CVE-2008-3459
EPSS 0.59%
Description
Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.
How to fix CVE-2008-3459
To remediate CVE-2008-3459, upgrade the affected package to a fixed version below.
- Debian/openvpn—upgrade to 2.1~rc9-1 or later
Is CVE-2008-3459 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.1~rc9-1