Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com From: Corinna Vinschen To: cygwin AT cygwin DOT com Subject: [ANNOUNCEMENT] Updated: openssl-0.9.7b-1, openssl-devel-0.9.7b-1 Reply-To: cygwin AT cygwin DOT com Message-Id: <20030930194425.EB53532A8A7@redhat.com> Date: Tue, 30 Sep 2003 15:44:25 -0400 (EDT) I've updated the version of OpenSSL to 0.9.7c-1. This also includes the openssl-devel package. This is a bugfix and security update. The Cygwin version matches the official source tree except for a minor tweak in the top level Makefile. ========================================================================= IMPORTANT NOTE: There will be no 0.9.6j compatibility package anymore. The 0.9.6 package is only kept for backward compatibility of packages built for Cygwin 1.3.x. I strongly recommend to upgrade packages to Cygwin 1.5.x and then automatically to OpenSSL-0.9.7c ASAP. THIS APPLIES ESPECIALLY FOR CYGWIN DISTRIBUTION PACKAGE MAINTAINERS! ========================================================================= The official release announcement text as of today follows: OpenSSL version 0.9.7c and 0.9.6k released ========================================== OpenSSL - The Open Source toolkit for SSL/TLS http://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 0.9.7c of our open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release and incorporates changes and bugfixes to the toolkit (for a complete list see http://www.openssl.org/source/exp/CHANGES ). We also release 0.9.6k, which contains the same security bugfix as 0.9.7c and a few more small bugfixes compared to 0.9.6j. For more details of the security issues being fixed in this release please see http://www.openssl.org/news/secadv_20030930.txt The most significant changes are: o Security: fix vulnerabilities in ASN.1 parsing CAN-2003-0543, CAN-2003-0544 [0.9.7c & 0.9.6k] o Security: fix additional vulnerability in ASN.1 parsing CAN-2003-0545 [0.9.7c] o Only accept a client cert if the server requests one [0.9.7c & 0.9.6k] o Various S/MIME bug and compatibility fixes [0.9.7c] We consider OpenSSL 0.9.7c to be the best version of OpenSSL available and we strongly recommend that users of older versions upgrade as soon as possible. OpenSSL 0.9.7c is available for download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under http://www.openssl.org/source/mirror.html): o http://www.openssl.org/source/ o ftp://ftp.openssl.org/source/ For those who want or have to stay with the 0.9.6 series of OpenSSL, we strongly recommend that you upgrade to OpenSSL 0.9.6k as soon as possible. It's available in the same location as 0.9.7c. To update your installation, click on the "Install Cygwin now" link on the http://cygwin.com/ web page. This downloads setup.exe to your system. Once you've downloaded setup.exe, run it and select "Net" ("Devel" for the openssl-devel package) and then click on the appropriate field until the above announced version number appears if it is not displayed already. If you have questions or comments, please send them to the Cygwin mailing list at: cygwin AT cygwin DOT com . I would appreciate it if you would use this mailing list rather than emailing me directly. This includes ideas and comments about the setup utility or Cygwin in general. If you want to make a point or ask a question, the Cygwin mailing list is the appropriate place. *** CYGWIN-ANNOUNCE UNSUBSCRIBE INFO *** If you want to unsubscribe from the cygwin-announce mailing list, look at the "List-Unsubscribe: " tag in the email header of this message. Send email to the address specified there. It will be in the format: cygwin-announce-unsubscribe-you=yourdomain DOT com AT cygwin DOT com If you need more information on unsubscribing, start reading here: http://sources.redhat.com/lists.html#unsubscribe-simple Please read *all* of the information on unsubscribing that is available starting at this URL. I implore you to READ this information before sending email about how you "tried everything" to unsubscribe. In 100% of the cases where people were unable to unsubscribe, the problem was that they hadn't actually read and comprehended the unsubscribe instructions. If you need to unsubscribe from cygwin-announce or any other mailing list, reading the instructions at the above URL is guaranteed to provide you with the info that you need. -- Corinna Vinschen Please, send mails regarding Cygwin to Cygwin Developer mailto:cygwin AT cygwin DOT com Red Hat, Inc. -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/