<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openvpn.git/debian, branch debian/2.5.1-2</title>
<subtitle>Debian repo for openvpn</subtitle>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/'/>
<entry>
<title>Changelog for 2.5.1-2</title>
<updated>2021-04-28T13:13:12+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-04-28T12:42:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=97fe526142e16e550572991c109f7926cc444cbc'/>
<id>97fe526142e16e550572991c109f7926cc444cbc</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>CVE-2020-15078: Authentication bypass with deferred authentication</title>
<updated>2021-04-28T13:12:01+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-04-28T12:38:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=a398f557fd1320096e140f8ca297481ae75e12b3'/>
<id>a398f557fd1320096e140f8ca297481ae75e12b3</id>
<content type='text'>
Overview

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass
authentication and access control channel data on servers configured
with deferred authentication, which can be used to potentially trigger
further information leaks.

Detailed description

This bug allows - under very specific circumstances - to trick a server
using delayed authentication (plugin or management) into returning a
PUSH_REPLY before the AUTH_FAILED message, which can possibly be used
to gather information about a VPN setup.

In combination with "--auth-gen-token" or a user-specific token auth
solution it can be possible to get access to a VPN with an
otherwise-invalid account.

Pre-Dependency:
CVE-2020-15078-0.patch: https://github.com/OpenVPN/openvpn/commit/14511010

CVE-Fix:
CVE-2020-15078-1.patch: https://github.com/OpenVPN/openvpn/commit/3aca477a
CVE-2020-15078-2.patch: https://github.com/OpenVPN/openvpn/commit/3d18e308
CVE-2020-15078-3.patch: https://github.com/OpenVPN/openvpn/commit/f7b3bf06

Closes: #987380
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Overview

OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass
authentication and access control channel data on servers configured
with deferred authentication, which can be used to potentially trigger
further information leaks.

Detailed description

This bug allows - under very specific circumstances - to trick a server
using delayed authentication (plugin or management) into returning a
PUSH_REPLY before the AUTH_FAILED message, which can possibly be used
to gather information about a VPN setup.

In combination with "--auth-gen-token" or a user-specific token auth
solution it can be possible to get access to a VPN with an
otherwise-invalid account.

Pre-Dependency:
CVE-2020-15078-0.patch: https://github.com/OpenVPN/openvpn/commit/14511010

CVE-Fix:
CVE-2020-15078-1.patch: https://github.com/OpenVPN/openvpn/commit/3aca477a
CVE-2020-15078-2.patch: https://github.com/OpenVPN/openvpn/commit/3d18e308
CVE-2020-15078-3.patch: https://github.com/OpenVPN/openvpn/commit/f7b3bf06

Closes: #987380
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5.1-1</title>
<updated>2021-02-24T18:54:59+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2021-02-24T18:54:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=a8b5c8b8223889ccbb3f415ba206027a4f1b3b67'/>
<id>a8b5c8b8223889ccbb3f415ba206027a4f1b3b67</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5.0-1</title>
<updated>2020-10-28T18:39:28+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-10-28T18:39:28+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=76fee93e6fe89e5575bae2840b585d2f025b9050'/>
<id>76fee93e6fe89e5575bae2840b585d2f025b9050</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5~rc3-1</title>
<updated>2020-10-20T17:18:06+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-10-20T17:18:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=e366d0b3bf15f6e839f52229d3bd4d8d333cea46'/>
<id>e366d0b3bf15f6e839f52229d3bd4d8d333cea46</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5~rc2-1</title>
<updated>2020-09-30T19:12:32+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-09-30T19:12:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=4ca7910f8fbd80a28780cff34d27b481ae882f67'/>
<id>4ca7910f8fbd80a28780cff34d27b481ae882f67</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Downgrade debhelper-compat to 12 for easier backports</title>
<updated>2020-09-30T19:10:36+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-09-30T19:10:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=b97ad09a3b8c0017db0a677667a7215f1a98cccf'/>
<id>b97ad09a3b8c0017db0a677667a7215f1a98cccf</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Changelog for 2.5~beta3-1</title>
<updated>2020-09-01T14:55:17+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-09-01T14:55:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=457cf61d5ab5ff5643e0b9d58a790f3ed2bdcec9'/>
<id>457cf61d5ab5ff5643e0b9d58a790f3ed2bdcec9</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Revert "d/gbp.conf for experimental 2.5 branch"</title>
<updated>2020-09-01T14:53:07+00:00</updated>
<author>
<name>Bernhard Schmidt</name>
<email>berni@debian.org</email>
</author>
<published>2020-09-01T14:53:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=9ce71e1c58a83737b045861173254911fda9a76a'/>
<id>9ce71e1c58a83737b045861173254911fda9a76a</id>
<content type='text'>
This reverts commit d3986a312f5fbcfd0e78e6b147eef419fb4e5f54.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit d3986a312f5fbcfd0e78e6b147eef419fb4e5f54.
</pre>
</div>
</content>
</entry>
<entry>
<title>Drop reload support from systemd unit files (LP: #1868127)</title>
<updated>2020-08-31T23:17:53+00:00</updated>
<author>
<name>Lucas Kanashiro</name>
<email>lucas.kanashiro@canonical.com</email>
</author>
<published>2020-05-26T19:45:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.jff.email/cgit/openvpn.git/commit/?id=69b02b1f7fd609d84ace13ab04697158de2418a9'/>
<id>69b02b1f7fd609d84ace13ab04697158de2418a9</id>
<content type='text'>
The current reload implementation (sending a SIGHUP signal to the
process) fails, and the difference between reload and restart is not
clear. Systemd does not require an implementation for reload.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The current reload implementation (sending a SIGHUP signal to the
process) fails, and the difference between reload and restart is not
clear. Systemd does not require an implementation for reload.
</pre>
</div>
</content>
</entry>
</feed>
