-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 02 Apr 2025 17:45:15 +0200 Source: openvpn Binary: openvpn openvpn-dbgsym Architecture: mips64el Version: 2.6.3-1+deb12u3 Distribution: bookworm Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Bernhard Schmidt Description: openvpn - virtual private network daemon Closes: 1074488 1086653 1101935 Changes: openvpn (2.6.3-1+deb12u3) bookworm; urgency=medium . [ Bernhard Schmidt ] * Cherry-Pick upstream fixes for various CVEs (Closes: #1074488) - CVE-2025-2704: possible ASSERT() on OpenVPN servers using --tls-crypt-v2 (Closes: #1101935) - CVE-2024-5594: malicious peer can DoS or send garbage to logs - CVE-2024-28882: client can circumvent management client-kill both (Closes: #1074488) * Run salsa pipeline in Bookworm environment - add d/source/options to make it build in Bookworm Salsa . [ Aquila Macedo ] * d/p/sample-keys-renew-10-years: import upstream patch to update expired certificates used in the build-time tests (Closes: #1086653) Checksums-Sha1: 246e1d2f481e527c212838192a8c92e6452d0c72 1315804 openvpn-dbgsym_2.6.3-1+deb12u3_mips64el.deb d46e91bbb400589b3c469436df5fae299d65368a 7523 openvpn_2.6.3-1+deb12u3_mips64el-buildd.buildinfo 223f6b1d7fbd638afc5c2a0500ebe0f57617360e 620092 openvpn_2.6.3-1+deb12u3_mips64el.deb Checksums-Sha256: d593ce863f8c95ea071f3be4c10e6242ca0d362dab07e16ead25c1b06eb8f9f8 1315804 openvpn-dbgsym_2.6.3-1+deb12u3_mips64el.deb 52850a327a582abe8375d915b7ce13e858db878199e42ecb4616634f602acb24 7523 openvpn_2.6.3-1+deb12u3_mips64el-buildd.buildinfo 1525938c37c5e5147852af3c37eeffab822bf7e2c12abfb6d4be240ed3068b71 620092 openvpn_2.6.3-1+deb12u3_mips64el.deb Files: dc9783a95c1986c97f0102358d695f7f 1315804 debug optional openvpn-dbgsym_2.6.3-1+deb12u3_mips64el.deb 28374bc4e99cd7e3562449320947cb1a 7523 net optional openvpn_2.6.3-1+deb12u3_mips64el-buildd.buildinfo dbb0b98515cafe1c8c56550a975d6d01 620092 net optional openvpn_2.6.3-1+deb12u3_mips64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERbXMbY9VMQqnSaVEV4aVsMglzVcFAmgeNRQACgkQV4aVsMgl zVdpRBAAntlJsnlndITOQWLlBEEzL++g6D6j0EGOwaiwwgFGBXbOvJ8k7qYxE/Tw OoWyvpLA7xy9m7pLQ4qTXO1ZGgPrUxdt1pnmmWL7mST4QX8tKMaTupryDliOFp5e m4YDw81x+YIS3B56DWg0JI0H9OHV8YuQFXO2cWpTav0QTzfzgdVGx5gl+TbMZOtB xOYFKMZFJ9iVPk0327NdaVggZWp9/a597pwhWQKsnLbNE2RMIuHbh2lRxuLJ3nl5 raVhOWQIv35/z7vlMilVP7IKTkS0Cv26/Sw0wRzzp6VWWnrq6jB/Fk0v9HfvtNsJ dFOo07Qi3ljfgQ6gwfPznLU9Eei0GymPdrr7FJQlwHMzs3EhDfVQ/3D1mObwSFSK eFRK3nD63PWELB27AlXA57oAThz2gRQYb33mKJzigxZ6gyCfNp516KlPCUQwq+Jk FJzXkpsdTjEq90nMtLY4f5iXGXYzJ4qC4gRswEMZgBQC7aeIhWNwz4gwGT43aMFI nEYBnnisCf00wuakk7cYtB1SuqujtDd17M0YRc/5q0lco6/ewtLmJV3AGLU97VOD 3tu1T2Ub96ZuwGx2wtTHm7EZAIqFdPDSjYmBY1tB97E6mZJf1eznrbRo4MDaUbWW QVKeOpgpYDI4r0sUWMcsztKM6jiaU9fOe9WEcE+eFcxN3/QtM78= =PCz2 -----END PGP SIGNATURE-----