[jdev] [ANN] slixmpp 1.4.2 released

Emmanuel Gil Peyrot linkmauve at linkmauve.fr
Thu Jan 31 15:09:54 UTC 2019


Hello,

We are pleased to announce the 1.4.2 release of slixmpp!
https://lab.louiz.org/poezio/slixmpp/tags/slix-1.4.2

It is a bugfix release, mainly fixing performance and security issues,
here is the changelog:
- Do not do channel binding without TLS.
- Add default timeout of 120s for IQs to prevent slowdowns over
  long-running sessions.
- Fix CVE-2019-1000021: make the XEP-0223 plugin actually make the node
  private.
- Do not query vcard avatars unconditionnally, to improve startup time
  of clients.
- Fix GSSAPI (thanks Jelmer Vernooij!)

Note that the current upstream is now available on louiz’ GitLab:
https://lab.louiz.org/poezio/slixmpp

-- 
The slixmpp authors
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: not available
URL: <https://www.jabber.org/jdev/attachments/20190131/50294723/attachment.sig>


More information about the JDev mailing list