<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openvpn.git, branch debian/2.5.1-3</title>
<subtitle>Debian repo for openvpn</subtitle>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/'/>
<entry>
<title>Changelog for 2.5.1-3</title>
<updated>2021-05-14T07:47:35+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-05-14T07:47:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=053febf36f28a97d409738e7e4880dc2130abfb4'/>
<id>053febf36f28a97d409738e7e4880dc2130abfb4</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Cherry-Pick "Fix condition to generate session keys"</title>
<updated>2021-05-14T07:39:26+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-05-14T07:39:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=730212a2ac6d5c920b605763c7b62a7730f5f3f3'/>
<id>730212a2ac6d5c920b605763c7b62a7730f5f3f3</id>
<content type='text'>
Closes: #988478
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Closes: #988478
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix easyrsa invocation in autopkgtest</title>
<updated>2021-05-13T19:47:02+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-05-13T19:47:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=b566f12d3c95e5af707c6683a4959a06af1d8194'/>
<id>b566f12d3c95e5af707c6683a4959a06af1d8194</id>
<content type='text'>
The server-setup-with-ca autopkgtest was failing because easyrsa was
interactively asking for input, although the EASYRSA_BATCH variable
was set. Using the --batch command line option fixes this issue.

Closes: #983662
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The server-setup-with-ca autopkgtest was failing because easyrsa was
interactively asking for input, although the EASYRSA_BATCH variable
was set. Using the --batch command line option fixes this issue.

Closes: #983662
</pre>
</div>
</content>
</entry>
<entry>
<title>Adapt autopkgtest output to 2.5</title>
<updated>2021-05-13T19:34:49+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-05-13T19:34:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=f7be1241bce9ce4960dfcf708cc0a94c02ff55e0'/>
<id>f7be1241bce9ce4960dfcf708cc0a94c02ff55e0</id>
<content type='text'>
OpenVPN 2.5 slightly changed the output of some steps due to
the switch from iproute2 to the newer Netlink based interface.
This was not noticed because the autopkgtest of OpenVPN is not
run in debci infrastructure (machine-isolation not supported)

This patch was imported from Ubuntu, thanks a lot!

Partially fixes Bug#983662, but there is more work to do
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
OpenVPN 2.5 slightly changed the output of some steps due to
the switch from iproute2 to the newer Netlink based interface.
This was not noticed because the autopkgtest of OpenVPN is not
run in debci infrastructure (machine-isolation not supported)

This patch was imported from Ubuntu, thanks a lot!

Partially fixes Bug#983662, but there is more work to do
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5.1-2</title>
<updated>2021-04-28T13:13:12+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-04-28T12:42:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=97fe526142e16e550572991c109f7926cc444cbc'/>
<id>97fe526142e16e550572991c109f7926cc444cbc</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>CVE-2020-15078: Authentication bypass with deferred authentication</title>
<updated>2021-04-28T13:12:01+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-04-28T12:38:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=a398f557fd1320096e140f8ca297481ae75e12b3'/>
<id>a398f557fd1320096e140f8ca297481ae75e12b3</id>
<content type='text'>
Overview

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass
authentication and access control channel data on servers configured
with deferred authentication, which can be used to potentially trigger
further information leaks.

Detailed description

This bug allows - under very specific circumstances - to trick a server
using delayed authentication (plugin or management) into returning a
PUSH_REPLY before the AUTH_FAILED message, which can possibly be used
to gather information about a VPN setup.

In combination with "--auth-gen-token" or a user-specific token auth
solution it can be possible to get access to a VPN with an
otherwise-invalid account.

Pre-Dependency:
CVE-2020-15078-0.patch: https://github.com/OpenVPN/openvpn/commit/14511010

CVE-Fix:
CVE-2020-15078-1.patch: https://github.com/OpenVPN/openvpn/commit/3aca477a
CVE-2020-15078-2.patch: https://github.com/OpenVPN/openvpn/commit/3d18e308
CVE-2020-15078-3.patch: https://github.com/OpenVPN/openvpn/commit/f7b3bf06

Closes: #987380
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Overview

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass
authentication and access control channel data on servers configured
with deferred authentication, which can be used to potentially trigger
further information leaks.

Detailed description

This bug allows - under very specific circumstances - to trick a server
using delayed authentication (plugin or management) into returning a
PUSH_REPLY before the AUTH_FAILED message, which can possibly be used
to gather information about a VPN setup.

In combination with "--auth-gen-token" or a user-specific token auth
solution it can be possible to get access to a VPN with an
otherwise-invalid account.

Pre-Dependency:
CVE-2020-15078-0.patch: https://github.com/OpenVPN/openvpn/commit/14511010

CVE-Fix:
CVE-2020-15078-1.patch: https://github.com/OpenVPN/openvpn/commit/3aca477a
CVE-2020-15078-2.patch: https://github.com/OpenVPN/openvpn/commit/3d18e308
CVE-2020-15078-3.patch: https://github.com/OpenVPN/openvpn/commit/f7b3bf06

Closes: #987380
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5.1-1</title>
<updated>2021-02-24T18:54:59+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-02-24T18:54:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=a8b5c8b8223889ccbb3f415ba206027a4f1b3b67'/>
<id>a8b5c8b8223889ccbb3f415ba206027a4f1b3b67</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Update upstream source from tag 'upstream/2.5.1'</title>
<updated>2021-02-24T18:54:19+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-02-24T18:54:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=d717dbfa8d0807202f5ad05f7db53925cf63a446'/>
<id>d717dbfa8d0807202f5ad05f7db53925cf63a446</id>
<content type='text'>
Update to upstream version '2.5.1'
with Debian dir 7ffab8b9a1f4bee8b10a736ef58cdbac4bfd4b14</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Update to upstream version '2.5.1'
with Debian dir 7ffab8b9a1f4bee8b10a736ef58cdbac4bfd4b14</pre>
</div>
</content>
</entry>
<entry>
<title>New upstream version 2.5.1</title>
<updated>2021-02-24T18:54:12+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-02-24T18:54:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=4ee98f284a93c3b855092d35ac21371d9dcad65b'/>
<id>4ee98f284a93c3b855092d35ac21371d9dcad65b</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5.0-1</title>
<updated>2020-10-28T18:39:28+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-10-28T18:39:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=76fee93e6fe89e5575bae2840b585d2f025b9050'/>
<id>76fee93e6fe89e5575bae2840b585d2f025b9050</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
