Re: Forthcoming OpenSSL Bug Fix Release

Dr Paul Dale <[email protected]> Thu, 27 Oct 2022 09:41:42 +1100
Newsgroups gmane.comp.encryption.openssl.announce,gmane.comp.encryption.openssl.user,gmane.comp.security.oss.general
Organization OpenSSL
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------nWluHlx9aoNd8iCrcxFJi0Kr
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

1.1.1 is not susceptible to the CVE that is being fixed in 3.0:

    /the forthcoming release of OpenSSL version 1.1.1s that is a *bug
    fix* release/.

(highlight added).


Dr Paul Dale

On 26/10/22 22:17, Matan Giladi wrote:
> Does 1.1.1s is going to include any security fix?
> Can you please confirm that the critical issue found in 3.0.6 version is irrelevant for 1.1.1?
>
> -----Original Message-----
> From: openssl-announce<[email protected]>  On Behalf Of Ing. Martin Koci, MBA
> Sent: Tuesday, October 25, 2022 21:36
> To:[email protected];[email protected];[email protected];[email protected]
> Subject: Forthcoming OpenSSL Bug Fix Release
>
> Hello,
>
> In addition to the already announced 3.0.7 release, the OpenSSL project team would like to announce the forthcoming release of OpenSSL version 1.1.1s that is a bug fix release.
>
> This bug fix release will be made available on Tuesday 1st November 2022 between 1300-1700 UTC too.
>
> Yours
> The OpenSSL Project Team
>
>
> Email secured by Check Point
> Report Phishing:https://mta-cnf.iaas.checkpoint.com/mta_feedback?id=b3dc9e6004806fac5adb86a1a47504d00416eb2590b631502621736f0652d7ea&ck=3D4CC6C8CB55;48DE55E160E5;C5CEAA199888;&v=m
>
> Email secured by Check Point

--------------nWluHlx9aoNd8iCrcxFJi0Kr
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    1.1.1 is not susceptible to the CVE that is being fixed in 3.0:<br>
    <blockquote><i>the forthcoming release of OpenSSL version 1.1.1s
        that is a <b>bug fix</b> release</i>.<br>
    </blockquote>
    (highlight added).<br>
    <br>
    <br>
    Dr Paul Dale<br>
    <br>
    <div class="moz-cite-prefix">On 26/10/22 22:17, Matan Giladi wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <pre class="moz-quote-pre" wrap="">Does 1.1.1s is going to include any security fix?
Can you please confirm that the critical issue found in 3.0.6 version is irrelevant for 1.1.1?

-----Original Message-----
From: openssl-announce <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a> On Behalf Of Ing. Martin Koci, MBA
Sent: Tuesday, October 25, 2022 21:36
To: <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>; <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
Subject: Forthcoming OpenSSL Bug Fix Release

Hello,

In addition to the already announced 3.0.7 release, the OpenSSL project team would like to announce the forthcoming release of OpenSSL version 1.1.1s that is a bug fix release.

This bug fix release will be made available on Tuesday 1st November 2022 between 1300-1700 UTC too.

Yours
The OpenSSL Project Team


Email secured by Check Point
Report Phishing: <a class="moz-txt-link-freetext" href="https://mta-cnf.iaas.checkpoint.com/mta_feedback?id=b3dc9e6004806fac5adb86a1a47504d00416eb2590b631502621736f0652d7ea&amp;ck=3D4CC6C8CB55;48DE55E160E5;C5CEAA199888;&amp;v=m">https://mta-cnf.iaas.checkpoint.com/mta_feedback?id=b3dc9e6004806fac5adb86a1a47504d00416eb2590b631502621736f0652d7ea&amp;ck=3D4CC6C8CB55;48DE55E160E5;C5CEAA199888;&amp;v=m</a>

Email secured by Check Point
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------nWluHlx9aoNd8iCrcxFJi0Kr--