Back

CVE-2005-3393

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

Published: Nov 1, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
openvpn openvpn 2.0
openvpn openvpn 2.0_beta11
openvpn openvpn_access_server 2.0.1
openvpn openvpn_access_server 2.0.2

GitHub Security Advisory GHSA-26pq-368c-c8f2

Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.48%

Top 12% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub