Thursday, July 4, 2013

[CentOS-announce] CESA-2013:1014 Important CentOS 5 java-1.6.0-openjdk Update

CentOS Errata and Security Advisory 2013:1014 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1014.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
2c38bf51cef2befcf717f8f486ae37867a5bd29ee42908ddf4d5d3b55436f2d3 java-1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9.i386.rpm
861d7c8fa3ff46b78a64187b45609921e49bec920fa00614fa52533b36db15ed java-1.6.0-openjdk-demo-1.6.0.0-1.41.1.11.11.90.el5_9.i386.rpm
992c01478b0662346ccb9561e46d5dadf281f9c523eb79112f9e2e5edc80cbae java-1.6.0-openjdk-devel-1.6.0.0-1.41.1.11.11.90.el5_9.i386.rpm
145d3a00005749d448b83077533e949591e6f732b108eb948769510cc51d11ed java-1.6.0-openjdk-javadoc-1.6.0.0-1.41.1.11.11.90.el5_9.i386.rpm
0a60d36f1a3ed0ad11c5d3a18890b079ed54ea3d9e1d757f78a0973b74120d61 java-1.6.0-openjdk-src-1.6.0.0-1.41.1.11.11.90.el5_9.i386.rpm

x86_64:
ca6b524ba111aaf9481e070a1185376dbde8d3c6a9a166b0a4af4a6f36619224 java-1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9.x86_64.rpm
26e9b66d4794be564bfe4e3c17d85cc244b22b2b1a923cb35e6ba245ff72c022 java-1.6.0-openjdk-demo-1.6.0.0-1.41.1.11.11.90.el5_9.x86_64.rpm
1b4c55b1209f5f3af0bb58b249e0a96eba4ae2fb576c38d8fc5f086915d4af2e java-1.6.0-openjdk-devel-1.6.0.0-1.41.1.11.11.90.el5_9.x86_64.rpm
ef1484a976bd9f8f7db3a5943d19e12da3ea2497ca3e449c2a501ed640fdd5bc java-1.6.0-openjdk-javadoc-1.6.0.0-1.41.1.11.11.90.el5_9.x86_64.rpm
0b3a822767944484bd5393e0ac6899f04efcfabf0aed83ae971141c4b547cf56 java-1.6.0-openjdk-src-1.6.0.0-1.41.1.11.11.90.el5_9.x86_64.rpm

Source:
f9c9ff547c9c99d5bd3a7971d42c71c980392a4102274da09d02f8af2197fe62 java-1.6.0-openjdk-1.6.0.0-1.41.1.11.11.90.el5_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[USN-1900-1] Linux kernel (EC2) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJR1T/3AAoJEAUvNnAY1cPYRnMP/RqCxwQb9HCAlLpvWl+VDugG
KKeElgqzLCIpQbEKn5X2GtYwyMQMMAiV9yhD8wz4RL5aMkHfREzG8a6Qdo1I83/R
N9VVtrcUe9wfcCehwk6X54q5kS+9Cn6VYqs83UfNiO65mBNfhTwJskOizwkk9LRc
kybla9yn+9dZSlYYxi4/HQMv7IaSAVtT74js7Q0FLoSJE0Xa3fZtnyG3dTtDejP6
kPx7KXH4AvviHUAyOsqVIIz/Y4Y1SEz2DLbk+Jw94YbdYx5vQtexOPlrS/hVDbS4
kxQDBPiY0XbhhYFkQkclM47AgHCP3zMpV2skuEGJWRUllilhwFo+D3xwBUWsibRi
qbSHXD80B9MlaGKPjAWaFm5t4othY5sDEX16lwHCQcXp0kMGOVlC9RYQA4xRJC41
vHfCxdI2C3TJZRcaXg1JZ+pNeBTBoUWqzDxJvu46m0bVD0YVMcYoWqpBvfmH09qC
Jp3UIFUfvUV8F/iYcvaGRVHpytkLWyXkbNNRrDi3XrJLUjN7wyHfg4le3nevVUsY
ZqigUDt8cUQCTgihdUKrS6pzSp1Kn0qmvhZpdyQTm92qkkhizs8X1SGGk8sEr+Ou
i1woSxEyxweU9cuenW7b0K+1vTWaGSxwwJ3iAsnI5DdFwPB5/CF4WScfWYv6zbsv
cvnkDXN/5WMdYgeviw+V
=bYNE
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1900-1
July 04, 2013

linux-ec2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ec2: Linux kernel for EC2

