<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>111116</bug_id>
          
          <creation_ts>2005-11-01 03:16 0000</creation_ts>
          <short_desc>net-misc/openvpn: format string and DoS vulnerabilities</short_desc>
          <delta_ts>2005-11-06 10:44:56 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.frsirt.com/bulletins/2510</bug_file_loc>
          <status_whiteboard>B2 [glsa]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          <dependson>111267</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>casta@xwing.info</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>genbug@Chamillionaire.breakpoint.cc</cc>
    
    <cc>luckyduck@gentoo.org</cc>
    
    <cc>uberlord@gentoo.org</cc>
    
    <cc>warpzero@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>casta@xwing.info</who>
            <bug_when>2005-11-01 03:16:32 0000</bug_when>
            <thetext>Looking at this advisory : http://www.frsirt.com/bulletins/2510
OpenVPN &lt;= 2.0.2 has 2 vulnerabilities.
Please bump to 2.0.3 as quick as possible

Regards</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-01 03:54:53 0000</bug_when>
            <thetext>Ccing rest of herd as luckyduck has been away for some time. Please bump to 2.0.3.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>uberlord@gentoo.org</who>
            <bug_when>2005-11-01 04:59:33 0000</bug_when>
            <thetext>Adding myself as I&apos;ve been looking after openvpn due to a (now solved)
baselayout-1.12.0_pre issue as luckyduck is away (for long time) and warpzero is
no longer a dev (iirc)

Koon, openvpn-2.0.3 isn&apos;t released yet and has no source tarball or any 2.0.3
download available from their site.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-01 05:50:04 0000</bug_when>
            <thetext>They pulled the release, probably needs a small last-minute fix.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>genbug@Chamillionaire.breakpoint.cc</who>
            <bug_when>2005-11-01 12:53:14 0000</bug_when>
            <thetext>Are we talking abour 2.0.3 or 2.0.4 ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>genbug@Chamillionaire.breakpoint.cc</who>
            <bug_when>2005-11-01 12:54:46 0000</bug_when>
            <thetext>Are we talking abour 2.0.3 or 2.0.4 ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>casta@xwing.info</who>
            <bug_when>2005-11-01 13:02:57 0000</bug_when>
            <thetext>OK, 2.0.3 was released this morning then removed a few hours after...
Now 2.0.4 is released with the correct fixes (see http://openvpn.net/changelog.html)

So now bump is for 2.0.4 skipping 2.0.3 ;)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>uberlord@gentoo.org</who>
            <bug_when>2005-11-02 04:24:31 0000</bug_when>
            <thetext>2.0.4 is now in the tree</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-02 04:34:03 0000</bug_when>
            <thetext>Arches please test and mark 2.0.4 stable
Target KEYWORDS=&quot;alpha amd64 ppc ppc-macos sparc x86&quot;
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>ticho@gentoo.org</who>
            <bug_when>2005-11-02 06:52:45 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-11-02 10:10:37 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>uberlord@gentoo.org</who>
            <bug_when>2005-11-02 10:26:21 0000</bug_when>
            <thetext>2.0.4 removed as to having the new init script
2.0.4-r1 added with old script - please mark this version stable
2.0.4-r2 has the new init script

Sorry for any confusion/problems/whatever</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2005-11-02 12:14:18 0000</bug_when>
            <thetext>2.0.4-r1 stable on ppc-macos</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-11-03 06:05:50 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>uberlord@gentoo.org</who>
            <bug_when>2005-11-03 10:08:03 0000</bug_when>
            <thetext>openvpn-2.0.5 just got released with fixes another serious issue
I&apos;ve just comitted it to the tree, fixing bug #111369, marked ~ARCH

The 2.0.4 ebuilds are still there, but are un-useable on Linux.
ChangeLog snippet

* Fixed bug in Linux get_default_gateway function
  introduced in 2.0.4, which would cause redirect-gateway
  on Linux clients to fail.
* Restored easy-rsa/2.0 tree (backported from 2.1 beta
  series) which accidentally disappeared in
  2.0.2 -&gt; 2.0.4 transition.

I&apos;ll leave it upto you guys if you want to stable 2.0.5 as technically 2.0.4 has
the security fix but as the openvpn guys said, it may be unuseable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>uberlord@gentoo.org</who>
            <bug_when>2005-11-03 10:09:56 0000</bug_when>
            <thetext>Uh - if this goes stable, then mark 2.0.5 stable and NOT 2.0.5-r1 which has the
new init script</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-03 10:52:16 0000</bug_when>
            <thetext>We should definitely have 2.0.5 stable rather than 2.0.4...

Upstream really fucked up this release big time.
Readding arches that already tested 2.0.4...
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-11-03 11:15:02 0000</bug_when>
            <thetext>Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>halcy0n@gentoo.org</who>
            <bug_when>2005-11-03 21:53:10 0000</bug_when>
            <thetext>x86 done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>grobian@gentoo.org</who>
            <bug_when>2005-11-04 03:14:51 0000</bug_when>
            <thetext>ppc-macos done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-11-04 06:45:15 0000</bug_when>
            <thetext>sparc stable, let&apos;s hope it&apos;s the last one.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-11-05 05:38:38 0000</bug_when>
            <thetext>Alpha stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2005-11-06 04:40:45 0000</bug_when>
            <thetext>amd64 stable, sorry for the delay</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-11-06 10:44:56 0000</bug_when>
            <thetext>GLSA 200511-07</thetext>
          </long_desc>
      
    </bug>

</bugzilla>