On Wednesday, October 25, 2023 at 1:42:17 p.m. UTC-4, Randall wrote:present, we are not planning to release a 3.2 build until it reaches beta state.
The latest patches for the OpenSSL 3.0.x and 3.1.x series are now available on the ITUGLIB website. Release notes are available at https://www.openssl.org/news/openssl-3.0-notes.html and https://www.openssl.org/news/openssl-3.1-notes.html.
Both releases contain fixes for CVE-2023-5363 (Moderate) - Incorrect cipher key & IV length processing described in the release notes.
The 3.2 series is still in alpha state. If you are interested in testing with this series, please let ITUGLIB know here. This series is not binary compatible with the 3.0.x and 3.1.x series, so you will need to recompile your code to use it. At
to obtain patched builds.The 1.1.1 and 1.0.2 series are no longer under official support, and do not receive security updates, so you should move off those releases. If you cannot move off those releases, please contact me to facilitate fee-based premium support from OpenSSL
Regards,Please be aware that 3.0.12 has already had reports of breakage in the pkcs11 engine and with coreutils prngd. Please let ITUGLIB know here if you encounter any problems.
Randall Becker
On Behalf of the ITUGLIB Technical Committee
The latest patches for the OpenSSL 3.0.x and 3.1.x series are now available on the ITUGLIB website. Release notes are available at https://www.openssl.org/news/openssl-3.0-notes.html and https://www.openssl.org/news/openssl-3.1-notes.html.we are not planning to release a 3.2 build until it reaches beta state.
Both releases contain fixes for CVE-2023-5363 (Moderate) - Incorrect cipher key & IV length processing described in the release notes.
The 3.2 series is still in alpha state. If you are interested in testing with this series, please let ITUGLIB know here. This series is not binary compatible with the 3.0.x and 3.1.x series, so you will need to recompile your code to use it. At present,
The 1.1.1 and 1.0.2 series are no longer under official support, and do not receive security updates, so you should move off those releases. If you cannot move off those releases, please contact me to facilitate fee-based premium support from OpenSSLto obtain patched builds.
Regards,
Randall Becker
On Behalf of the ITUGLIB Technical Committee
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (0 / 16) |
Uptime: | 156:07:18 |
Calls: | 10,384 |
Calls today: | 1 |
Files: | 14,056 |
Messages: | 6,416,468 |