HomeFreeBSD

Security upgrade to OpenVPN 2.3.11, breaking POLARSSL option.

Description

Security upgrade to OpenVPN 2.3.11, breaking POLARSSL option.

Quoting upstream maintainers' release notes:
"This release fixes two vulnerabilities: a port-share bug with DoS
potential and a buffer overflow by user supplied data when using pam
authentication. In addition a number of small fixes and improvements are
included."

WARNING: this upgrade breaks the PolarSSL-based build due to an oversight in the cipher suite selection hardening, crashing PolarSSL-based builds with a 0-pointer deferences. Marking port BROKEN if POLARSSL is set.

Changelog: https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn23

Details

Provenance
mandreeAuthored on
Parents
rP415092: Upgrade CHERI LLVM and Qemu ports to new snapshots supporting the
Branches
Unknown
Tags
Unknown