The OpenVPN 2.7_alpha1 through 2.7_beta1 releases are susceptible to script injection attacks when connecting to untrusted VPN services.
-
The pushed --dns and --dhcp-option arguments are not properly sanitised when passing them to the --dns-updown script hook, allowing them to inject additional commands being performed on the client.
+
The pushed `--dns` and `--dhcp-option` arguments are not properly sanitised when passing them to the `--dns-updown` script hook, allowing them to inject additional commands being performed on the client.
-
This iisue affects only POSIX platforms, such as BSD, Linux, MacOS and similar platforms.
+
This issue affects only POSIX platforms, such as BSD, Linux, MacOS and similar platforms.