You can subscribe to this list here.
| 2002 | Jan | Feb | Mar | Apr (24) | May (14) | Jun (29) | Jul (33) | Aug (3) | Sep (8) | Oct (18) | Nov (1) | Dec (10) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2003 | Jan (3) | Feb (33) | Mar (7) | Apr (28) | May (30) | Jun (5) | Jul (10) | Aug (7) | Sep (32) | Oct (41) | Nov (20) | Dec (10) |
| 2004 | Jan (24) | Feb (18) | Mar (57) | Apr (40) | May (55) | Jun (48) | Jul (77) | Aug (15) | Sep (56) | Oct (80) | Nov (74) | Dec (52) |
| 2005 | Jan (38) | Feb (42) | Mar (39) | Apr (56) | May (79) | Jun (73) | Jul (16) | Aug (23) | Sep (68) | Oct (77) | Nov (52) | Dec (27) |
| 2006 | Jan (27) | Feb (18) | Mar (51) | Apr (62) | May (28) | Jun (50) | Jul (36) | Aug (33) | Sep (47) | Oct (50) | Nov (77) | Dec (13) |
| 2007 | Jan (15) | Feb (8) | Mar (14) | Apr (18) | May (25) | Jun (16) | Jul (16) | Aug (19) | Sep (32) | Oct (17) | Nov (5) | Dec (5) |
| 2008 | Jan (64) | Feb (25) | Mar (25) | Apr (6) | May (28) | Jun (20) | Jul (10) | Aug (27) | Sep (28) | Oct (59) | Nov (37) | Dec (43) |
| 2009 | Jan (40) | Feb (25) | Mar (12) | Apr (57) | May (46) | Jun (29) | Jul (39) | Aug (10) | Sep (20) | Oct (42) | Nov (50) | Dec (57) |
| 2010 | Jan (82) | Feb (165) | Mar (256) | Apr (260) | May (36) | Jun (87) | Jul (53) | Aug (89) | Sep (107) | Oct (51) | Nov (88) | Dec (117) |
| 2011 | Jan (69) | Feb (60) | Mar (113) | Apr (71) | May (67) | Jun (90) | Jul (88) | Aug (90) | Sep (48) | Oct (64) | Nov (69) | Dec (118) |
| 2012 | Jan (49) | Feb (528) | Mar (351) | Apr (190) | May (238) | Jun (193) | Jul (104) | Aug (100) | Sep (57) | Oct (41) | Nov (47) | Dec (51) |
| 2013 | Jan (94) | Feb (57) | Mar (96) | Apr (105) | May (77) | Jun (102) | Jul (27) | Aug (81) | Sep (32) | Oct (53) | Nov (127) | Dec (65) |
| 2014 | Jan (113) | Feb (59) | Mar (104) | Apr (259) | May (70) | Jun (70) | Jul (146) | Aug (45) | Sep (58) | Oct (149) | Nov (77) | Dec (83) |
| 2015 | Jan (53) | Feb (66) | Mar (86) | Apr (50) | May (135) | Jun (76) | Jul (151) | Aug (83) | Sep (97) | Oct (262) | Nov (245) | Dec (231) |
| 2016 | Jan (131) | Feb (233) | Mar (97) | Apr (138) | May (221) | Jun (254) | Jul (92) | Aug (248) | Sep (168) | Oct (275) | Nov (477) | Dec (445) |
| 2017 | Jan (218) | Feb (217) | Mar (146) | Apr (172) | May (216) | Jun (252) | Jul (164) | Aug (192) | Sep (190) | Oct (143) | Nov (255) | Dec (182) |
| 2018 | Jan (295) | Feb (164) | Mar (113) | Apr (147) | May (64) | Jun (262) | Jul (184) | Aug (90) | Sep (69) | Oct (364) | Nov (102) | Dec (101) |
| 2019 | Jan (119) | Feb (64) | Mar (64) | Apr (102) | May (57) | Jun (154) | Jul (84) | Aug (81) | Sep (76) | Oct (102) | Nov (233) | Dec (89) |
| 2020 | Jan (38) | Feb (170) | Mar (155) | Apr (172) | May (120) | Jun (223) | Jul (461) | Aug (227) | Sep (268) | Oct (113) | Nov (56) | Dec (124) |
| 2021 | Jan (121) | Feb (48) | Mar (334) | Apr (345) | May (207) | Jun (136) | Jul (71) | Aug (112) | Sep (122) | Oct (173) | Nov (184) | Dec (223) |
| 2022 | Jan (197) | Feb (206) | Mar (156) | Apr (212) | May (192) | Jun (170) | Jul (143) | Aug (380) | Sep (182) | Oct (148) | Nov (128) | Dec (269) |
| 2023 | Jan (248) | Feb (196) | Mar (264) | Apr (36) | May (123) | Jun (66) | Jul (120) | Aug (48) | Sep (157) | Oct (198) | Nov (300) | Dec (273) |
| 2024 | Jan (271) | Feb (147) | Mar (207) | Apr (78) | May (107) | Jun (168) | Jul (151) | Aug (51) | Sep (438) | Oct (221) | Nov (302) | Dec (357) |
| 2025 | Jan (451) | Feb (219) | Mar (326) | Apr (232) | May (306) | Jun (181) | Jul (452) | Aug (282) | Sep (620) | Oct (793) | Nov (682) | Dec |
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
| | | | | | | 1 (4) |
| 2 (3) | 3 | 4 (4) | 5 (1) | 6 (1) | 7 | 8 (3) |
| 9 | 10 (5) | 11 (11) | 12 (7) | 13 | 14 | 15 (2) |
| 16 | 17 | 18 | 19 | 20 | 21 | 22 |
| 23 | 24 (8) | 25 (5) | 26 (8) | 27 (5) | 28 | 29 (2) |
| 30 (4) | 31 (10) | | | | | |
| From: Илья Ш. <chi...@gm...> - 2015-08-01 19:18:22 |
