CVE Database
/

CVE-2025-3908

Back to search

CVE-2025-3908

Published: May 19, 2025

Modified: May 20, 2025

PUBLISHED

Description

The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.

VendorProductVersions

OpenVPN

OpenVPN 3 Linux

affected
v20 - <= v24

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now