CentOS Errata and Security Advisory 2013:1142 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1142.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
a3bffc1a95511fe06c09eea91aa6b7613e151c217ed4114c2b321ccdb27afc0e thunderbird-17.0.8-5.el6.centos.i686.rpm
x86_64:
3d1d21625f80c337c4bbce97675c1ead883579aea4186908b6ce11fc26ffcbac thunderbird-17.0.8-5.el6.centos.x86_64.rpm
Source:
0f2ba7e315682bd634019c48982b5a8e25f2ff05889344db1cad7ed61382314f thunderbird-17.0.8-5.el6.centos.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Friday, August 9, 2013
Thursday, August 8, 2013
poppler soname bump in rawhide
Hi,
I plan to rebase poppler in rawhide to poppler-0.24.0 at 19th of August.
There are several changes and 1 soname bump (libpoppler.so.37 to
libpoppler.so.43). It also adds support for Qt5.
I've prepared a scratch build of poppler-0.24.0 against which you can
test your packages. You can find the build here:
http://koji.fedoraproject.org/koji/taskinfo?taskID=5794682
or here:
http://mkasik.fedorapeople.org/poppler/
Regards
Marek
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[CentOS-announce] CEBA-2013:1146 CentOS 6 nss-pam-ldapd Update
CentOS Errata and Bugfix Advisory 2013:1146
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1146.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
2b9b463c19a42424b4a9e45b414b68897bfb82d46381621fe382f4a446c29409 nss-pam-ldapd-0.7.5-18.2.el6_4.i686.rpm
x86_64:
2b9b463c19a42424b4a9e45b414b68897bfb82d46381621fe382f4a446c29409 nss-pam-ldapd-0.7.5-18.2.el6_4.i686.rpm
167b24d4bd19e09ca0639b21185a12547b415a00ee4bde96cb6ee66fb8d40f6f nss-pam-ldapd-0.7.5-18.2.el6_4.x86_64.rpm
Source:
db2472a9bf272cba36b901960f2290592222718c63eb8ba136e65a555d409e11 nss-pam-ldapd-0.7.5-18.2.el6_4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1146.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
2b9b463c19a42424b4a9e45b414b68897bfb82d46381621fe382f4a446c29409 nss-pam-ldapd-0.7.5-18.2.el6_4.i686.rpm
x86_64:
2b9b463c19a42424b4a9e45b414b68897bfb82d46381621fe382f4a446c29409 nss-pam-ldapd-0.7.5-18.2.el6_4.i686.rpm
167b24d4bd19e09ca0639b21185a12547b415a00ee4bde96cb6ee66fb8d40f6f nss-pam-ldapd-0.7.5-18.2.el6_4.x86_64.rpm
Source:
db2472a9bf272cba36b901960f2290592222718c63eb8ba136e65a555d409e11 nss-pam-ldapd-0.7.5-18.2.el6_4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Wednesday, August 7, 2013
[CentOS-announce] CESA-2013:1144 Moderate CentOS 6 nss, nss-util, nss-softokn, and nspr Update
CentOS Errata and Security Advisory 2013:1144 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1144.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0f58d15d6a0701a653cdb2edb28c4637177a28205d4125a75b058401eb701638 nspr-4.9.5-2.el6_4.i686.rpm
4bfc730889575fbfd3d9e381b7795a932ef4e5934980373cb25e07a37345da86 nspr-devel-4.9.5-2.el6_4.i686.rpm
7ae168ed04f50160d9ad74573546c2fd6283604f105c84b54e47f2fc85030a64 nss-3.14.3-4.el6_4.i686.rpm
a2dcfab2e26fc6ea3315e8edc350e4d187ee696953df9e8c2897de3520a4335e nss-devel-3.14.3-4.el6_4.i686.rpm
433800763e54157c6a9d53df5522bff0624927697418ad84505d3d1dac67c158 nss-pkcs11-devel-3.14.3-4.el6_4.i686.rpm
18802405fe1c3aab26686261dae07eff2b87ca29e352d5dc167eae85d038e305 nss-softokn-3.14.3-3.el6_4.i686.rpm
2a667eebdb02342f05998f0f90f8241625ae2860b6152f3f4f6a50813ba2af98 nss-softokn-devel-3.14.3-3.el6_4.i686.rpm
b3de628d33e606d08fc20371f8f31d2cde47894c0ff710d48dfadadfac436b19 nss-softokn-freebl-3.14.3-3.el6_4.i686.rpm
605febe4e77275e1e2f82c572c96edff7eb3bdddba6babb40ba611b7c6a982a2 nss-softokn-freebl-devel-3.14.3-3.el6_4.i686.rpm
c8aa5e227980f3de0ef1e9f84376d489c4d0c0a78b9f19ddf78dd17a41ac3864 nss-sysinit-3.14.3-4.el6_4.i686.rpm
6b8a1e7f4b154929665b6906bf0ec5cab0986b6baa9745615ae08dc0cb331c88 nss-tools-3.14.3-4.el6_4.i686.rpm
dba88322b701b9cdd9d40943cd7f8ed5b00d4e9a789c46ba3e8ed0000184af44 nss-util-3.14.3-3.el6_4.i686.rpm
af95b7bcb6e5927034d3b8a304fbda7442c4311538651dcc3c6a7c62d5636762 nss-util-devel-3.14.3-3.el6_4.i686.rpm
x86_64:
0f58d15d6a0701a653cdb2edb28c4637177a28205d4125a75b058401eb701638 nspr-4.9.5-2.el6_4.i686.rpm
57d33fdbd3ab84c918960216edcab613bf584d603f0a494d6e3e5ec91a330416 nspr-4.9.5-2.el6_4.x86_64.rpm
4bfc730889575fbfd3d9e381b7795a932ef4e5934980373cb25e07a37345da86 nspr-devel-4.9.5-2.el6_4.i686.rpm
