Your message dated Fri, 11 Oct 2024 12:50:22 +0000
with message-id <[email protected]>
and subject line Bug#1074425: fixed in openvpn-auth-ldap 2.0.4-4
has caused the Debian Bug report #1074425,
regarding openvpn-auth-ldap: CVE-2024-28820
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1074425: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1074425
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: openvpn-auth-ldap
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for openvpn-auth-ldap.
CVE-2024-28820[0]:
| Buffer overflow in the extract_openvpn_cr function in openvpn-cr.c
| in openvpn-auth-ldap (aka the Three Rings Auth-LDAP plugin for
| OpenVPN) 2.0.4 allows attackers with a valid LDAP username and who
| can control the challenge/response password field to pass a string
| with more than 14 colons into this field and cause a buffer
| overflow.
https://github.com/threerings/openvpn-auth-ldap/pull/92
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-28820
https://www.cve.org/CVERecord?id=CVE-2024-28820
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: openvpn-auth-ldap
Source-Version: 2.0.4-4
Done: Aniol Martí <[email protected]>
We believe that the bug you reported is fixed in the latest version of
openvpn-auth-ldap, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Aniol Martí <[email protected]> (supplier of updated openvpn-auth-ldap package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Mon, 23 Sep 2024 17:15:54 +0200
Source: openvpn-auth-ldap
Architecture: source
Version: 2.0.4-4
Distribution: unstable
Urgency: medium
Maintainer: Aniol Martí <[email protected]>
Changed-By: Aniol Martí <[email protected]>
Closes: 1074425 1075345
Changes:
openvpn-auth-ldap (2.0.4-4) unstable; urgency=medium
.
* Add Yavor Doganov's patch to fix build with GCC 14 (Closes: #1075345).
* Add patch to fix CVE-2024-28820 (Closes: #1074425)
* Update standards version to 4.7.0.
* Watch tags instead of releases in upstream.
Checksums-Sha1:
d0de4fc64ad83bdcbaff1303be3294f97d89e340 2104 openvpn-auth-ldap_2.0.4-4.dsc
d428946095c9b535a09b5ee994bb420c4c615d4f 8808
openvpn-auth-ldap_2.0.4-4.debian.tar.xz
7be01b354e2938b542993550b24dc21f5211235b 6779
openvpn-auth-ldap_2.0.4-4_source.buildinfo
Checksums-Sha256:
39692e22252fae17960900d0abbc19c4a6f3d30f3020d3b9699274767cfe279a 2104
openvpn-auth-ldap_2.0.4-4.dsc
e52b6d18e8baf1c32056c606cf8b2eef215b0ae39980755e18c92057c473a781 8808
openvpn-auth-ldap_2.0.4-4.debian.tar.xz
270be57e362b3a17ab8c00fd6946cff29def36154d76b2a7ff02ebc8a7e2dc55 6779
openvpn-auth-ldap_2.0.4-4_source.buildinfo
Files:
b0d183a9cb8d8a08fbc94e0b0619a039 2104 net optional
openvpn-auth-ldap_2.0.4-4.dsc
9592d3e8878ef76839356bf087fd01ae 8808 net optional
openvpn-auth-ldap_2.0.4-4.debian.tar.xz
912bd526dfcbf6a89b515748426d0ad4 6779 net optional
openvpn-auth-ldap_2.0.4-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJFBAEBCAAvFiEEAxkNfn0I1/8fM5/DGbYJgR8GqZQFAmcJGpYRHGFtYXJ0aUBj
YWxpdS5jYXQACgkQGbYJgR8GqZS1+BAAhVTNnkeT+OvMIjCluAJArMb5TaHnKG96
bsEWIxEmvArdryYAIF5ug9Rt3VAxKiTOm5u/qKWByeFMw18H4XnVANAu0CEDgP8L
C0/4GimtrFw6W6h+vKsLX6oPegS2ljYwVyKisLEMdpC0pHEuhYxUNw0JS+vDlmw5
yD6F04hCcpj5v/XaXOb+AnBWzqlbBD8R9B/C3zlta0zIWy3AoTcw4jfLcnVnYwot
SMTSrym4cGWGbZ2pANyPndiGq1LnEccddXZXpIh2Z8tNqaaJpFlrzwu66GbEJRz7
Npeyre7YjNXZr1USDckIwcJrWQTN0I1nZDCKgCE+dtH2riq1XQifPp9tOYcDwjZB
pKyRqn3Eyfwy7NNkcuzEUX3ulbP+IiKaaDdOD9mgUV/6nrDJzrahz8/R19GId5cO
C9RZz57HfER4xu8c5NJ0sw0+f0u53N1Xl+HcWhjbr69qeCp+SIhXeUVhbIPmYO3c
z0b3pqMqXJJHryHFE9TWlxJ62QFCCXyyuBb3l4dhnO2uZ6MYDbkXeN4k8kVMoXkl
41E0Hgd9xCRCdSeig7S4LmQJRKioIqpZruK/3B3Rkh0ohpSeiMTRNgFDfDBbDIw6
u7Rc6D3mzASaX4NU2dQSw4D7F1x1CUCwJuh3JA3aDIZ2fAuw8/viZLtInpehdY5e
uyyEGvfUz1c=
=KIDk
-----END PGP SIGNATURE-----
pgpY7pcX95osB.pgp
Description: PGP signature
--- End Message ---