A vulnerability in OpenVPN allows data substitution in plugins and third-party handlers.

Details about the vulnerability (CVE-2024-5594) in the OpenVPN package for creating virtual private networks have been revealed, which could lead to the injection of arbitrary data into third-party executable files or plugins on the other side of the connection. The vulnerability is caused by the lack of validation for null bytes and invalid characters when processing control messages such as PUSH_REPLY.

The issue has been resolved in OpenVPN releases 2.5.11 and 2.6.11, compiled in June 2024. The release notes classified the vulnerability as a minor issue, resulting in junk data being written to the log or an increase in CPU load. In an update published a few days ago, the issue was reclassified as critical (danger level 9.1 out of 10).

Details on the exploitation are not yet provided. The fix involves stopping the processing of messages with invalid characters and validating invalid characters throughout the entire buffer, not just in the part before the null byte. Validation for special characters and null bytes has been added for the commands "AUTH_FAILED", "PUSH_*", "RESTART", "HALT", "INFO_PRE", "INFO", "CR_RESPONSE", "AUTH_PENDING", and "EXIT."

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster