openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.
[
{
"id": "CVE-2018-9336-6f6cb009",
"target": {
"function": "GetStartupData",
"file": "src/openvpnserv/interactive.c"
},
"signature_version": "v1",
"signature_type": "Function",
"digest": {
"length": 1801.0,
"function_hash": "76249174896798077986787021284902443957"
},
"source": "https://github.com/openvpn/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b",
"deprecated": false
},
{
"id": "CVE-2018-9336-b726e6c2",
"target": {
"file": "src/openvpnserv/interactive.c"
},
"signature_version": "v1",
"signature_type": "Line",
"digest": {
"line_hashes": [
"289438739866009732693574682006466857681",
"321565621241284017888958497464079295163",
"195788173835312840708182270129385780967",
"157149519107656280786448143671546800758",
"330594636882758798577265977046886899589",
"61946047064732831183916419652892674079",
"73819516014268841906567609661453268985",
"53477928483126425049698987735296952292",
"160457593547376328576023042434816934222",
"102247858346367447205334963596539921621",
"37760868789385960205315602176273650548",
"53416876412599990887617656792587425944",
"231052184390747051670143023779207169899",
"82101472118118567585578736071106229258",
"306507218426212718522252431219043743649",
"2766319541782805131682120927575304148",
"110753385165441245116358304053334545450",
"290008412599615179597160777647644121426",
"197093618283534262316211851307390296078",
"231838072196818321118202676689277965807",
"163136148559021466918701586049456598696",
"57652015971833478580836840077705432245",
"188431597377538567314213316948483171797",
"45804946495876171431938301213448644363",
"35490655318343064911912676930636225462",
"189921561168834180170229040099364593666",
"234424307210144426171304176440220006390",
"60869185759417503061368576737633381064",
"106049124931381612333091018629992720739",
"148025771116657418264690920352564529771",
"184864002078368697997805638241742679035",
"230318638235804652942591183825937822078",
"243422924903089937958313966285867213026",
"297557170468421667846869797139637183819",
"34671599296192400017110588308363004350",
"292353436963983896055666031584247941394",
"61570016092430263203832958639438681880",
"141441711254298611049517417527928691692",
"120353406661613926063927761543085251023",
"293785784376869473936078925543400440146",
"125496552704587362904006732753252071462"
],
"threshold": 0.9
},
"source": "https://github.com/openvpn/openvpn/commit/1394192b210cb3c6624a7419bcf3ff966742e79b",
"deprecated": false
}
]