|
| StreamSec Tools 4.1.4.361 — maintenance release | |
| Henrick Wibell Hellström 2026-10-07 22:03:07 Registered user |
StreamSec Tools 4.1.4.361 released (2026-10-07)
StreamSec Tools 4.1.4.361 is now available for all supported Delphi versions, XE3 through 13 Florence. This is a maintenance, hardening and conformance release. The main areas: - SSH, SFTP and SNIP-over-SSH: a large set of robustness fixes across connection teardown, channel flow control and window handling, multi-threaded send and receive, local and remote port forwarding, and strict validation of message numbers and field lengths on the wire. Strict KEX is now applied at every key exchange. Fixes for the macOS, iOS, Android and ARM targets are included. - The cipher component (TstCipher): correctness fixes for streaming, in-place and piecewise encryption and decryption, for the padding modes (PKCS5, zeroes, 10s, SSL3, CTS, StrSecII) and for the AEAD modes GCM, CCM and EAX. - ASN.1, object identifiers and certificate contents: more robust reading, writing and naming of OIDs, of extensions and name attributes of a type the library does not itself list, and of attribute values carried as ANY. - CMS / S/MIME: SEED-CBC under the RFC 4010 object identifier, corrected SMIMECapabilities items, and deprecation of RC2 in S/MIME capabilities. - RSA key generation from FIPS 186 provable primes. - Interfaces that had been declared with another interface's GUID now each carry their own. Around forty entries are marked BEHAVIOUR CHANGE: they alter what existing code does without any source change on your part. Please read those in CHANGES.txt before upgrading. The full changelog for this release is CHANGES_4.1.4.361.txt. New in the documentation: SECURITY.txt, our coordinated vulnerability disclosure policy - how to report a vulnerability, what happens to a report, and when the details become public - as called for by the EU Cyber Resilience Act. It is also published at https://www.streamsec.com/index.php?id=security. Security fixes are posted as free source patches in this Announcements section. Security support: each licensed release is supported for five years from its publication date - 4.1.4.361 until 2031-10-07 - and every security update issued in that period is kept available for at least ten years after it is issued. Attachments: |