Description
OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable
Problem types
CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Product status
3.0 (minor release)
References
openvpn.net/...sources/openvpn-connect-for-macos-change-log/