CVE Vulnerabilities

CVE-2006-1629

Published: Apr 06, 2006 | Modified: May 12, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.

Affected Software

Name Vendor Start Version End Version
Openvpn Openvpn 2.0 (including) 2.0 (including)
Openvpn Openvpn 2.0.4 (including) 2.0.4 (including)
Openvpn_access_server Openvpn 2.0.1 (including) 2.0.1 (including)
Openvpn_access_server Openvpn 2.0.2 (including) 2.0.2 (including)
Openvpn_access_server Openvpn 2.0.3 (including) 2.0.3 (including)
Openvpn_access_server Openvpn 2.0.5 (including) 2.0.5 (including)

References