Unrated severityNVD Advisory· Published Nov 1, 2005· Updated Apr 16, 2026
CVE-2005-3393
CVE-2005-3393
Description
Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.
Affected products
4cpe:2.3:a:openvpn:openvpn_access_server:2.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openvpn:openvpn_access_server:2.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:openvpn:openvpn_access_server:2.0.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- secunia.com/advisories/17376nvdPatchVendor Advisory
- www.securityfocus.com/bid/15239nvdPatch
- marc.infonvd
- openvpn.net/changelog.htmlnvd
- secunia.com/advisories/17447nvd
- secunia.com/advisories/17452nvd
- secunia.com/advisories/17480nvd
- www.debian.org/security/2005/dsa-885nvd
- www.gentoo.org/security/en/glsa/glsa-200511-07.xmlnvd
- www.novell.com/linux/security/advisories/2005_25_sr.htmlnvd
- www.securityfocus.com/archive/1/415487nvd
- www.vupen.com/english/advisories/2005/2255nvd
News mentions
0No linked articles in our index yet.