https://www.openssl.org/news/secadv_20140605.txt
I will provide x2goclient-4.0.2.0+build3 for Windows as soon as I can. It will contain the patched OpenSSL (1.0.1h). 1st, Win32 OpenSSL needs to be updated to 1.01h: http://slproweb.com/products/Win32OpenSSL.html (Once this page is updated, you may need to hit refresh.)
If I am not mistaken, I do not need to recompile x2goclient.exe, I merely need to replace the 2 Win32 OpenSSL .DLL files: libeay32.dll ssleay32.dll If anyone knows this for a fact, let me know.
-Mike#2