POODLE vulnerability block
This new version of the Webcrossing server has been upgraded to prevent the so-called “POODLE vulnerability” discovered by Google at the end of last year. Read more about POODLE here.
Please note the vulnerability only affects sites using SSL certificates (sites with https:// urls). If you are not using secure connections it does not affect you. If you are using secure connections, for your entire site, or part of it, we recommend upgrading to this new build.
Note: Blocking the POODLE vulnerability means removing support for SSL v3 and requiring secure connections from browsers which support TLS. All recent versions of browsers support TLS and also default to blocking SSL v3. The only remaining well-known browser without TLS support is IE6, which was released in 2001 for Windows XP and is long deprecated. If you have users with IE6 browsers, and are providing secure connections, those users will not be able to access your site after upgrading. We recommend advising IE6 users to upgrade their browser.
Secure outgoing requests are TLS
In addition to upgrading incoming secure connections to your Webcrossing server, the new version also upgrades the way secure outgoing requests are made. In previous versions, outgoing requests would be made using SSL v3. With the new build, outgoing requests are made using TLS, assuring scriptable API access to such sites as LinkedIn and Facebook, which have also stopped supporting SSL v3 as of the end of last year.
Fix to persistent connections and missing pages
The new build also includes a fix for persistent HTTP connections to missing pages (HTTP 404 errors) which were sometimes not releasing the connection. These connections are now being dropped and made available for other connections. The problem did not affect many sites, but if a site was under a heavy load and many connections were being made to pages which did not actually exist at the site, it was possible for the listening connection limit to be reached, thus making the site inaccessible on certain ports. This fix prevents that problem from occurring.
Clarification in Email Services settings
The instructions in the Email Services control panel have been updated to clarify that if a site wishes to use outgoing email notifications of new posts to subscribers that at least one email domain for the site must be set. This is also required for receiving posts by email.
The latest release version is now Webcrossing 6.4 source: 1682 2015-02-14.
We will be upgrading all hosted customers, and coordinate the upgrade timing as needed.
All self-hosted customers with valid support and maintenance contracts can download this new version at no cost.
For security’s sake, if you make use of secure connections we strongly recommend upgrading to the new version. If you are a self-hosted customer and have a valid support and maintenance contract, please contact support for access to the new server. If your support and maintenance contract has expired, please contact us to renew so we can provide you with this important update.
A recap of other recent upgrades: Version 1678 2014-12-02 was released in December 2014 and added a new Unified Email Digest feature (previous versions only could send digests from each folder separately). Version 1675 2014-09-27 was released on October 8 with enclosure reference count fixes. Version 1673 2014-08-31 was released on September 8 and fixed attachment deletion and cluster attachment propagation issues. Version 1670 2014-04-25 was released on May 7, 2014 and fixed an important stability issue which, under certain circumstances, could cause a Webcrossing server process to silently quit, leaving the site unresponsive, and also added a new feature to allow guest users to visit sites licensed for a limited number of users (a so-called “seat license”).
The latest release includes all those fixes and enhancements.



