-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Wed, 2 Nov 2005 16:25:04 +0100 Source: openvpn Binary: openvpn Architecture: source powerpc Version: 2.0-1sarge2 Distribution: stable-security Urgency: high Maintainer: Martin Schulze <joey@debian.org> Changed-By: Alberto Gonzalez Iniesta <agi@inittab.org> Description: openvpn - Virtual Private Network daemon Changes: openvpn (2.0-1sarge2) stable-security; urgency=high . * Sarge security release. * Applied upstream patches to fix the following security bugs: - DoS vulnerability on the server in TCP mode. (CVE-2005-3409) - Format string vulnerability in the foreign_option function in options.c could potentially allow a malicious or compromised server to execute arbitrary code on the client. (CVE-2005-3393) Files: 1cea04a008a9b888b404c7ec2e5c2ef2 629 net optional openvpn_2.0-1sarge2.dsc a48a32ae512664fa21ac2f18b13aca8b 52800 net optional openvpn_2.0-1sarge2.diff.gz 8baabfbe69032a23414ca0e97caec7b9 309090 net optional openvpn_2.0-1sarge2_powerpc.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) iD8DBQFDadEFW5ql+IAeqTIRAgFfAJoDmCDhoYBffv83ROKQSVlLVP2XvACgsSfB UrMicNIvu18bkPn4UG5JETc= =fegj -----END PGP SIGNATURE----- Accepted: openvpn_2.0-1sarge2.diff.gz to pool/main/o/openvpn/openvpn_2.0-1sarge2.diff.gz openvpn_2.0-1sarge2.dsc to pool/main/o/openvpn/openvpn_2.0-1sarge2.dsc openvpn_2.0-1sarge2_powerpc.deb to pool/main/o/openvpn/openvpn_2.0-1sarge2_powerpc.deb -- To UNSUBSCRIBE, email to debian-changes-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org