-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

Easy-RSA has issued it's first CVE.

During the transitionary phase between OpenSSL v1.1.x and v3.x.x
a minor weakness was discovered when encryption the CA private key.

CVE Record:
* https://www.cve.org/CVERecord?id=CVE-2024-13454

Full details:
* https://community.openvpn.net/openvpn/wiki/CVE-2024-13454

Bug report:
* https://github.com/OpenVPN/easy-rsa/issues/1122

Thanks are given to the help and guidance received,
while confirming this CVE.

If there are further questions then please feel free to ask.

Kind Regards
Richard Bonhomme.

On behalf of OpenVPN & Easy-RSA.

Sent with Proton Mail secure email.
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wsC5BAEBCgBtBYJnoQR1CZBPl5z2a5C4nUUUAAAAAAAcACBzYWx0QG5vdGF0
aW9ucy5vcGVucGdwanMub3Jn3Gu49ybv2mRAB8J0EVehHzJbtiVxBjPL4O7D
Xnp8gysWIQQJvD1EZ6ONcnnFVVVPl5z2a5C4nQAA7aMIAIGmvQOaatP8Gdor
pU1VqPzji84e+rz2PiTCZtqMdwa8uHhYD0z1PycrAOBU/F/zGmFdsC1z1SRm
xXnHuGKn3RRiqzAPVaNCoHAx5tA1mV436QlZOtmUKt+RtadKt4ZZeT20Dt2i
zioM1YLbCgv+BNOWUEwhvhtpNmwE+0RpCrw4YQLc3DNCjF5P3mAQI7naq/LZ
00l1KPPxp5ulbWtLIgqtXMxsgSbydK1wjNJvf5GZDlADFc5BbHHC5RoPjQZm
Eezci+9LdAH5xa6G1l9tOA/8F3qgx1nF/rx7VzWspYRIMeF9B57S831TN3z4
dAOsomGnxaeO1zggz8XRLTeyYYc=
=U8pi
-----END PGP SIGNATURE-----

Attachment: publickey - tincantech@protonmail.com - 0x09BC3D44.asc
Description: application/pgp-keys

Attachment: publickey - tincantech@protonmail.com - 0x09BC3D44.asc.sig
Description: PGP signature

_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to