User Tools

Site Tools


doc:release-notes-mswin:x2goclient-4.0.2.1

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Last revision Both sides next revision
doc:release-notes-mswin:x2goclient-4.0.2.1 [2014/09/02 02:29]
mikedep333 Add 4.0.2.1+hotfix1+build4
doc:release-notes-mswin:x2goclient-4.0.2.1 [2014/10/10 11:52]
mikedep333 Update for 4.0.2.1+hotfix1+build6
Line 1: Line 1:
 ====== Windows-Specific Release notes for X2Go Client 4.0.2.1 ====== ====== Windows-Specific Release notes for X2Go Client 4.0.2.1 ======
 +
 +===== Security Update: 4.0.2.1+hotfix1+build6 =====
 +
 +On 2014-10-10, 4.0.2.1+hotfix1+build6 was released with the following changes:
 +CVE-2014-6278
 +    - Windows: Cygwin Bash (sh.exe) updated from 4.1.14-7 to 4.1.17-9. 4.1.17-9 fixes CVE-2014-6278.
 +    - Windows: The aforementioned Cygwin Bash update also fixes the vulnerabilities fixed in 4.1.16-8, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277.
 +    - Windows: Cygwin krb5 (Kerberos) updated from 1.12.1-2 to 1.12.2-1, which fixes CVE-2014-4341 through -4345.
 +
 +For the exact details of the bash and krb5 updates, see the respective release announcements:
 +https://cygwin.com/ml/cygwin-announce/2014-10/msg00015.html
 +
 +https://cygwin.com/ml/cygwin-announce/2014-10/msg00004.html
 +
 +https://cygwin.com/ml/cygwin-announce/2014-10/msg00008.html
 +
 +The X2Go project has not done an analysis of whether X2Go Client was actually affected by these vulnerabilities. In fact, it seems very unlikely that X2Go Client for Windows is affected by the krb5 vulnerabilities because X2Go Client for Windows uses PuTTY for Kerberos authentication instead. (Cygwin krb5 is merely installed because it is a dependency of Cygwin SSH.) However, as a precaution, we are releasing this updated build of X2Go Client for Windows. Unless an analysis is performed, we strongly encourage all users to update. This includes users of the "misc" fonts and "full" fonts builds.
 +
 +===== Security Update: 4.0.2.1+hotfix1+build5 =====
 +
 +On 2014-09-30, 4.0.2.1+hotfix1+build5 was released with the following changes:
 +
 +    - Windows: Cygwin Bash (sh.exe) updated from 4.1.10-4 to 4.1.14-7. This fixes the "Shellshock" vulnerability.
 +
 +For the exact details of the bash update, see the Cygwin Bash release announcement for 4.1.14-7
 +
 +https://cygwin.com/ml/cygwin-announce/2014-09/msg00040.html
 +
 +The X2Go project has not done an analysis of whether X2Go Client was actually affected by the "Shellshock" vulnerability. However, as a precaution, we are releasing this updated build of X2Go Client for Windows with the fixed cygwin bash. Unless an analysis is performed, we strongly encourage all users to update. This includes users of the "misc" fonts and "full" fonts builds.
  
 ===== Bugfix Update: 4.0.2.1+hotfix1+build4 ===== ===== Bugfix Update: 4.0.2.1+hotfix1+build4 =====
Line 36: Line 65:
 ===== Available Builds ===== ===== Available Builds =====
  
-All builds with version "4.0.2.1+hotfix1+build3" in their filename are current.+All builds with version "4.0.2.1+hotfix1+build6" in their filename are current.
  
