LWN.net Logo

Fedora alert FEDORA-2013-7552 (openvpn)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: openvpn-2.3.1-2.fc17
Date:  Thu, 16 May 2013 02:50:42 +0000
Message-ID:  <20130516025040.DF4EC20C46@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-7552 2013-05-07 17:58:25 -------------------------------------------------------------------------------- Name : openvpn Product : Fedora 17 Version : 2.3.1 Release : 2.fc17 URL : http://openvpn.net/ Summary : A full-featured SSL VPN solution Description : OpenVPN is a robust and highly flexible tunneling application that uses all of the encryption, authentication, and certification features of the OpenSSL library to securely tunnel IP networks over a single UDP or TCP port. It can use the Marcus Franz Xaver Johannes Oberhumer's LZO library for compression. -------------------------------------------------------------------------------- Update Information: Fix for SSL vulnerability. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 8 2013 Kalev Lember <kalevlember@gmail.com> 2.3.1-2 - Update perl requires filtering * Tue Apr 2 2013 Jon Ciesla <limburgher@gmail.com> 2.3.1-1 - 2.3.1, BZ 929402. * Thu Feb 14 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild * Tue Jan 15 2013 Jon Ciesla <limburgher@gmail.com> 2.3.0-1 - 2.3.0, BZ 893700. * Wed Sep 26 2012 Jon Ciesla <limburgher@gmail.com> 2.2.2-9 - Dropped net-tools, BZ 785794. * Wed Sep 5 2012 Jon Ciesla <limburgher@gmail.com> 2.2.2-8 - Dropped config from tmpfiles conf. * Wed Sep 5 2012 Jon Ciesla <limburgher@gmail.com> 2.2.2-7 - Fix tmpfiles location, BZ 840188. - Fix run ownership, BZ 854440. * Fri Jul 20 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.2.2-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild * Thu Apr 12 2012 Jon Ciesla <limburgher@gmail.com> 2.2.2-5 - Add hardened build. -------------------------------------------------------------------------------- References: [ 1 ] Bug #960196 - CVE-2013-2061 openvpn: use of non-constant-time memcmp in HMAC comparison in openvpn_decrypt [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=960196 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openvpn' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds