Описание
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
A flaw was found in OpenVPN that occurs when a connection is being established or updated. A remote attacker could exploit this timing issue to crash the OpenVPN server, causing a temporary service disruption (Denial of Service). In some cases, it could also allow an attacker to view fragments of the server's temporary internal memory, potentially exposing sensitive data.
Отчет
This Moderate impact flaw in OpenVPN is a race condition that can be remotely triggered during TLS session promotion. Successful exploitation could lead to a server crash, resulting in a denial of service, or potentially leak heap memory. The vulnerability's reliance on specific timing for the race condition to occur contributes to its Moderate severity.
Меры по смягчению последствий
To reduce the attack surface, restrict network access to the OpenVPN server to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the OpenVPN port (default 1194/UDP or 443/TCP) from known, authorized sources. This operational control limits the ability of unauthorized remote attackers to attempt exploitation.
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug ...
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
EPSS
6.5 Medium
CVSS3