Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 32 FEDORA-2021-d6b9d8497b Moderate: OpenVPN Authentication Bypass

fedora
Calendar Grey April 28, 2021
Dist Fedora Esm H88
An update for OpenVPN on Fedora 32 tackles vulnerabilities related to authentication bypass and possible data exposure risks from external threats.
Security update - OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authenti...

Summary

OpenVPN is a robust and highly flexible tunneling application that uses all

of the encryption, authentication, and certification features of the

OpenSSL library to securely tunnel IP networks over a single UDP or TCP

port. It can use the Marcus Franz Xaver Johannes Oberhumers LZO library

for compression.

Security update - OpenVPN 2.5.1 and earlier versions allows a remote attackers

to bypass authentication and access control channel data on servers configured

with deferred authentication, which can be used to potentially trigger further

information leaks. (CVE-2020-15078)

* Wed Apr 21 2021 David Sommerseth - 2.4.11-1

- Update to upstream OpenVPN 2.4.11

- Fixes CVE-2020-15078

su -c 'dnf upgrade --advisory FEDORA-2021-d6b9d8497b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Change Log

References

Update Instructions

Product: Fedora 32
Version: 2.4.11
Release: 1.fc32
URL:
Summary: A full-featured SSL VPN solution

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here