Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openvpn | Openvpn | 2.0 (including) | 2.0 (including) |
Openvpn | Openvpn | 2.0_beta11 (including) | 2.0_beta11 (including) |
Openvpn_access_server | Openvpn | 2.0.1 (including) | 2.0.1 (including) |
Openvpn_access_server | Openvpn | 2.0.2 (including) | 2.0.2 (including) |
Openvpn | Ubuntu | dapper | * |
Openvpn | Ubuntu | devel | * |
Openvpn | Ubuntu | edgy | * |
Openvpn | Ubuntu | feisty | * |