A corrective release of OpenVPN 2.5.3 has been prepared, a package for creating virtual private networks that allows for an encrypted connection between two client machines or enables the operation of a centralized VPN server for simultaneous work with multiple clients. The OpenVPN code is distributed under the GPLv2 license, and ready binary packages are generated for Debian, Ubuntu, CentOS, RHEL, and Windows.
In the new version, a vulnerability (CVE-2021-3606) has been fixed, which only manifested in the build for the Windows platform. This vulnerability allowed the loading of OpenSSL configuration files from writable external directories, altering encryption settings. In the new version, loading OpenSSL configuration files is completely disabled.
Among the non-security-related changes, the addition of the ‘—auth-token-user’ option (similar to ‘—auth-token’ but without applying ‘—auth-user-pass’), improvements in the build process for Windows, enhanced support for the mbedtls library, and updates to copyright notices in the code (cosmetic changes) are noted.
Additionally, it is worth mentioning that Opera has disabled its VPN for Russian users at the request of Roskomnadzor. Currently, the VPN functionality has stopped working in the beta and developer versions of the browser. Roskomnadzor claims that the restrictions are necessary for 'responding to threats of bypassing restrictions on access to child pornography, suicidal, drug-related, and other prohibited content.' In addition to Opera VPN, the blocking has also been applied to the VyprVPN service.
Earlier, Roskomnadzor sent warnings to 10 VPN services demanding 'connection to the state information system (FGIS)' to block access to prohibited resources in Russia, with Opera VPN and VyprVPN among them. 9 out of 10 services ignored the requirement or refused to cooperate with Roskomnadzor (NordVPN, Hide My Ass!, Hola VPN, OpenVPN, VyprVPN, ExpressVPN, TorGuard, IPVanish, VPN Unlimited). Only the Kaspersky Secure Connection product complied with the requirements.
Source: opennet.ru