59f0d2d2396a6eb7cb4e9220a20e8dfa5266ea7db576df822f811db7236144f1 nspr-devel-4.9.5-2.el6_4.x86_64.rpm
7ae168ed04f50160d9ad74573546c2fd6283604f105c84b54e47f2fc85030a64 nss-3.14.3-4.el6_4.i686.rpm
2ff15881fafd6fa527870e68505c3ba8c9b2bf1a85aa7a552105acd42190594c nss-3.14.3-4.el6_4.x86_64.rpm
a2dcfab2e26fc6ea3315e8edc350e4d187ee696953df9e8c2897de3520a4335e nss-devel-3.14.3-4.el6_4.i686.rpm
ca3c264dca47cc751bab6d8e5be9f9082624fdccccc2bbc4ead802e8a197b57c nss-devel-3.14.3-4.el6_4.x86_64.rpm
433800763e54157c6a9d53df5522bff0624927697418ad84505d3d1dac67c158 nss-pkcs11-devel-3.14.3-4.el6_4.i686.rpm
a1570ffea92be30305656b4c55e5303fe882975f2de5897c4241de2b3c76b183 nss-pkcs11-devel-3.14.3-4.el6_4.x86_64.rpm
18802405fe1c3aab26686261dae07eff2b87ca29e352d5dc167eae85d038e305 nss-softokn-3.14.3-3.el6_4.i686.rpm
f9e2fd78ce1753318dc58cc4a25256f9df080acedb72e71ba18acfaa6273c807 nss-softokn-3.14.3-3.el6_4.x86_64.rpm
2a667eebdb02342f05998f0f90f8241625ae2860b6152f3f4f6a50813ba2af98 nss-softokn-devel-3.14.3-3.el6_4.i686.rpm
117d1a28427043e135d37d67cf0194a1bb11cc5cf7cafd85052daff62707958c nss-softokn-devel-3.14.3-3.el6_4.x86_64.rpm
b3de628d33e606d08fc20371f8f31d2cde47894c0ff710d48dfadadfac436b19 nss-softokn-freebl-3.14.3-3.el6_4.i686.rpm
6d2da6ca90216ee54b0b3b21d81b2625d7f445cfbe5dc96f6aa9c7b596a1cbdf nss-softokn-freebl-3.14.3-3.el6_4.x86_64.rpm
605febe4e77275e1e2f82c572c96edff7eb3bdddba6babb40ba611b7c6a982a2 nss-softokn-freebl-devel-3.14.3-3.el6_4.i686.rpm
1af74a48132ed48e31251c266ba874bb668ce960bdcae358766b41d4f8b128e7 nss-softokn-freebl-devel-3.14.3-3.el6_4.x86_64.rpm
41229dc949f87617afe24002aa67b55f983a0048b8857f8cc8aef5932b9e2e19 nss-sysinit-3.14.3-4.el6_4.x86_64.rpm
fa478a0b151e56838d0dc36a7c1bdb53888ebb54d931b314d329a679b4703ff8 nss-tools-3.14.3-4.el6_4.x86_64.rpm
dba88322b701b9cdd9d40943cd7f8ed5b00d4e9a789c46ba3e8ed0000184af44 nss-util-3.14.3-3.el6_4.i686.rpm
dec26cdc286feb5d39b3fd0ae745a7900df3888b43901b3b86e2d99869005876 nss-util-3.14.3-3.el6_4.x86_64.rpm
af95b7bcb6e5927034d3b8a304fbda7442c4311538651dcc3c6a7c62d5636762 nss-util-devel-3.14.3-3.el6_4.i686.rpm
84a63ecf7366f2275029a26422280179dd18fd0d1215324c472acf8eba42a970 nss-util-devel-3.14.3-3.el6_4.x86_64.rpm
Source:
dbeec138d5284b66d667ec45c8e07548801aa3a5db5955bbaa4313bc6c949def nspr-4.9.5-2.el6_4.src.rpm
467f81da27edec40bd8e64809e53f156b396aa54bb397f5c18adb5d2eab3aeee nss-3.14.3-4.el6_4.src.rpm
08b72f9ad32172a9017328f5bb652280aafb7f35bdcf0b704a0d3a6fddd1d0ee nss-softokn-3.14.3-3.el6_4.src.rpm
7bf46cfaeacf80ac9e3d2197d2f3589b84f2125fe008f34a63751da36829dc23 nss-util-3.14.3-3.el6_4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1144.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0f58d15d6a0701a653cdb2edb28c4637177a28205d4125a75b058401eb701638 nspr-4.9.5-2.el6_4.i686.rpm
4bfc730889575fbfd3d9e381b7795a932ef4e5934980373cb25e07a37345da86 nspr-devel-4.9.5-2.el6_4.i686.rpm
7ae168ed04f50160d9ad74573546c2fd6283604f105c84b54e47f2fc85030a64 nss-3.14.3-4.el6_4.i686.rpm
a2dcfab2e26fc6ea3315e8edc350e4d187ee696953df9e8c2897de3520a4335e nss-devel-3.14.3-4.el6_4.i686.rpm
433800763e54157c6a9d53df5522bff0624927697418ad84505d3d1dac67c158 nss-pkcs11-devel-3.14.3-4.el6_4.i686.rpm
18802405fe1c3aab26686261dae07eff2b87ca29e352d5dc167eae85d038e305 nss-softokn-3.14.3-3.el6_4.i686.rpm
2a667eebdb02342f05998f0f90f8241625ae2860b6152f3f4f6a50813ba2af98 nss-softokn-devel-3.14.3-3.el6_4.i686.rpm
b3de628d33e606d08fc20371f8f31d2cde47894c0ff710d48dfadadfac436b19 nss-softokn-freebl-3.14.3-3.el6_4.i686.rpm
605febe4e77275e1e2f82c572c96edff7eb3bdddba6babb40ba611b7c6a982a2 nss-softokn-freebl-devel-3.14.3-3.el6_4.i686.rpm
c8aa5e227980f3de0ef1e9f84376d489c4d0c0a78b9f19ddf78dd17a41ac3864 nss-sysinit-3.14.3-4.el6_4.i686.rpm
6b8a1e7f4b154929665b6906bf0ec5cab0986b6baa9745615ae08dc0cb331c88 nss-tools-3.14.3-4.el6_4.i686.rpm
dba88322b701b9cdd9d40943cd7f8ed5b00d4e9a789c46ba3e8ed0000184af44 nss-util-3.14.3-3.el6_4.i686.rpm
af95b7bcb6e5927034d3b8a304fbda7442c4311538651dcc3c6a7c62d5636762 nss-util-devel-3.14.3-3.el6_4.i686.rpm
x86_64:
0f58d15d6a0701a653cdb2edb28c4637177a28205d4125a75b058401eb701638 nspr-4.9.5-2.el6_4.i686.rpm
57d33fdbd3ab84c918960216edcab613bf584d603f0a494d6e3e5ec91a330416 nspr-4.9.5-2.el6_4.x86_64.rpm
4bfc730889575fbfd3d9e381b7795a932ef4e5934980373cb25e07a37345da86 nspr-devel-4.9.5-2.el6_4.i686.rpm
