[SECURITY] Updated: openssl-1.0.1h-1, libopenssl098-0.9.8za-1

Yaakov Selkowitz yselkowitz@cygwin.com
Fri Jun 6 08:13:00 GMT 2014


The following packages have been updated in the Cygwin distribution:

* openssl-1.0.1h-1
* libopenssl098-0.9.8za-1 (x86 only)
* libopenssl100-1.0.1h-1
* openssl-devel-1.0.1h-1

The OpenSSL toolkit provides support for secure communications between 
machines. OpenSSL includes a certificate management tool and shared 
libraries which provide various cryptographic algorithms and protocols.

This release includes fixes for several CVEs, including CVE-2014-0224 
(SSL/TLS man-in-the-middle).  Full details on these fixes are available 
here:

https://www.openssl.org/news/secadv_20140605.txt

The legacy libopenssl098 package has also been updated for the benefit 
of those packages still dependent thereon.

-- 

Yaakov
(on behalf of Corinna)


CYGWIN-ANNOUNCE UNSUBSCRIBE INFO
================================

If you want to unsubscribe from the cygwin-announce mailing list, please 
use the automated form at:

http://cygwin.com/lists.html#subscribe-unsubscribe

If this does not work, then look at the "List-Unsubscribe: " tag in the 
email header of this message.  Send email to the address specified 
there.  It will be in the format:

cygwin-announce-unsubscribe-you=yourdomain.com@cygwin.com

If you need more information on unsubscribing, start reading here:

http://sourceware.org/lists.html#unsubscribe-simple

Please read *all* of the information on unsubscribing that is available 
starting at this URL.



More information about the Cygwin-announce mailing list