issues in various packages, in various SUSE products. Please see the referenced advisory for further information.
Debian has released advisory DSA 885-1 to address this issue. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200511-07 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/openvpn-2.0.4"
Mandriva advisory MDKSA-2005:206 is available to address this issue in Multi Network Firewall 2.0. Please see the referenced advisory for more information.
Mandriva advisory MDKSA-2005:206-1 is available to address this issue. Please see the referenced advisory for more information.
OpenVPN OpenVPN 2.0
OpenVPN OpenVPN 2.0 beta11
OpenVPN OpenVPN 2.0.1
OpenVPN OpenVPN 2.0.2
Solution:
OpenVPN 2.0.4 is available to address this issue.
OpenPKG advisory OpenPKG-SA-2005.023 is available to address this issue. Please see the referenced advisory for more information.
SUSE has released advisory SUSE-SR:2005:025 to address this, and other issues in various packages, in various SUSE products. Please see the referenced advisory for further information.
Debian has released advisory DSA 885-1 to address this issue. Please see the referenced advisory for more information.
Gentoo has released advisory GLSA 200511-07 to address this issue. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to update their computers:
emerge --sync
emerge --ask --oneshot --verbose ">=net-misc/openvpn-2.0.4"
Mandriva advisory MDKSA-2005:206 is available to address this issue in Multi Network Firewall 2.0. Please see the referenced advisory for more information.
Mandriva advisory MDKSA-2005:206-1 is available to address this issue. Please see the referenced advisory for more information.
OpenVPN OpenVPN 2.0
-
Debian openvpn_2.0-1sarge2_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_alpha.deb -
Debian openvpn_2.0-1sarge2_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_amd64.deb -
Debian openvpn_2.0-1sarge2_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_arm.deb -
Debian openvpn_2.0-1sarge2_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_hppa.deb -
Debian openvpn_2.0-1sarge2_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_i386.deb -
Debian openvpn_2.0-1sarge2_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_ia64.deb -
Debian openvpn_2.0-1sarge2_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_m68k.deb -
Debian openvpn_2.0-1sarge2_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_mips.deb -
Debian openvpn_2.0-1sarge2_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_mipsel.deb -
Debian openvpn_2.0-1sarge2_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_powerpc.deb -
Debian openvpn_2.0-1sarge2_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_s390.deb -
Debian openvpn_2.0-1sarge2_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/openvpn/openvpn_2.0-1sa rge2_sparc.deb -
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenVPN OpenVPN 2.0 beta11
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenVPN OpenVPN 2.0.1
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
OpenVPN OpenVPN 2.0.2
-
OpenVPN OpenVPN 2.0.4
http://openvpn.net/download.html#stable
References
OpenVPN Client Remote Format String Vulnerability
References:
References:
- OpenVPN Change Log (OpenVPN)
- OpenVPN Homepage (OpenVPN)
- OpenVPN[v2.0.x]: foreign_option() formart string vulnerability. (v9
)