7.6
CVSSv2

CVE-2008-3459

Published: 04/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unspecified vulnerability in OpenVPN 2.1-beta14 up to and including 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

Vulnerable Product Search on Vulmon Subscribe to Product

openvpn openvpn 2.1

Vendor Advisories

Debian Bug report logs - #493488 "CVE-2008-3459: Remote command execution" Package: openvpn; Maintainer for openvpn is Bernhard Schmidt <berni@debianorg>; Source for openvpn is src:openvpn (PTS, buildd, popcon) Reported by: Florian Weimer <fw@denebenyode> Date: Sat, 2 Aug 2008 20:48:02 UTC Severity: grave Tags: ...