SHA256
1
0
forked from pool/openvpn
Go to file
Mohd Saquib 475b121128 Accepting request 1126537 from home:msaquib:branches:network:vpn
- update to 2.6.7:
  * CVE-2023-46850 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly
    use a send buffer after it has been free()d in some circumstances,
    causing some free()d memory to be sent to the peer. All configurations
    using TLS (e.g. not using --secret) are affected by this issue. 
  * CVE-2023-46849 OpenVPN versions between 2.6.0 and 2.6.6 incorrectly
    restore --fragment configuration in some circumstances, leading to a
    division by zero when --fragment is used. On platforms where division
    by zero is fatal, this will cause an OpenVPN crash.
  * DCO: warn if DATA_V1 packets are sent by the other side - this a hard
    incompatibility between a 2.6.x client connecting to a 2.4.0-2.4.4
    server, and the only fix is to use --disable-dco.
  * Remove OpenSSL Engine method for loading a key. This had to be removed
    because the original author did not agree to relicensing the code with
    the new linking exception added. This was a somewhat obsolete feature
    anyway as it only worked with OpenSSL 1.x, which is end-of-support.
  * add warning if p2p NCP client connects to a p2mp server - this is a
    combination that used to work without cipher negotiation (pre 2.6 on
    both ends), but would fail in non-obvious ways with 2.6 to 2.6.
  * add warning to --show-groups that not all supported groups are listed
    (this is due the internal enumeration in OpenSSL being a bit weird,
    omitting X448 and X25519 curves).
  * --dns: remove support for exclude-domains argument (this was a new 2.6
    option, with no backend support implemented yet on any platform, and it
    turns out that no platform supported it at all - so remove option again)
  * warn user if INFO control message too long, do not forward to management
    client (safeguard against protocol-violating server implementations)
  * DCO-WIN: get and log driver version (for easier debugging).
  * print "peer temporary key details" in TLS handshake
  * log OpenSSL errors on failure to set certificate, for example if the

OBS-URL: https://build.opensuse.org/request/show/1126537
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=197
2023-11-15 08:05:59 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=1 2007-01-15 23:28:38 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=1 2007-01-15 23:28:38 +00:00
client-netconfig.down Accepting request 41476 from network:vpn 2010-06-21 17:25:12 +00:00
client-netconfig.up Accepting request 41476 from network:vpn 2010-06-21 17:25:12 +00:00
openvpn-2.3-plugin-man.dif Accepting request 1086749 from home:polslinux:branches:network:vpn 2023-05-12 13:56:37 +00:00
openvpn-2.6.7.tar.gz Accepting request 1126537 from home:msaquib:branches:network:vpn 2023-11-15 08:05:59 +00:00
openvpn-2.6.7.tar.gz.asc Accepting request 1126537 from home:msaquib:branches:network:vpn 2023-11-15 08:05:59 +00:00
openvpn-tmpfile.conf Accepting request 451851 from home:darix:playground 2017-01-24 10:31:30 +00:00
openvpn.changes Accepting request 1126537 from home:msaquib:branches:network:vpn 2023-11-15 08:05:59 +00:00
openvpn.keyring Accepting request 1086749 from home:polslinux:branches:network:vpn 2023-05-12 13:56:37 +00:00
openvpn.README.SUSE - Updated README.SUSE, documented also the rcopenvpn compatibility 2014-01-14 10:46:24 +00:00
openvpn.service - bsc#1123557: --suppress-timestamps isn't needed by default. 2023-01-09 13:30:43 +00:00
openvpn.spec Accepting request 1126537 from home:msaquib:branches:network:vpn 2023-11-15 08:05:59 +00:00
openvpn.target - Fixed openvpn-tmpfile.conf to use GID root, there is no openvpn group. 2013-04-23 13:22:31 +00:00
rcopenvpn Accepting request 888332 from home:cboltz:branches:network:vpn 2021-04-26 07:00:42 +00:00