CVE-2006-1629
EPSS 3.6%openvpn - design error
Published: 4/6/2006Modified: 4/28/2026
Also known as:DEBIAN-CVE-2006-1629
Description
OpenVPN 2.0 through 2.0.5 allows remote malicious servers to execute arbitrary code on the client by using setenv with the LD_PRELOAD environment variable.
Affected packages (2)
- Debian/openvpnfrom 0, < 2.0.6-1
- Debian/openvpnfrom 0, < 2.0-1sarge3