OpenVPN 3 Linux Symlink Vulnerability in Configuration Initialization Tool

Vulnerability

A vulnerability in the configuration initialization tool of OpenVPN 3 Linux, specifically in versions 20 through 24, allows local attackers to exploit symlinks that point to arbitrary directories. This exploitation can lead to unauthorized changes in ownership and permissions of the targeted directories.

Impact

Exploitation of this vulnerability could result in unauthorized modification of directory ownership and permissions, potentially leading to further privilege escalation or unauthorized access to sensitive files.

Remediation

Users can upgrade to OpenVPN 3 Linux version 24.1, released on May 19, 2025, to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.