Beveiligingsadvies

CVE-2025-3908

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-19 14:59:08
Laatst bijgewerkt 2025-05-20 18:04:08
Toegewezen door OpenVPN
CVSS-score 6.2
Status PUBLISHED

Beschrijving

The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.