Double free memory error in OpenVPN for Windows - CVE-2018-9336
Published: April 24, 2018
Vulnerability identifier: #VU12129
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-9336
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to double-free memory error in Interactive Service. A remote attacker can trigger memory corruption and cause the service to crash.
The weakness exists due to double-free memory error in Interactive Service. A remote attacker can trigger memory corruption and cause the service to crash.
Affected software
OpenVPN for Windows
openvpn (Alpine package)
Slackware Linux
Opensuse
openvpn (Alpine package)
Slackware Linux
Opensuse
How to mitigate CVE-2018-9336
Update to version 2.4.6.
openvpn (Alpine package) - update to 2.4.9-r0