CVE-2018-9336

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-9336
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-9336.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-9336
Related
Published
2018-05-01T18:29:00Z
Modified
2024-12-05T15:19:28.561465Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service. This could cause a denial-of-service through memory corruption or possibly have unspecified other impact including privilege escalation.

References

Affected packages

Alpine:v3.10 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.11 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.12 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.13 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.14 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.15 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.16 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.17 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.18 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.19 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.20 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Alpine:v3.21 / openvpn

Package

Name
openvpn
Purl
pkg:apk/alpine/openvpn?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-r0

Affected versions

2.*

2.0.9-r0
2.0.9-r1
2.0.9-r2
2.1.1-r0
2.1.1-r1
2.1.1-r2
2.1.3-r0
2.1.4-r0
2.1.4-r1
2.2.0-r0
2.2.0-r1
2.2.0-r2
2.2.2-r0
2.3.0-r0
2.3.1-r0
2.3.2-r0
2.3.2-r1
2.3.2-r2
2.3.3-r0
2.3.4-r0
2.3.5-r0
2.3.6-r0
2.3.6-r1
2.3.7-r0
2.3.8-r0
2.3.8-r1
2.3.9-r0
2.3.10-r0
2.3.10-r1
2.3.10-r2
2.3.11-r0
2.3.12-r0
2.3.12-r1
2.3.14-r0
2.4.0-r0
2.4.1-r0
2.4.1-r1
2.4.2-r0
2.4.3-r0
2.4.4-r0
2.4.4-r1
2.4.5-r0
2.4.5-r1

Git / github.com/openvpn/openvpn

Affected ranges

Type
GIT
Repo
https://github.com/openvpn/openvpn
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v2.*

v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1_rc1
v2.1_rc10
v2.1_rc11
v2.1_rc12
v2.1_rc13
v2.1_rc14
v2.1_rc15
v2.1_rc16
v2.1_rc17
v2.1_rc18
v2.1_rc19
v2.1_rc2
v2.1_rc20
v2.1_rc21
v2.1_rc22
v2.1_rc3
v2.1_rc4
v2.1_rc5
v2.1_rc6
v2.1_rc7
v2.1_rc8
v2.1_rc9
v2.2-RC
v2.2-RC2
v2.2-beta4
v2.2-beta5
v2.3-alpha1
v2.3_alpha2
v2.3_alpha3
v2.3_beta1
v2.4_alpha1
v2.4_alpha2
v2.4_beta1
v2.4_beta2
v2.4_rc1
v2.4_rc2