2016-11-10
Software Version 6.4.7
SSL encryption improved
- New designation for encryption strengths: "normal", "weak (Windows XP compatible)" and "very weak"
- Adjusting the default setting to "normal" when reinstalling. This provides more security and prevents the Sweet32 attack
- Please check your existing encryption strength under "System > Web interface > Security" and switch to "normal" if possible
More improvements
- Security update for Linux kernel closes Dirty Cow vulnerability
- E-mails that contain only a file attachment and no text part are now correctly replaced by the attachment filter
- Performance of the web proxy for more than 200 active users improved
- Help with change queue conflicts
- Cumulative security update fixes 24 vulnerabilities
(bash-4.3.42: CVE-2016-7543 und CVE-2016-7543, bind-9.10.4-P4:
CVE-2016-8864, c-ares-1.12.0: CVE-2016-5180, curl-ssl-7.51.0:
CVE-2016-7167, CVE-2016-8615, CVE-2016-8616, CVE-2016-8617,
CVE-2016-8618, CVE-2016-8619, CVE-2016-8620, CVE-2016-8621,
CVE-2016-8622, CVE-2016-8623, CVE-2016-8624, CVE-2016-8625,
ghostscript-9.20: CVE-2016-7976, CVE-2016-7978 und CVE-2016-7979,
libxml2-2.9.4: CVE-2016-4658 und CVE-2016-5131, linux-3.14.79:
CVE-2016-5195 und CVE-2016-6828, tar-1.29: CVE-2016-6321)
- Updating Linux basic services
(squid-3.5.22)
Back to overview