From d362a8d7226be4321dac701e61dbb7d5bb41e13a90730325759b6e63a69baea5 Mon Sep 17 00:00:00 2001 From: OBS User buildservice-autocommit Date: Fri, 11 Jun 2021 20:30:29 +0000 Subject: [PATCH] Accepting request 898085 from network:vpn baserev update by copy to link target OBS-URL: https://build.opensuse.org/request/show/898085 OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=163 --- openvpn.changes | 17 ----------------- 1 file changed, 17 deletions(-) diff --git a/openvpn.changes b/openvpn.changes index 56706da..4bcba90 100644 --- a/openvpn.changes +++ b/openvpn.changes @@ -1,23 +1,6 @@ ------------------------------------------------------------------- Mon May 31 15:29:08 UTC 2021 - Dirk Müller -- update to 2.4.11 (bsc#1185279): - * CVE-2020-15078 see https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements - - * This bug allows - under very specific circumstances - to trick a server using - delayed authentication (plugin or management) into returning a PUSH_REPLY - before the AUTH_FAILED message, which can possibly be used to gather - information about a VPN setup. - * In combination with "--auth-gen-token" or an user-specific token auth - solution it can be possible to get access to a VPN with an - otherwise-invalid account. - * Fix potential NULL ptr crash if compiled with DMALLOC -- drop sysv5 init support, it hasn't build successfully in ages - and is build-disabled in devel project - -------------------------------------------------------------------- -Mon May 31 15:29:08 UTC 2021 - Dirk Müller - - update to 2.4.11 (bsc#1185279): * CVE-2020-15078 see https://community.openvpn.net/openvpn/wiki/SecurityAnnouncements