So more OpenSSL vulnerabilities were announced yesterday: https://www.openssl.org/news/secadv_20141015.txt
And OpenSSL 1.0.1j was released.
My normal process would be "Update Cygwin OpenSSL binaries and Win32 OpenSSL binaries and then re-release X2Go Client for Windows 4.0.2.1 with a new build # at the end."
However, probably make it unaffected by most OpenSSL vulns, but I do not wish
to do an analysis.
So what I think I'll do is this:
Note that we will still be bundling the very latest Cygwin packages, except for OpenSSH. I will keep Cygwin OpenSSH at 6.6.1p1-2, rather than 6.7p1-1, because there has not been enough time to test such a large change to X2Go Client for Windows. Cygwin's OpenSSH was updated on 2014-10-11.
Also note that VcXsrv 1.16.1.0 was released on 2014-10-13. (1.16.0.0 was never released.) I will not be upgrading to that on such short notice.
-Mike#2
[1] http://sourceforge.net/p/vcxsrv/code/ci/master/tree/openssl/ [2] http://sourceforge.net/u/mikedep333/vcxsrv/ci/xp-latestmsvc2013-x2gochanges/...
On Thu, Oct 16, 2014 at 07:49:16PM -0400, Michael DePaulo wrote:
So more OpenSSL vulnerabilities were announced yesterday: https://www.openssl.org/news/secadv_20141015.txt
Also note that VcXsrv 1.16.1.0 was released on 2014-10-13. (1.16.0.0 was never released.) I will not be upgrading to that on such short notice.
-Mike#2
Hi Mike,
do you have access to windows 8.1? There where some reports on the irc channel that VcXsrv does not work on it. Maybe you test can if the new VcXsrv works on 8.1 again.
Bye Henning
On Fri, Oct 17, 2014 at 2:54 AM, Henning Heinold <h.heinold@tarent.de> wrote:
On Thu, Oct 16, 2014 at 07:49:16PM -0400, Michael DePaulo wrote:
So more OpenSSL vulnerabilities were announced yesterday: https://www.openssl.org/news/secadv_20141015.txt
Also note that VcXsrv 1.16.1.0 was released on 2014-10-13. (1.16.0.0 was never released.) I will not be upgrading to that on such short notice.
-Mike#2
Hi Mike,
do you have access to windows 8.1? There where some reports on the irc channel that VcXsrv does not work on it. Maybe you test can if the new VcXsrv works on 8.1 again.
Bye Henning
Hi Henning and others,
http://blogs.vmware.com/workstation/2014/10/workstation-10-issue-recent-micr...
Maybe KB2995388 is at fault for VcXsrv not working. These monthly "Optional" "update rollups" make so many changes to Windows 8.1. They are more like mini service packs.
FYI: I successfully tested 1.15.2.1-xp+vc2013+x2go1 on Windows XP 32-bit SP3.
Nightly builds of x2goclient-4.0.3.0-2014.10.18-f74084f-setup.exe with all 3 OpenSSL updates are building now. http://code.x2go.org/releases/binary-win32/x2goclient/heuler/mingw32-4.8/qt-... http://code.x2go.org/releases/binary-win32/x2goclient/heuler/mingw32-4.4/qt-... (I still intend to officially launch only the mingw32-4.8 build).
-Mike