[ubuntu/plucky-proposed] openvpn 2.6.13-1ubuntu3 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Thu Apr 3 12:30:51 UTC 2025


openvpn (2.6.13-1ubuntu3) plucky; urgency=medium

  * SECURITY UPDATE: denial of service issue
    - debian/patches/CVE-2025-2704.patch: allow tls-crypt-v2 to be setup
      only on initial packet of a session in src/openvpn/ssl.c,
      src/openvpn/ssl_common.h, src/openvpn/ssl_pkt.c,
      src/openvpn/ssl_pkt.h, src/openvpn/tls_crypt.c,
      src/openvpn/tls_crypt.h, tests/unit_tests/openvpn/test_tls_crypt.c.
    - CVE-2025-2704

Date: Tue, 01 Apr 2025 12:03:56 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openvpn/2.6.13-1ubuntu3
-------------- next part --------------
Format: 1.8
Date: Tue, 01 Apr 2025 12:03:56 -0400
Source: openvpn
Built-For-Profiles: noudeb
Architecture: source
Version: 2.6.13-1ubuntu3
Distribution: plucky
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 openvpn (2.6.13-1ubuntu3) plucky; urgency=medium
 .
   * SECURITY UPDATE: denial of service issue
     - debian/patches/CVE-2025-2704.patch: allow tls-crypt-v2 to be setup
       only on initial packet of a session in src/openvpn/ssl.c,
       src/openvpn/ssl_common.h, src/openvpn/ssl_pkt.c,
       src/openvpn/ssl_pkt.h, src/openvpn/tls_crypt.c,
       src/openvpn/tls_crypt.h, tests/unit_tests/openvpn/test_tls_crypt.c.
     - CVE-2025-2704
Checksums-Sha1:
 2e805289c80d0d1ea163bafaa10a127f7522d336 2297 openvpn_2.6.13-1ubuntu3.dsc
 e2b07717ea040450f9d8bce846d0de2916141513 68020 openvpn_2.6.13-1ubuntu3.debian.tar.xz
 292ed3523ff126da39b00f3dabb48e12ce0a1e9d 7390 openvpn_2.6.13-1ubuntu3_source.buildinfo
Checksums-Sha256:
 9df03a1a019ce0bd4c481b7c72464460a0aba5150c24f6c2bc6970caaa214a2a 2297 openvpn_2.6.13-1ubuntu3.dsc
 5d10ecafefaf926e92b25ca49d0c346832fa3560331a83c75e07d955e74a8361 68020 openvpn_2.6.13-1ubuntu3.debian.tar.xz
 5e4b9650ccd7a2b3eb3a7c9bc4f35bd245b5518d110c48a6cde226d7336fcbd9 7390 openvpn_2.6.13-1ubuntu3_source.buildinfo
Files:
 eb2ea38e7e0cbdb298c349925d925bf1 2297 net optional openvpn_2.6.13-1ubuntu3.dsc
 b5caac75adfc37960271342836697dda 68020 net optional openvpn_2.6.13-1ubuntu3.debian.tar.xz
 cfcc9560e37a408fc69535d1e003c551 7390 net optional openvpn_2.6.13-1ubuntu3_source.buildinfo
Original-Maintainer: Bernhard Schmidt <berni at debian.org>


More information about the plucky-changes mailing list