摘要:
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
安全等级: Low
公告ID: KylinSec-SA-2024-2214
发布日期: 2024年5月27日
关联CVE: CVE-2023-7235
The OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables.
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2023-7235 | KY3.4-4A | openvpn | Unaffected |
CVE-2023-7235 | KY3.4-5 | openvpn | Unaffected |
CVE-2023-7235 | KY3.5.1 | openvpn | Unaffected |
CVE-2023-7235 | KY3.5.2 | openvpn | Unaffected |