|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2014-16273 (openvpn)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 20 Update: openvpn-2.3.6-1.fc20
Date:  Sat, 13 Dec 2014 09:43:06 +0000
Message-ID:  <20141213094330.6D9C260CA22B@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-16273 2014-12-04 05:22:47 -------------------------------------------------------------------------------- Name : openvpn Product : Fedora 20 Version : 2.3.6 Release : 1.fc20 URL : http://openvpn.net/ Summary : A full-featured SSL VPN solution Description : OpenVPN is a robust and highly flexible tunneling application that uses all of the encryption, authentication, and certification features of the OpenSSL library to securely tunnel IP networks over a single UDP or TCP port. It can use the Marcus Franz Xaver Johannes Oberhumer's LZO library for compression. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2014-8104. https://community.openvpn.net/openvpn/wiki/SecurityAnnoun... -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 1 2014 Jon Ciesla <limburgher@gmail.com> 2.3.6-1 - 2.3.6, CVE-2014-8104. * Fri Nov 21 2014 Ralf Corsépius <corsepiu@fedoraproject.org> - 2.3.5-2 - Rework package doc handling (RHBZ #1165004). * Tue Oct 28 2014 Jon Ciesla <limburgher@gmail.com> 2.3.5-1 - 2.3.5. * Tue Aug 26 2014 Jan Vcelak <jvcelak@fedoraproject.org> 2.3.4-4 * Fri Nov 21 2014 Ralf Corsépius <corsepiu@fedoraproject.org> - 2.3.2-7 - Rework package doc handling (RHBZ #1165004). * Tue Aug 26 2014 Jan Vcelak <jvcelak@fedoraproject.org> 2.3.2-6 - Enable systemd support. * Sun Jan 19 2014 Ville Skyttä <ville.skytta@iki.fi> - 2.3.2-5 - Don't order service after syslog.target. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1169487 - CVE-2014-8104 openvpn: authenticated user can DoS OpenVPN by sending a too-short control channel packet to server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1169487 [ 2 ] Bug #1169488 - CVE-2014-8104 openvpn: authenticated user can DoS OpenVPN by sending a too-short control channel packet to server [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1169488 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update openvpn' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds