Softether-vpnclient-v4.27-9667-beta-2018.05.26-windows-x86_x64-intel.exe (42.96 MB)
Release Date: 2018-05-29 <Latest Build>
OS: Windows, CPU: Intel (x86 and x64)
(Windows 98 / 98 SE / ME / NT 4.0 SP6a / 2000 SP4 / XP SP2, SP3 / Vista SP1, SP2 / 7 SP1 / 8 / 8.1 / 10 / Server 2003 SP2 / Server 2008 SP1, SP2 / Hyper-V Server 2008 / Server 2008 R2 SP1 / Hyper-V Server 2008 R2 / Server 2012 / Hyper-V Server 2012 / Server 2012 R2 / Hyper-V Server 2012 R2 / Server 2016)

Changelog:
Homepage:
Download Link:
Official Download Link:
Release Date: 2018-05-29 <Latest Build>
OS: Windows, CPU: Intel (x86 and x64)
(Windows 98 / 98 SE / ME / NT 4.0 SP6a / 2000 SP4 / XP SP2, SP3 / Vista SP1, SP2 / 7 SP1 / 8 / 8.1 / 10 / Server 2003 SP2 / Server 2008 SP1, SP2 / Hyper-V Server 2008 / Server 2008 R2 SP1 / Hyper-V Server 2008 R2 / Server 2012 / Hyper-V Server 2012 / Server 2012 R2 / Hyper-V Server 2012 R2 / Server 2016)

Changelog:
- SoftEther VPN 4.27 Build 9668 Beta (May 29, 2018)
Fixed the "-fPIC" error at the make command on Ubuntu Linux.
- SoftEther VPN 4.27 Build 9666 Beta (April 21, 2018)
Fixed an issue that the VPN Client Virtual Network Driver fails to communicate when LTE or 3G wireless modems are used to connect to the internet by the computer running Windows 10 Spring Creators Update (version 1803). Please be careful that It is necessary to reinstall the device driver of the Virtual Network Adapter after upgrading the VPN client to build 9666 or later in order to solve the problem.
When reinstalling the device driver of the Virtual Network Driver card, we changed the behavior as to cleanup the older driver before installing the newer driver.
When installing a new device driver of the Virtual Network Driver card, we changed the initial random MAC address from 00-AC-xx-xx-xx-xx to 5E-xx-xx-xx-xx-xx. This realizes the compliance with the local address bit of the MAC address rule.
There was one vulnerability on SoftEther VPN for Windows. When loading the DLL file by the LoadLibrary() function in Windows VPN programs, we changed the behavior not to search the current directory. Based on this improvement, even if there are untrusted DLL files in the current directory, it is now safe to avoid the problem of unexpected security problem caused by the default loading behavior of Windows. Acknowledgments: This is based on a report by Herman Groeneveld, aka Sh4d0wman.
- SoftEther VPN 4.25 Build 9656 RTM (January 15, 2018)
There are 11 vulnerabilities on SoftEther VPN. There vulnerabilities are found by the source code audit process conducted by You do not have permission to view the full content of this post. Log in or register now. and You do not have permission to view the full content of this post. Log in or register now. in late 2017. This build fixes all of these vulnerabilities.
7 missing memory boundaries checks and similar memory problems. There are no risk of arbitrary code execution or intrusion on these bugs in my analysis. However, these problems may lead to crash the running server process. So these bugs must be fixed.
- Buffer overread in ParseL2TPPacket()
- Memory corruption in IcmpParseResult
- Missing bounds check in ParseUDP() can lead to invalid memory access
- Out-of-bounds read in IPsec_PPP.c (unterminated string buffer)
- Overlapping parameters to memcpy() via StrToIp6()
- PACK ReadValue() crash vulnerability
- Potential use of uninitialized memory via IPToInAddr6()
4 memory leaks. While the amount of leakage is very small per time, these bugs can finally cause process crash by out of memory. So these bugs must be fixed.
- Memory leak in NnReadDnsRecord
- Memory leak in RadiusLogin()
- Memory leak via ParsePacketIPv4WithDummyMacHeader
- Remote memory leak in OpenVPN server code
1 coding improvement. This is not a bug, however, I fixed the code to avoid furture misunderstanding.
- RecvAll can return success on failure (leading to use of uninitialized memory)
Contributors for this bugfix:
- Max Planck Institute for Molecular Genetics
- Mr. Guido Vranken
Also, this build has the following improvements:
- Fix a bug in the Win32EnumDirExW() function.
- Add the Alternative subject name field on the new X.509 certificate creation.
Homepage:
You do not have permission to view the full content of this post. Log in or register now.
Download Link:
Official Download Link:
You do not have permission to view the full content of this post. Log in or register now.

