James Yonan | 12 Sep 10:17

OpenVPN 2.0.8 and 2.1_beta15 released

2006.09.12 -- Version 2.0.8

* Windows installer updated with OpenSSL 0.9.7k DLLs to fix
  RSA Signature Forgery (CVE-2006-4339).

* No changes to OpenVPN source code between 2.0.7 and 2.0.8.

2006.09.12 -- Version 2.1-beta15

* Windows installer updated with OpenSSL 0.9.7k DLLs to fix
  RSA Signature Forgery (CVE-2006-4339).

* Fixed bug introduced with the --port-share directive
  (back in 2.1-beta9 which causes TLS soft resets
  (1 per hour by default) in TCP server mode to force
  a blockage of tunnel packets and later time-out and
  restart the connection.

* pkcs11 changes:
  1. Modified ssl.c to not FATAL and return to init.c
     so auth-retry will work.
  2. Modifed pkcs11-helper.c to fix some problem with
     multiple providers.
  3. Updated makefile.w32-vc to include lladdr.*, updated
     linkage libraries.
  4. Modified lladdr.c to be compiled under visual C.
  5. Added retry counter to PKCS#11 PIN hook.
  6. Modified PKCS#11 PIN retry loop to return correct error
     code when PIN is incorrect.
  7. Fix handling (ignoring) zero sized attributes.
(Continue reading)

James Yonan | 1 Oct 15:02

OpenVPN 2.0.9 and 2.1-beta16 released

2006.10.01 -- Version 2.0.9

* Windows installer updated with OpenSSL 0.9.7l DLLs to fix
  published vulnerabilities.

* Fixed TAP-Win32 bug that caused BSOD on Windows Vista
  (Henry Nestler).  The TAP-Win32 driver has now been
  upgraded to version 8.4.

2006.10.01 -- Version 2.1-beta16

* Windows installer updated with OpenSSL 0.9.7l DLLs to fix
  published vulnerabilities.

* Fixed TAP-Win32 bug that caused BSOD on Windows Vista
  (Henry Nestler).

* Autodetect 32/64 bit Windows in installer and install
  appropriate TAP driver (Mathias Sundman, Hypherion).

* Fixed bug in loopback self-test introduced
  in 2.1-beta15 where self test as invoked by
  "make check" would not properly exit after
  2 minutes (Paul Howarth).

James

-------------------------------------------------------------------------
Take Surveys. Earn Cash. Influence the Future of IT
Join SourceForge.net's Techsay panel and you'll get the chance to share your
(Continue reading)

James Yonan | 12 Sep 20:25

Re: [Openvpn-users] OpenVPN 2.0.8 and 2.1_beta15 released

James Miller wrote:
>> -----Original Message-----
>> From: openvpn-users-bounces <at> lists.sourceforge.net
>> [mailto:openvpn-users-bounces <at> lists.sourceforge.net]On Behalf Of James
>> Yonan
>> Sent: Tuesday, September 12, 2006 3:17 AM
>> To: 'openvpn-users'; OpenVPN devel;
>> openvpn-announce <at> lists.sourceforge.net
>> Subject: [Openvpn-users] OpenVPN 2.0.8 and 2.1_beta15 released
>>
>>
>> 2006.09.12 -- Version 2.0.8
>>
>> * Windows installer updated with OpenSSL 0.9.7k DLLs to fix
>>   RSA Signature Forgery (CVE-2006-4339).
>>
>> * No changes to OpenVPN source code between 2.0.7 and 2.0.8.
>>
>> 2006.09.12 -- Version 2.1-beta15
>>
>> * Windows installer updated with OpenSSL 0.9.7k DLLs to fix
>>   RSA Signature Forgery (CVE-2006-4339).
>>
>>     
>
>
> Hello everyone.  I see the new 2.1 beta has a fix for (CVE-2006-4339).  Does
> this mean 2.0.7 is not affected by the OpenSSL RSA Signature Forgery
> vulnerablility?
>   
(Continue reading)


Gmane