MitM attack in OpenVPN for Windows - CVE-2017-7520

 

MitM attack in OpenVPN for Windows - CVE-2017-7520

Published: June 22, 2017


Vulnerability identifier: #VU7165
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7520
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack or obtain potentially sensitive client's information.

If clients use a HTTP proxy with NTLM authentication (i.e. "--http-proxy <server> <port> [<authfile>|'auto'|'auto-nct'] ntlm2"), a man-in-the-middle attacker between the client and the proxy can cause the client to crash or disclose at most 96 bytes of stack memory. The disclosed stack memory is likely to contain the proxy password.


Affected software

OpenVPN for Windows

Arch Linux
Debian Linux
Amazon Linux AMI
Fedora
SUSE Linux
Ubuntu
Slackware Linux
Opensuse
openvpn

How to mitigate CVE-2017-7520

Update OpenVPN to version 2.4.3.

openvpn - addressed in versions 2.3.17-1.fc24, 2.4.3-1.el6, 2.4.3-1.el7, 2.4.3-1.fc25, 2.4.3-1.fc26

External References

Related Security Bulletins