Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.
| Software | From | Fixed in |
|---|---|---|
| openvpn / openvpn | 2.0 | 2.0.x |
| openvpn / openvpn | 2.0_beta11 | 2.0_beta11.x |
| openvpn / openvpn_access_server | 2.0.1 | 2.0.1.x |
| openvpn / openvpn_access_server | 2.0.2 | 2.0.2.x |