CVE-2025-3908
19.05.2025, 15:15
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
Vendor | Product | Version |
---|---|---|
openvpn | openvpn3linux | 20 ≤ 𝑥 ≤ 24 |
𝑥
= Vulnerable software versions