Details:

Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)

An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)

A format string vulnerability was discovered in Broadcom B43 wireless
driver for the Linux kernel. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-2852)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-354-ec2 2.6.32-354.67

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-1900-1
CVE-2012-4508, CVE-2013-2141, CVE-2013-2852

Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-354.67

[USN-1899-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJR1T/QAAoJEAUvNnAY1cPYjXMQALYPq8wP/hzy3fLl+ru5Guyr
wtbBK6T2jaiaHE04OPlkRwjb2k9wP4fSU9x6IW9apdeaM+8VWVsr1DYwYo17eUsG
cPq3XE8idgqEH4gJS65rnYTkoAG6mPFbjdPfDFzyMb7BEguUbOqhko1oU9tPTm0q
c5slPlbhQDtgU1yjkGfFwBH0/OqZ3+Z4WKrUVji0/maNx91yT5z8uVx7GXRgv5ZY
t139ZuAHnNDAvfPXSgfBGS1DD1VN2CLqAnn9UQSucWLStHgXjUooI8Bt64LJp1J9
uGInmSUWbWTJiXqYUmsqYwDop2wswIuccNeRNG4mmeciiyUgo2QZOZQflnWy3kt5
IcZ4PKwd8p0z34fjZ1zEZ5bVgJDHIDa55GEddU80z/9kz3mbRTi8rTGiNXdMWF8P
rbtlm4iVS3rIJ13qitpGb8gZlf7tP21Lid//Cbnonww4nJC8AwkpzTR2EfBGpxDg
sEQJWIp7XmnOLpoukZOtUFJbUkQ57/+NSRULydyTDPqVkm0J2DQ/LEA7OjjnXNah
xrEISIp8Fqs1iCb4lpXir2gyqXR8MeM0vfhHcgrZ9jJwRVgkMWdObVHfqkS4yijg
5Y3M9GlJ59EgtHCZlXVIbCgsnpqBZckJZ/51rBxtNzTjv0tRSM+DSu94qYT4rIzP
JXc+TNZVhr2mIZKNaahu
=CsZo
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1899-1
July 04, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)

An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)

A format string vulnerability was discovered in Broadcom B43 wireless
driver for the Linux kernel. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-2852)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-49-386 2.6.32-49.111
linux-image-2.6.32-49-generic 2.6.32-49.111
linux-image-2.6.32-49-generic-pae 2.6.32-49.111
linux-image-2.6.32-49-ia64 2.6.32-49.111
linux-image-2.6.32-49-lpia 2.6.32-49.111
linux-image-2.6.32-49-powerpc 2.6.32-49.111
linux-image-2.6.32-49-powerpc-smp 2.6.32-49.111
linux-image-2.6.32-49-powerpc64-smp 2.6.32-49.111
linux-image-2.6.32-49-preempt 2.6.32-49.111
linux-image-2.6.32-49-server 2.6.32-49.111
linux-image-2.6.32-49-sparc64 2.6.32-49.111
linux-image-2.6.32-49-sparc64-smp 2.6.32-49.111
linux-image-2.6.32-49-versatile 2.6.32-49.111
linux-image-2.6.32-49-virtual 2.6.32-49.111

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-1899-1
CVE-2012-4508, CVE-2013-2141, CVE-2013-2852

Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-49.111

Wednesday, July 3, 2013

[USN-1898-1] OpenSSL vulnerability

==========================================================================
Ubuntu Security Notice USN-1898-1
July 04, 2013

openssl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

Applications could be made to expose sensitive information over the
network.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

The TLS protocol 1.2 and earlier can encrypt compressed data without
properly obfuscating the length of the unencrypted data, which allows
man-in-the-middle attackers to obtain plaintext content by observing
length differences during a series of guesses in which a provided string
potentially matches an unknown string in encrypted and compressed traffic.
This is known as a CRIME attack in HTTP. Other protocols layered on top of
TLS may also make these attacks practical.

