CVE-2018-7544

NameCVE-2018-7544
DescriptionA cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openvpn (PTS)jessie, jessie (lts)2.3.4-5+deb8u3vulnerable
stretch (security), stretch (lts), stretch2.4.0-6+deb9u4vulnerable
buster2.4.7-1+deb10u1vulnerable
bullseye2.5.1-3vulnerable
bookworm (security), bookworm2.6.3-1+deb12u2vulnerable
trixie2.6.7-1vulnerable
sid2.6.9-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
openvpnsource(unstable)(unfixed)unimportant

Notes

Not a security issue per se, later versions might explicitly warn in
affected problematic configurations in both the documentation and with
a runtime warning.

Search for package or bug name: Reporting problems