Use-after-free in OpenVPN for Windows - CVE-2023-46850

 

Use-after-free in OpenVPN for Windows - CVE-2023-46850

Published: November 10, 2023


Vulnerability identifier: #VU82951
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46850
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to openvpn incorrectly uses a send buffer after it has been freed. Under certain circumstances the freed memory can be sent to the client peer, resulting in information disclosure. The vulnerability affects TLS configuration.


Affected software

OpenVPN for Windows
Debian Linux
Gentoo Linux
Ubuntu
Fedora
openvpn (Ubuntu package)
openvpn (Debian package)
net-vpn/openvpn
openvpn
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 VPN Module

How to mitigate CVE-2023-46850

Install updates from vendor's website.

OpenVPN for Windows - update to 2.6.7
openvpn (Ubuntu package) - addressed in versions 2.6.1-1ubuntu1.1, 2.6.5-0ubuntu1.1
openvpn (Debian package) - update to 2.6.3-1+deb12u2
net-vpn/openvpn - update to 2.6.7
openvpn - addressed in versions 2.6.7-1.fc38, 2.6.7-1.fc39, 2.6.8-1.fc38, 2.6.8-1.fc39
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 VPN Module - update to 3.000.400
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400

External References

Related Security Bulletins