CVE-2018-9336

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-9336
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-9336.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-9336
Downstream
Related
Published
2018-05-01T18:29:00Z
Modified
2025-10-07T23:27:12.624605Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

References

Affected packages

Git / github.com/openvpn/openvpn

Affected ranges

Type
GIT
Repo
https://github.com/openvpn/openvpn
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v2.*

v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1_rc1
v2.1_rc10
v2.1_rc11
v2.1_rc12
v2.1_rc13
v2.1_rc14
v2.1_rc15
v2.1_rc16
v2.1_rc17
v2.1_rc18
v2.1_rc19
v2.1_rc2
v2.1_rc20
v2.1_rc21
v2.1_rc22
v2.1_rc3
v2.1_rc4
v2.1_rc5
v2.1_rc6
v2.1_rc7
v2.1_rc8
v2.1_rc9
v2.2-RC
v2.2-RC2
v2.2-beta4
v2.2-beta5
v2.3-alpha1
v2.3_alpha2
v2.3_alpha3
v2.3_beta1
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4_alpha1
v2.4_alpha2
v2.4_beta1
v2.4_beta2
v2.4_rc1
v2.4_rc2

Database specific

{
    "vanir_signatures": [
        {
            "signature_version": "v1",
            "digest": {
                "length": 1801.0,
                "function_hash": "76249174896798077986787021284902443957"
            },
            "source": "https://github.com/openvpn/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b",
            "deprecated": false,
            "target": {
                "file": "src/openvpnserv/interactive.c",
                "function": "GetStartupData"
            },
            "signature_type": "Function",
            "id": "CVE-2018-9336-6f6cb009"
        },
        {
            "signature_version": "v1",
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "289438739866009732693574682006466857681",
                    "321565621241284017888958497464079295163",
                    "195788173835312840708182270129385780967",
                    "157149519107656280786448143671546800758",
                    "330594636882758798577265977046886899589",
                    "61946047064732831183916419652892674079",
                    "73819516014268841906567609661453268985",
                    "53477928483126425049698987735296952292",
                    "160457593547376328576023042434816934222",
                    "102247858346367447205334963596539921621",
                    "37760868789385960205315602176273650548",
                    "53416876412599990887617656792587425944",
                    "231052184390747051670143023779207169899",
                    "82101472118118567585578736071106229258",
                    "306507218426212718522252431219043743649",
                    "2766319541782805131682120927575304148",
                    "110753385165441245116358304053334545450",
                    "290008412599615179597160777647644121426",
                    "197093618283534262316211851307390296078",
                    "231838072196818321118202676689277965807",
                    "163136148559021466918701586049456598696",
                    "57652015971833478580836840077705432245",
                    "188431597377538567314213316948483171797",
                    "45804946495876171431938301213448644363",
                    "35490655318343064911912676930636225462",
                    "189921561168834180170229040099364593666",
                    "234424307210144426171304176440220006390",
                    "60869185759417503061368576737633381064",
                    "106049124931381612333091018629992720739",
                    "148025771116657418264690920352564529771",
                    "184864002078368697997805638241742679035",
                    "230318638235804652942591183825937822078",
                    "243422924903089937958313966285867213026",
                    "297557170468421667846869797139637183819",
                    "34671599296192400017110588308363004350",
                    "292353436963983896055666031584247941394",
                    "61570016092430263203832958639438681880",
                    "141441711254298611049517417527928691692",
                    "120353406661613926063927761543085251023",
                    "293785784376869473936078925543400440146",
                    "125496552704587362904006732753252071462"
                ]
            },
            "source": "https://github.com/openvpn/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b",
            "deprecated": false,
            "target": {
                "file": "src/openvpnserv/interactive.c"
            },
            "signature_type": "Line",
            "id": "CVE-2018-9336-b726e6c2"
        }
    ]
}