59f0d2d2396a6eb7cb4e9220a20e8dfa5266ea7db576df822f811db7236144f1 nspr-devel-4.9.5-2.el6_4.x86_64.rpm
7ae168ed04f50160d9ad74573546c2fd6283604f105c84b54e47f2fc85030a64 nss-3.14.3-4.el6_4.i686.rpm
2ff15881fafd6fa527870e68505c3ba8c9b2bf1a85aa7a552105acd42190594c nss-3.14.3-4.el6_4.x86_64.rpm
a2dcfab2e26fc6ea3315e8edc350e4d187ee696953df9e8c2897de3520a4335e nss-devel-3.14.3-4.el6_4.i686.rpm
ca3c264dca47cc751bab6d8e5be9f9082624fdccccc2bbc4ead802e8a197b57c nss-devel-3.14.3-4.el6_4.x86_64.rpm
433800763e54157c6a9d53df5522bff0624927697418ad84505d3d1dac67c158 nss-pkcs11-devel-3.14.3-4.el6_4.i686.rpm
a1570ffea92be30305656b4c55e5303fe882975f2de5897c4241de2b3c76b183 nss-pkcs11-devel-3.14.3-4.el6_4.x86_64.rpm
18802405fe1c3aab26686261dae07eff2b87ca29e352d5dc167eae85d038e305 nss-softokn-3.14.3-3.el6_4.i686.rpm
f9e2fd78ce1753318dc58cc4a25256f9df080acedb72e71ba18acfaa6273c807 nss-softokn-3.14.3-3.el6_4.x86_64.rpm
2a667eebdb02342f05998f0f90f8241625ae2860b6152f3f4f6a50813ba2af98 nss-softokn-devel-3.14.3-3.el6_4.i686.rpm
117d1a28427043e135d37d67cf0194a1bb11cc5cf7cafd85052daff62707958c nss-softokn-devel-3.14.3-3.el6_4.x86_64.rpm
b3de628d33e606d08fc20371f8f31d2cde47894c0ff710d48dfadadfac436b19 nss-softokn-freebl-3.14.3-3.el6_4.i686.rpm
6d2da6ca90216ee54b0b3b21d81b2625d7f445cfbe5dc96f6aa9c7b596a1cbdf nss-softokn-freebl-3.14.3-3.el6_4.x86_64.rpm
605febe4e77275e1e2f82c572c96edff7eb3bdddba6babb40ba611b7c6a982a2 nss-softokn-freebl-devel-3.14.3-3.el6_4.i686.rpm
1af74a48132ed48e31251c266ba874bb668ce960bdcae358766b41d4f8b128e7 nss-softokn-freebl-devel-3.14.3-3.el6_4.x86_64.rpm
41229dc949f87617afe24002aa67b55f983a0048b8857f8cc8aef5932b9e2e19 nss-sysinit-3.14.3-4.el6_4.x86_64.rpm
fa478a0b151e56838d0dc36a7c1bdb53888ebb54d931b314d329a679b4703ff8 nss-tools-3.14.3-4.el6_4.x86_64.rpm
dba88322b701b9cdd9d40943cd7f8ed5b00d4e9a789c46ba3e8ed0000184af44 nss-util-3.14.3-3.el6_4.i686.rpm
dec26cdc286feb5d39b3fd0ae745a7900df3888b43901b3b86e2d99869005876 nss-util-3.14.3-3.el6_4.x86_64.rpm
af95b7bcb6e5927034d3b8a304fbda7442c4311538651dcc3c6a7c62d5636762 nss-util-devel-3.14.3-3.el6_4.i686.rpm
84a63ecf7366f2275029a26422280179dd18fd0d1215324c472acf8eba42a970 nss-util-devel-3.14.3-3.el6_4.x86_64.rpm
Source:
dbeec138d5284b66d667ec45c8e07548801aa3a5db5955bbaa4313bc6c949def nspr-4.9.5-2.el6_4.src.rpm
467f81da27edec40bd8e64809e53f156b396aa54bb397f5c18adb5d2eab3aeee nss-3.14.3-4.el6_4.src.rpm
08b72f9ad32172a9017328f5bb652280aafb7f35bdcf0b704a0d3a6fddd1d0ee nss-softokn-3.14.3-3.el6_4.src.rpm
7bf46cfaeacf80ac9e3d2197d2f3589b84f2125fe008f34a63751da36829dc23 nss-util-3.14.3-3.el6_4.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Excludearch/Exclusivearch reminder
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.20 (GNU/Linux)
iQIcBAEBCgAGBQJSAq/jAAoJEEs3sNgP+7tegZgP/1J8ikWI/W5kVdH+A2UgVv6U
qko7IWf9CBL8jWwsYmOZOI8Lpg4Ns1ebF+F6uwze94iJMqJ69KOrrQlcFZs3rStM
O/B7gySaFUEsBbmxqX1ParD1w+/1zUwvEonmNta2/nUD6CUil9u9MU6ZxnXnkX5w
dCGK0iPM4x8GQjsgK/pMAHnfisOTcpUKuIRdP5oMqoMBPkJNUbKcXmDbznZv0LJ7
Lr7M/mNna7KzL5iQQPmtwd3Ib8riuO1x5RawEuX0ksIiX01HzplwbZYA97XPIjSD
PJWla5xDLGqV3TyrZ4fqCUz15bs4wynQn4BkkSiKaLSfFcB4qcIAd0+ubsjmbTYh
UbKNNdBZXMy5CNxmzS52SJ9IifvnovcmnPvDSqm4/PvCzffYO+UdGAH4XvCcz4EA
hcg74WwU6AAdJqd6X6QrTEKYhCK/wSwFQ6BoIbD2pvDG4JSUEd9Yzx1s6pdXJt16
+cMocWPyXIsXGKsg8WkrbZrixjkIQ9U6Niw+oFoABwLKkKfdq7oojHzrEXL4lH+X
nsFN3dRmsZqWrSOtFsOdIiZ2P2U+s6ibCvbZ97rUlovwnKcl4YwBgcev8R19hppE
Q9BXtouadJgtdTX32ooYI+rVv50w7193e7YVqcYGwbV2pHjmH62Wg57NqqGjlDgs
if/FRtIF7fBWaikgH2QA
=7BDs
-----END PGP SIGNATURE-----
Greetings.
With the recent addition of arm in our primary buildsystem, I am seeing
some packages add ExcludeArch: arm or ExclusiveArch: %{ix86}
First, please DO NOT add ExclusiveArch on x86, unless your package
really and truly doesn't build on ANY of our secondary arches too.
(ppc64, s390).
If you exclude arm support for now, please file a bug against your
package with the information about the missing arm support and then
add "F-ExcludeArch-arm" to the Blocks field on your bug. This will make
the arm team aware of the issue, as well as FESCo to track what items
are missing for full primary promotion.
Please see:
https://fedoraproject.org/wiki/Packaging:Guidelines#Architecture_Build_Failures
for additional information.
