Vulnerabilities in OpenVPN and SoftEther VPN

The release of OpenVPN 2.6.7 has been prepared, a package for creating virtual private networks that allows for encrypted connections between two client machines or the operation of a centralized VPN server for multiple clients simultaneously. In the new version, two vulnerabilities have been addressed:

  • CVE-2023-46850 — accessing memory after it has been freed (use-after-free) may lead to sending process memory content to the other side of the connection, and potentially to remote code execution. The issue appears in configurations using TLS (run without the ‘—secret’ parameter).
  • CVE-2023-46849 — a division by zero situation may lead to remote initiation of a crash in access server configurations using the ‘—fragment’ option.

Changes in OpenVPN 2.6.7 not related to security:

  • A warning has been added when another side sends DATA_V1 packets while attempting to connect OpenVPN 2.6.x clients to incompatible servers based on versions 2.4.0-2.4.4 (to eliminate compatibility issues, the ‘—disable-dco’ option can be used).
  • The outdated method linked to OpenSSL 1.x, which uses the OpenSSL Engine to load keys, has been removed. The reason given is the author's unwillingness to re-license the code with new binding exceptions.
  • A warning has been added when a p2p NCP client connects to serwera p2mp (a combination used for operation without cipher negotiation), as there are issues when using version 2.6.x on both sides of the connection.
  • A warning has been added that the ‘—show-groups’ flag does not display all supported groups.
  • Processing of the argument ‘exclude-domains’ in the ‘—dns’ parameter, which appeared in branch 2.6 but is currently not supported by backends, has been removed.
  • A warning has been added, shown if the INFO control message is too large and cannot be redirected to the client.
  • Support for the CMake build system has been added for builds using MinGW and MSVC. Support for the old MSVC build system has been removed.

Additionally, the discovery of 9 vulnerabilities in open source software can be noted. VPN-serwerze SoftEther. Jednym z problemów (CVE-2023-27395) przypisano krytyczny poziom niebezpieczeństwa — podatność spowodowana przepełnieniem bufora może prowadzić do zdalnego wykonania kodu po stronie klienta podczas próby połączenia z serwerem kontrolowanym przez napastnika. Podatność została naprawiona w czerwcowej aktualizacji SoftEther VPN 4.42 Build 9798 RTM. Dwie inne podatności (CVE-2023-32634, CVE-2023-27516) pozwalają na nieautoryzowany dostęp do sesji VPN podczas ataku MITM dzięki wykorzystaniu domyślnych danych logowania do serwera RPC. Podatności zostały usunięte w formie łatki.

Podatności CVE-2023-31192 i CVE-2023-32275 (łatka) mogą prowadzić do wycieku poufnych informacji w niektórych pakietach w wyniku ataków MITM. Pozostałe 4 podatności (CVE-2023-22325, CVE-2023-23581, CVE-2023-22308 i CVE-2023-25774) mogą być stosowane do wywołania odmowy usługi, na przykład do wymuszenia zerwania połączenia lub awaryjnego zakończenia pracy klienta. W kodzie źródłowym SoftEther VPN niedawno wprowadzono poprawkę 7 podatności, o których szczegóły są jeszcze nieznane.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster