Bug#895135: openvpn client DNS security hole in update-resolv-conf

2018-07-29 Thread Jörg Frings-Fürst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 tags 895135 - security severity 895135 wishlist thanks Hello Roger, thank you for spending your time helping to make Debian better with this bug report. Some comments on your bug report: The steps required to use the update-resolv-conf script

Bug#895135: openvpn client DNS security hole in update-resolv-conf

2018-04-07 Thread Roger Price
Package: openvpn Version: 2.4.0-6+deb9u2 Severity: grave Tags: security Justification: user security hole Dear Maintainer, * What led up to the situation? openvpn client received DNS from server but silently used local, possibly compromised DNS server. In the stretch openvpn server