Servers that use the open source OpenVPN for connections running over a virtual private network for security purposes can be compromised using the Shellshock bug in the Bash command line for Linux.
OpenVPN of a "tunnel" between the user and a secure server. It relies on a security protocol using SSL/TLS to exchange encryption keys.
These servers may be put at risk because the software includes configuration options that allow custom commands during the session.
Fredrik Strömberg, co-founder of the Swedish VPN company Mullvad, states in a message that many of the commands are already variables that, in some cases, can also be controlled by the client.
The researcher made the discovery last week and got in touch with the administrators of OpenVPN. VPN service providers that use this package can avoid the Shellshock problem by ensuring that Bash is not used to execute commands.

