OpenSSH 7.1 has just been released. It will be available from the mirrors listed at https://www.openssh.org/ shortly.. From: Damien Miller Date: Fri, 21 Aug 2015 00:11:02 -0600 (MDT) To:
The OpenBSD project has released version 5.3 of OpenSSH, the free implementation of the Secure Shell protocol (SSH). The main changes in OpenSSH are support for path names with more than 256 characters and that support for Windows 95/98/ME has been dropped.. Apart from this, there are only minor fixes. An overview of all the changes are to be found in the release notes. OpenSSH is available under a BSD licence and funded through donations. The full release notes are here: From: Damien Miller To:
OpenSSH 4.5 has just been released. It will be available from the mirrors listed at https://www.openssh.org/ shortly. OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0 implementation and includes sftp client and server support. . OpenSSH 4.5 has just been released. It will be available from the mirrors listed at https://www.openssh.org/ shortly. OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0 implementation and includes sftp client and server support. Once again, we would like to thank the OpenSSH community for their continued support of the project, especially those who contributed code or patches, reported bugs, tested snapshots and purchased T-shirts or posters. T-shirt, poster and CD sales directly support the project. Pictures and more information can be found at: http://www.openbsd.org/tshirts.html and For international orders use and for European orders, use Changes since OpenSSH 4.4: =========================== This is a bugfix only release. No new features have been added. Security bugs resolved in this release: * Fix a bug in the sshd privilege separation monitor that weakened its verification of successful authentication. This bug is not known to be exploitable in the absence of additional vulnerabilities. This release includes the following non-security fixes: * Several compilation fixes for portable OpenSSH * Fixes to Solaris SMF/process contract support (bugzilla #1255) Thanks to everyone who has contributed patches, reported bugs and tested releases. Checksums: ========= - SHA1 (openssh-4.5.tar.gz) = def3de1557181062d788695b9371d02635af39fb - SHA1 (openssh-4.5p1.tar.gz) = 2eefcbbeb9e4fa16fa4500dec107d1a09d3d02d7 Reporting Bugs: ============== - please read https://www.openssh.org/report.html and http://bugzilla.mindrot.org/ OpenSSH is brought to you by Markus Friedl, Niels Provos, Theo de Raadt, Kevin Steves, Damien Miller, Darren Tucker, Jason McIntyre, Tim Rice and BenLindstrom. . OpenSSH 4.5 has been released, incorporating various enhancements and rectifications to its SSH protocol features.. OpenSSH, SSH, Secure Shell, Bug Fixes, Protocol Enhancements. . LinuxSecurity.com Team
The Debian Project has released an update to its popular GNU/Linux distribution, with security-related bugfixes a key feature. "This is the first update of Debian GNU/Linux 3.1 (codename 'Sarge') which mainly adds security updates to the stable release, along with some corrections to serious problems," said Debian security team member Martin Schulze in an e-mail announcing the update. . Schulze said systems administrators who regularly updated their Debian-based systems with security patches would not have to update much software. The update contains fixes for 172 pieces of software, including high-profile entries like spam-buster SpamAssassin, Web browser Mozilla Firefox and its sister project the Thunderbird e-mail client, the PHP and Python scripting languages, Web server Apache and anti-virus software ClamAV, in addition to the Linux kernel. The link for this article located at ZDNet is no longer available. . Ubuntu's new release bolsters safety by addressing vulnerabilities, affecting 150 applications such as Chrome and Nginx.. Debian Linux, Software Fixes, Security Update, Administration, Bug Fixes. . LinuxSecurity.com Team
