Correction releases for OpenVPN 2.5.6 and 2.4.12 have been prepared. This package for creating virtual private networks allows for encrypted connections between two client machines or enables the operation of a centralized VPN server for simultaneous client connections. The OpenVPN code is distributed under the GPLv2 license, and ready binary packages are available for Debian, Ubuntu, CentOS, RHEL, and Windows.
The new versions address a vulnerability that could potentially bypass authentication through manipulation of external plugins supporting deferred authentication mode (deferred_auth). The issue arises when multiple plugins send deferred authentication responses, allowing an external user to gain access based on incomplete credentials. Starting with the releases of OpenVPN 2.5.6 and 2.4.12, attempts to use deferred authentication with multiple plugins will result in an error message.
Other changes include the addition of the new plugin sample-plugin/defer/multi-auth.c, which can be useful for testing the simultaneous use of different authentication plugins to prevent vulnerabilities similar to the one discussed above. On the Linux platform, the option '—mtu-disc maybe|yes' has been established. A memory leak in the route addition procedures has been fixed.
Source: opennet.ru