This update disables compression for all programs using SSL and TLS
provided by the OpenSSL library. To re-enable compression for programs
that need compression to communicate with legacy services, define the
variable OPENSSL_DEFAULT_ZLIB in the program's environment.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libssl1.0.0 1.0.1c-4ubuntu8.1

Ubuntu 12.10:
libssl1.0.0 1.0.1c-3ubuntu2.5

Ubuntu 12.04 LTS:
libssl1.0.0 1.0.1-4ubuntu5.10

Ubuntu 10.04 LTS:
libssl0.9.8 0.9.8k-7ubuntu8.15

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1898-1
CVE-2012-4929

Package Information:
https://launchpad.net/ubuntu/+source/openssl/1.0.1c-4ubuntu8.1
https://launchpad.net/ubuntu/+source/openssl/1.0.1c-3ubuntu2.5
https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.10
https://launchpad.net/ubuntu/+source/openssl/0.9.8k-7ubuntu8.15

Cooperative Bug Isolation for Fedora 19 / x86_64 and i386

The Cooperative Bug Isolation Project (CBI) is now available for Fedora
19 on both x86_64 (64-bit) and i386 (32-bit) platforms. We currently
offer instrumented versions of Evolution, The GIMP, Gnumeric, Liferea,
Nautilus, Pidgin, and Rhythmbox. Download and install
<http://research.cs.wisc.edu/cbi/downloads/rpm/fedora/19/tools/x86_64/cbi-package-config-19-13.noarch.rpm>
or
<http://research.cs.wisc.edu/cbi/downloads/rpm/fedora/19/tools/i386/cbi-package-config-19-13.noarch.rpm>
to automatically configure your system to use the CBI repository. Or
visit <http://research.cs.wisc.edu/cbi/> to learn more about this project.

It's that easy! Tell your friends! Tell your neighbors! The more of
you there are, the more bugs we can find.

We still offer CBI packages for earlier releases as well, going all the
way back to Fedora 1. When and if you decide to upgrade to Fedora 19,
we'll be ready for you. Until then, your participation remains valuable
even on older distributions.

-- Dr. Ben, the CBI guy
--
announce mailing list
announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/announce

[USN-1897-1] PyMongo vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJR1GgXAAoJEGVp2FWnRL6TvskQAJ46VTtlVMB1wqBeBc6XJ8vy
G9lY1LfJ8V987+QW32BFLLm2mzUlZrbafynokK8llYhTv4pop+NTAKGtXYRDRptz
zzF/H75Q/56c7T/dEvstsfvqIwP0OiwSFiKhHu2MZ7fh6XJlV16TLIwmuT9SAmuI
zwSFiaEQzVl306BGIeaM34hSyw+RLom7VEgAmSKeiJWDb0UeVBeHyR70cvmXpG7n
24MQEMLET6k9XFXCUF3fbkdktYDsqE/8C3/8OwmVLbzYzNsIs/B7JkoUaBnDyEgd
RTs5PNzZoMe/XxTRnxxyydvNmo5cvT8npxyO9VIUlOtR8nqYHU6eam13uTHfY8m5
4hZgbED/jstdaHYdn/8kOfpDFQhfAb7Bj6XrcfP2wc6eQ1Ks5Ueuwj53XE1JjirT
NAC4qfcWqnjXq8oIzELylokJpJWwTFppzOQFXXH469nZ/YEO1bJV4cS88RyPY8PU
yH8BrTKifffI+qd+K2ZZFLi7yWcNW3iKPmJhJuKbVC6i8s1GMT0rtkWXuU+YL1MH
fnqolCP9M6TC/PYOeZDVmizt8yYVadBV3PAB3/mFIXQUO1XP6rmWNnuWSlGUHGSi
zLTDxSDJYFDXxjOmN11ptjJH+WtTjFA5YTQE4213iDL1IXjuPWYWkSO2xaZdrX+4
ENBMoYY36DrlvCeO8kgE
=Qvop
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1897-1
July 03, 2013

pymongo vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

PyMongo could be made to crash under certain conditions.