Thank you for your cooperation.
kevin
Version: GnuPG v2.0.20 (GNU/Linux)
iQIcBAEBCgAGBQJSAq/jAAoJEEs3sNgP+7tegZgP/1J8ikWI/W5kVdH+A2UgVv6U
qko7IWf9CBL8jWwsYmOZOI8Lpg4Ns1ebF+F6uwze94iJMqJ69KOrrQlcFZs3rStM
O/B7gySaFUEsBbmxqX1ParD1w+/1zUwvEonmNta2/nUD6CUil9u9MU6ZxnXnkX5w
dCGK0iPM4x8GQjsgK/pMAHnfisOTcpUKuIRdP5oMqoMBPkJNUbKcXmDbznZv0LJ7
Lr7M/mNna7KzL5iQQPmtwd3Ib8riuO1x5RawEuX0ksIiX01HzplwbZYA97XPIjSD
PJWla5xDLGqV3TyrZ4fqCUz15bs4wynQn4BkkSiKaLSfFcB4qcIAd0+ubsjmbTYh
UbKNNdBZXMy5CNxmzS52SJ9IifvnovcmnPvDSqm4/PvCzffYO+UdGAH4XvCcz4EA
hcg74WwU6AAdJqd6X6QrTEKYhCK/wSwFQ6BoIbD2pvDG4JSUEd9Yzx1s6pdXJt16
+cMocWPyXIsXGKsg8WkrbZrixjkIQ9U6Niw+oFoABwLKkKfdq7oojHzrEXL4lH+X
nsFN3dRmsZqWrSOtFsOdIiZ2P2U+s6ibCvbZ97rUlovwnKcl4YwBgcev8R19hppE
Q9BXtouadJgtdTX32ooYI+rVv50w7193e7YVqcYGwbV2pHjmH62Wg57NqqGjlDgs
if/FRtIF7fBWaikgH2QA
=7BDs
-----END PGP SIGNATURE-----
Greetings.
With the recent addition of arm in our primary buildsystem, I am seeing
some packages add ExcludeArch: arm or ExclusiveArch: %{ix86}
First, please DO NOT add ExclusiveArch on x86, unless your package
really and truly doesn't build on ANY of our secondary arches too.
(ppc64, s390).
If you exclude arm support for now, please file a bug against your
package with the information about the missing arm support and then
add "F-ExcludeArch-arm" to the Blocks field on your bug. This will make
the arm team aware of the issue, as well as FESCo to track what items
are missing for full primary promotion.
Please see:
https://fedoraproject.org/wiki/Packaging:Guidelines#Architecture_Build_Failures
for additional information.
Thank you for your cooperation.
kevin
[CentOS-announce] CESA-2013:1142 Important CentOS 5 thunderbird Update
CentOS Errata and Security Advisory 2013:1142 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1142.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0f42911c5588336dc341f9eedb47111e15d902c89812e4c9509981ecd524a964 thunderbird-17.0.8-5.el5.centos.i386.rpm
x86_64:
925fa770e515eb877055fe1977d2e81fadbd8e1b8abad1d6c6e39eddeb9db502 thunderbird-17.0.8-5.el5.centos.x86_64.rpm
Source:
8fa005546557d77f963333d95cfc42c9c1160d23f60e1c2ab2a8a962c82fdbcf thunderbird-17.0.8-5.el5.centos.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1142.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0f42911c5588336dc341f9eedb47111e15d902c89812e4c9509981ecd524a964 thunderbird-17.0.8-5.el5.centos.i386.rpm
x86_64:
925fa770e515eb877055fe1977d2e81fadbd8e1b8abad1d6c6e39eddeb9db502 thunderbird-17.0.8-5.el5.centos.x86_64.rpm
Source:
8fa005546557d77f963333d95cfc42c9c1160d23f60e1c2ab2a8a962c82fdbcf thunderbird-17.0.8-5.el5.centos.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[announce] NYC*BUG Tonight: A Decade of NYC*BUG
Wednesday, August 7
645 PM
Suspenders Bar and Restaurant
111 Broadway
A Decade of NYC*BUG
The New York City *BSD Group was launched in December 2003 and became
public at Linux Expo in January 2004.
We weren't sure exact what we wanted, but we knew what we *didn't* want.
We didn't aim to be just another hobbyist user group attracting the
socially inept. And nor did we aim to become another resume filling
association with a fee-based membership, filling our free evenings with
sales talks.
We wandered into unknown worlds. The BSD community has never been
advocacy-driven, preferring to let the software stand on its own two
feet. And certainly the reputation of an "uncivil *BSD society" caused
us to wonder what NYC*BUG could ultimately morph into.
And it was not always easy.
One local, long-time BSD developer welcomed us with open arms with
comments like:
they are just doing what linux group does... probably same ppl too
cu
Ten years later we can look back and be proud of our accomplishments. We
have run four NYCBSDCons and raised funds to hosting a lot of mirrors
and projects. But more importantly, we should determine what we did
right, and how we can continue NYC*BUG for another ten years.
This meeting will look at the broad picture of where NYC*BUG has been,
and hopefully draw some lessons for everyone about technical user
groups, the *BSD community and more generally how.
****
Other upcoming meetings:
September 4: Postgresql + ZFS on FreeBSD
August 2: A Year After Sandy
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
645 PM
Suspenders Bar and Restaurant
111 Broadway
A Decade of NYC*BUG
The New York City *BSD Group was launched in December 2003 and became
public at Linux Expo in January 2004.
We weren't sure exact what we wanted, but we knew what we *didn't* want.
We didn't aim to be just another hobbyist user group attracting the
socially inept. And nor did we aim to become another resume filling
association with a fee-based membership, filling our free evenings with
sales talks.
We wandered into unknown worlds. The BSD community has never been
advocacy-driven, preferring to let the software stand on its own two
feet. And certainly the reputation of an "uncivil *BSD society" caused
us to wonder what NYC*BUG could ultimately morph into.
And it was not always easy.
One local, long-time BSD developer welcomed us with open arms with
comments like:
they are just doing what linux group does... probably same ppl too
cu
Ten years later we can look back and be proud of our accomplishments. We
have run four NYCBSDCons and raised funds to hosting a lot of mirrors
and projects. But more importantly, we should determine what we did
right, and how we can continue NYC*BUG for another ten years.
This meeting will look at the broad picture of where NYC*BUG has been,
and hopefully draw some lessons for everyone about technical user
groups, the *BSD community and more generally how.
