CVE-2017-7521: Double Free
Published Jun 27, 2017
·Updated
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to remote denial-of-service due to memory exhaustion caused by memory leaks and double-free issue in extractx509extension().
Affected Software
9 affected components
OpenVPN OpenVPN<=2.3.16
OpenVPN OpenVPN=2.4.0
OpenVPN OpenVPN=2.4.0-alpha2
OpenVPN OpenVPN=2.4.0-beta1
OpenVPN OpenVPN=2.4.0-beta2
OpenVPN OpenVPN=2.4.0-rc1
OpenVPN OpenVPN=2.4.0-rc2
OpenVPN OpenVPN=2.4.1
OpenVPN OpenVPN=2.4.2
Event History
Jun 27, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7521?
CVE-2017-7521 is classified as a remote denial-of-service vulnerability due to memory exhaustion.
2
How do I fix CVE-2017-7521?
To fix CVE-2017-7521, upgrade to OpenVPN version 2.4.3 or later, or 2.3.17 or later.
3
Which versions of OpenVPN are affected by CVE-2017-7521?
OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to CVE-2017-7521.
4
Can CVE-2017-7521 be exploited remotely?
Yes, CVE-2017-7521 can be exploited remotely, leading to a denial of service by causing memory exhaustion.
5
What impact does CVE-2017-7521 have on OpenVPN users?
CVE-2017-7521 can cause instability and downtime for OpenVPN services, affecting users' ability to connect.