Overview
Request 205451 accepted
- Applied upstream patch changing to use a constant time memcmp
when comparing HMACs in openvpn_decrypt to address ciphertext
injection in UDP mode (CVE-2013-2061, bnc#843509).
[0006-openvpn-2.0.9-HMAC-memcmp-CVE-2013-2061_bnc843509.patch]
- Join openvpn.service systemd cgroup in start when needed, e.g.
when starting with further parameters. (bnc#781106)
- Created by mtomaschewski
- In state accepted
Request History
mtomaschewski created request
- Applied upstream patch changing to use a constant time memcmp
when comparing HMACs in openvpn_decrypt to address ciphertext
injection in UDP mode (CVE-2013-2061, bnc#843509).
[0006-openvpn-2.0.9-HMAC-memcmp-CVE-2013-2061_bnc843509.patch]
- Join openvpn.service systemd cgroup in start when needed, e.g.
when starting with further parameters. (bnc#781106)
vpereirabr accepted request
ok