CVE Vulnerabilities

CVE-2006-1629

Published: Apr 06, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

Affected Software

NameVendorStart VersionEnd Version
OpenvpnOpenvpn2.0 (including)2.0 (including)
OpenvpnOpenvpn2.0.4 (including)2.0.4 (including)
Openvpn_access_serverOpenvpn2.0.1 (including)2.0.1 (including)
Openvpn_access_serverOpenvpn2.0.2 (including)2.0.2 (including)
Openvpn_access_serverOpenvpn2.0.3 (including)2.0.3 (including)
Openvpn_access_serverOpenvpn2.0.5 (including)2.0.5 (including)

References