OpenVPN servers can be vulnerable to Shellshock Bash vulnerability
Virtual private network servers based on OpenVPN might be vulnerable to remote code execution attacks through Shellshock and other recent flaws that affect the Bash Unix shell.
The OpenVPN attack vector was described in a post on Hacker News Tuesday by Fredrik Strömberg, co-founder of a commercial VPN service called Mullvad.
“OpenVPN has a number of configuration options that can call custom commands during different stages of the tunnel session,” Strömberg said. “Many of these commands are called with environmental variables set, some of which can be controlled by the client.”
Shellshock and several other flaws found in the Bash Unix shell over the past week stem from errors in how the command-line interpreter parses strings passed to it as environment variables. These strings can be crafted to trick Bash into evaluating parts of them as separate commands.
To read this article in full or to leave a comment, please click here
leave a reply: