PT-2006-2627 · Openvpn · Openvpn
Hendrik Weimer
·
Publicado
2006-04-06
·
Atualizado
2024-06-15
·
CVE-2006-1629
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
OpenVPN versions 2.0 through 2.0.5
Description:
The issue allows remote malicious servers to execute arbitrary code on the client. This is achieved by using the
setenv function with the LD PRELOAD environment variable, which can lead to code execution.Recommendations:
For OpenVPN versions 2.0 through 2.0.5, consider updating to a version where this issue is fixed, as using
setenv with LD PRELOAD can pose a significant risk. As a temporary workaround, consider restricting the use of the LD PRELOAD environment variable in the client configuration to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Openvpn