Changes between Initial Version and Version 3 of Ticket #12139
- Timestamp:
- 07/03/2019 10:38:55 PM (6 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #12139
- Property Milestone 8.5 → 9.0
- Property Owner changed from to
- Property Status new → assigned
-
TabularUnified Ticket #12139 – Description
initial v3 2 2 3 3 {{{ 4 5 4 Version 5.55, 2019.06.10, urgency: HIGH 6 5 7 6 Security bugfixes 8 Fixed a Windows local privilege escalation vulnerability caused insecure OpenSSL cross-compilation defaults. Successful exploitation requires stunnel to be deployed as a Windows service, and user-writable C:\ folder. This vulnerability was discovered and reported by Rich Mirch. 9 OpenSSL DLLs updated to version 1.1.1c. 7 - Fixed a Windows local privilege escalation vulnerability caused 8 insecure OpenSSL cross-compilation defaults. Successful exploitation 9 requires stunnel to be deployed as a Windows service, and user- 10 writable C:\ folder. 11 - OpenSSL DLLs updated to version 1.1.1c. 10 12 11 13 Bugfixes 12 Implemented a workaround for Windows hangs caused by its inability to the monitor the same socket descriptor from multiple threads. 13 Windows configuration (including cryptographic keys) is now completely removed at uninstall. 14 A number of testing framework fixes and improvements. 15 14 - Implemented a workaround for Windows hangs caused by its inability 15 to monitor the same socket descriptor from multiple threads. 16 - Windows configuration (including cryptographic keys) is now 17 completely removed at uninstall. 18 - A number of testing framework fixes and improvements. 16 19 }}}