Copssh 6.1.1 release date: 2017-11-11Changelog Copssh version 6.1.1 comes with the latest version LibreSSL (2.6.3). Upgrade logic in our installers are also improved. 2017
Nagwin 3.0.0 release date: 2017-10-17Changelog Nagwin 3.0.0 contains the latest version of Nagios Core (4.3.4), primarily a bugfix release. We have also updated Cygwin and GNU tools to their latest versions. 2017
cwRsync 5.6.0 release date: 2017-10-05Changelog Version 5.6.0 of cwRsync client/server installers is a maintenance release and come with the latest available versions of Cygwin, GNU Tools, OpenSSH and Putty. LibreSSL is now used as the SSL library for OpenSSH binaries. 2017
Copssh 6.1.0 (security) release date: 2017-10-04Changelog Copssh version 6.1.0 comes with the latest versions of OpenSSH (7.6) and LibreSSL (2.5.5). We have also updated the Cygwin and GNU Tools to their latest available versions. Security issue: sftp-server(8): in read-only mode, sftp-server was incorrectly permitting creation of zero-length files. Reported by Michal Zalewski. Potentially-incompatible changes in OpenSSH: This release includes a number of changes that may affect existing configurations: ssh(1): delete SSH protocol version 1 support, associated configuration options and documentation. ssh(1)/sshd(8): remove support for the hmac-ripemd160 MAC. ssh(1)/sshd(8): remove support for the arcfour, blowfish and CAST ciphers. Refuse RSA keys <1024 bits in length and improve reporting for keys that do not meet this requirement. ssh(1): do not offer CBC ciphers by default. 2017
Nagwin 2.9.0 release date: 2017-06-04Changelog Nagwin 2.9.0 is contains the latest version of Nagios Core (4.3.2) containing lots of fixes and enhancements. We have also updated Cygwin and GNU tools to their latest versions. 2017
Copssh 6.0.0 release date: 2017-05-20Changelog Copssh version 6.0.0 is a major update and uses now LibreSSL instead of OpenSSL as the cryptographic library provider. LibreSSL is a version of the TLS/crypto stack forked from OpenSSL in 2014, with goals of modernizing the codebase, improving security, and applying best practice development processes. Primary development occurs inside the OpenBSD source tree with the usual care the project is known for. On a regular basis the code is re-packaged for portable use by other operating systems (Linux, FreeBSD, Windows, etc). See https://en.wikipedia.org/wiki/LibreSSL for more detailed information. We have also upgraded Cygwin and GNU tools to their latest available versions. 2017
Nagwin 2.8.0 (security) release date: 2017-04-01Changelog Nagwin 2.8.0 is contains the latest version of Nagios Core (4.3.1) containing lots of fixes and enhancements. PHP FastCGI is now configured to start with two worker processes for better Pnp4Nagios performance. Our installer is now made more upgrade friendly and will not touch the configuration in the etc directory at all. Nagios security fix: CVE-2016-6209 (v 4.3.0) 2017
cwRsync 5.5.3 release date: 2017-03-28Changelog Version 5.5.3 of cwRsync client/server installers is a maintenance release and come with the latest available versions of Cygwin, GNU Tools, OpenSSH and OpenSSL. 2017
Copssh 5.9.0 (security) release date: 2017-03-22Changelog Copssh version 5.9.0 bundle contains latest versions of OpenSSH (7.5p1), OpenSSL (1.0.1k), Cygwin and GNU tools. Installers use now quoted service executable paths to avoid potential misuse of unquoted path vulnerabilities. OpenSSH Security fixes: ssh(1), sshd(8): Fix weakness in CBC padding oracle countermeasures that allowed a variant of the attack fixed in OpenSSH 7.3 to proceed. Note that the OpenSSH client disables CBC ciphers by default, sshd offers them as lowest-preference options and will remove them by default entriely in the next release. Reported by Jean Paul Degabriele, Kenny Paterson, Martin Albrecht and Torben Hansen of Royal Holloway, University of London. sftp-client(1): [portable OpenSSH only] On Cygwin, a client making a recursive file transfer could be maniuplated by a hostile server to perform a path-traversal attack. creating or modifying files outside of the intended target directory. Reported by Jann Horn of Google Project Zero. OpenSSL Security fixes: Truncated packet could crash via OOB read (CVE-2017-3731) BN_mod_exp may produce incorrect results on x86_64 (CVE-2017-3732) Montgomery multiplication may produce incorrect results (CVE-2016-7055) 2017
Copssh 5.8.1 release date: 2017-02-08Changelog Copssh version 5.8.1 bundle contains server installers with improved support for domain based service accounts. We have also updated the Control Panel to configure many advanced server-wide options through the GUI. User specific advanced options are also updated to support more options. Lack of proper permissions on the host private keys are now fixed so that they are only visible to the service account. 2017