stable

openvpn-2.4.11-1.el8

FEDORA-EPEL-2021-0754fdd085 created by dsommers 2 years ago for Fedora EPEL 8

Security update - OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks. (CVE-2020-15078)

This update has been submitted for testing by dsommers.

2 years ago

This update's test gating status has been changed to 'ignored'.

2 years ago

This update's test gating status has been changed to 'waiting'.

2 years ago

This update's test gating status has been changed to 'ignored'.

2 years ago

This update has been pushed to testing.

2 years ago

dsommers edited this update.

2 years ago
User Icon jstevens commented & provided feedback 2 years ago
karma

I updated one server, and the VPN is still working properly.

Not sure about the bug fix, as I don't know how to test that; I don't know if there's a POC or a assessment test script somewhere.

This update can be pushed to stable now if the maintainer wishes

2 years ago

This update has been submitted for stable by bodhi.

2 years ago

This update has been pushed to stable.

2 years ago

Please login to add feedback.

Metadata
Type
security
Severity
urgent
Karma
1
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-1
Stable by Karma
2
Stable by Time
14 days
Dates
submitted
2 years ago
in testing
2 years ago
in stable
2 years ago
modified
2 years ago
BZ#1952936 CVE-2020-15078 openvpn: Authentication bypass with deferred authentication [epel-all]
0
0

Automated Test Results