CVE-2008-3459
published 2008-08-04CVE-2008-3459: Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via…
PriorityP342high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
2.12%
79.8th percentile
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openvpn | < openvpn 2.1~rc9-1 (bookworm) | openvpn 2.1~rc9-1 (bookworm) |
| openvpn | openvpn | — | — |
| openvpn | openvpn | >= 0 < 2.1~rc9-1 | 2.1~rc9-1 |
| openvpn | openvpn | >= 0 < 2.1~rc9-1 | 2.1~rc9-1 |
| openvpn | openvpn | >= 0 < 2.1~rc9-1 | 2.1~rc9-1 |
| openvpn | openvpn | >= 0 < 2.1~rc9-1 | 2.1~rc9-1 |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.6HIGH
vendor_debian7.6LOW
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w779-ggw7-rxjh: Unspecified vulnerability in OpenVPN 2
ghsa_unreviewed·2022-05-02
CVE-2008-3459 [HIGH] GHSA-w779-ggw7-rxjh: Unspecified vulnerability in OpenVPN 2
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
OSV
CVE-2008-3459: Unspecified vulnerability in OpenVPN 2
osv·2008-08-04·CVSS 7.6
CVE-2008-3459 [HIGH] CVE-2008-3459: Unspecified vulnerability in OpenVPN 2
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
Debian
CVE-2008-3459: openvpn - Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on...
vendor_debian·2008·CVSS 7.6
CVE-2008-3459 [HIGH] CVE-2008-3459: openvpn - Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on...
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
Scope: local
bookworm: resolved (fixed in 2.1~rc9-1)
bullseye: resolved (fixed in 2.1~rc9-1)
forky: resolved (fixed in 2.1~rc9-1)
sid: resolved (fixed in 2.1~rc9-1)
trixie: resolved (fixed in 2.1~rc9-1)
Red Hat
openvpn: client command execution through remotely received configuration directives
vendor_redhat·CVSS 7.6
CVE-2008-3459 [HIGH] openvpn: client command execution through remotely received configuration directives
openvpn: client command execution through remotely received configuration directives
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
No detection rules found.
No public exploits indexed.
http://openvpn.net/index.php/documentation/change-log/changelog-21.htmlhttp://www.securityfocus.com/bid/30532http://www.securitytracker.com/id?1020626http://www.vupen.com/english/advisories/2008/2316https://exchange.xforce.ibmcloud.com/vulnerabilities/44209http://openvpn.net/index.php/documentation/change-log/changelog-21.htmlhttp://www.securityfocus.com/bid/30532http://www.securitytracker.com/id?1020626http://www.vupen.com/english/advisories/2008/2316https://exchange.xforce.ibmcloud.com/vulnerabilities/44209
2008-08-04
Published