[ubuntu/focal-updates] openvpn 2.4.7-1ubuntu2.20.04.2 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue May 4 12:28:17 UTC 2021


openvpn (2.4.7-1ubuntu2.20.04.2) focal-security; urgency=medium

  * SECURITY UPDATE: data channel v2 packet injection
    - debian/patches/CVE-2020-11810.patch: fix illegal client float in
      src/openvpn/multi.c.
    - CVE-2020-11810
  * SECURITY UPDATE: Authentication bypass with deferred authentication
    - debian/patches/CVE-2020-15078.patch: ensure key state is
      authenticated before sending push reply in src/openvpn/push.c.
    - CVE-2020-15078

Date: 2021-04-27 15:20:09.421924+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/openvpn/2.4.7-1ubuntu2.20.04.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list