Denial of service in OpenVPN for Windows - CVE-2017-7479

 

Denial of service in OpenVPN for Windows - CVE-2017-7479

Published: May 15, 2017 / Updated: May 16, 2017


Vulnerability identifier: #VU6545
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2017-7479
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: OpenVPN
Affected software:
OpenVPN for Windows

Detailed vulnerability description

The vulnerability allows a remote authenticated attacker to cause DoS conditions on the target system.

The weakness exists due to improper user-input validation. A remote attacker can cause the packet-IDs on the target server to be consumed, trigger the server process to hit an ASSERT() and stop running.

Successful exploitation of the vulnerability of results in denial of service.

How to mitigate CVE-2017-7479

Update to version 2.3.15, 2.4.2 or later.

Sources