poprawka pakietu do tworzenia wirtualnych sieci prywatnych . W nowej wersji vulnerability (CVE-2020-11810) that allows a client session to be switched to a new IP address that was not previously authorized. This issue can be exploited to just connected clients at the stage when the peer-id has already been formed, but the session key agreement has not been completed (one client can stop the sessions of other clients).
Wśród innych zmian:
- On the Windows platform, it is allowed to use search unicode strings in the option "—cryptoapicert";
- Bypassing expired certificates in the Windows certificate store is ensured;
- Resolved an issue with the inability to load multiple CRLs (Certificate Revocation Lists) hosted in one file when using the "—crl-verify" option on systems with OpenSSL;
- When using the option "—auth-user-pass file" with a file containing only a username for password request, an interface for managing credentials is now required (requesting a password through OpenVPN via console prompt output has been discontinued);
- The order of checking user interactive services has been changed (on Windows, the configuration location is first checked, and then a request is sent to the domain controller);
- Issues with building on the FreeBSD platform when using the flag "—enable-async-push" have been resolved.
Źródło: opennet.ru