 <note>There will be no regular release of "4.0.2.1" because bug [[http://bugs.x2go.org/cgi-bin/bugreport.cgi?bug=546|546]] was discovered at the last minute. Instead, "4.0.2.1+hotfix1" will be the 1st released version of 4.0.2.1. It contains a fix for said bug.</note> <note>There will be no regular release of "4.0.2.1" because bug [[http://bugs.x2go.org/cgi-bin/bugreport.cgi?bug=546|546]] was discovered at the last minute. Instead, "4.0.2.1+hotfix1" will be the 1st released version of 4.0.2.1. It contains a fix for said bug.</note>
Line 42: Line 71:
 ==== Current Builds ==== ==== Current Builds ====
  
-The regular build, x2goclient-4.0.2.1+hotfix1+build4-setup.exe, is available under this folder here+The regular build, x2goclient-4.0.2.1+hotfix1+build6-setup.exe, is available under this folder: 
-  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build4/+  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build6/
  
-The "misc" fonts build, x2goclient-4.0.2.1+hotfix1+build4-miscfonts-setup.exe, is available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.+The "misc" fonts build, x2goclient-4.0.2.1+hotfix1+build6-miscfonts-setup.exe, is available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.
      
-The "full" fonts build, x2goclient-4.0.2.1+hotfix1+build4-fullfonts-setup.exe, is available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.+The "full" fonts build, x2goclient-4.0.2.1+hotfix1+build6-fullfonts-setup.exe, is available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.
  
-A debug build, x2goclient-4.0.2.1+hotfix1+build4-debug-setup.exe, is also available under the folder listed below. If you experience a bug and would like to assist with debugging it, this build is for you. It does not include any of the fonts.+A debug build, x2goclient-4.0.2.1+hotfix1+build6-debug-setup.exe, is also available under the folder listed below. If you experience a bug and would like to assist with debugging it, this build is for you. It does not include any of the fonts.
  
-  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build4/non-default-builds/+  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build6/non-default-builds/
  
  
 ==== Previous Builds ==== ==== Previous Builds ====
  
-The regular builds, x2goclient-4.0.2.1+hotfix1+build3-setup.exe & x2goclient-4.0.2.1+hotfix1-setup.exe, are available under these folders:+The regular builds, x2goclient-4.0.2.1+hotfix1 through x2goclient-4.0.2.1+hotfix1+build5-setup.exe, are available under these folders: 
 +  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build5/ 
 +  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build4/
   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build3/   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build3/
   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1/   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1/
  
  
-The "misc" fonts builds, x2goclient-4.0.2.1+hotfix1+build3-miscfonts-setup.exe x2goclient-4.0.2.1+hotfix1-miscfonts-setup.exe, are available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.+The "misc" fonts builds, x2goclient-4.0.2.1+hotfix1-miscfonts-setup.exe through x2goclient-4.0.2.1+hotfix1+build5-miscfonts-setup.exe, are available under the folders listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.
      
-The "full" fonts builds, x2goclient-4.0.2.1+hotfix1+build3-fullfonts-setup.exe x2goclient-4.0.2.1+hotfix1-fullfonts-setup.exe, are available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.+The "full" fonts builds, x2goclient-4.0.2.1+hotfix1-fullfonts-setup.exe through x2goclient-4.0.2.1+hotfix1+build5-fullfonts-setup.exe, are available under the folder listed below. See the "Noteworthy Windows-Specific Bugs" below for more info.
  
-Debug builds, x2goclient-4.0.2.1+hotfix1+build3-debug-setup.exe x2goclient-4.0.2.1+hotfix1-debug-setup.exe, are also available under the folder listed below. If you experience a bug and would like to assist with debugging it, these builds are for you. They do not include any of the fonts.+Debug builds,  x2goclient-4.0.2.1+hotfix1-debug-setup.exe through x2goclient-4.0.2.1+hotfix1+build5-debug-setup.exe, are also available under the folder listed below. If you experience a bug and would like to assist with debugging it, these builds are for you. They do not include any of the fonts.
  
 +  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build5/non-default-builds/
 +  * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build4/non-default-builds/
   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build3/non-default-builds/   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1+build3/non-default-builds/
   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1/non-default-builds/   * http://code.x2go.org/releases/binary-win32/x2goclient/releases/4.0.2.1+hotfix1/non-default-builds/
doc/release-notes-mswin/x2goclient-4.0.2.1.txt · Last modified: 2014/10/10 11:59 by mikedep333