This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
doc:release-notes-mswin:x2goclient-4.0.2.1 [2014/07/12 22:46] mikedep333 Make the note about 4.0.2.1+hotfix1 a wiki note |
doc:release-notes-mswin:x2goclient-4.0.2.1 [2014/10/10 11:59] (current) mikedep333 4.0.2.1+hotfix1+build6: Update wording |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== Windows-Specific Release notes for X2Go Client 4.0.2.1 ====== | ====== Windows-Specific Release notes for X2Go Client 4.0.2.1 ====== | ||
+ | |||
+ | ===== Security Update: 4.0.2.1+hotfix1+build6 ===== | ||
+ | |||
+ | On 2014-10-10, 4.0.2.1+hotfix1+build6 was released with the following changes: | ||
+ | CVE-2014-6278 | ||
+ | - Windows: Cygwin Bash (sh.exe) updated from 4.1.14-7 to 4.1.17-9. 4.1.17-9 fixes CVE-2014-6278. | ||
+ | - Windows: The aforementioned Cygwin Bash update also fixes the vulnerabilities fixed in 4.1.16-8, CVE-2014-7186, | ||
+ | - Windows: Cygwin krb5 (Kerberos) updated from 1.12.1-2 to 1.12.2-1, which fixes CVE-2014-4341 through -4345. | ||
+ | |||
+ | For the exact details of the bash and krb5 updates, see the respective release announcements: | ||
+ | https:// | ||
+ | |||
+ | https:// | ||
+ | |||
+ | https:// | ||
+ | |||
+ | As with most vulnerabilities in 3rd party software, the X2Go project has not done an analysis of whether X2Go Client was actually affected by these vulnerabilities. In fact, it seems unlikely that X2Go Client for Windows is affected by the krb5 vulnerabilities because X2Go Client for Windows uses PuTTY for Kerberos authentication instead. (Cygwin krb5 is merely installed because it is a dependency of Cygwin SSH.) However, as a precaution, we are releasing this updated build of X2Go Client for Windows. Unless an analysis is performed, we strongly encourage all users to update. This includes users of the " | ||
+ | |||
+ | ===== Security Update: 4.0.2.1+hotfix1+build5 ===== | ||
+ | |||
+ | On 2014-09-30, 4.0.2.1+hotfix1+build5 was released with the following changes: | ||
+ | |||
+ | - Windows: Cygwin Bash (sh.exe) updated from 4.1.10-4 to 4.1.14-7. This fixes the " | ||
+ | |||
+ | For the exact details of the bash update, see the Cygwin Bash release announcement for 4.1.14-7 | ||
+ | |||
+ | https:// | ||
+ | |||
+ | The X2Go project has not done an analysis of whether X2Go Client was actually affected by the " | ||
+ | |||
+ | ===== Bugfix Update: 4.0.2.1+hotfix1+build4 ===== | ||
+ | |||
+ | On 2014-09-02, 4.0.2.1+hotfix1+build4 was released with the following changes: | ||
+ | |||
+ | - Windows: Fix missing VcXsrv/ | ||
+ | |||
+ | Users are advised to update from 4.0.2.1+hotfix1+build3 to 4.0.2.1+hotfix1+build4 if they are affected by this bug. | ||
+ | |||
+ | ===== Security Update: 4.0.2.1+hotfix1+build3 ===== | ||
+ | |||
+ | On 2014-08-09, 4.0.2.1+hotfix1+build3 was released with the following changes: | ||
+ | |||
+ | - Windows: Win32 OpenSSL updated from 1.0.1h to 1.0.1i, which fixes the 9 CVEs announced on 2014-08-06. | ||
+ | - Windows: Cygwin OpenSSL updated from 1.0.1h-1 to 1.0.1i-1, which fixes the 9 CVEs announced on 2014-08-06. | ||
+ | |||
+ | All users of 4.0.2.1+hotfix1 and earlier are strongly encouraged to update to 4.0.2.1+hotfix1+build3. This includes users of the “misc” fonts and “full” fonts builds. | ||
+ | |||
+ | Also, please note: | ||
+ | |||
+ | - x2goclient " | ||
===== Major Windows-specific changes since 4.0.2.0+build4 ===== | ===== Major Windows-specific changes since 4.0.2.0+build4 ===== | ||
- | < | + | < |
=== Smaller Installer === | === Smaller Installer === | ||
Line 15: | Line 65: | ||
===== Available Builds ===== | ===== Available Builds ===== | ||
- | All builds with version " | + | All builds with version " |
< | < | ||
Line 21: | Line 71: | ||
==== Current Builds ==== | ==== Current Builds ==== | ||
- | The regular build, x2goclient-4.0.2.1+hotfix1-setup.exe, | + | The regular build, x2goclient-4.0.2.1+hotfix1+build6-setup.exe, is available under this folder: |
+ | * http:// | ||
+ | |||
+ | The " | ||
+ | |||
+ | The " | ||
+ | |||
+ | A debug build, x2goclient-4.0.2.1+hotfix1+build6-debug-setup.exe, | ||
+ | |||
+ | * http:// | ||
+ | |||
+ | |||
+ | ==== Previous Builds ==== | ||
+ | |||
+ | The regular builds, x2goclient-4.0.2.1+hotfix1 through x2goclient-4.0.2.1+hotfix1+build5-setup.exe, | ||
+ | * http:// | ||
+ | * http:// | ||
+ | * http:// | ||
* http:// | * http:// | ||
- | The " | + | |
+ | The " | ||
| | ||
- | The " | + | The " |
- | A debug build, x2goclient-4.0.2.1+hotfix1-debug-setup.exe, | + | Debug builds, x2goclient-4.0.2.1+hotfix1-debug-setup.exe through x2goclient-4.0.2.1+hotfix1+build5-debug-setup.exe, |
- | * http:// | + | * http:// |
+ | * http:// | ||
+ | * http:// | ||
+ | | ||
===== Supported Windows Versions ===== | ===== Supported Windows Versions ===== |