The OpenSSL project team is pleased to announce the release of version 0.9.6h of our open source toolkit for SSL/TLS. This new OpenSSL version is a bugfix release. This will be the last release in the 0.9.6 series. . .. The OpenSSL project team is pleased to announce the release of version 0.9.6h of our open source toolkit for SSL/TLS. This new OpenSSL version is a bugfix release. This will be the last release in the 0.9.6 series . OpenSSL version 0.9.6h released =============================== OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org:443/ The OpenSSL project team is pleased to announce the release of version 0.9.6h of our open source toolkit for SSL/TLS. This new OpenSSL version is a bugfix release. This will be the last release in the 0.9.6 series. The most significant changes are: o New configuration targets for Tandem OSS and A/UX. o New OIDs for Microsoft attributes. o Better handling of SSL session caching. o Better comparison of distinguished names. o Better handling of shared libraries in a mixed GNU/non-GNU environment. o Support assembler code with Borland C. o Fixes for length problems. o Fixes for uninitialised variables. o Fixes for memory leaks, some unusual crashes and some race conditions. o Fixes for smaller building problems. o Updates of manuals, FAQ and other instructive documents. We consider OpenSSL 0.9.6h to be the best version of OpenSSL available and we strongly recommend that users of older versions upgrade as soon as possible. OpenSSL 0.9.6h is available for download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under o o [1] OpenSSL comes in the form of two distributions this time. The reasons for this is that we want to deploy the external crypto device support but don't want to have it part of the "normal" distribution just yet. The distribution containing the external crypto devicesupport is popularly called "engine", and is considered experimental. It's been fairly well tested on Unix and flavors thereof. If run on a system with no external crypto device, it will work just like the "normal" distribution. The distribution file names are: o openssl-0.9.6h.tar.gz [normal] MD5 checksum: 621bef36ad61012bb71945a1cb449073 o openssl-engine-0.9.6h.tar.gz [engine] MD5 checksum: a7e3f5c0a5451ca666e4cbe23a8617a2 The checksums were calculated using the following commands: openssl md5 < openssl-0.9.6h.tar.gz openssl md5 < openssl-engine-0.9.6h.tar.gz Yours, The OpenSSL Project Team... Mark J. Cox Ben Laurie Andy Polyakov Ralf S. Engelschall Richard Levitte Geoff Thorpe Dr. Stephen Henson Bodo Möller Lutz Jänicke Ulf Möller . OpenSSL version 1.1.1g is launched featuring essential patches and enhancements aimed at maximizing SSL/TLS toolkit efficiency.. OpenSSL Release, Bugfix Updates, SSL Improvements. . LinuxSecurity.com Team
Opera Software today released Opera 6.03 for Linux, a pure security upgrade that will implement changes in OpenSSL made public on Aug. 7, 2002 by the CERT Coordination Center (CERT/CC) as well as correct other bugfixes. . .. Opera Software today released Opera 6.03 for Linux, a pure security upgrade that will implement changes in OpenSSL made public on Aug. 7, 2002 by the CERT Coordination Center (CERT/CC) as well as correct other bugfixes . Opera Software is committed to offering its users the latest in browser security. When vulnerability in the third-party code was made public, work began to implement the new changes. The CERT/CC advisory is available at: 2002 CERT Advisories "We are committed to ensuring the very latest in browser security to all users," says Jon S. von Tetzchner, CEO, Opera Software ASA. "A Windows fix was released on August 13, and we are pleased to now offer our Linux users a version that eliminates the flaw in OpenSSL." The changelog for Opera 6.03 for Linux is available at: https://www.opera.com:443/opera -Whole Article . Opera Software today released Opera 6.03 for Linux, a pure security upgrade that will implement chan. opera, software, today, released, linux, security, upgrade, implement. . LinuxSecurity.com Team
Huagang Xie writes: "The LIDS project has just released LIDS 0.9.11 for kernel version 2.2.18. It contain a bugfix for lidsadm. For more detail, please visit ." I use LIDS on a daily basis and love it. Anybody who . . . . Huagang Xie writes: "The LIDS project has just released LIDS 0.9.11 for kernel version 2.2.18. It contain a bugfix for lidsadm. For more detail, please visit ." I use LIDS on a daily basis and love it. Anybody who is interested in a kernel-level IDS system should definately check it out! The link for this article located at is no longer available. . Huagang Xie writes: 'The LIDS project has just released LIDS 0.9.11 for kernel version 2.2.18. It co. huagang, writes, project, released, kernel, version. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.