CVE-2006-1629: Critical severity openvpn openvpn vulnerability
Published Apr 6, 2006
·Updated
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LDPRELOAD environment variable.
Affected Software
6 affected components
OpenVPN OpenVPN=2.0
OpenVPN OpenVPN=2.0.4
OpenVPN OpenVPN Access Server=2.0.1
OpenVPN OpenVPN Access Server=2.0.2
OpenVPN OpenVPN Access Server=2.0.3
OpenVPN OpenVPN Access Server=2.0.5
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 6, 2006
CVE Published
10:04 PM
Apr 7, 2006
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1629?
CVE-2006-1629 is classified as a critical vulnerability due to its ability to allow execution of arbitrary code on client machines.
2
How do I fix CVE-2006-1629?
To fix CVE-2006-1629, users should upgrade to OpenVPN version 2.0.6 or later, which addresses the vulnerability.
3
Which versions of OpenVPN are affected by CVE-2006-1629?
OpenVPN versions 2.0 through 2.0.5, including OpenVPN Access Server versions 2.0.1 through 2.0.5, are affected by CVE-2006-1629.
4
Can CVE-2006-1629 be exploited remotely?
Yes, CVE-2006-1629 can be exploited remotely by malicious servers manipulating the LD_PRELOAD environment variable.
5
What type of vulnerability is CVE-2006-1629?
CVE-2006-1629 is an arbitrary code execution vulnerability that affects the OpenVPN client.