Desktop: Windows: Client uses ancient OpenSSL version

Created on 4 Sep 2018  路  10Comments  路  Source: nextcloud/desktop

The Windows client (daily build) is built against OpenSSL 1.0.1h from 2014, which contains many security vulnerabilities.

Please update the OpenSSL version to a more recent one of the 1.0.x series.

Additional information: https://www.openssl.org/news/vulnerabilities-1.0.1.html

Most helpful comment

grafik

4,5 years are centuries in security years, IMHO . And as @klada linked to, there are known vulnerabilities

All 10 comments

Hi! It is actually built against 1.1.x but we ran into this issue https://github.com/arvidn/libtorrent/issues/1931 and therefore we had to include 2 older dll's in the installer. I believe that is where this version displayed in settings is coming from.

Just seen this today as well.

AFAIU it is just about the names of dlls, or?

Just checked OC's client on my windows machine and it is using new named files.

The final release of the new client still shows 1.0.1h in the general section.

This is on our todo to look into. However both our windows skillz are suboptimal.

grafik

4,5 years are centuries in security years, IMHO . And as @klada linked to, there are known vulnerabilities

@PhilLab Can you help the desktop team to update the libs?

Hey,

have you seen our latest builds already? They are not outdated anymore ;-)

For the current 2.5.3 release: It's built with a current version and security fixes: OpenSSL 1.0.2s (2019-05-28)

client-win-2 5 3-ssl-part

What matters here is the sub-release 's' of May 28. The 1.0.x versions receive security updates till the end of this year.

Great!
Damn, I missed the v2.5.3 release.
Just did the update and hooray, I got a newer ssl lib.

Thank you.

@rakekniven You're welcome :-)

Good news: The next Windows release will include OpenSSL 1.1.1c with TLS 1.3 support 馃樃

For details see: https://github.com/nextcloud/desktop/issues/906#issuecomment-522713258

Time to close the issue 馃樇

Was this page helpful?
0 / 5 - 0 ratings