Software Description:
- pymongo: Python interface to the MongoDB document-oriented database

Details:

Jibbers McGee discovered that PyMongo incorrectly handled certain invalid
DBRefs. An attacker could use this issue to cause PyMongo to crash,
resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-bson 2.2-4ubuntu0.1
python-bson-ext 2.2-4ubuntu0.1

Ubuntu 12.10:
python-bson 2.2-2ubuntu0.1
python-bson-ext 2.2-2ubuntu0.1

Ubuntu 12.04 LTS:
python-bson 2.1-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1897-1
CVE-2013-2132

Package Information:
https://launchpad.net/ubuntu/+source/pymongo/2.2-4ubuntu0.1
https://launchpad.net/ubuntu/+source/pymongo/2.2-2ubuntu0.1
https://launchpad.net/ubuntu/+source/pymongo/2.1-1ubuntu0.1

[announce] NYC*BUG Tonight: zfs(8), More Proof Unix is Dead

Wednesday, July 3
645 PM
Suspenders Restaurant and Bar
111 Broadway in Manhattan

It's almost the ten year anniversary of NYC*BUG, and it is the 20 year
anniversary of FreeBSD. Join us in celebration this evening with a talk
by long-time NYC*BUG hacker Isaac Levy.

* * *

zfs(8), More Proof UNIX is Dead, Isaac (.ike) Levy

"This (ZFS) is definately one of the most exciting things for me to see
happening."
- 2007, Kirk McKusick, original author of the UFS/FFS Filesystem

Six years of use is enough time for this presenter to trust a new
filesystem.

The aim of this talk is to provide enough information to dive right into
using ZFS, professionally and personally. This presentation assumes
basic UNIX knowledge, and a mind ready to be blown.

The Zettabyte File System (ZFS) is a combined filesystem and logical
volume manager. Originally designed by Sun Microsystems, pjd@ ported ZFS
to FreeBSD over 6 years ago. The features of ZFS include protection
against data corruption, support for high storage capacities,
integration of the concepts of filesystem and volume management,
snapshots and copy-on-writeclones, continuous integrity checking and
automatic repair, RAID-Z and native NFSv4 ACLs.

And that's not even the fun stuff...

Have you ever wanted to just add a disk to grow a RAID volume?
Have you ever wanted to choose to boot from a particular snapshot of a
volume?
Have you ever wanted to change filesystem settings on a live mounted
volume, like atime or readonly?
Have you ever waited while your life slips away while formatting
multi-TB disks?
Have you ever needed to dynamically change the hard limits of a logical
disk partition?
Have you ever dreamed of block-level disk compression, to actually put
all those fast CPU cores to *some* use?
Have you ever wanted filesystems to perform atomic acrobatics like great
database systems can?

This presentation aims to provide a solid overview of:

ZFS core features
ZFS practical usage, from laptops to mammoth file storage
Some modern SATA "gotchas" will be covered
ZFS advanced/special uses, and paths to follow outside this talk
The general state of ZFS on FreeBSD, (and other projects)

About the speaker:

.ike has been using ZFS, for big and small, since it first hit FreeBSD.
Today in ike's professional life, his team is responsible for many racks
of servers booting on ZFS volumes (Solaris).

Ike has spent more than 15 years obsessed with high-availability systems
on the internet. Lucky to stand on the shoulders of UNIX giants, his
background includes partnering to run an early Virtual Server ISP
(before there was a cloud), as well as having a long history standing up
internet-facing applications on UNIX systems and networks.

.ike has been a part of NYC*BUG since it was first launched in January
2004. He was a long-time member of the Lower East Side Mac Unix User
Group, and is still in denial that this group no longer exists. He has
spoken frequently on a number of UNIX and internet security topics at
various venues, particularly on the issue of FreeBSD`s jail(8), (a
presentation now banned on several continents). .ike also likes POSIX
shell programming, ssh, and digitizes rare books for fun.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

[USN-1890-2] Firefox regression

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/

iQEcBAEBAgAGBQJR1DrvAAoJEGEfvezVlG4PWkUH/j67uyiOlxFO/De5cicRaPbb
29ON/duREDIRGaqeZ41x3kt0rqKQkUIcDXW+gUgG7aOVaop3L5f5PBqhayqGFGl8
TjewCicnPENwblw+hTtlieKBY/DZ5Yk/ss/6FPpXi7RPc6v7QfbqJbpC5Y9zqa30
E92UZSx6aNIWR3NPB2/8r7+1zvnvVLCfON20CjJyuqZCpIXJheXlsCFF8uccXjoZ
tkYELtbosTZhIZsW/EG2XmR+uoUpjqQtVvHogsm2b34npG+R/O6icTY7XqyOkTa1
FPOpniFf22UR0B4JjZNMbtng1z7FjU/EvRM0Z7b2MSDHHNlKsDO/PSRVCiIsoRQ=
=HePG
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1890-2
July 03, 2013

firefox regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

USN-1890-1 introduced a regression in Firefox.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

