Skip to content
Snippets Groups Projects
  1. Dec 15, 2021
    • kali's avatar
      [bug] avoid installing in custom paths · e694a038
      kali authored and Kali Kaneko's avatar Kali Kaneko committed
      A vulnerability in QtIFW produces improper ACLs to be set when
      installing in custom locations. This can lead to privilege escalation if
      a non-privileged user overwrites the openvpn binary. Thanks to
      researchers at Tenable for finding and reporting this!
      
      Impact is considered low-medium, since an installation outside of the
      suggested path is needed to trigger the issue.
      
      Privileged execution of openvpn should be abandoned in next release, in
      favor of the interactive service.
      
      A bug upstream should be filed since other projects could be affected by
      this vulnerability too.
      
      -Resolves: #569
      Unverified
      e694a038
  2. Dec 14, 2021
  3. Dec 01, 2021
    • Kali Kaneko's avatar
      [feat] disable autostart · f9111457
      Kali Kaneko authored
      we've agreed that the autostart behaviour can be unexpected;
      we'll expose the ability under preferences (it can be controlled via cli
      right now).
      Unverified
      f9111457
  4. Jul 12, 2021
  5. Jun 22, 2021
  6. Jun 14, 2021
Loading