Re: [Openvpn-devel] Possible security bug

2006-04-03 Thread James Yonan
Alberto, By default, the OpenVPN client doesn't accept pushed options from the server unless "pull" or "client" is specified. The idea is that once you agree to accept configuration info from the server, you are trusting (to a certain extent) in its integrity, so there are limits in how far

[Openvpn-devel] Possible security bug

2006-04-03 Thread Alberto Gonzalez Iniesta
Hi all, I have just received the following bug report from the Debian Bug Track System: -- From: Hendrik Weimer As described in http://www.osreviews.net/reviews/security/openvpn OpenVPN contains a security hole that allows a malicious VPN server to take over connected clients. OpenVPN allows t