Use-after-free in OpenVPN for Windows - CVE-2023-46850
Published: November 10, 2023
Vulnerability identifier: #VU82951
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-46850
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to openvpn incorrectly uses a send buffer after it has been freed. Under certain circumstances the freed memory can be sent to the client peer, resulting in information disclosure. The vulnerability affects TLS configuration.
Affected software
OpenVPN for Windows
Debian Linux
Gentoo Linux
Ubuntu
Fedora
openvpn (Ubuntu package)
openvpn (Debian package)
net-vpn/openvpn
openvpn
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 VPN Module
Debian Linux
Gentoo Linux
Ubuntu
Fedora
openvpn (Ubuntu package)
openvpn (Debian package)
net-vpn/openvpn
openvpn
IBM MaaS360 Cloud Extender Agent
IBM MaaS360 Mobile Enterprise Gateway
IBM MaaS360 VPN Module
How to mitigate CVE-2023-46850
Install updates from vendor's website.
OpenVPN for Windows - update to 2.6.7
openvpn (Ubuntu package) - addressed in versions 2.6.1-1ubuntu1.1, 2.6.5-0ubuntu1.1
openvpn (Debian package) - update to 2.6.3-1+deb12u2
net-vpn/openvpn - update to 2.6.7
openvpn - addressed in versions 2.6.7-1.fc38, 2.6.7-1.fc39, 2.6.8-1.fc38, 2.6.8-1.fc39
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 VPN Module - update to 3.000.400
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
openvpn (Ubuntu package) - addressed in versions 2.6.1-1ubuntu1.1, 2.6.5-0ubuntu1.1
openvpn (Debian package) - update to 2.6.3-1+deb12u2
net-vpn/openvpn - update to 2.6.7
openvpn - addressed in versions 2.6.7-1.fc38, 2.6.7-1.fc39, 2.6.8-1.fc38, 2.6.8-1.fc39
IBM MaaS360 Cloud Extender Agent - update to 3.000.300.025
IBM MaaS360 VPN Module - update to 3.000.400
IBM MaaS360 Mobile Enterprise Gateway - update to 3.000.400
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenVPN
- Fedora 38 update for openvpn
- Fedora 39 update for openvpn
- Debian update for openvpn
- Ubuntu update for openvpn
- Fedora 38 update for openvpn
- Fedora 39 update for openvpn
- Multiple vulnerabilities in IBM MaaS360 Cloud Extender Agent, Mobile Enterprise Gateway and VPN Module
- Gentoo update for OpenVPN