I do not mind about "the official repo". can you provide more details on that? 2015-08-01 18:07 GMT+05:00 Gert Doering <ge...@gr...>: > Hi, > > On Fri, Jul 31, 2015 at 11:57:26AM +0200, Samuel Thibault wrote: >> But without a central repository where people would get to know about >> your version, then it's even more probable that you'll remain the only >> user... > > Indeed. Who *is* maintaining the radius plugin these days? What is > "the official" repo? > > I found some stuff on > > http://www.nongnu.org/radiusplugin/ > > (no change since 2010, but the debian package has "more recent" updates, > and the ubuntu package even has a patch from Samuel Thibault :-) ) > > http://www.bytebucket.org/02strich/openvpn-auth-radius/src > > (this seems to be a fork, many of the files have the commit message > "initial commit - based on 2.1 Beta", but there has been a bit of activity > in 2012 and 2014... not very much, so merging the stuff back should not > be very hard) > > gert > > -- > USENET is *not* the non-clickable part of WWW! > //www.muc.de/~gert/ > Gert Doering - Munich, Germany ge...@gr... > fax: +49-89-35655025 ge...@ne... |
| From: Gert D. <ge...@gr...> - 2015-08-01 14:48:06 |
Your patch has been applied to the master and release/2.3 branch. commit cc377dec820f9e6e7e72981013eb3857aa6ea5ce (master) commit 338f11821fa7ce95c768b0cc074f3af7346b19fa (release/2.3) Author: Steffan Karger Date: Wed Jul 29 12:30:26 2015 +0200 Fix overflow check in openvpn_decrypt() Signed-off-by: Steffan Karger <ste...@fo...> Acked-by: Arne Schwabe <ar...@rf...> Message-Id: <143...@fo...> URL: http://article.gmane.org/gmane.network.openvpn.devel/9974 Signed-off-by: Gert Doering <ge...@gr...> -- kind regards, Gert Doering |
| From: Gert D. <ge...@gr...> - 2015-08-01 13:07:27 |
Hi, On Fri, Jul 31, 2015 at 11:57:26AM +0200, Samuel Thibault wrote: > But without a central repository where people would get to know about > your version, then it's even more probable that you'll remain the only > user... Indeed. Who *is* maintaining the radius plugin these days? What is "the official" repo? I found some stuff on http://www.nongnu.org/radiusplugin/ (no change since 2010, but the debian package has "more recent" updates, and the ubuntu package even has a patch from Samuel Thibault :-) ) http://www.bytebucket.org/02strich/openvpn-auth-radius/src (this seems to be a fork, many of the files have the commit message "initial commit - based on 2.1 Beta", but there has been a bit of activity in 2012 and 2014... not very much, so merging the stuff back should not be very hard) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany ge...@gr... fax: +49-89-35655025 ge...@ne... |
| From: Arne S. <ar...@rf...> - 2015-08-01 12:57:55 |
Am 01.07.15 um 13:03 schrieb ste...@fo...: > From: Steffan Karger <ste...@fo...> > > Sebastian Krahmer from the SuSE security team reported that the buffer > overflow check in openvpn_decrypt() was too strict according to the > cipher update function contract: > > "The amount of data written depends on the block alignment of the > encrypted data: as a result the amount of data written may be anything > from zero bytes to (inl + cipher_block_size - 1) so outl should contain > sufficient room." > > This stems from the way CBC mode works, which caches input and 'flushes' > it block-wise to the output buffer. We do allocate enough space for this > extra block in the output buffer for CBC mode, but not for CFB/OFB modes. > > This patch: > * updates the overflow check to also verify that the extra block required > according to the function contract is available. > * uses buf_inc_len() to double-check for overflows during en/decryption. > * also reserves the extra block for non-CBC cipher modes. > > In practice, I could not find a way in which this would fail. The plaintext > is never longer than the ciphertext, and the implementations of CBC/OFB/CBC > for AES and BF in both OpenSSL and PolarSSL/mbed TLS do not use the buffer > beyond the plaintext length when decrypting. However, some funky OpenSSL > engine I did not check *might* use the buffer space required by the > function contract. So we should still make sure we have enough room > anyway. > ACK from me. Arne |