OpenVPN 3 Linux Symlink Vulnerability in Configuration Initialization Tool
Vulnerability
A vulnerability in the configuration initialization tool of OpenVPN 3 Linux, specifically in versions 20 through 24, allows local attackers to exploit symlinks that point to arbitrary directories. This exploitation can lead to unauthorized changes in ownership and permissions of the targeted directories.
Impact
Exploitation of this vulnerability could result in unauthorized modification of directory ownership and permissions, potentially leading to further privilege escalation or unauthorized access to sensitive files.
Remediation
Users can upgrade to OpenVPN 3 Linux version 24.1, released on May 19, 2025, to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
