首页 | 编程语言 | 网站建设 | 游戏天堂 | 冲浪宝典 | 网络安全 | 操作系统 | 软件时空 | 硬件指南 | 病毒相关 | IT 认证
软讯网络 > 网络安全 > 安全知识 > OpenVPN new release 2005.11.01 -- Version 2.0.4
【标  题】:OpenVPN new release 2005.11.01 -- Version 2.0.4
【关键字】:OpenVPN,new,release,2005.11.01,--,Version,2.0.4
【来  源】:http://blog.chinaunix.net/article.php?articleId=54911&blogId=2389

OpenVPN new release 2005.11.01 -- Version 2.0.4

重要更新,一定记得更新

* Security fix -- Affects non-Windows OpenVPN clients of
version 2.0 or higher which connect to a malicious or
compromised server. A format string vulnerability
in the foreign_option function in options.c could
potentially allow a malicious or compromised server
to execute arbitrary code on the client. Only
non-Windows clients are affected. The vulnerability
only exists if (a) the client's TLS negotiation with
the server succeeds, (b) the server is malicious or
has been compromised such that it is configured to
push a maliciously crafted options string to the client,
and (c) the client indicates its willingness to accept
pushed options from the server by having "pull" or
"client" in its configuration file (Credit: Vade79).
CVE-2005-3393
* Security fix -- Potential DoS vulnerability on the
server in TCP mode. If the TCP server accept() call
returns an error status, the resulting exception handler
may attempt to indirect through a NULL pointer, causing
a segfault. Affects all OpenVPN 2.0 versions.
CVE-2005-3409
* Fix attempt of assertion at multi.c:1586 (note that
this precise line number will vary across different
versions of OpenVPN).
* Added ".PHONY: plugin" to Makefile.am to work around
"make dist" issue.
* Fixed double fork issue that occurs when --management-hold
is used.
* Moved TUN/TAP read/write log messages from --verb 8 to 6.
* Warn when multiple clients having the same common name or
username usurp each other when --duplicate-cn is not used.
* Modified Windows and Linux versions of get_default_gateway
to return the route with the smallest metric
if multiple 0.0.0.0/0.0.0.0 entries are present.

2005.09.25 -- Version 2.0.3-rc1

* openvpn_plugin_abort_v1 function wasn't being properly
registered on Windows.
* Fixed a bug where --mode server --proto tcp-server --cipher none
operation could cause tunnel packet truncation.

各个端口的入侵:【上一篇】
严重警告:fdisk /mbr不可轻易使用,否则后果严重:【下一篇】
【相关文章】
  • IPCop and Openvpn HOWTO
  • 使用 ssh 不用输入密码 -- putty 版.
  • pix ---cisco 26 做VPN
  • OpenVPN中connect/disconnect脚本,用于计费
  • m0n0wall 1.2 release VPN 问题
  • Informix入门之---日志分析
  • Informix IDS Version History
  • linux下oracle备份脚本--exp
  • Ora2html--收集Oracle数据库信息 -ORACLE
  • 北京创天诚信科技有限公司-----短信相关产品报价单
  • 【随机文章】
  • ldap samba实现windows域管理
  • 树型控件(视图)二
  • 如何用VC实现软件注册
  • Web开发者的实用网址
  • 广州.NET 俱乐部--2005年12月16日Party行车路线
  • VC++基础:枚举当前打开的所有窗口
  • FreeBSD下用mrtg监控本机流量、内存、cpu使用率、整网流量:)
  • SET命令
  • Pro* C/C++ Select Insert 演示
  • word 自动恢复文档
  • 【相关评论】
    没有相关评论
    【发表评论】
    姓名:
    邮件:
    随机码*
    评论*
          
    |  首 页  |  版权声明  |  联系我们   |  网站地图  |
    CopyRight © 2004-2007 软讯网络 All Rigths Reserved.