[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-devel
Subject:    Re: How far back do we support third party libraries?
From:       George Staikos <staikos () kde ! org>
Date:       2000-09-08 10:21:28
[Download RAW message or body]

On Fri, 08 Sep 2000, Dirk Mueller wrote:
> On Fre, 08 Sep 2000, George Staikos wrote:
> > The subject says it all.  Do we support libraries that are 3-4 revisions
> > old? In particular (yes, it just keeps coming up) OpenSSL versions older
> > than 0.9.5 (maybe 0.9.4 is ok too - I haven't checked) seem to cause
> > problems. They are all related to bugs in OpenSSL itself however.  For
> > instance, the const issue mentioned on core-devel.  This is not present
> > in the latest code, 0.9.5a.
>
> I think it's dangerous to support old OpenSSL versions. That's because
> 0.9.5a fixes several grave security issues in the library. I'm not sure if
> they apply for https, but if, then we have to force users to upgrade.
  
  Ah yes, I forgot to mention this one too :)

-- 
George Staikos
 
>> Visit http://master.kde.org/mailman/listinfo/kde-devel#unsub to unsubscribe <<

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic