From e748ba9741f6540f4675c23e3e37b73e822c13a4 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 31 May 2021 20:59:14 +0100 Subject: gentoo resync : 31.05.2021 --- metadata/glsa/glsa-202105-25.xml | 49 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 metadata/glsa/glsa-202105-25.xml (limited to 'metadata/glsa/glsa-202105-25.xml') diff --git a/metadata/glsa/glsa-202105-25.xml b/metadata/glsa/glsa-202105-25.xml new file mode 100644 index 000000000000..da213f1833fc --- /dev/null +++ b/metadata/glsa/glsa-202105-25.xml @@ -0,0 +1,49 @@ + + + + OpenVPN: Authentication bypass + A vulnerability has been found in OpenVPN, allowing attackers to + bypass the authentication process. + + openvpn + 2021-05-26 + 2021-05-26 + 785115 + remote + + + 2.5.2 + 2.5.2 + + + +

OpenVPN is a multi-platform, full-featured SSL VPN solution.

+
+ +

It was discovered that OpenVPN incorrectly handled deferred + authentication. +

+
+ +

A remote attacker could bypass authentication and access control channel + data and trigger further information leaks. +

+
+ +

Configure OpenVPN server to not use deferred authentication.

+
+ +

All OpenVPN users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-vpn/openvpn-2.5.2" + + +
+ + CVE-2020-15078 + + whissi + whissi +
-- cgit v1.2.3