<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openvpn.git/debian/patches/CVE-2017-7508.patch, branch stretch</title>
<subtitle>Debian repo for openvpn</subtitle>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/'/>
<entry>
<title>Import Debian changes 2.4.0-6+deb9u1</title>
<updated>2017-06-29T19:26:15+00:00</updated>
<author>
<name>Alberto Gonzalez Iniesta</name>
<email>agi@inittab.org</email>
</author>
<published>2017-06-22T16:00:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=3637e1aa7ac62f0bba5e9a196e42f22cb93a498b'/>
<id>3637e1aa7ac62f0bba5e9a196e42f22cb93a498b</id>
<content type='text'>
openvpn (2.4.0-6+deb9u1) stretch-security; urgency=high

   * SECURITY UPDATE: (Closes: #865480)
     - CVE-2017-7508.patch. Fix remotely-triggerable ASSERT() on malformed IPv6
       packet.
     - CVE-2017-7520.patch. Prevent two kinds of stack buffer OOB reads and a
       crash for invalid input data.
     - CVE-2017-7521.patch. Fix potential double-free in --x509-alt-username.
     - CVE-2017-7521bis.patch. Fix remote-triggerable memory leaks.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
openvpn (2.4.0-6+deb9u1) stretch-security; urgency=high

   * SECURITY UPDATE: (Closes: #865480)
     - CVE-2017-7508.patch. Fix remotely-triggerable ASSERT() on malformed IPv6
       packet.
     - CVE-2017-7520.patch. Prevent two kinds of stack buffer OOB reads and a
       crash for invalid input data.
     - CVE-2017-7521.patch. Fix potential double-free in --x509-alt-username.
     - CVE-2017-7521bis.patch. Fix remote-triggerable memory leaks.
</pre>
</div>
</content>
</entry>
</feed>
