OpenVPN 2.4.9 ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ

ื’ืขืฉืืคืŸ ืงืขืจืขืงื˜ื™ื•ื• ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืึท ืคึผืขืงืœ ืคึฟืึทืจ ืงืจื™ื™ื™ื˜ื™ื ื’ ื•ื•ื™ืจื˜ื•ืึทืœ ืคึผืจื™ื•ื•ืึทื˜ ื ืขื˜ื•ื•ืึธืจืงืก OpenVPN 2.4.9. ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ื™ืœื™ืžืึทื ื™ื™ื˜ืึทื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2020-11810) ื•ื•ืึธืก ืึทืœืึทื•ื– ืึท ืงืœื™ืขื ื˜ ืกืขืกื™ืข ืฆื• ื–ื™ื™ืŸ ื˜ืจืึทื ืกืคืขืจื“ ืฆื• ืึท ื ื™ื™ึทืข IP ืึทื“ืจืขืก ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ื‘ื™ื– ืึทื”ืขืจ ืึธื˜ืขืจื™ื™ื–ื“. ื“ื™ ืคึผืจืึธื‘ืœืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืฆื• ื™ื ื˜ืขืจืึทืคึผืฉืึทื ื– ืึท ื ื™ื™ ืคืืจื‘ื•ื ื“ืŸ ืงืœื™ืขื ื˜ ืื™ืŸ ื“ืขืจ ื‘ื™ื ืข ื•ื•ืขืŸ ื“ื™ ื™ื™ึทื ืงื•ืงื -ืฉื™ื™ึทืŸ ืื™ื– ืฉื•ื™ืŸ ื’ืขืฉืืคืŸ, ืึธื‘ืขืจ ื“ื™ ืคืึทืจื”ืึทื ื“ืœื•ื ื’ ืคื•ืŸ ืกืขืกื™ืข ืฉืœื™ืกืœืขืŸ ืื™ื– ื ื™ืฉื˜ ื’ืขืขื ื“ื™ืงื˜ (ืื™ื™ืŸ ืงืœื™ืขื ื˜ ืงืขื ืขืŸ ื”ืึทืœื˜ืŸ ื“ื™ ืกืขืฉืึทื ื– ืคื•ืŸ ืื ื“ืขืจืข ืงืœื™ื™ืึทื ืฅ).

ืื ื“ืขืจืข ืขื ื“ืขืจื•ื ื’ืขืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ:

  • ืื•ื™ืฃ ื“ื™ Windows ืคึผืœืึทื˜ืคืึธืจืžืข, ืขืก ืื™ื– ื“ืขืจืœื•ื™ื‘ื˜ ืฆื• ื ื•ืฆืŸ ืื•ื ื™ืงืึธื“ ื–ื•ื›ืŸ ืกื˜ืจื™ื ื’ืก ืื™ืŸ ื“ื™ "-cryptoapicert" ืึธืคึผืฆื™ืข;
  • ื™ื ืฉื•ืจื– ืึทื– ืื•ื™ืกื’ืขื’ืื ื’ืขืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื–ืขื ืขืŸ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืื™ืŸ ื“ื™ Windows ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืงืจืึธื;
  • ื“ื™ ืคึผืจืึธื‘ืœืขื ืžื™ื˜ ื“ื™ ื™ื ืึทื‘ื™ืœื™ื˜ื™ ืฆื• ืœืึธื“ืŸ ืขื˜ืœืขื›ืข CRLs (Certificate Revocation List) ืื™ืŸ ืื™ื™ืŸ ื˜ืขืงืข ื•ื•ืขืŸ ื ื™ืฆืŸ ื“ื™ "--crl-verify" ืึธืคึผืฆื™ืข ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ืžื™ื˜ OpenSSL ืื™ื– ืกืึทืœื•ื•ื“;
  • ื•ื•ืขืŸ ืื™ืจ ื ื•ืฆืŸ ื“ื™ ืึธืคึผืฆื™ืข "-auth-user-pass file", ืื•ื™ื‘ ืขืก ืื™ื– ื‘ืœื•ื™ื– ืึท ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืื™ืŸ ื“ืขืจ ื˜ืขืงืข, ืฆื• ื‘ืขื˜ืŸ ืึท ืคึผืึทืจืึธืœ, ืึท ืฆื•ื‘ื™ื ื“ ืคึฟืึทืจ ืึธื ืคื™ืจื•ื ื’ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ืื™ื– ืื™ืฆื˜ ืคืืจืœืื ื’ื˜ (ืจื™ืงื•ื•ืขืก ืึท ืคึผืึทืจืึธืœ ื ื™ืฆืŸ OpenVPN ื“ื•ืจืš ืึท ืคึผื™ื ื˜ืœืขืš ืื™ืŸ ื“ื™ ืงืึทื ืกืึธื•ืœ ืื™ื– ืฉื•ื™ืŸ ื ื™ื˜ ืžืขื’ืœืขืš);
  • ื“ืขืจ ืกื“ืจ ืคื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื• ื‘ืึทื“ื™ื ื•ื ื’ืก ืคื•ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ื– ืคืืจืขื ื“ืขืจื˜ (ืื™ืŸ Windows, ื“ื™ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ืึธืจื˜ ืื™ื– ืขืจืฉื˜ืขืจ ืึธืคึผื’ืขืฉื˜ืขืœื˜, ืื•ืŸ ื“ืขืžืึธืœื˜ ืึท ื‘ืงืฉื” ืื™ื– ื’ืขืฉื™ืงื˜ ืฆื• ื“ื™ ืคืขืœื“ ืงืึธื ื˜ืจืึธืœืœืขืจ);
  • ืคืึทืจืคืขืกื˜ื™ืงื˜ ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื‘ื ื™ืŸ ืื•ื™ืฃ ื“ื™ FreeBSD ืคึผืœืึทื˜ืคืึธืจืžืข ื•ื•ืขืŸ ื ื™ืฆืŸ ื“ื™ "--enable-async-push" ืคืึธืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’