UBUNTU-CVE-2018-7544

Source
https://ubuntu.com/security/CVE-2018-7544
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-7544.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-7544
Related
Published
2018-03-16T15:29:00Z
Modified
2018-03-16T15:29:00Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

* DISPUTED * A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

References

Affected packages

Ubuntu:Pro:14.04:LTS / openvpn

Package

Name
openvpn
Purl
pkg:deb/ubuntu/openvpn?arch=src?distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.2-4ubuntu1
2.3.2-5ubuntu1
2.3.2-7ubuntu1
2.3.2-7ubuntu2
2.3.2-7ubuntu3
2.3.2-7ubuntu3.1
2.3.2-7ubuntu3.2
2.3.2-7ubuntu3.2+esm1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:16.04:LTS / openvpn

Package

Name
openvpn
Purl
pkg:deb/ubuntu/openvpn?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.7-1ubuntu1
2.3.7-2ubuntu1
2.3.8-1ubuntu1
2.3.10-1ubuntu1
2.3.10-1ubuntu2
2.3.10-1ubuntu2.1
2.3.10-1ubuntu2.2
2.3.10-1ubuntu2.2+esm1

Ecosystem specific

{
    "ubuntu_priority": "low"
}

Ubuntu:Pro:18.04:LTS / openvpn

Package

Name
openvpn
Purl
pkg:deb/ubuntu/openvpn?arch=src?distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.4.3-4ubuntu1
2.4.4-1ubuntu1
2.4.4-2ubuntu1
2.4.4-2ubuntu1.1
2.4.4-2ubuntu1.2
2.4.4-2ubuntu1.3
2.4.4-2ubuntu1.5
2.4.4-2ubuntu1.6
2.4.4-2ubuntu1.7

Ecosystem specific

{
    "ubuntu_priority": "low"
}