Bug 1085803 - (CVE-2018-7544) VUL-1: CVE-2018-7544: openvpn: Cross-protocol scripting issue was discovered in the management interface
(CVE-2018-7544)
VUL-1: CVE-2018-7544: openvpn: Cross-protocol scripting issue was discovered ...
Status: REOPENED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P4 - Low : Minor
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/202165/
CVSSv3:SUSE:CVE-2018-7544:5.3:(AV:N/...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-03-19 09:10 UTC by Karol Babioch
Modified: 2023-02-20 10:43 UTC (History)
6 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-03-19 09:10:05 UTC
CVE-2018-7544

A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can execute arbitrary management commands, obtain sensitive information, or cause a denial of service (SIGTERM) by triggering XMLHttpRequest actions in a web browser. This is demonstrated by a multipart/form-data POST to http://localhost:23000 with a "signal SIGTERM" command in a TEXTAREA element. NOTE: The vendor disputes that this is a vulnerability. They state that this is the result of improper configuration of the OpenVPN instance rather than an intrinsic vulnerability, and now more explicitly warn against such configurations in both the management-interface documentation, and with a runtime warning.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-7544
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-7544.html
http://www.cvedetails.com/cve/CVE-2018-7544/
Comment 1 Karol Babioch 2018-03-19 09:11:18 UTC
This has been disputed upstream and will be addressed with a documentation change and runtime warning. We should probably port these changes over, once available. Nothing too serious, though.
Comment 7 Swamp Workflow Management 2021-05-12 13:26:57 UTC
SUSE-SU-2021:1576-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1185279
CVE References: CVE-2018-7544,CVE-2020-15078
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    openvpn-2.3.8-16.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Swamp Workflow Management 2021-05-12 13:28:10 UTC
SUSE-SU-2021:1577-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1169925,1185279
CVE References: CVE-2018-7544,CVE-2020-11810,CVE-2020-15078
JIRA References: 
Sources used:
SUSE Linux Enterprise Module for Basesystem 15-SP3 (src):    openvpn-2.4.3-5.7.1
SUSE Linux Enterprise Module for Basesystem 15-SP2 (src):    openvpn-2.4.3-5.7.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 9 Swamp Workflow Management 2021-05-12 13:44:04 UTC
SUSE-SU-2021:14723-1: An update that fixes two vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1185279
CVE References: CVE-2018-7544,CVE-2020-15078
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 11-SECURITY (src):    openvpn-openssl1-2.3.2-0.10.9.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 10 Swamp Workflow Management 2021-05-15 19:17:55 UTC
openSUSE-SU-2021:0734-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1085803,1169925,1185279
CVE References: CVE-2018-7544,CVE-2020-11810,CVE-2020-15078
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    openvpn-2.4.3-lp152.6.3.1
Comment 11 Thomas Leroy 2021-12-02 13:56:46 UTC
Still missing for SUSE:SLE-11-SP1:Update and SUSE:SLE-11-SP3:Update
Comment 15 Mohd Saquib 2023-02-20 10:43:06 UTC
Oops closed by mistake... Assigning to security team as it is security bug

BTW is this patch relevant for SLE-11-SP1?

$ osc -A int maintained openvpn
SUSE:SLE-10-SP3:Update:Test/openvpn
SUSE:SLE-11-SP1:Update/openvpn                       <-------
SUSE:SLE-11-SP3:Update/openvpn using sources from SUSE:Maintenance:27789/openvpn.SUSE_SLE-11-SP3_Update
SUSE:SLE-11:Update/openvpn
SUSE:SLE-12:Update/openvpn
SUSE:SLE-15-SP4:Update/openvpn
SUSE:SLE-15:Update/openvpn