public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* [ANNOUNCEMENT] [SECURITY] Updated: openssl-1.0.1h-1, libopenssl098-0.9.8za-1
@ 2014-06-06  8:13 Yaakov Selkowitz
  2014-06-06 15:42 ` Andrew Schulman
  0 siblings, 1 reply; 3+ messages in thread
From: Yaakov Selkowitz @ 2014-06-06  8:13 UTC (permalink / raw)
  To: cygwin

The following packages have been updated in the Cygwin distribution:

* openssl-1.0.1h-1
* libopenssl098-0.9.8za-1 (x86 only)
* libopenssl100-1.0.1h-1
* openssl-devel-1.0.1h-1

The OpenSSL toolkit provides support for secure communications between 
machines. OpenSSL includes a certificate management tool and shared 
libraries which provide various cryptographic algorithms and protocols.

This release includes fixes for several CVEs, including CVE-2014-0224 
(SSL/TLS man-in-the-middle).  Full details on these fixes are available 
here:

https://www.openssl.org/news/secadv_20140605.txt

The legacy libopenssl098 package has also been updated for the benefit 
of those packages still dependent thereon.

-- 

Yaakov
(on behalf of Corinna)


CYGWIN-ANNOUNCE UNSUBSCRIBE INFO
================================

If you want to unsubscribe from the cygwin-announce mailing list, please 
use the automated form at:

http://cygwin.com/lists.html#subscribe-unsubscribe

If this does not work, then look at the "List-Unsubscribe: " tag in the 
email header of this message.  Send email to the address specified 
there.  It will be in the format:

cygwin-announce-unsubscribe-you=yourdomain.com@cygwin.com

If you need more information on unsubscribing, start reading here:

http://sourceware.org/lists.html#unsubscribe-simple

Please read *all* of the information on unsubscribing that is available 
starting at this URL.

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [ANNOUNCEMENT] [SECURITY] Updated: openssl-1.0.1h-1, libopenssl098-0.9.8za-1
  2014-06-06  8:13 [ANNOUNCEMENT] [SECURITY] Updated: openssl-1.0.1h-1, libopenssl098-0.9.8za-1 Yaakov Selkowitz
@ 2014-06-06 15:42 ` Andrew Schulman
  2014-06-06 23:10   ` Yaakov Selkowitz
  0 siblings, 1 reply; 3+ messages in thread
From: Andrew Schulman @ 2014-06-06 15:42 UTC (permalink / raw)
  To: cygwin

> The following packages have been updated in the Cygwin distribution:
> 
> * openssl-1.0.1h-1
> * libopenssl098-0.9.8za-1 (x86 only)
> * libopenssl100-1.0.1h-1
> * openssl-devel-1.0.1h-1
> 
> The OpenSSL toolkit provides support for secure communications between 
> machines. OpenSSL includes a certificate management tool and shared 
> libraries which provide various cryptographic algorithms and protocols.
> 
> This release includes fixes for several CVEs, including CVE-2014-0224 
> (SSL/TLS man-in-the-middle).  Full details on these fixes are available 
> here:
> 
> https://www.openssl.org/news/secadv_20140605.txt

I don't see any reason here that programs that depend on libopenssl100,
such as stunnel, would need to be rebuit for this update.  Do you?


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [ANNOUNCEMENT] [SECURITY] Updated: openssl-1.0.1h-1, libopenssl098-0.9.8za-1
  2014-06-06 15:42 ` Andrew Schulman
@ 2014-06-06 23:10   ` Yaakov Selkowitz
  0 siblings, 0 replies; 3+ messages in thread
From: Yaakov Selkowitz @ 2014-06-06 23:10 UTC (permalink / raw)
  To: cygwin

On 2014-06-06 10:42, Andrew Schulman wrote:
> I don't see any reason here that programs that depend on libopenssl100,
> such as stunnel, would need to be rebuit for this update.  Do you?

No, but it would be nice if maintainers would rebuild their programs 
still dependent on libopenssl098 (on x86).


Yaakov


--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-06-06 23:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2014-06-06  8:13 [ANNOUNCEMENT] [SECURITY] Updated: openssl-1.0.1h-1, libopenssl098-0.9.8za-1 Yaakov Selkowitz
2014-06-06 15:42 ` Andrew Schulman
2014-06-06 23:10   ` Yaakov Selkowitz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).