Browse code

Preparing release 2.5.11

version.m4, ChangeLog, Changes.rst

Signed-off-by: Gert Doering <gert@greenie.muc.de>

Gert Doering authored on 2024/07/18 21:23:03
Showing 3 changed files
... ...
@@ -1,6 +1,12 @@
1 1
 OpenVPN Change Log
2 2
 Copyright (C) 2002-2022 OpenVPN Inc <sales@openvpn.net>
3 3
 
4
+2024.07.18 -- Version 2.5.11
5
+
6
+Arne Schwabe (2):
7
+      Properly handle null bytes and invalid characters in control messages
8
+      Allow trailing \r and \n in control channel message
9
+
4 10
 2024.03.21 -- Version 2.5.10
5 11
 
6 12
 Arne Schwabe (1):
... ...
@@ -1,3 +1,15 @@
1
+Overview of changes in 2.5.11
2
+=============================
3
+Security fixes
4
+--------------
5
+- CVE-2024-5594: control channel: refuse control channel messages with
6
+  nonprintable characters in them.  Security scope: a malicious openvpn
7
+  peer can send garbage to openvpn log, or cause high CPU load.
8
+  (Reynir Björnsson)
9
+
10
+  (Backport of the security fix in 2.6.11 and the fix for the bugfix
11
+  in 2.6.12)
12
+
1 13
 Overview of changes in 2.5.10
2 14
 =============================
3 15
 Security fixes
... ...
@@ -3,12 +3,12 @@ define([PRODUCT_NAME], [OpenVPN])
3 3
 define([PRODUCT_TARNAME], [openvpn])
4 4
 define([PRODUCT_VERSION_MAJOR], [2])
5 5
 define([PRODUCT_VERSION_MINOR], [5])
6
-define([PRODUCT_VERSION_PATCH], [.10])
6
+define([PRODUCT_VERSION_PATCH], [.11])
7 7
 m4_append([PRODUCT_VERSION], [PRODUCT_VERSION_MAJOR])
8 8
 m4_append([PRODUCT_VERSION], [PRODUCT_VERSION_MINOR], [[.]])
9 9
 m4_append([PRODUCT_VERSION], [PRODUCT_VERSION_PATCH], [[]])
10 10
 define([PRODUCT_BUGREPORT], [openvpn-users@lists.sourceforge.net])
11
-define([PRODUCT_VERSION_RESOURCE], [2,5,10,0])
11
+define([PRODUCT_VERSION_RESOURCE], [2,5,11,0])
12 12
 dnl define the TAP version
13 13
 define([PRODUCT_TAP_WIN_COMPONENT_ID], [tap0901])
14 14
 define([PRODUCT_TAP_WIN_MIN_MAJOR], [9])