CVE-2008-3459

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
openvpnopenvpn
2.1:beta-14
openvpnopenvpn
2.1:beta-15
openvpnopenvpn
2.1:beta-16
openvpnopenvpn
2.1:rc_1
openvpnopenvpn
2.1:rc_2
openvpnopenvpn
2.1:rc_3
openvpnopenvpn
2.1:rc_4
openvpnopenvpn
2.1:rc_5
openvpnopenvpn
2.1:rc_6
openvpnopenvpn
2.1:rc_7
openvpnopenvpn
2.1:rc_8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openvpn
bullseye
2.5.1-3
fixed
etch
not-affected
bookworm
2.6.3-1+deb12u2
fixed
bookworm (security)
2.6.3-1+deb12u2
fixed
sid
2.6.12-1
fixed
trixie
2.6.12-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openvpn
natty
not-affected
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
ignored
gutsy
not-affected
feisty
not-affected
dapper
not-affected
Common Weakness Enumeration