OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openvpn | Openvpn | 2.0 (including) | 2.0 (including) |
| Openvpn | Openvpn | 2.0.4 (including) | 2.0.4 (including) |
| Openvpn_access_server | Openvpn | 2.0.1 (including) | 2.0.1 (including) |
| Openvpn_access_server | Openvpn | 2.0.2 (including) | 2.0.2 (including) |
| Openvpn_access_server | Openvpn | 2.0.3 (including) | 2.0.3 (including) |
| Openvpn_access_server | Openvpn | 2.0.5 (including) | 2.0.5 (including) |