OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openvpn | Openvpn | 2.0 (including) | 2.0 (including) |
Openvpn | Openvpn | 2.0.4 (including) | 2.0.4 (including) |
Openvpn_access_server | Openvpn | 2.0.1 (including) | 2.0.1 (including) |
Openvpn_access_server | Openvpn | 2.0.2 (including) | 2.0.2 (including) |
Openvpn_access_server | Openvpn | 2.0.3 (including) | 2.0.3 (including) |
Openvpn_access_server | Openvpn | 2.0.5 (including) | 2.0.5 (including) |