USN-1890-1 fixed vulnerabilities in Firefox. This update introduced a
regression which sometimes resulted in Firefox using the wrong network
proxy settings. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-1682, CVE-2013-1683)

Abhishek Arya discovered multiple use-after-free bugs. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to execute arbitrary code with the privileges of the user
invoking Firefox. (CVE-2013-1684, CVE-2013-1685, CVE-2013-1686)

Mariusz Mlynski discovered that user defined code within the XBL scope of
an element could be made to bypass System Only Wrappers (SOW). An attacker
could potentially exploit this to execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2013-1687)

Mariusz Mlynski discovered that the profiler user interface incorrectly
handled data from the profiler. If the user examined profiler output
on a specially crafted page, an attacker could potentially exploit this to
execute arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1688)

A crash was discovered when reloading a page that contained content using
the onreadystatechange event. An attacker could potentially exploit this
to execute arbitrary code with the privileges of the user invoking Firefox
(CVE-2013-1690)

Johnathan Kuskos discovered that Firefox sent data in the body of
XMLHttpRequest HEAD requests. An attacker could exploit this to conduct
Cross-Site Request Forgery (CSRF) attacks. (CVE-2013-1692)

Paul Stone discovered a timing flaw in the processing of SVG images with
filters. An attacker could exploit this to view sensitive information.
(CVE-2013-1693)

Boris Zbarsky discovered a flaw in PreserveWrapper. An attacker could
potentially exploit this to cause a denial of service via application
crash, or execute code with the privileges of the user invoking Firefox.
(CVE-2013-1694)

Bob Owen discovered that a sandboxed iframe could use a frame element
to bypass its own restrictions. (CVE-2013-1695)

Frédéric Buclin discovered that the X-Frame-Options header is ignored
in multi-part responses. An attacker could potentially exploit this
to conduct clickjacking attacks. (CVE-2013-1696)

It was discovered that XrayWrappers could be bypassed to call
content-defined methods in certain circumstances. An attacker could
exploit this to cause undefined behaviour. (CVE-2013-1697)

Matt Wobensmith discovered that the getUserMedia permission dialog
displayed the wrong domain in certain circumstances. An attacker could
potentially exploit this to trick the user in to giving a malicious
site access to their microphone or camera. (CVE-2013-1698)

It was discovered that the measures for preventing homograph attacks
using Internationalized Domain Names (IDN) were not sufficient
for certain Top Level Domains (TLD). An attacker could potentially
exploit this to conduct URL spoofing and phishing attacks.
(CVE-2013-1699)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
firefox 22.0+build2-0ubuntu0.13.04.2

Ubuntu 12.10:
firefox 22.0+build2-0ubuntu0.12.10.2

Ubuntu 12.04 LTS:
firefox 22.0+build2-0ubuntu0.12.04.2

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1890-2
http://www.ubuntu.com/usn/usn-1890-1
https://launchpad.net/bugs/1194841

Package Information:
https://launchpad.net/ubuntu/+source/firefox/22.0+build2-0ubuntu0.13.04.2
https://launchpad.net/ubuntu/+source/firefox/22.0+build2-0ubuntu0.12.10.2
https://launchpad.net/ubuntu/+source/firefox/22.0+build2-0ubuntu0.12.04.2

Announcing the release of Fedora 19 for Power

The Fedora Secondary Arch Team for Power is delighted to announce the
release of Fedora 19 ("Schrödinger's Cat") for Power architecture. Open
the box and take a look for yourself!

Fedora is a leading-edge, free and open source operating system that
continues to deliver innovative features to many users, with a new
release about every six months.

Download it now:

http://fedoraproject.org/en/get-fedora-options#2nd_arches

Detailed information about this release on Power can be seen in the
release notes:
https://fedoraproject.org/wiki/Architectures/PowerPC/F19_release_announcement

For the general release notes for this release take a look here:
http://docs.fedoraproject.org/en-US/Fedora/19/html/Release_Notes/

** What's New in Fedora 19 for Power? **

* The new LLVMPipe rendering engine is now fully functional and enabled
by default. This greatly speeds up graphics rendering on systems with no
3D graphics drivers or working with VNC sessions.

A complete list with details of each new feature is available here:
http://fedoraproject.org/wiki/Releases/19/FeatureList

*** Downloads, upgrades, documentation, and common bugs ***

Start by downloading Fedora 19:
http://fedoraproject.org/en/get-fedora-options#2nd_arches

If you are upgrading from a previous release of Fedora, refer to:
http://fedoraproject.org/wiki/Upgrading

Fedora now includes FedUp in order to enable an easy upgrade to Fedora 19.

*** Documentation ***

Read the full release notes for Fedora 19, guides for several languages,
and learn about known bugs and how to report new ones:
http://docs.fedoraproject.org/

Because of the number of changes to the installer, we particularly
suggest taking a peek at the Installation Guide:
http://docs.fedoraproject.org/en-US/Fedora/19/html/Installation_Guide/index.html

Fedora 19 common bugs are documented at:
http://fedoraproject.org/wiki/Common_F19_bugs

This page includes information on several known bugs in the installer,
so we recommend reading it before installing Fedora 19.

*** Contributing ***

We can't build Fedora inside a box. We need your help! Bug reports are
especially helpful--if you encounter any issues, please report them!

Fedora is a fantastic, friendly community, and we have many ways in
which you can contribute, including documentation, marketing, design,
QA, and development.

To learn how to help us, visit:
http://join.fedoraproject.org/

*** Fedora 20 ***

Fedora 20 has been in active development for several months already. We
plan to release it in November 2013, though the final schedule is part
of the planning process and subject to change:

https://fedoraproject.org/wiki/Releases/20/Schedule

*** Contact information ***

If you are a journalist or reporter, you can find additional information
here:

https://fedoraproject.org/wiki/Press

In the name of the whole Fedora Secondary Arch Team for Power i'd like
to thank everyone making this an awesome release.

Thanks & regards, Phil

--
Philipp Knirsch | Tel.: +49-711-96437-470
Manager Core Services | Fax.: +49-711-96437-111
Red Hat GmbH | Email: Phil Knirsch <pknirsch@redhat.com>
Wankelstrasse 5 | Web: http://www.redhat.com/
D-70563
Stuttgart, Germany
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce

Reminder: Fedora 17 end of life on 2013-07-30

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Greetings.

This is a reminder email about the end of life process for Fedora 17.

Fedora 17 will reach end of life on 2013-07-30, and no further updates
will be pushed out after that time. Additionally, with the recent
release of Fedora 19, no new packages will be added to the Fedora 17
collection.

Please see http://fedoraproject.org/wiki/DistributionUpgrades for more
information on upgrading from Fedora 17 to a newer release.


Dennis
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)

iEYEARECAAYFAlHUNr8ACgkQkSxm47BaWfeMyACfclL38HAQ5BH6JwkzyjUhuCoo
5rkAnjdoGzPhPvB3pLlZhXJEddKkn4tW
=vE+d
-----END PGP SIGNATURE-----
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce

[USN-1896-1] Module::Signature perl module vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJR1CGNAAoJEGVp2FWnRL6TatgP/ihdpiuEJxUrdkWPS0WsmBMA
cPLceXgmNcZJXZMlMgNEixmF0LRW7al5F55WQiq5aeH32S3dN5n0+lDNNmS+ZwS+
jajKA5Z55VsvG7+IMhOs3kElv+cYXEt6X7GN5piMtO6Q5ni3FZ5RdzNAMR6NUZPz
/qkoeQF/EZJtbgB5M99nUTA3OOXZf87yzzZxLfMdFJxvRu9XscN98CkzjbNyu/zf
4trve85kqbd7R3s6FWI4yWm8tpW8q47PAPeq/3X4XxzbC7RkQN99NymCJd1GgXM4
kegr95Bfr+tl7wdD2HpYdtvPgJ4d58AsChbSz6Z2wxHI7jrgYpl03VVrI+HSc6X8
HlZaKJ6O8cYraKwVyaxkVrv/glESuBueXfLkwurXojyaZEokkWMy0ktay1PuMRwo
jg4wciohN9S+VWgMiDOvN/nYCXkibHeoc+cHx1ZnBQ+DpN2Op+Ek6ifNmDEs22Ja
Bn1EvPU3N1KMtW+03jLW1s2NN41j4CXAuyuZW2+uxLpjaM0TiryfXMkXD0vbpj/M
aFBnmswyi2s+A5VRCdQ1kL3d2x5bqkySO8mKC7J7lI2PlpRa7vEpfoee/JxWRHQI
QEyVgMQhiRi+2X3typBDlZ/sTdXW500wyg2dq0IcqbW8jfXQvXJW1qaMFJ8F2EqZ
W7MVtXQpqh9CkQ7uxkv0
=h5It
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1896-1
July 03, 2013

