From mboxrd@z Thu Jan 1 00:00:00 1970 From: Erik Kapfer To: development@lists.ipfire.org Subject: [PATCH 3/3] ovpn_reorganize_encryption: Integrate LZO from global to advanced section Date: Sat, 27 Apr 2019 16:05:51 +0200 Message-ID: <20190427140551.10647-3-ummeegge@ipfire.org> In-Reply-To: <20190427140551.10647-1-ummeegge@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============4712582959486701658==" List-Id: --===============4712582959486701658== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Fixes: #11819 - Since the Voracle vulnerability, LZO is better placed under advanced sectio= n cause under specific circumstances it is exploitable. - Warning/hint has been added in the option defaults description. Signed-off-by: Erik Kapfer --- html/cgi-bin/ovpnmain.cgi | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/html/cgi-bin/ovpnmain.cgi b/html/cgi-bin/ovpnmain.cgi index d7895e600..c5eac26a9 100644 --- a/html/cgi-bin/ovpnmain.cgi +++ b/html/cgi-bin/ovpnmain.cgi @@ -785,6 +785,7 @@ if ($cgiparams{'ACTION'} eq $Lang::tr{'save-adv-options'}= ) { $vpnsettings{'MAX_CLIENTS'} =3D $cgiparams{'MAX_CLIENTS'}; $vpnsettings{'REDIRECT_GW_DEF1'} =3D $cgiparams{'REDIRECT_GW_DEF1'}; $vpnsettings{'CLIENT2CLIENT'} =3D $cgiparams{'CLIENT2CLIENT'}; + $vpnsettings{'COMPLZO'} =3D $cgiparams{'DCOMPLZO'}; $vpnsettings{'ADDITIONAL_CONFIGS'} =3D $cgiparams{'ADDITIONAL_CONFIGS'}; $vpnsettings{'DHCP_DOMAIN'} =3D $cgiparams{'DHCP_DOMAIN'}; $vpnsettings{'DHCP_DNS'} =3D $cgiparams{'DHCP_DNS'}; @@ -2654,6 +2655,9 @@ ADV_ERROR: $checked{'REDIRECT_GW_DEF1'}{'off'} =3D ''; $checked{'REDIRECT_GW_DEF1'}{'on'} =3D ''; $checked{'REDIRECT_GW_DEF1'}{$cgiparams{'REDIRECT_GW_DEF1'}} =3D 'CHECKE= D'; + $checked{'DCOMPLZO'}{'off'} =3D ''; + $checked{'DCOMPLZO'}{'on'} =3D ''; + $checked{'DCOMPLZO'}{$cgiparams{'DCOMPLZO'}} =3D 'CHECKED'; $checked{'ADDITIONAL_CONFIGS'}{'off'} =3D ''; $checked{'ADDITIONAL_CONFIGS'}{'on'} =3D ''; $checked{'ADDITIONAL_CONFIGS'}{$cgiparams{'ADDITIONAL_CONFIGS'}} =3D 'CH= ECKED'; @@ -2732,7 +2736,7 @@ print < =20 - + =20 @@ -2745,6 +2749,11 @@ print < =20 + $Lang::tr{'comp-lzo'} + + $Lang::tr{'openvpn default'}: off ($Lang::tr= {'attention'} exploitable via Voracle) + + $Lang::tr{'ovpn add conf'} @@ -5248,8 +5257,6 @@ END - $Lang::tr{'comp-lzo'} - =20
--=20 2.12.2 --===============4712582959486701658==--