Hi,

On Fri, Jun 26, 2015 at 12:16:43PM +0200, David Sommerseth wrote:
> * Exploitable out-of-bounds read in X509_cmp_time (CVE-2015-1789)
> This might be an issue on OpenVPN on the server side.  However,
> --tls-auth will reduce the attack vector to one of your own users.

As we're not using X509_cmp_time()...

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             g...@greenie.muc.de
fax: +49-89-35655025                        g...@net.informatik.tu-muenchen.de

Attachment: pgpQYRJERXZp_.pgp
Description: PGP signature

Reply via email to