Vulnerability Name:

CVE-2018-9336 (CCN-142490)

Assigned:2018-04-26
Published:2018-04-26
Updated:2018-06-13
Summary:openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-415
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-9336

Source: CCN
Type: BugTraq Mailing List, Thu, 26 Apr 2018 21:43:21 -0700 (PDT)
[slackware-security] openvpn (SSA:2018-116-01)

Source: SLACKWARE
Type: Mailing List, Third Party Advisory
SSA:2018-116-01

Source: CONFIRM
Type: Release Notes, Vendor Advisory
https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24

Source: XF
Type: UNKNOWN
openvpn-cve20189336-dos(142490)

Source: CCN
Type: openvpn GIT Repository
Fix potential double-free() in Interactive Service (CVE-2018-9336)

Source: CONFIRM
Type: Patch, Third Party Advisory
https://github.com/OpenVPN/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://github.com/OpenVPN/openvpn/releases/tag/v2.4.6

Source: MISC
Type: Exploit, Third Party Advisory
https://www.tenable.com/security/research/tra-2018-09

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openvpn:openvpn:*:*:*:*:*:*:*:* (Version >= 2.4.0 and < 2.4.6)

  • Configuration 2:
  • cpe:/o:slackware:slackware_linux:13.0:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:13.1:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:13.37:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:14.0:*:*:*:*:*:*:*
  • OR cpe:/o:slackware:slackware_linux:14.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openvpn:openvpn:2.4.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20189336
    V
    CVE-2018-9336
    2023-06-22
    oval:org.opensuse.security:def:7727
    P
    openvpn-2.5.6-150400.3.6.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3133
    P
    libXRes1-1.0.7-3.53 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94763
    P
    openvpn-2.5.5-150400.1.5 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1181
    P
    Security update for the Linux Kernel (Important)
    2022-06-14
    oval:org.opensuse.security:def:523
    P
    Security update for u-boot (Important)
    2022-06-13
    oval:org.opensuse.security:def:252
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:843
    P
    Security update for the Linux Kernel (Important)
    2022-03-30
    oval:org.opensuse.security:def:1189
    P
    Security update for the Linux Kernel (Critical)
    2022-02-11
    oval:org.opensuse.security:def:113069
    P
    openvpn-2.5.3-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69935
    P
    Security update for curl (Moderate)
    2021-10-06
    oval:org.opensuse.security:def:106507
    P
    openvpn-2.5.3-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:89767
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61612
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71353
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103422
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96732
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47597
    P
    dpdk-17.11.4-3.6 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47721
    P
    libimobiledevice6-1.2.0-7.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47959
    P
    automake-1.13.4-6.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48035
    P
    gtk2-data-2.24.31-9.6.28 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47045
    P
    liblua5_2-32bit-5.2.2-4.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48105
    P
    libdmx1-1.1.3-3.51 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48259
    P
    pam_yubico-2.26-1.25 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47180
    P
    xdg-utils-20140630-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48201
    P
    libssh4-0.8.7-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47505
    P
    strongswan-5.1.3-25.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47707
    P
    libfreetype6-2.6.3-7.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47745
    P
    libmusicbrainz4-2.1.5-27.79 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47842
    P
    pam_krb5-2.4.4-4.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47044
    P
    libltdl7-2.4.2-14.30 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48043
    P
    hyper-v-7-7.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48167
    P
    libpango-1_0-0-1.40.1-9.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47059
    P
    libpcsclite1-1.8.10-3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48170
    P
    libpcsclite1-1.8.10-7.6.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47373
    P
    liblzo2-2-2.08-1.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47706
    P
    libfreebl3-3.29.5-58.12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48272
    P
    pigz-2.3-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:72011
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101028
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62270
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:67770
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15) (Important)
    2021-06-18
    oval:org.opensuse.security:def:48832
    P
    freerdp-2.0.0~git.1463131968.4e66df7-11.69 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48964
    P
    rhythmbox-3.4-6.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48934
    P
    libndp0-1.6-2.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48621
    P
    sblim-sfcb-1.4.8-8.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71010
    P
    libpng16-16-1.6.34-1.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48767
    P
    cyrus-sasl-digestmd5-32bit-2.1.26-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71123
    P
    xen-libs-4.10.1_04-1.4 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48910
    P
    gstreamer-0_10-plugins-good-0.10.31-16.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48863
    P
    libpcrecpp0-32bit-8.39-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48407
    P
    dstat-0.7.2-1.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48705
    P
    rhythmbox-3.0.2-1.92 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:100612
    P
    (Moderate)
    2021-05-27
    oval:org.opensuse.security:def:69830
    P
    Security update for qemu (Important)
    2021-04-16
    oval:org.opensuse.security:def:66487
    P
    Security update for gimp (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:1827
    P
    perl-Config-IniFiles-2.94-1.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116836
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:93899
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61932
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71673
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107278
    P
    openvpn-2.4.3-5.3.19 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:64423
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67670
    P
    libdmx-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50210
    P
    pulseaudio-module-bluetooth on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66579
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49284
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64336
    P
    libjasper4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50264
    P
    Security update for openvpn (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73152
    P
    libevent-2_1-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73270
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49230
    P
    libserf-1-1 on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:20189336000
    V
    CVE-2018-9336 on Ubuntu 17.10 (artful) - medium.
    2018-05-01
    oval:com.ubuntu.bionic:def:20189336000
    V
    CVE-2018-9336 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-05-01
    oval:com.ubuntu.bionic:def:201893360000000
    V
    CVE-2018-9336 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-05-01
    oval:com.ubuntu.trusty:def:20189336000
    V
    CVE-2018-9336 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-05-01
    oval:com.ubuntu.xenial:def:201893360000000
    V
    CVE-2018-9336 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-05-01
    oval:com.ubuntu.xenial:def:20189336000
    V
    CVE-2018-9336 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-05-01
    BACK
    openvpn openvpn *
    slackware slackware linux 13.0
    slackware slackware linux 13.1
    slackware slackware linux 13.37
    slackware slackware linux 14.0
    slackware slackware linux 14.1
    openvpn openvpn 2.4.5