Purevpn · Purevpn Linux Client · CVE-2023-48957
**Name of the Vulnerable Software and Affected Versions**
PureVPN Linux client version 2.0.2
**Description**
The PureVPN Linux client fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers. This issue is related to improper access controls in the DNS query handler.
**Recommendations**
For PureVPN Linux client version 2.0.2, upgrade to version 2.0.3 to remediate the issue. As a temporary workaround, consider restricting access to the DNS query handler until the patch is applied.