The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://community.openvpn.net/Security%20Announcements/CVE-2025-3908 | vendor advisory |
http://www.openwall.com/lists/oss-security/2025/05/20/2 | mailing list |