# OSSEC 4.0.0 Release Notes #2182
atomicturtle
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Release Maintainers
Contributors on this release
Release Notes
Major security and stability release addressing critical memory safety issues and modernizing cryptographic implementations. This release includes fixes for multiple heap use-after-free (UAF) vulnerabilities, uncontrolled recursion in XML parsing, and implementation of secure random number generation for agent key creation. Additionally, file integrity monitoring has been modernized with SHA-256 support, and several external dependencies have been updated to their latest stable versions.
Warning
AES Encryption Now Default for Agent Communication
OSSEC 4.0.0 agents now use AES encryption by default for agent-server communication. This is NOT backwards compatible with OSSEC 3.8.0 and older servers.
Migration Options:
ossec.conf:Configuration Changes
🔒 Security Fixes
General Fixes & Improvements
This discussion was created from the release # OSSEC 4.0.0 Release Notes.
Beta Was this translation helpful? Give feedback.
All reactions