Resource management error in OpenVPN for Windows - CVE-2020-11810
Published: May 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application that allows a timing attack to be carried out against OpenVPN clients.
An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small time window (usually within a few seconds) between the victim client connection starting and the server PUSH_REPLY response back to the client. This attack will only work if Negotiable Cipher Parameters (NCP) is in use.
Affected software
Arch Linux
Amazon Linux AMI
Fedora
Slackware Linux
SUSE Linux Enterprise Module for Basesystem
Ubuntu
openEuler
openvpn (Alpine package)
openvpn-devel
openvpn
openvpn-auth-pam-plugin
openvpn-auth-pam-plugin-debuginfo
openvpn-debuginfo
openvpn-debugsource
openvpn (Ubuntu package)
openvpn-help
How to mitigate CVE-2020-11810
openvpn (Alpine package) - update to 2.4.9-r0
openvpn-devel - update to 2.4.3-5.7.1
openvpn - update to 2.4.3-5.7.1
openvpn-auth-pam-plugin - update to 2.4.3-5.7.1
openvpn-auth-pam-plugin-debuginfo - update to 2.4.3-5.7.1
openvpn-debuginfo - update to 2.4.3-5.7.1
openvpn-debugsource - update to 2.4.3-5.7.1
openvpn (Ubuntu package) - addressed in versions 2.4.4-2ubuntu1.5, 2.4.7-1ubuntu2.20.04.2, 2.4.9-3ubuntu1.1, 2.5.1-1ubuntu1.1
openvpn - update to 2.4.8-5
openvpn-debuginfo - update to 2.4.8-5
openvpn-debugsource - update to 2.4.8-5
openvpn-devel - update to 2.4.8-5
openvpn-help - update to 2.4.8-5
openvpn - addressed in versions 2.4.9-1.el6, 2.4.9-1.el7, 2.4.9-1.el8, 2.4.9-1.fc30, 2.4.9-1.fc31, 2.4.9-1.fc32
External References
- https://bugzilla.suse.com/show_bug.cgi?id=1169925
- https://community.openvpn.net/openvpn/ticket/1272
- https://github.com/OpenVPN/openvpn/commit/37bc691e7d26ea4eb61a8a434ebd7a9ae76225ab
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FGHHV4YZANZW45KZTJJGVGPFMSXYRCKZ/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JII7RYYYRBPQNEGGVSOXCM7JUZ43T3VH/
- https://patchwork.openvpn.net/patch/1079/
- https://security-tracker.debian.org/tracker/CVE-2020-11810
Related Security Bulletins
- Denial of service in OpenVPN
- Amazon Linux AMI update for openvpn
- Resource management error in openvpn (Alpine package)
- Arch Linux update for openvpn
- Slackware Linux update for openvpn
- Ubuntu update for openvpn
- openEuler update for openvpn
- SUSE update for openvpn
- Fedora 30 update for openvpn
- Fedora 32 update for openvpn
- Fedora 31 update for openvpn
- Fedora EPEL 7 update for openvpn
- Fedora EPEL 8 update for openvpn
- Fedora EPEL 6 update for openvpn