****
Other upcoming meetings:
September 4: Postgresql + ZFS on FreeBSD
August 2: A Year After Sandy
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
[CentOS-announce] CESA-2013:1140 Critical CentOS 6 firefox Update
CentOS Errata and Security Advisory 2013:1140 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1140.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
d606c6e6aec2aaf56e7dcf58fb90e08e10987186df4570e3fc39c27eb493cf08 firefox-17.0.8-1.el6.centos.i686.rpm
f79b361189050266adf06e690280790980056bc8825824dbf2be4b015fc80040 xulrunner-17.0.8-3.el6.centos.i686.rpm
8df0546cb9fb6949a02ff39969f31ee6c9096537af871bb7f09ea25dbc33d5d0 xulrunner-devel-17.0.8-3.el6.centos.i686.rpm
x86_64:
d606c6e6aec2aaf56e7dcf58fb90e08e10987186df4570e3fc39c27eb493cf08 firefox-17.0.8-1.el6.centos.i686.rpm
766377ffe748104e1e85f0c4445742e72c0ef1bb25eba2e2f511bcde5878d99c firefox-17.0.8-1.el6.centos.x86_64.rpm
f79b361189050266adf06e690280790980056bc8825824dbf2be4b015fc80040 xulrunner-17.0.8-3.el6.centos.i686.rpm
ab5d8ca811a832e5518c3e577b217b95ba97e026f5de332cb9d807ee8f46d128 xulrunner-17.0.8-3.el6.centos.x86_64.rpm
8df0546cb9fb6949a02ff39969f31ee6c9096537af871bb7f09ea25dbc33d5d0 xulrunner-devel-17.0.8-3.el6.centos.i686.rpm
f11a4a684c88fc91bec55d11656b7da167f560f24bc26419a16f62205f4d09b4 xulrunner-devel-17.0.8-3.el6.centos.x86_64.rpm
Source:
430bb851de108431f8a4ba41dfe09775e5778e123ccd745e2b11d6759908e938 firefox-17.0.8-1.el6.centos.src.rpm
b2eb74f446f3f783143cbde5323ef83068c4cacacdeb876e28af4c2e00016ace xulrunner-17.0.8-3.el6.centos.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1140.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
d606c6e6aec2aaf56e7dcf58fb90e08e10987186df4570e3fc39c27eb493cf08 firefox-17.0.8-1.el6.centos.i686.rpm
f79b361189050266adf06e690280790980056bc8825824dbf2be4b015fc80040 xulrunner-17.0.8-3.el6.centos.i686.rpm
8df0546cb9fb6949a02ff39969f31ee6c9096537af871bb7f09ea25dbc33d5d0 xulrunner-devel-17.0.8-3.el6.centos.i686.rpm
x86_64:
d606c6e6aec2aaf56e7dcf58fb90e08e10987186df4570e3fc39c27eb493cf08 firefox-17.0.8-1.el6.centos.i686.rpm
766377ffe748104e1e85f0c4445742e72c0ef1bb25eba2e2f511bcde5878d99c firefox-17.0.8-1.el6.centos.x86_64.rpm
f79b361189050266adf06e690280790980056bc8825824dbf2be4b015fc80040 xulrunner-17.0.8-3.el6.centos.i686.rpm
ab5d8ca811a832e5518c3e577b217b95ba97e026f5de332cb9d807ee8f46d128 xulrunner-17.0.8-3.el6.centos.x86_64.rpm
8df0546cb9fb6949a02ff39969f31ee6c9096537af871bb7f09ea25dbc33d5d0 xulrunner-devel-17.0.8-3.el6.centos.i686.rpm
f11a4a684c88fc91bec55d11656b7da167f560f24bc26419a16f62205f4d09b4 xulrunner-devel-17.0.8-3.el6.centos.x86_64.rpm
Source:
430bb851de108431f8a4ba41dfe09775e5778e123ccd745e2b11d6759908e938 firefox-17.0.8-1.el6.centos.src.rpm
b2eb74f446f3f783143cbde5323ef83068c4cacacdeb876e28af4c2e00016ace xulrunner-17.0.8-3.el6.centos.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2013:1140 Critical CentOS 5 firefox Update
CentOS Errata and Security Advisory 2013:1140 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1140.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0fd111d99fd3247e21ee663e5d15238eccd25aff8ef145b224203059b7719549 firefox-17.0.8-1.el5.centos.i386.rpm
bf9ea3ba8425d286a40dbd37d697ef4a7cfe884c7abb9b8ada63e79031048a89 xulrunner-17.0.8-3.el5_9.i386.rpm
4a9e979a06d7fab3e0ea7b322fb1e602a805cd9ba0bfeed62c62a843d9ce4be6 xulrunner-devel-17.0.8-3.el5_9.i386.rpm
x86_64:
0fd111d99fd3247e21ee663e5d15238eccd25aff8ef145b224203059b7719549 firefox-17.0.8-1.el5.centos.i386.rpm
3f605403f601215de227a98d7a62d0491153da5a06cfb093ac7ea6a524423361 firefox-17.0.8-1.el5.centos.x86_64.rpm
bf9ea3ba8425d286a40dbd37d697ef4a7cfe884c7abb9b8ada63e79031048a89 xulrunner-17.0.8-3.el5_9.i386.rpm
2cd3ee9785aee017728e748f7b3fe773701a420920750ea13d44e5531169e0d9 xulrunner-17.0.8-3.el5_9.x86_64.rpm
4a9e979a06d7fab3e0ea7b322fb1e602a805cd9ba0bfeed62c62a843d9ce4be6 xulrunner-devel-17.0.8-3.el5_9.i386.rpm
6f95e74859fd807ca2c334d2dcf01a4ac07b1cda233b7ffe16888dbadc45b88d xulrunner-devel-17.0.8-3.el5_9.x86_64.rpm
Source:
7a33b9581d894767f9513e4a49ce1c2fd763848ab7cbd836f6a19a52747cdd1e firefox-17.0.8-1.el5.centos.src.rpm
fc50bc7a0edb0a5b3eb7667d81230d29df6b3bd4e7707888d23dc2dbc5986569 xulrunner-17.0.8-3.el5_9.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1140.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0fd111d99fd3247e21ee663e5d15238eccd25aff8ef145b224203059b7719549 firefox-17.0.8-1.el5.centos.i386.rpm
bf9ea3ba8425d286a40dbd37d697ef4a7cfe884c7abb9b8ada63e79031048a89 xulrunner-17.0.8-3.el5_9.i386.rpm
4a9e979a06d7fab3e0ea7b322fb1e602a805cd9ba0bfeed62c62a843d9ce4be6 xulrunner-devel-17.0.8-3.el5_9.i386.rpm
x86_64:
0fd111d99fd3247e21ee663e5d15238eccd25aff8ef145b224203059b7719549 firefox-17.0.8-1.el5.centos.i386.rpm
3f605403f601215de227a98d7a62d0491153da5a06cfb093ac7ea6a524423361 firefox-17.0.8-1.el5.centos.x86_64.rpm
bf9ea3ba8425d286a40dbd37d697ef4a7cfe884c7abb9b8ada63e79031048a89 xulrunner-17.0.8-3.el5_9.i386.rpm
2cd3ee9785aee017728e748f7b3fe773701a420920750ea13d44e5531169e0d9 xulrunner-17.0.8-3.el5_9.x86_64.rpm
4a9e979a06d7fab3e0ea7b322fb1e602a805cd9ba0bfeed62c62a843d9ce4be6 xulrunner-devel-17.0.8-3.el5_9.i386.rpm
6f95e74859fd807ca2c334d2dcf01a4ac07b1cda233b7ffe16888dbadc45b88d xulrunner-devel-17.0.8-3.el5_9.x86_64.rpm
Source:
7a33b9581d894767f9513e4a49ce1c2fd763848ab7cbd836f6a19a52747cdd1e firefox-17.0.8-1.el5.centos.src.rpm
fc50bc7a0edb0a5b3eb7667d81230d29df6b3bd4e7707888d23dc2dbc5986569 xulrunner-17.0.8-3.el5_9.src.rpm
--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[USN-1925-1] Thunderbird vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/
iQEcBAEBAgAGBQJSAi3SAAoJEGEfvezVlG4PD3oIAJuFNO2rzSYLFnq/rV7sHYF0
J0ScxWJtkwelwmncRd+oQSHvRaWiXIPRvef3X0kB2tkeFAKqPzMz824pwLG1sC0p
u6AJBqkqrZN7JrQ5FeKgcqfhBRNNZCcnC8xT3eBZMCakFb+RW1Z+nhSUxwHB21VS
s060I4jBczan5UN9GVQG9ay0wibMO3olUvwkUnOUB1epcf/ub9K3YO+BRShJ/LXs
7chmCYHjqDwW1XMcq8Hrs3eHok0a4Qh4zU7M3RY1B4hnftdBYYJHx2V2gOQzaAqt
q1mXJR071Xg2VgDCaMezmgKg/uRDYRPQuiUwTvjPiwh8UfsxmizanzZKke4+JWA=
=Nnu8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1925-1
August 07, 2013
