Perl 5.28.1.2 Suggested OpenSSL 1.1.1a series update
[email protected] (Iverson Golden) Wed, 13 Feb 2019 10:50:40 -0500
| Newsgroups | perl.win32.vanilla |
|---|---|
| Message-ID | <CAF+4DwMoeYc4vha8p9X6e7vue7jQMqaPobXs4j_DaoJQMCwedg@mail.gmail.com> |
--000000000000509d3f0581c88a75 Content-Type: text/plain; charset="UTF-8" Hello All, I am trying to get a stable version of perl that has the latest version of OpenSSL installed on it. As I am sure you are aware OpenSSL before the release of the 1.1.1 series will be at the end of its lifecycle in less than a year. Some of the vendors that I work with to mitigate vulnerabilities in there software use Perl. So the request is that the new versions going forward will have a openSSL library which is not at the end of its lifecycle and does not yet have any CVE on the NIST NVD site. With that said I know its wishful thinking considering new vulnerabilities are being discovered all the time with for openSSL. However, trying to keep up with the latest OpenSSL versions 1.1.1 and possibly in the near future the 3.0.0 series will greatly help reduce producing updates that are still using vulnerable openSSL libraries. I hope this will help developers of the next version and I look forward to reviewing the updates! Thanks, Iverson Golden, MSIT, Sec+ --000000000000509d3f0581c88a75 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Hello All,</div><div><br></div><div>I am trying to ge= t a stable version of perl that has the latest version of OpenSSL installed= on it. As I am sure you are aware OpenSSL before the release of the 1.1.1 = series will be at the end of its lifecycle in less than a year. Some of the= vendors that I work with to mitigate vulnerabilities in there software use= Perl. So the request is that the new versions going forward will have a op= enSSL library which is not at the end of its lifecycle and does not yet hav= e any CVE on the NIST NVD site. With that said I know its wishful thinking= =C2=A0considering new vulnerabilities are being discovered all the time wit= h for openSSL. However, trying to keep up with the latest OpenSSL versions = 1.1.1 and possibly in the near future the 3.0.0 series will greatly help re= duce producing updates that are still using vulnerable openSSL libraries. I= hope this will help developers of the next version and I look forward to r= eviewing the updates! </div><div><br></div><div>Thanks,</div><div><br></div= ><div>Iverson Golden, MSIT, Sec+</div><div><br></div></div> --000000000000509d3f0581c88a75--