From URL, "OpenVPN 2.1 up to v2.4.11 and v2.5.5 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials. This issue is resolved in OpenVPN 2.4.12 and v2.5.6 where the OpenVPN server process will stop running with the following error message in the logs: Exiting due to multiple authentication plug-ins performing deferred authentication. Only one authentication plug-in doing deferred auth is allowed. Ignoring the result and stopping now, the current authentication result is not to be trusted." Please bump to 2.5.6.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d85036d80926637fb9170e9a02ca9c6f3f35086b commit d85036d80926637fb9170e9a02ca9c6f3f35086b Author: Tomáš Mózes <hydrapolic@gmail.com> AuthorDate: 2022-04-19 22:41:00 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2022-04-23 01:22:45 +0000 net-vpn/openvpn: bump to 2.5.6 Bug: https://bugs.gentoo.org/835514 Closes: https://bugs.gentoo.org/818436 Signed-off-by: Tomáš Mózes <hydrapolic@gmail.com> Closes: https://github.com/gentoo/gentoo/pull/25120 Signed-off-by: Sam James <sam@gentoo.org> net-vpn/openvpn/Manifest | 1 + net-vpn/openvpn/openvpn-2.5.6.ebuild | 197 +++++++++++++++++++++++++++++++++++ 2 files changed, 198 insertions(+)
Please stable when ready.
Please cleanup
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=fe4473d49e5050fff69ba9135163bb00b7c70710 commit fe4473d49e5050fff69ba9135163bb00b7c70710 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-09-22 06:34:37 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-09-22 06:35:01 +0000 [ GLSA 202409-08 ] OpenVPN: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/835514 Bug: https://bugs.gentoo.org/917272 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202409-08.xml | 45 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 45 insertions(+)