thunderbird vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Jeff Gilbert and Henrik Skupin discovered multiple memory safety issues
in Thunderbird. If the user were tricked in to opening a specially crafted
message with scripting enabled, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2013-1701)
It was discovered that a document's URI could be set to the URI of
a different document. If a user had scripting enabled, an attacker
could potentially exploit this to conduct cross-site scripting (XSS)
attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. If a user had scripting enabled, an attacker could
potentially exploit this to conduct cross-site scripting (XSS) attacks,
or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2013-1710)
Cody Crews discovered that some Javascript components performed security
checks against the wrong URI, potentially bypassing same-origin policy
restrictions. If a user had scripting enabled, an attacker could exploit
this to conduct cross-site scripting (XSS) attacks or install addons
from a malicious site. (CVE-2013-1713)
Federico Lanusse discovered that web workers could bypass cross-origin
checks when using XMLHttpRequest. If a user had scripting enabled, an
attacker could potentially exploit this to conduct cross-site scripting
(XSS) attacks. (CVE-2013-1714)
Georgi Guninski and John Schoenick discovered that Java applets could
access local files under certain circumstances. If a user had scripting
enabled, an attacker could potentially exploit this to steal confidential
data. (CVE-2013-1717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
thunderbird 17.0.8+build1-0ubuntu0.13.04.1
Ubuntu 12.10:
thunderbird 17.0.8+build1-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
thunderbird 17.0.8+build1-0ubuntu0.12.04.1
After a standard system update you need to restart Thunderbird to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1925-1
CVE-2013-1701, CVE-2013-1709, CVE-2013-1710, CVE-2013-1713,
CVE-2013-1714, CVE-2013-1717, https://launchpad.net/bugs/1208041
Package Information:
https://launchpad.net/ubuntu/+source/thunderbird/17.0.8+build1-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/thunderbird/17.0.8+build1-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/thunderbird/17.0.8+build1-0ubuntu0.12.04.1
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/
iQEcBAEBAgAGBQJSAi3SAAoJEGEfvezVlG4PD3oIAJuFNO2rzSYLFnq/rV7sHYF0
J0ScxWJtkwelwmncRd+oQSHvRaWiXIPRvef3X0kB2tkeFAKqPzMz824pwLG1sC0p
u6AJBqkqrZN7JrQ5FeKgcqfhBRNNZCcnC8xT3eBZMCakFb+RW1Z+nhSUxwHB21VS
s060I4jBczan5UN9GVQG9ay0wibMO3olUvwkUnOUB1epcf/ub9K3YO+BRShJ/LXs
7chmCYHjqDwW1XMcq8Hrs3eHok0a4Qh4zU7M3RY1B4hnftdBYYJHx2V2gOQzaAqt
q1mXJR071Xg2VgDCaMezmgKg/uRDYRPQuiUwTvjPiwh8UfsxmizanzZKke4+JWA=
=Nnu8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1925-1
August 07, 2013
thunderbird vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in Thunderbird.
Software Description:
- thunderbird: Mozilla Open Source mail and newsgroup client
Details:
Jeff Gilbert and Henrik Skupin discovered multiple memory safety issues
in Thunderbird. If the user were tricked in to opening a specially crafted
message with scripting enabled, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Thunderbird.
(CVE-2013-1701)
It was discovered that a document's URI could be set to the URI of
a different document. If a user had scripting enabled, an attacker
could potentially exploit this to conduct cross-site scripting (XSS)
attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. If a user had scripting enabled, an attacker could
potentially exploit this to conduct cross-site scripting (XSS) attacks,
or execute arbitrary code with the privileges of the user invoking
Thunderbird. (CVE-2013-1710)
Cody Crews discovered that some Javascript components performed security
checks against the wrong URI, potentially bypassing same-origin policy
restrictions. If a user had scripting enabled, an attacker could exploit
this to conduct cross-site scripting (XSS) attacks or install addons
from a malicious site. (CVE-2013-1713)
Federico Lanusse discovered that web workers could bypass cross-origin
checks when using XMLHttpRequest. If a user had scripting enabled, an
attacker could potentially exploit this to conduct cross-site scripting
(XSS) attacks. (CVE-2013-1714)
Georgi Guninski and John Schoenick discovered that Java applets could
access local files under certain circumstances. If a user had scripting
enabled, an attacker could potentially exploit this to steal confidential
data. (CVE-2013-1717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
thunderbird 17.0.8+build1-0ubuntu0.13.04.1
Ubuntu 12.10:
thunderbird 17.0.8+build1-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
thunderbird 17.0.8+build1-0ubuntu0.12.04.1
After a standard system update you need to restart Thunderbird to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1925-1
CVE-2013-1701, CVE-2013-1709, CVE-2013-1710, CVE-2013-1713,
CVE-2013-1714, CVE-2013-1717, https://launchpad.net/bugs/1208041
Package Information:
https://launchpad.net/ubuntu/+source/thunderbird/17.0.8+build1-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/thunderbird/17.0.8+build1-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/thunderbird/17.0.8+build1-0ubuntu0.12.04.1
Tuesday, August 6, 2013
[USN-1924-2] Ubufox and Unity Firefox Extension update
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/
iQEcBAEBAgAGBQJSAVQQAAoJEGEfvezVlG4P1aoIAJyBNLbDjOtEvTWNf3byx8kw
3D/H91GSeQFjVoapx8nmk1gHUVaxn+5jLqeA36kGgm8tX3YwdwWwcSCufr8Wxazh
SVNSsC4py0xOue7PirrGGnqE4pd1auHNBJkp9SyGhwfh39LuWDl3jNqUmr8rKDrJ
oIaWZr36VaY/KqptJvBhKsazuxMBO26gEKCllm8YMbrL/OO9VpKy/pgWrFb8xZF+
Vn6DPaVpO+MqneE5UetPlhnbgWf/SugVECfJTg/rWhbCT/e73hO0gtMOm3lLxrqT
dEHtNxzQT1bDa4H+6hJymVyR0OtkXyEiNmbO8WkEpRu0yQj9drwoH0tgm/+MliE=
=RSNt
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1924-2
August 06, 2013
ubufox, unity-firefox-extension update
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
This update provides compatible packages for Firefox 23.
