OpenVPN 2.5.2 and 2.4.11 Update Addressing Vulnerability

Corrective releases for OpenVPN 2.5.2 and 2.4.11 have been prepared. This package enables the creation of virtual private networks, allowing for an encrypted connection between two client machines or enabling a centralized VPN server for simultaneous client operation. The OpenVPN code is distributed under the GPLv2 license, and ready-to-use binary packages are available for Debian, Ubuntu, CentOS, RHEL, and Windows.

The new releases fix a vulnerability (CVE-2020-15078) that allows a remote attacker to bypass authentication and access controls, potentially leading to data leakage about VPN settings. This issue only occurs on servers configured to use deferred authentication. Under certain circumstances, an attacker may compel the server to return a PUSH_REPLY message containing configuration data before sending an AUTH_FAILED message. When combined with the use of the '--auth-gen-token' parameter or a user-defined token-based authentication scheme, this vulnerability may permit access to the VPN using a non-operational account. VPN Among the non-security-related changes is the expanded output of information about TLS ciphers agreed upon for client usage, including accurate details regarding support for TLS 1.3 and EC certificates. Furthermore, the absence of a CRL file containing a list of revoked certificates at the start of OpenVPN is now treated as an error, leading to the termination of the application.

Release of Chrome OS 90 proxy serverCorrective releases for OpenVPN 2.5.2 and 2.4.11 have been prepared. This package allows for encrypted connections between two client machines or establishes a centralized VPN server operation.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster