PT-2006-2627 · Openvpn · Openvpn

Hendrik Weimer

·

Published

2006-04-06

·

Updated

2024-06-15

·

CVE-2006-1629

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: OpenVPN versions 2.0 through 2.0.5
Description: The issue allows remote malicious servers to execute arbitrary code on the client. This is achieved by using the setenv function with the LD PRELOAD environment variable, which can lead to code execution.
Recommendations: For OpenVPN versions 2.0 through 2.0.5, consider updating to a version where this issue is fixed, as using setenv with LD PRELOAD can pose a significant risk. As a temporary workaround, consider restricting the use of the LD PRELOAD environment variable in the client configuration to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1629
DSA-1045-1
OPENSUSE-SU-2024:11128-1

Affected Products

Openvpn