The release of GNOME 3.38.2 just two months after the first point release brings further improvements and bug fixes to the desktop environment. . Coming two months after the first point release, GNOME 3.38.2 is here with better support for the GNOME OS project that lets developers and user test drive upcoming features of the popular desktop environment. This support was implemented in the GNOME Boxes software, which now comes with up-to-date download URLs for GNOME OS, the ability to install GNOME OS under the osinfo custom database, as well as updated recommended downloads for the latest Linux distro releases and improved handling of file extensions. The link for this article located at 9 to 5 Linux is no longer available. . KDE Plasma 5.20 introduces optimizations and new features, elevating the experience for coders and end-users in the open-source desktop environment.. GNOME 3.38.2 Release,Bug Fixes,User Enhancements. . LinuxSecurity.com Team
We love Docker and containers. But, the more we use containers the more we worry exactly what it is we're running when we spin them up. So, Linux giant and cloud power Red Hat and Black Duck, a leader in automating securing and managing open-source software, are working together on establishing a secure and trusted model for containerized application delivery. . We love containers because they enable consistent operating environments for development, testing, and deployment. That's the good news. The bad news is that container security has lagged behind its advantages. . Red Hat and Black Duck's partnership enhances container security, ensuring applications deliver trust through integration of open source management and robust container tools. Container Security, Open Source Management, Trusted Delivery. . LinuxSecurity.com Team
Tech giants listed as part of the National Security Agency. So there The link for this article located at BusinessWeek is no longer available. . So thereThe link for this article located at BusinessWeek is no longer available.. giants, listed, national, security, agency, therethe, article, located. . Dave Wreski
There's a new development version of John the Ripper. It may be obtained at the usual location: /john/ . . . . Subject: John the Ripper 1.6.37 Date: Tue, 24 Feb 2004 17:07:30 +0300 From: Solar Designer To:
The OpenSSL project team is pleased to announce the release of version 0.9.6h of our open source toolkit for SSL/TLS. This new OpenSSL version is a bugfix release. This will be the last release in the 0.9.6 series. . .. The OpenSSL project team is pleased to announce the release of version 0.9.6h of our open source toolkit for SSL/TLS. This new OpenSSL version is a bugfix release. This will be the last release in the 0.9.6 series . OpenSSL version 0.9.6h released =============================== OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org:443/ The OpenSSL project team is pleased to announce the release of version 0.9.6h of our open source toolkit for SSL/TLS. This new OpenSSL version is a bugfix release. This will be the last release in the 0.9.6 series. The most significant changes are: o New configuration targets for Tandem OSS and A/UX. o New OIDs for Microsoft attributes. o Better handling of SSL session caching. o Better comparison of distinguished names. o Better handling of shared libraries in a mixed GNU/non-GNU environment. o Support assembler code with Borland C. o Fixes for length problems. o Fixes for uninitialised variables. o Fixes for memory leaks, some unusual crashes and some race conditions. o Fixes for smaller building problems. o Updates of manuals, FAQ and other instructive documents. We consider OpenSSL 0.9.6h to be the best version of OpenSSL available and we strongly recommend that users of older versions upgrade as soon as possible. OpenSSL 0.9.6h is available for download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under o o [1] OpenSSL comes in the form of two distributions this time. The reasons for this is that we want to deploy the external crypto device support but don't want to have it part of the "normal" distribution just yet. The distribution containing the external crypto devicesupport is popularly called "engine", and is considered experimental. It's been fairly well tested on Unix and flavors thereof. If run on a system with no external crypto device, it will work just like the "normal" distribution. The distribution file names are: o openssl-0.9.6h.tar.gz [normal] MD5 checksum: 621bef36ad61012bb71945a1cb449073 o openssl-engine-0.9.6h.tar.gz [engine] MD5 checksum: a7e3f5c0a5451ca666e4cbe23a8617a2 The checksums were calculated using the following commands: openssl md5 < openssl-0.9.6h.tar.gz openssl md5 < openssl-engine-0.9.6h.tar.gz Yours, The OpenSSL Project Team... Mark J. Cox Ben Laurie Andy Polyakov Ralf S. Engelschall Richard Levitte Geoff Thorpe Dr. Stephen Henson Bodo Möller Lutz Jänicke Ulf Möller . OpenSSL version 1.1.1g is launched featuring essential patches and enhancements aimed at maximizing SSL/TLS toolkit efficiency.. OpenSSL Release, Bugfix Updates, SSL Improvements. . LinuxSecurity.com Team
