This is primarily a maintenance release with bugfixes and improvements. This release also fixes a security issue (CVE-2020-11810) which allows disrupting service of a freshly connected client that has not yet negotiated session keys. The vulnerability cannot be used to inject or steal VPN traffic. Release announcement: https://openvpn.net/community-downloads/#heading-13812 Full list of changes: https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24#OpenVPN2.4.9 Signed-off-by: Magnus Kroken <mkroken@gmail.com> |
||
|---|---|---|
| .. | ||
| 001-reproducible-remove_DATE.patch | ||
| 100-mbedtls-disable-runtime-version-check.patch | ||
| 110-openssl-dont-use-deprecated-ssleay-symbols.patch | ||
| 111-openssl-add-missing-include-statements.patch | ||
| 210-build_always_use_internal_lz4.patch | ||
| 220-disable_des.patch | ||