Double free error in OpenVPN for Windows - CVE-2017-7521
Published: June 21, 2017
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to double free error when processing --x509-alt-username attribute. A remote unauthenticated attacker can trigger double free error and crash the affected server or potentially execute arbitrary code.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Arch Linux
Debian Linux
Amazon Linux AMI
Fedora
SUSE Linux
Slackware Linux
Ubuntu
Opensuse
openvpn
How to mitigate CVE-2017-7521
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenVPN
- Slackware Linux update for openvpn
- Ubuntu update for OpenVPN
- openSUSE update for openvpn
- Amazon Linux update for openvpn
- Debian update for openvpn
- SUSE Linux update for openvpn-openssl1
- Arch Linux update for openvpn
- Ubuntu update for OpenVPN
- SUSE Linux update for openvpn
- Fedora 24 update for openvpn
- Fedora 25 update for openvpn
- Fedora 26 update for openvpn
- Fedora EPEL 6 update for openvpn
- Fedora EPEL 7 update for openvpn