Back to Database
Status published
Critical
CVE-2006-1629
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute...
Vulnerability Description
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-1629
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25667
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:069
- http://www.vupen.com/english/advisories/2006/1261
- http://www.securityfocus.com/bid/17392
- http://openvpn.net/changelog.html
- http://www.osreviews.net/reviews/security/openvpn-print
- http://secunia.com/advisories/19531
- http://www.debian.org/security/2006/dsa-1045
- http://secunia.com/advisories/19598
- http://sourceforge.net/mailarchive/forum.php?thread_id=10093825&forum_id=8482
- http://secunia.com/advisories/19837
- http://www.osvdb.org/24444
- http://secunia.com/advisories/19897
- http://www.novell.com/linux/security/advisories/2006_04_28.html
More from openvpn
View All →CVE-2020-9442
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN...
High
7.8
CVE-2020-8953
OpenVPN Access Server 2.8.x before 2.8.1 allows LDAP authentication bypass...
Critical
9.8
CVE-2020-20813
Control Channel in OpenVPN 2.4.7 and earlier allows remote attackers...
High
7.5
CVE-2020-11810
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An...
Low
3.7
CVE-2020-11462
An issue was discovered in OpenVPN Access Server before 2.7.0...
High
7.5
Affected Vendor
openvpn
View all reports →Affected Software
openvpn, openvpn access server
Vulnerable Versions:
2.0, 2.0.4, 2.0.1, 2.0.2, 2.0.3, 2.0.5
Timeline
Official Publish:
April 6th, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.