The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.9.7 contains several changes and enhancements in many fields; please check out the NEWS and CHANGES files for details. Some of the changes made break compatibility, so that application developers and distribution providers may need a transition period.. . .. The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.9.7 contains several changes and enhancements in many fields; please check out the NEWS and CHANGES files for details. Some of the changes made break compatibility, so that application developers and distribution providers may need a transition period. Date: Tue, 16 Apr 2002 16:56:50 +0200 From: Lutz Jaenicke Reply-To: openssl-users@openssl.org To: openssl-announce@openssl.org, openssl-dev@openssl.org, openssl-users@openssl.org Subject: Announcement of OpenSSL 0.9.6d and 0.9.7 Release Plan and Schedule Announcement of OpenSSL 0.9.6d and 0.9.7 Release Plan and Schedule ================================================================== The OpenSSL developers team is pleased to announce the upcoming release of OpenSSL 0.9.7. OpenSSL 0.9.7 contains several changes and enhancements in many fields; please check out the NEWS and CHANGES files for details. Some of the changes made break compatibility, so that application developers and distribution providers may need a transition period. We have therefore decided for a 2-step strategy: * Release 0.9.6d: OpenSSL 0.9.6d will be the last release of the 0.9.6 series, containing all of the latest bugfixes while maintaining compatibility. * Release 0.9.7: OpenSSL 0.9.7 contains many enhancements and some incompatible changes. It also includes the bugfixes found in 0.9.6d (except for those obsoleted by other changes). We intend to provide releases according to the following schedule: 16 Apr 2002: 0.9.6d-beta1 30 Apr 2002: 0.9.6d The changes between 0.9.6c and 0.9.6d are quite small so that we donot expect too many problems. Therefore only one beta release is planned. 30 Apr 2002: 0.9.7-beta1 13 May 2002: 0.9.7-beta2 ... As the changes between 0.9.6x and 0.9.7 are numerous, we are prepared to handle more beta releases. The number of beta releases may change with error reports coming in. If no more errors are found after beta2, the final release will be made. If more errors are found in beta2, beta3 will be introduced and so on. Testing 0.9.7-beta... does not only mean to download and call "make install" and/or "make test" on different platforms. We explicitely ask application developers and users to test out the functionality of applications and/or integrate new functionality or adjust to the API changes. If these checks are not done in the beta phase and applications are only tested once 0.9.7 is released, bug fixes may be delayed until the release of 0.9.7a, if required. Be reminded that changes are also available via the daily snapshots. Incompatible Changes with 0.9.7: ================================ - List will be provided with the 0.9.7-beta releases. Known Problems with 0.9.7: ========================== > From the OpenSSL STATUS file: o BIGNUM library failures on 64-bit platforms (0.9.7-dev): - BN_mod_mul verificiation (bc) fails for solaris64-sparcv9-cc and other 64-bit platforms Checked on Result alpha-cc (Tru64 version 4.0) works linux-alpha+bwx-gcc doesn't work. Reported by Sean O'Riordain OpenBSD-sparc64 doesn't work. BN_mod_mul breaks. Needs checked on [add platforms here] - BN_mod_mul verification fails for mips3-sgi-irix unless configured with no-asm Bug reports: ============ - Bug reports should be sent to
Since 4.1-RELEASE was produced in August 2000, RSA released their code into the public domain and a number of other security enhancements were made possible through the FreeBSD project's permission to export cryptographic code from the United States. These changes are . . . . Since 4.1-RELEASE was produced in August 2000, RSA released their code into the public domain and a number of other security enhancements were made possible through the FreeBSD project's permission to export cryptographic code from the United States. These changes are fully reflected in 4.1.1-RELEASE, making it one of the most secure "out of the box" releases of FreeBSDwe've ever done. The link for this article located at FreeBSD is no longer available. . FreeBSD 4.1.1-RELEASE marks a significant advancement in security and cryptographic features, enhancing overall resilience against cyber threats and ensuring data protection. FreeBSD 4.1.1, Cryptographic Updates, Security Features. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.