Blame
| d7f686 | David Sommerseth | 2025-05-19 14:58:36 | 1 | # CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink |
| b89af0 | David Sommerseth | 2025-05-20 09:47:28 | 2 | The OpenVPN 3 Linux v20 introduced a new command, `openvpn3-admin init-config`, to help getting an initial base configuration adopted to the currently running host. This command must be run as `root`. |
| cf36d0 | David Sommerseth | 2025-05-16 20:10:35 | 3 | |
| b89af0 | David Sommerseth | 2025-05-20 09:47:28 | 4 | It was discovered that this tool will follow symlinks when changing ownership and permissions on two of the directories the OpenVPN 3 Linux D-Bus services depends on. |
| 5 | ||||
| 6 | All versions from v20 through v24 are affected. This has been resolved in OpenVPN 3 Linux v24.1. |
|||
| d7f686 | David Sommerseth | 2025-05-19 14:58:36 | 7 | |
| 8 | https://www.cve.org/CVERecord?id=CVE-2025-3908 |
|||
| 9 | ||||
| 10 | Reported by: Wolfgang Frisch, SUSE Security team |
