CVE-2018-9336
Slackware Security Advisory - openvpn Updates
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.
openvpnserv.exe (también conocido como interactive service helper) en OpenVPN en versiones 2.4.x anteriores a la 2.4.6 permite que un atacante local provoque una doble liberación (double free) de memoria enviando una petición mal formada al servicio interactivo. Esto podría provocar una denegación de servicio (DoS) al corromper la memoria o, posiblemente, otro impacto no especificado, incluyendo el escalado de privilegios.
New openvpn packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-05 CVE Reserved
- 2018-04-27 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2025-04-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-415: Double Free
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/OpenVPN/openvpn/releases/tag/v2.4.6 | Release Notes |
URL | Date | SRC |
---|---|---|
https://www.tenable.com/security/research/tra-2018-09 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/OpenVPN/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b | 2018-06-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openvpn Search vendor "Openvpn" | Openvpn Search vendor "Openvpn" for product "Openvpn" | >= 2.4.0 < 2.4.6 Search vendor "Openvpn" for product "Openvpn" and version " >= 2.4.0 < 2.4.6" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 13.0 Search vendor "Slackware" for product "Slackware Linux" and version "13.0" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 13.1 Search vendor "Slackware" for product "Slackware Linux" and version "13.1" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 13.37 Search vendor "Slackware" for product "Slackware Linux" and version "13.37" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 14.0 Search vendor "Slackware" for product "Slackware Linux" and version "14.0" | - |
Affected
| ||||||
Slackware Search vendor "Slackware" | Slackware Linux Search vendor "Slackware" for product "Slackware Linux" | 14.1 Search vendor "Slackware" for product "Slackware Linux" and version "14.1" | - |
Affected
|