Aktualizacja OpenVPN 2.4.9

Uformowane poprawka pakietu do tworzenia wirtualnych sieci prywatnych OpenVPN 2.4.9. W nowej wersji naprawiono vulnerability (CVE-2020-11810) that allows a client session to be switched to a new IP address that was not previously authorized. This issue can be exploited to interrupt just connected clients at the stage when the peer-id has already been formed, but the session key agreement has not been completed (one client can stop the sessions of other clients).

Wśród innych zmian:

  • On the Windows platform, it is allowed to use search unicode strings in the option "—cryptoapicert";
  • Bypassing expired certificates in the Windows certificate store is ensured;
  • Resolved an issue with the inability to load multiple CRLs (Certificate Revocation Lists) hosted in one file when using the "—crl-verify" option on systems with OpenSSL;
  • When using the option "—auth-user-pass file" with a file containing only a username for password request, an interface for managing credentials is now required (requesting a password through OpenVPN via console prompt output has been discontinued);
  • The order of checking user interactive services has been changed (on Windows, the configuration location is first checked, and then a request is sent to the domain controller);
  • Issues with building on the FreeBSD platform when using the flag "—enable-async-push" have been resolved.

Źródło: opennet.ru

Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS 🔥 Kup solidny hosting stron z ochroną przed DDoS, serwery VPS VDS | ProHoster