Double free error in OpenVPN for Windows - CVE-2017-7521

 

Double free error in OpenVPN for Windows - CVE-2017-7521

Published: June 21, 2017


Vulnerability identifier: #VU7143
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2017-7521
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: OpenVPN
Affected software:
OpenVPN for Windows

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to double free error when processing --x509-alt-username attribute. A remote unauthenticated attacker can trigger double free error and crash the affected server or potentially execute arbitrary code.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


How to mitigate CVE-2017-7521

Update OpenVPN to version 2.4.3.

Sources