Netgate heeft versie 26.03.1 van pfSense Plus uitgebracht. Dit pakket is gebaseerd op het besturingssysteem FreeBSD en richt zich op router- en firewalltaken. Het is verkrijgbaar in de gratis Community Edition en een Plus-uitvoering, die voorheen als Factory Edition werd aangeboden. De Plus-uitvoering draait op de hardware die Netgate aanbiedt, als virtuele machine in AWS of Azure. In tegenstelling tot de Community Edition is het echter geen open source.
Het is in 2004 begonnen als een afsplitsing van m0n0wall vanwege verschillende visies bij de ontwikkelaars en in de loop van de jaren uitgegroeid tot een router- en firewallpakket dat in zowel kleine als zeer grote omgevingen kan worden ingezet. Voor meer informatie verwijzen we naar deze pagina. De changelog voor deze uitgave ziet er als volgt uit:
Security/ErrataThis release contains several security fixes, some of which were previously released via the Recommended System Patches feature of the System Patches Package.
pfSense Plus
- pfSense-SA-26_03.webgui - Potential Stored XSS in
diag_arp.phpwhen using ISC DHCP #16763- pfSense-SA-26_04.webgui - Potential XSS in RSS Widget feed content post titles #16770
- pfSense-SA-26_05.webgui - Potential XSS in Captive Portal widget #16773
- Several security and errata fixes were merged from FreeBSD, including fixes for vulnerabilities discovered in the DHCP client.
- Several base system packages were updated to address various upstream security issues.
Changes in this version of pfSense Plus software.
Aliases / TablesAuthentication
- Changed: Increase amount of system alias content printed in alias list #16118
Captive Portal
- Fixed: LDAP shell authentication does not honor configured group DN restriction #16799
Configuration Upgrade
- Fixed: Captive Portal authentication messages are not logged #16818
- Fixed: Potential XSS in Captive Portal widget #16773
Console Menu
- Fixed: Configuration upgrades fail to properly upgrade firewall rules for revisions
10.6and10.8#16840Dashboard
- Fixed: Repeatedly attempting to cancel console menu operations with
Ctrl-Ccan drop the user into the password change flow #16782Diagnostics
- Fixed: Potential XSS in RSS Widget feed content post titles #16770
Dynamic DNS
- Fixed: Potential Stored XSS in
diag_arp.phpwhen using ISC DHCP #16763IPsec
- Added: Log errors when determining the RFC2136 update source address #16819
OpenVPN
- Fixed: IPsec daemon can crash if a peer initiates two rekeys for the same child SA #16836
Operating System
- Fixed: Automatically generated
vpn_networkstable is missing OpenVPN networks #16795- Fixed: All OpenVPN instances are restarted when applying changes to any assigned interface #16815
PHP Interpreter
- Fixed: Kernel panic due to race condition on a
bpfdevice #16790Rules / NAT
- Fixed: NULL bytes in an IP address can trigger PHP errors from
ip2long()#16771User Manager / Privileges
- Added: Add MAP-E port set (PSID) support to manual outbound NAT rules #11901
- Fixed: Firewall rule source option
This Firewall (self)is not available when duplicating floating rules #16729Wake on LAN
- Fixed: Creating a new user ignores certificate checkbox value if the certificate fields are populated #16721
- Fixed: Links to send WOL packets are not handled consistently, may fail to send #16803