libmodule-signature-perl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Module::Signature could be made to run programs if it verified a signature.

Software Description:
- libmodule-signature-perl: module to manipulate CPAN SIGNATURE files

Details:

Florian Weimer discovered that the Module::Signature perl module
incorrectly loaded unknown ciphers from relative directories. An attacker
could possibly use this flaw to execute arbitrary code when a signature is
verified.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libmodule-signature-perl 0.68-1ubuntu0.13.04.1

Ubuntu 12.10:
libmodule-signature-perl 0.68-1ubuntu0.12.10.1

Ubuntu 12.04 LTS:
libmodule-signature-perl 0.68-1ubuntu0.12.04.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1896-1
CVE-2013-2145

Package Information:

https://launchpad.net/ubuntu/+source/libmodule-signature-perl/0.68-1ubuntu0.13.04.1

https://launchpad.net/ubuntu/+source/libmodule-signature-perl/0.68-1ubuntu0.12.10.1

https://launchpad.net/ubuntu/+source/libmodule-signature-perl/0.68-1ubuntu0.12.04.1

Tuesday, July 2, 2013

[USN-1895-1] libvirt vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJR0zWUAAoJEGVp2FWnRL6TyFkP/2aRAC2s983SIFx9VJzKMVgJ
byQzdjhEsNQeA769a4nNgKX+xic2acUUqWbTjnjBqSUmA6Ihx3e0Fe6kvVJA+Oib
uN649KddYuY5Ag7U5/RTCUm8nGv7l7ptgqN4kkAKFNgMg3JT5b4gnUMf0oRH8B9e
Tz+p54Jhqb0ck6/zuqHUl/566Wgu14mUb/mATj8ob8Wc0afiE+FWlcxsA7Jq7PcO
xFtcLSHTImadpQ57BUx0NSZc0xcAho7EhmH/dAdHLf9ywIfMm561CpvGG92414LC
qEzRyc1TQdCkRfRXFNvMskg4+3C/QXTwtSDBG8my2wRP5HkImpWs3Ym+WliLrOU0
P0J3uZAew8GTJsyQYagyTKPvbIy51NRXCRcuiIAQaLj9nwuXtDWILpFbOZpJzCUl
0Gj3tyCn/Pn0pr18tFPWAHJvHkqMCb5FS68sqdUjW72NssAQ+1ZUcs5GdzhqQEwn
Sj7PjraSCwh6vu6AWFVIuqnWJ+SrYYVZSJ6o1/AhZ4BbCHrpWMtvGBJsjz+OHryM
MrVd71vsl+wlOKRIuRWXdFQljd4AKYJdpzxqCJJF2J8e5sVaGutdoeHi8PDlu6Qm
sK/SP35CVyIPbtPeKgGAU5jEJTRDKsnIQTlJ1aBG6YpikV2qXFdfjg+k62D0ZnEj
S1aN8UVrdzFO1iXfssZH
=KpI5
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1895-1
July 02, 2013

libvirt vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04

Summary:

libvirt could be made to crash if it received specially crafted network
traffic.

Software Description:
- libvirt: Libvirt virtualization toolkit

Details:

It was discovered that libvirt incorrectly handled certain storage pool
requests. A remote attacker could use this issue to cause libvirt to
consume resources, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libvirt0 1.0.2-0ubuntu11.13.04.2

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1895-1
CVE-2013-1962

Package Information:
https://launchpad.net/ubuntu/+source/libvirt/1.0.2-0ubuntu11.13.04.2