PT-2006-2627 · Openvpn · Openvpn

Hendrik Weimer

·

Publicado

2006-04-06

·

Atualizado

2024-06-15

·

CVE-2006-1629

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenVPN versions 2.0 through 2.0.5
Description: The issue allows remote malicious servers to execute arbitrary code on the client. This is achieved by using the setenv function with the LD PRELOAD environment variable, which can lead to code execution.
Recommendations: For OpenVPN versions 2.0 through 2.0.5, consider updating to a version where this issue is fixed, as using setenv with LD PRELOAD can pose a significant risk. As a temporary workaround, consider restricting the use of the LD PRELOAD environment variable in the client configuration to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1629
DSA-1045-1
OPENSUSE-SU-2024:11128-1

Produtos afetados

Openvpn