Software Description:
- ubufox: Ubuntu Firefox specific configuration defaults and apt support
- unity-firefox-extension: Unity Integration for Firefox
Details:
USN-1924-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubufox and Unity Firefox Extension.
Original advisory details:
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
SetBody mutation event. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1704)
A use-after-free bug was discovered when generating a CRMF request with
certain parameters. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1705)
Aki Helin discovered a crash when decoding a WAV file in some
circumstances. An attacker could potentially exploit this to cause a
denial of service. (CVE-2013-1708)
It was discovered that a document's URI could be set to the URI of
a different document. An attacker could potentially exploit this to
conduct cross-site scripting (XSS) attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. An attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2013-1710)
Bobby Holley discovered that XBL scopes could be used to circumvent
XrayWrappers in certain circumstances. An attacked could potentially
exploit this to conduct cross-site scripting (XSS) attacks or cause
undefined behaviour. (CVE-2013-1711)
Cody Crews discovered that some Javascript components performed security
checks against the wrong URI, potentially bypassing same-origin policy
restrictions. An attacker could exploit this to conduct cross-site
scripting (XSS) attacks or install addons from a malicious site.
(CVE-2013-1713)
Federico Lanusse discovered that web workers could bypass cross-origin
checks when using XMLHttpRequest. An attacker could potentially exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2013-1714)
Georgi Guninski and John Schoenick discovered that Java applets could
access local files under certain circumstances. An attacker could
potentially exploit this to steal confidential data. (CVE-2013-1717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
xul-ext-ubufox 2.7-0ubuntu0.13.04.1
Ubuntu 12.10:
xul-ext-ubufox 2.7-0ubuntu0.12.10.1
xul-ext-unity 2.4.7-0ubuntu0.2
Ubuntu 12.04 LTS:
xul-ext-ubufox 2.7-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1924-2
http://www.ubuntu.com/usn/usn-1924-1
https://launchpad.net/bugs/1208039
Package Information:
https://launchpad.net/ubuntu/+source/ubufox/2.7-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/ubufox/2.7-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/unity-firefox-extension/2.4.7-0ubuntu0.2
https://launchpad.net/ubuntu/+source/ubufox/2.7-0ubuntu0.12.04.1
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/
iQEcBAEBAgAGBQJSAVQQAAoJEGEfvezVlG4P1aoIAJyBNLbDjOtEvTWNf3byx8kw
3D/H91GSeQFjVoapx8nmk1gHUVaxn+5jLqeA36kGgm8tX3YwdwWwcSCufr8Wxazh
SVNSsC4py0xOue7PirrGGnqE4pd1auHNBJkp9SyGhwfh39LuWDl3jNqUmr8rKDrJ
oIaWZr36VaY/KqptJvBhKsazuxMBO26gEKCllm8YMbrL/OO9VpKy/pgWrFb8xZF+
Vn6DPaVpO+MqneE5UetPlhnbgWf/SugVECfJTg/rWhbCT/e73hO0gtMOm3lLxrqT
dEHtNxzQT1bDa4H+6hJymVyR0OtkXyEiNmbO8WkEpRu0yQj9drwoH0tgm/+MliE=
=RSNt
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1924-2
August 06, 2013
ubufox, unity-firefox-extension update
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
This update provides compatible packages for Firefox 23.
Software Description:
- ubufox: Ubuntu Firefox specific configuration defaults and apt support
- unity-firefox-extension: Unity Integration for Firefox
Details:
USN-1924-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubufox and Unity Firefox Extension.
Original advisory details:
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
SetBody mutation event. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1704)
A use-after-free bug was discovered when generating a CRMF request with
certain parameters. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1705)
Aki Helin discovered a crash when decoding a WAV file in some
circumstances. An attacker could potentially exploit this to cause a
denial of service. (CVE-2013-1708)
It was discovered that a document's URI could be set to the URI of
a different document. An attacker could potentially exploit this to
conduct cross-site scripting (XSS) attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. An attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2013-1710)
Bobby Holley discovered that XBL scopes could be used to circumvent
XrayWrappers in certain circumstances. An attacked could potentially
exploit this to conduct cross-site scripting (XSS) attacks or cause
undefined behaviour. (CVE-2013-1711)
Cody Crews discovered that some Javascript components performed security
checks against the wrong URI, potentially bypassing same-origin policy
restrictions. An attacker could exploit this to conduct cross-site
scripting (XSS) attacks or install addons from a malicious site.
