PT-2005-1090 · Openvpn · Openvpn

Vade79

·

Published

2005-11-01

·

Updated

2024-06-15

·

CVE-2005-3393

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.0.4 OpenVPN version 2.0.x
Description The issue concerns a format string vulnerability in the foreign option function in options.c. This vulnerability allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option. Multiple vulnerabilities in the OpenVPN package may lead to breaches of confidentiality, integrity, and availability of protected information, and these vulnerabilities can be exploited remotely.
Recommendations For OpenVPN versions prior to 2.0.4, update to version 2.0.4 or later to resolve the issue. For OpenVPN version 2.0.x, update to a version outside of the 2.0.x range to mitigate the risk. As a temporary workaround, consider restricting access to the foreign option function in options.c until a patch is available. Avoid using format string specifiers in the dhcp-option command option until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09483
CVE-2005-3393
DSA-885-1
OPENSUSE-SU-2024:11128-1

Affected Products

Openvpn