NoMachine makes available version 10.1.7 to provide fixes for issues affecting earlier releases, as well as security patches addressing potential vulnerabilities in server-side components and web sessions.
Additionally, OpenSSL libraries shipped by NoMachine client and server packages have been updated to v3.0.22. The full list of CVE patched by the new OpenSSL v3.0.22 is available on their Official web site at:
https://openssl-library.org/news/openssl-3.0-notes/
With this release, we are pleased to announce that Personal Edition and Enterprise Desktop Subscription Packs are now available in larger denominations of 20, 40, and 100, both through our online store and authorized partners.
Trouble Reports solved by v10.1.7 are:
TR06X11868 - A shared printer may print a blank page when the session is started from Windows
TR12Q09497 - Autoreconnection fails with 'The connection with the server was lost' in a HA setup
TR09S10366 - Cannot add a node to a Cloud Server when UserNXDirectoryPath is enabled
TR08S10339 - Error "connection to the server was lost" or timeout occurs when NoMachine log rotation is enabled
TR08X11943 - Key-based authentication may fail under certain conditions
TR08X11938 - The NoMachine server may fail to start after a reboot
TR08X11937 - After the upgrade to v10, it may be not possible to delete some profile rules
TR08X11951 - A Cloud Server node could flood system logs when connection to parent server is lost
TR09X11975 - Possible privilege escalation by arbitrary code injection in the 'nxserver --login' process in v10
TR08X11930 - Possible Server-Side Request Forgery (SSRF) affecting NoMachine Web Player
TR08X11934 - Possible denial of service through a crafted mDNS packet on LAN
TR08X11921 - Possible privileges escalation through the server's backend authentication mechanism
TR07X11893 - Possible heap buffer overflow in NoMachine web application