Re: [Openvpn-devel] OpenVPN 2.1-beta12 released

2006-04-05 Thread James Yonan
James Yonan wrote: 2006.04.05 -- Version 2.1-beta12 * Security Vulnerability -- An OpenVPN client connecting to a malicious or compromised server could potentially receive "setenv" configuration directives from the server which could cause arbitrary code execution on the client via a LD_PRELO

[Openvpn-devel] OpenVPN 2.1-beta12 released

2006-04-05 Thread James Yonan
2006.04.05 -- Version 2.1-beta12 * Security Vulnerability -- An OpenVPN client connecting to a malicious or compromised server could potentially receive "setenv" configuration directives from the server which could cause arbitrary code execution on the client via a LD_PRELOAD attack. A succe