PT-2017-3265 · Openvpn+3 · Openvpn+3

Published

2017-06-06

·

Updated

2019-10-03

·

CVE-2017-7520

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.4.3 OpenVPN versions prior to 2.3.17
Description The issue is related to the improper handling of client connections to HTTP proxies with NTLMv2 authentication. It may allow a remote attacker to execute arbitrary code. The vulnerability can also be triggered by a man-in-the-middle attacker, potentially leading to denial-of-service and/or sensitive memory leaks.
Recommendations For versions prior to 2.4.3, update to version 2.4.3 or later. For versions prior to 2.3.17, update to version 2.3.17 or later. As a temporary workaround, consider restricting access to HTTP proxies with NTLMv2 authentication until a patch is applied.

Fix

DoS

Information Disclosure

Improper Certificate Validation

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1766
BDU:2018-00021
CVE-2017-7520
DLA-999-1
DSA-3900-1
MGASA-2017-0224
OPENSUSE-SU-2017_1680-1
SUSE-SU-2017:1635-1
SUSE-SU-2017:1718-1
USN-3339-1
USN-3339-2

Affected Products

Alt Linux
Openvpn
Suse
Ubuntu