Difference description to VPN Client x500 V1.4.2 Patch (2022-11-08)

Maintenance
  • Updated bundled OpenSSL to version 1.1.1q
  • Updated bundled OpenVPN to version 2.5.8
Security
  • Updated bundled stunnel to version 5.67
Notes
Regarding OpenSSL vulnerabilities CVE-2022-3786 and CVE-2022-3602:
  • the VPN Client and OpenVPN are built with OpenSSL 1.1.1 and are not vulnerable.
  • stunnel:
    • Windows and macOS: 5.67 is built with OpenSSL 3.0.7, which addresses the CVEs.
    • Linux: the package manager's stunnel is used, which usually dynamically links to the system OpenSSL version.
Please contact your IT department if you need to update the stunnel and/or OpenSSL packages.

URL for linking this AKB article: https://www.lenze.com/en-de/go/akb/202200354/1/
Kontaktformular