(CVE-2013-1713)
Federico Lanusse discovered that web workers could bypass cross-origin
checks when using XMLHttpRequest. An attacker could potentially exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2013-1714)
Georgi Guninski and John Schoenick discovered that Java applets could
access local files under certain circumstances. An attacker could
potentially exploit this to steal confidential data. (CVE-2013-1717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
xul-ext-ubufox 2.7-0ubuntu0.13.04.1
Ubuntu 12.10:
xul-ext-ubufox 2.7-0ubuntu0.12.10.1
xul-ext-unity 2.4.7-0ubuntu0.2
Ubuntu 12.04 LTS:
xul-ext-ubufox 2.7-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1924-2
http://www.ubuntu.com/usn/usn-1924-1
https://launchpad.net/bugs/1208039
Package Information:
https://launchpad.net/ubuntu/+source/ubufox/2.7-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/ubufox/2.7-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/unity-firefox-extension/2.4.7-0ubuntu0.2
https://launchpad.net/ubuntu/+source/ubufox/2.7-0ubuntu0.12.04.1
[USN-1924-1] Firefox vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/
iQEcBAEBAgAGBQJSAVOqAAoJEGEfvezVlG4PCKAIAKSFlv1deGTUHuE3HNzgwACD
qxVtzdAAyxYAb01rCalMvzIGDGkhQ/OWZFLu4f4SgyZnfkHiZAeDUClw9aw1sFhL
NernjOdeg/E/UBZQfT+M1oCrj2TsRHCpFtoRb9YKl/kVp7H6bUaFslISbVn7yy9b
E+zJc+kp7Un+2FIrvWwz5yrZ/SCrVd0AwTDHhLqnEScoUlNNgojqlbIav/ukTOvm
asMWDsakVPnHynnSdFW0g2qw5ksC+hLwIN8IFPNZi9HpdRcbVACYAk63unBorO40
WZLbfeumwqcwDbf4MeAb0IuDjkWXWrSlrZUzfe/zfRYuhW2vieD25nb9Ma+SrKY=
=pqLb
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1924-1
August 06, 2013
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
SetBody mutation event. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1704)
A use-after-free bug was discovered when generating a CRMF request with
certain parameters. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1705)
Aki Helin discovered a crash when decoding a WAV file in some
circumstances. An attacker could potentially exploit this to cause a
denial of service. (CVE-2013-1708)
It was discovered that a document's URI could be set to the URI of
a different document. An attacker could potentially exploit this to
conduct cross-site scripting (XSS) attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. An attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2013-1710)
Bobby Holley discovered that XBL scopes could be used to circumvent
XrayWrappers in certain circumstances. An attacked could potentially
exploit this to conduct cross-site scripting (XSS) attacks or cause
undefined behaviour. (CVE-2013-1711)
Cody Crews discovered that some Javascript components performed security
checks against the wrong URI, potentially bypassing same-origin policy
restrictions. An attacker could exploit this to conduct cross-site
scripting (XSS) attacks or install addons from a malicious site.
(CVE-2013-1713)
Federico Lanusse discovered that web workers could bypass cross-origin
checks when using XMLHttpRequest. An attacker could potentially exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2013-1714)
Georgi Guninski and John Schoenick discovered that Java applets could
access local files under certain circumstances. An attacker could
potentially exploit this to steal confidential data. (CVE-2013-1717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
firefox 23.0+build2-0ubuntu0.13.04.1
Ubuntu 12.10:
firefox 23.0+build2-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
firefox 23.0+build2-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1924-1
CVE-2013-1701, CVE-2013-1702, CVE-2013-1704, CVE-2013-1705,
CVE-2013-1708, CVE-2013-1709, CVE-2013-1710, CVE-2013-1711,
CVE-2013-1713, CVE-2013-1714, CVE-2013-1717, https://launchpad.net/bugs/1208039
Package Information:
https://launchpad.net/ubuntu/+source/firefox/23.0+build2-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/firefox/23.0+build2-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/firefox/23.0+build2-0ubuntu0.12.04.1
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Thunderbird-Trunk - http://www.enigmail.net/
iQEcBAEBAgAGBQJSAVOqAAoJEGEfvezVlG4PCKAIAKSFlv1deGTUHuE3HNzgwACD
qxVtzdAAyxYAb01rCalMvzIGDGkhQ/OWZFLu4f4SgyZnfkHiZAeDUClw9aw1sFhL
NernjOdeg/E/UBZQfT+M1oCrj2TsRHCpFtoRb9YKl/kVp7H6bUaFslISbVn7yy9b
E+zJc+kp7Un+2FIrvWwz5yrZ/SCrVd0AwTDHhLqnEScoUlNNgojqlbIav/ukTOvm
asMWDsakVPnHynnSdFW0g2qw5ksC+hLwIN8IFPNZi9HpdRcbVACYAk63unBorO40
WZLbfeumwqcwDbf4MeAb0IuDjkWXWrSlrZUzfe/zfRYuhW2vieD25nb9Ma+SrKY=
=pqLb
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1924-1
August 06, 2013
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Jeff Gilbert, Henrik Skupin, Ben Turner, Christian Holler,
Andrew McCreight, Gary Kwong, Jan Varga and Jesse Ruderman discovered
multiple memory safety issues in Firefox. If the user were tricked in to
opening a specially crafted page, an attacker could possibly exploit these
to cause a denial of service via application crash, or potentially execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1701, CVE-2013-1702)
A use-after-free bug was discovered when the DOM is modified during a
SetBody mutation event. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1704)
A use-after-free bug was discovered when generating a CRMF request with
certain parameters. If the user were tricked in to opening a specially
crafted page, an attacker could potentially exploit this to execute
arbitrary code with the privileges of the user invoking Firefox.
(CVE-2013-1705)
Aki Helin discovered a crash when decoding a WAV file in some
circumstances. An attacker could potentially exploit this to cause a
denial of service. (CVE-2013-1708)
It was discovered that a document's URI could be set to the URI of
a different document. An attacker could potentially exploit this to
conduct cross-site scripting (XSS) attacks. (CVE-2013-1709)
A flaw was discovered when generating a CRMF request in certain
circumstances. An attacker could potentially exploit this to conduct
cross-site scripting (XSS) attacks, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2013-1710)
Bobby Holley discovered that XBL scopes could be used to circumvent
XrayWrappers in certain circumstances. An attacked could potentially
exploit this to conduct cross-site scripting (XSS) attacks or cause
undefined behaviour. (CVE-2013-1711)
Cody Crews discovered that some Javascript components performed security
checks against the wrong URI, potentially bypassing same-origin policy
restrictions. An attacker could exploit this to conduct cross-site
scripting (XSS) attacks or install addons from a malicious site.
(CVE-2013-1713)
Federico Lanusse discovered that web workers could bypass cross-origin
checks when using XMLHttpRequest. An attacker could potentially exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2013-1714)
Georgi Guninski and John Schoenick discovered that Java applets could
access local files under certain circumstances. An attacker could
potentially exploit this to steal confidential data. (CVE-2013-1717)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.04:
firefox 23.0+build2-0ubuntu0.13.04.1
Ubuntu 12.10:
firefox 23.0+build2-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
firefox 23.0+build2-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-1924-1
CVE-2013-1701, CVE-2013-1702, CVE-2013-1704, CVE-2013-1705,
CVE-2013-1708, CVE-2013-1709, CVE-2013-1710, CVE-2013-1711,
CVE-2013-1713, CVE-2013-1714, CVE-2013-1717, https://launchpad.net/bugs/1208039
Package Information:
https://launchpad.net/ubuntu/+source/firefox/23.0+build2-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/firefox/23.0+build2-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/firefox/23.0+build2-0ubuntu0.12.04.1
Subscribe to:
Posts (Atom)