a patch release for creating virtual private networks . In the new version vulnerability (CVE-2020-11810) that allows a client's session to be transferred to a new IP address that was not previously authorized. This issue can be exploited to a newly connected client during the phase when the peer-id has been generated but the session key negotiation has not been completed (one client can disrupt the sessions of other clients).
Among other changes:
- On the Windows platform, it is now allowed to use search Unicode strings in the ââcryptoapicertâ option;
- Expired certificates in the Windows certificate store are now bypassed;
- Resolved the issue where multiple CRLs (Certificate Revocation Lists) hosted in a single file could not be loaded when using the ââcrl-verifyâ option on systems with OpenSSL;
- When using the ââauth-user-pass fileâ option with only the username present in the file for password prompts, an interface for managing credentials is now required (password prompts through OpenVPN's console output have been discontinued);
- The order of checking user interactive services has been changed (in Windows, the configuration location is checked first, followed by a query to the domain controller);
- Build issues on the FreeBSD platform when using the ââenable-async-pushâ flag have been resolved.
Source: opennet.ru
