This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
doc:release-notes-mswin:x2goclient-4.0.3.2 [2015/02/25 12:18] mikedep333 Security Update: 4.0.3.2-20150224 |
doc:release-notes-mswin:x2goclient-4.0.3.2 [2015/03/29 21:32] mikedep333 4.0.3.2-20150329 |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== Windows-Specific Release notes for X2Go Client 4.0.3.2 ====== | ====== Windows-Specific Release notes for X2Go Client 4.0.3.2 ====== | ||
+ | ===== Security Update: 4.0.3.2-20150301 ===== | ||
+ | |||
+ | On 2015-03-29, 4.0.3.2-20150329 was released with the following changes: | ||
+ | < | ||
+ | - Windows: Update bundled VcXsrv from 1.15.2.2-xp+vc2013+x2go1 to | ||
+ | 1.15.2.5 (X2Go/ | ||
+ | The differences relevant to X2Go are: | ||
+ | + CVE-2015-0255 was fixed in VcXsrv itself | ||
+ | + VcXsrv' | ||
+ | to 1.0.1m (fixes the multiple CVEs announced on 2015-03-19) | ||
+ | + VcXsrv' | ||
+ | to 1.4.9 (Fixes CVE-2015-1802 through CVE-2015-1804) | ||
+ | + VcXsrv' | ||
+ | to 2.5.5 (fixes CVE-2014-9656 through CVE-2014-9675) | ||
+ | - Windows: Update bundled Win32 OpenSSL from 1.0.1L to 1.0.1m, | ||
+ | which fixes the multiple CVEs announced on 2015-03-19. | ||
+ | - Windows: Update bundled PuTTY from 0.63 to 0.64. | ||
+ | In addition to other changes, CVE-2015-2157 has been fixed. | ||
+ | - Windows: Update bundled Cygwin openssl from 1.0.1k-1 to 1.0.2a-1. | ||
+ | This update fixes the multiple CVEs announced on 2015-03-19 | ||
+ | </ | ||
+ | As with most vulnerabilities in 3rd party software, the X2Go project has not done an analysis of whether X2Go Client was actually affected by these vulnerabilities. However, as a precaution, we strongly encourage all users to update. | ||
+ | ===== Security Update: 4.0.3.2-20150301 ===== | ||
+ | |||
+ | On 2015-03-01, 4.0.3.2-20150301 was released with the following changes: | ||
+ | |||
+ | - Windows: Update bundled VcXsrv from 1.15.2.3-xp+vc2013+x2go1 to 1.15.2.4-xp+vc2013+x2go1. The difference is that VcXsrv' | ||
+ | |||
+ | As with most vulnerabilities in 3rd party software, the X2Go project has not done an analysis of whether X2Go Client was actually affected by these vulnerabilities. However, as a precaution, we strongly encourage all users to update. | ||
===== Security Update: 4.0.3.2-20150224 ===== | ===== Security Update: 4.0.3.2-20150224 ===== | ||
Line 18: | Line 47: | ||
===== Available Builds ===== | ===== Available Builds ===== | ||
- | All builds with version " | + | All builds with version " |
==== Current Builds ==== | ==== Current Builds ==== | ||
- | The regular build, x2goclient-4.0.3.2-20150224-setup.exe, is available under this folder: | + | The regular build, x2goclient-4.0.3.2-20150329-setup.exe, is available under this folder: |
- | * http:// | + | * http:// |
- | A debug build, x2goclient-4.0.3.2-20150224-debug-setup.exe, | + | A debug build, x2goclient-4.0.3.2-20150329-debug-setup.exe, |
- | * http:// | + | * http:// |
==== Previous Builds ==== | ==== Previous Builds ==== | ||
- | The regular | + | The regular |
+ | * http:// | ||
+ | * http:// | ||
* http:// | * http:// | ||
- | A debug build, x2goclient-4.0.3.2-20150219-debug-setup.exe, | + | The debug builds, x2goclient-4.0.3.2-20150219-debug-setup.exe through x2goclient-4.0.3.2-20150301-setup.exe, |
+ | * http:// | ||
+ | * http:// | ||
* http:// | * http:// | ||
===== Supported Windows Versions ===== | ===== Supported Windows Versions ===== |