CVE Vulnerabilities

CVE-2008-3459

Published: Aug 04, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

Affected Software

Name Vendor Start Version End Version
Openvpn Openvpn 2.1-beta-14 (including) 2.1-beta-14 (including)
Openvpn Openvpn 2.1-beta-15 (including) 2.1-beta-15 (including)
Openvpn Openvpn 2.1-beta-16 (including) 2.1-beta-16 (including)
Openvpn Openvpn 2.1-rc_1 (including) 2.1-rc_1 (including)
Openvpn Openvpn 2.1-rc_2 (including) 2.1-rc_2 (including)
Openvpn Openvpn 2.1-rc_3 (including) 2.1-rc_3 (including)
Openvpn Openvpn 2.1-rc_4 (including) 2.1-rc_4 (including)
Openvpn Openvpn 2.1-rc_5 (including) 2.1-rc_5 (including)
Openvpn Openvpn 2.1-rc_6 (including) 2.1-rc_6 (including)
Openvpn Openvpn 2.1-rc_7 (including) 2.1-rc_7 (including)
Openvpn Openvpn 2.1-rc_8 (including) 2.1-rc_8 (including)
Openvpn Ubuntu hardy *
Openvpn Ubuntu upstream *

References