Package name openvpn
Date April 10th, 2006
Advisory ID MDKSA-2006:069
Affected versions MNF2.0, 2006.0
Synopsis Updated openvpn packages fix vulnerability

Problem Description

A vulnerability in OpenVPN 2.0 through 2.0.5 allows a malicious server
to execute arbitrary code on the client by using setenv with the
LD_PRELOAD environment variable.

Updated packages have been patched to correct this issue by removing
setenv support.

Updated Packages

Multi Network Firewall 2.0

Mandriva Linux 2006

Mandriva Linux 2006/X86_64

