Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenVPN客户端远程格式串处理漏洞
Vulnerability Description
OpenVPN是美国OpenVPN公司的一个用于创建虚拟专用网络(VPN)加密通道的软件包,它使用OpenSSL库来加密数据与控制信息,并允许创建的VPN使用公开密钥、电子证书或者用户名/密码来进行身份验证。 OpenVPN中存在远程格式串处理漏洞,远程攻击者可能利用此漏洞在主机上执行任意指令。恶意的服务器可以向客户端发送包含有格式标识符的特制命令选项,如dhcp-option,导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A