RELEASE OF Witango 5.0.1.062 Server for Windows, Linux and OS X Witango Technologies Pty Ltd have today publicly released Witango 5.0.1.062 on Windows, OS X and Linux. This new version removes the remote system buffer overrun vulnerability. Details of the vulnerability can be found at the following URLs:
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0038.html http://www.securitytracker.com/alerts/2003/Jul/1007231.html The vulnerability remains present in all Witango 5 versions prior to 5.0.1.062 and in all versions of Tango 2000. All Witango 5 Server users should update their system to the latest version as soon as possible. Tango 2000 servers attached to the internet should also be upgraded as soon as possible. Tango 2000 users who need assistance in upgrading should contact [EMAIL PROTECTED] A suite of minor issues are also addressed in this release including ODBC 3.0 interface, JDBC fixes, FileMaker and email issues, they are listed in the ReadMe of the installer or the ReadMe file that is installed with the server. NOTE: Users who use older ODBC database drivers that are not ODBC 3.x compliant should also upgrade their database drivers to a driver that is at least ODBC 3.0 compliant. The minimum requirements for running Witango Server 5 has changed to make ODBC drivers at least ODBC 3.0 compliant. Do not install Witango Server 5.0.1.062 if your ODBC driver does not support the ODBC 3.0 interface or above.� This may stop your applications from working if you are using old non ODBC 3.x compliant drivers. Contact your database vendor for a new ODBC driver. Installers for Witango Server 5.0.1.062 are now available for download from the following URL: http://witango.com/downloads.taf NOTE: Before installing the new version of the server in production Witango Technologies recommends testing your applications in a non production/mission critical environment. It is also recommended to back up your configuration directory prior to installation. Minimum Requirements to run Witango Server 5.0.1.062 ---------------------------------------------------- Hard Disk Space: 20MB free Memory: 128MB RAM Database Connectivity: ODBC driver manager, ODBC 3.0 or above database driver, JDBC, Oracle Call Interface (OCI) 8.1.5.6 or above or JVM: 1.4.1.01 or greater What's new in Witango Server 5.0.1.062 -------------------------------------- (Differences between 5.0.1.054 and 5.0.1.062) The JavaBean handler has been updated and enabled on all servers Added a JDBC datasource type Optimised Xpointer Fixed several XPointer bugs with 'all' and 'descendants' Enabled FileMaker AE interface on OS X FileMaker dbs may now be accessed via the JDBC interface Fixed bug where a throw error in error html loops continuously Fixed memory leak on ODBC connections (now ODBC 3.0 interface) Fixed bug in backoff algorithm for all datasource connection contentions Fixed WebStar plug-in to compensate for when WebStar chunked results Additional encryption, hash and encoding options added to the @CIPHER tag Apache 2.0.44 or greater plug-in (wapache2.so) on all platforms Fixed bug where witangoevents.log was not written when -u option used Added -o option to allow event log to be written to std out Fixed bug in plug-in which failed to remove a server from the load group Added ability to configure load splitting client on OS X (Professional) Fixed a buffer overrun vulnerability inherited from Tango 2000 Fixed bug to close database transactions if application file error occurred ****************************************************************** CORROBOREE 2003 - September 22nd to 26th 2003 - San Diego, CA, USA Witango Developers Conference and Training This year the format is a little changed. We will be combining the Developers Conference with Training sessions at all levels to ensure that the week provides the optimum opportunity for members of the community to advance their skills and broaden their approaches to Witango programming techniques. Look forward to seeing you there !! ********************************************************************* ________________________________________________________________________ TO UNSUBSCRIBE: Go to http://www.witango.com/maillist.taf
