From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 28456 invoked by alias); 18 Oct 2011 07:53:27 -0000 Received: (qmail 28393 invoked by uid 22791); 18 Oct 2011 07:53:01 -0000 X-Spam-Check-By: sourceware.org Received: from aquarius.hirmke.de (HELO calimero.vinschen.de) (217.91.18.234) by sourceware.org (qpsmtpd/0.83/v0.83-20-g38e4449) with ESMTP; Tue, 18 Oct 2011 07:52:42 +0000 Received: by calimero.vinschen.de (Postfix, from userid 500) id 2EE792CBDA0; Tue, 18 Oct 2011 09:52:39 +0200 (CEST) Date: Tue, 18 Oct 2011 07:53:00 -0000 From: Corinna Vinschen To: cygwin-apps@cygwin.com Cc: "Dr. Volker Zell" Subject: Re: SECURITY: gnutls Message-ID: <20111018075239.GA11654@calimero.vinschen.de> Reply-To: cygwin-apps@cygwin.com Mail-Followup-To: cygwin-apps@cygwin.com, "Dr. Volker Zell" References: <1318790948.7624.14.camel@YAAKOV04> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: User-Agent: Mutt/1.5.21 (2010-09-15) Mailing-List: contact cygwin-apps-help@cygwin.com; run by ezmlm Precedence: bulk Sender: cygwin-apps-owner@cygwin.com List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Mail-Followup-To: cygwin-apps@cygwin.com X-SW-Source: 2011-10/txt/msg00044.txt.bz2 On Oct 17 20:45, Chris Sutcliffe wrote: > On 16 October 2011 14:49, Yaakov (Cygwin/X) wrote: > > Dr. Volker Zell, > > > > gnutls 2.8.6 is susceptible to CVE-2009-3555.  This has been fixed since > > 2.10.0, but the current stable releases are 2.12.11 (ABI-compatible with > > 2.8.6) and 3.0.4 (which breaks ABI compatibility).  For now, please > > release 2.12.11 ASAP for all the apps currently dependent on > > libgnutls26. > > Is Dr. Volker Zell still active? The last post I can find from him > was from June of last year: > > http://sourceware.org/ml/cygwin/2010-06/msg00009.html I had a short mail exchange with Volker in August. He had some private problems to deal with. He wrote he would catch up at one point. Volker, I CCed you so you can chime in, ok? Thanks, Corinna -- Corinna Vinschen Please, send mails regarding Cygwin to Cygwin Project Co-Leader cygwin AT cygwin DOT com Red Hat