CVE Vulnerabilities

CVE-2008-3459

Published: Aug 04, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

Affected Software

Name Vendor Start Version End Version
Openvpn Openvpn 2.1-beta-14 (including) 2.1-beta-14 (including)
Openvpn Openvpn 2.1-beta-15 (including) 2.1-beta-15 (including)
Openvpn Openvpn 2.1-beta-16 (including) 2.1-beta-16 (including)
Openvpn Openvpn 2.1-rc_1 (including) 2.1-rc_1 (including)
Openvpn Openvpn 2.1-rc_2 (including) 2.1-rc_2 (including)
Openvpn Openvpn 2.1-rc_3 (including) 2.1-rc_3 (including)
Openvpn Openvpn 2.1-rc_4 (including) 2.1-rc_4 (including)
Openvpn Openvpn 2.1-rc_5 (including) 2.1-rc_5 (including)
Openvpn Openvpn 2.1-rc_6 (including) 2.1-rc_6 (including)
Openvpn Openvpn 2.1-rc_7 (including) 2.1-rc_7 (including)
Openvpn Openvpn 2.1-rc_8 (including) 2.1-rc_8 (including)
Openvpn Ubuntu hardy *
Openvpn Ubuntu upstream *

References