Thursday, October 3, 2013

vBSDcon Is Coming: Oct 25 - 27, 2013 in Herndon, VA

vBSDcon is a BSD-related conference occurring *this month* from 25th =96 27=
th, just 3 weeks away in the DC Metropolitan area. At a cost of only USD$7=
5, the time to register for this event is now! vBSDcon has an amazing list=
of speakers from the FreeBSD and OpenBSD communities, but participation fr=
om all sectors of the community is encouraged. Our list of speakers and th=
eir respective topics can be reviewed at http://www.vbsdcon.com<http://www.=
vbsdcon.com/>/.

In addition to plenary speakers, vBSDcon will also have lightning talks. T=
he topics for these talks is chosen by you! When attendees register for vB=
SDcon at http://www.vbsdcon.com<http://www.vbsdcon.com/>/, you are given th=
e opportunity to identify subjects and areas of interest to you. This will=
be translated into a lightning talk to be given by one of our attendees.

Be sure not to miss this event hosted by Verisign! This is your opportunit=
y to come together with others in the BSD communities for a series of round=
table discussions, educational sessions, best practice conversations, and e=
xclusive networking opportunities.

Registrations will be accepted now through October 23rd at http://www.vbsdc=
on.com<http://www.vbsdcon.com/>/. We look forward to seeing you all there!

--
Vincent (Rick) Miller
Systems Engineer
vmiller@verisign.com

t: 703-948-4395 m: 703-581-3068
12061 Bluemont Way, Reston, VA 20190

http://www.vbsdcon.com
http://www.verisigninc.com

[FreeBSD-Announce] vBSDcon Is Coming: Oct 25 - 27, 2013 in Herndon, VA

vBSDcon is a BSD-related conference occurring *this month* from 25th – 27th, just 3 weeks away in the DC Metropolitan area. At a cost of only USD$75, the time to register for this event is now! vBSDcon has an amazing list of speakers from the FreeBSD and OpenBSD communities, but participation from all sectors of the community is encouraged. Our list of speakers and their respective topics can be reviewed at http://www.vbsdcon.com/.

In addition to plenary speakers, vBSDcon will also have lightning talks. The topics for these talks is chosen by you! When attendees register for vBSDcon at http://www.vbsdcon.com/, you are given the opportunity to identify subjects and areas of interest to you. This will be translated into a lightning talk to be given by one of our attendees.

Be sure not to miss this event hosted by Verisign! This is your opportunity to come together with others in the BSD communities for a series of roundtable discussions, educational sessions, best practice conversations, and exclusive networking opportunities.

Registrations will be accepted now through October 23rd at http://www.vbsdcon.com/. We look forward to seeing you all there!

--
Vincent (Rick) Miller
Systems Engineer
vmiller@verisign.com<mailto:vmiller@verisign.com>

t: 703-948-4395 m: 703-581-3068
12061 Bluemont Way, Reston, VA 20190

http://www.vbsdcon.com
http://www.verisigninc.com

"This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed, and may contain information that is non-public, proprietary, privileged, confidential and exempt from disclosure under applicable law or may be constituted as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this message in error, notify sender immediately and delete this message immediately."
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

Wednesday, October 2, 2013

[CentOS-announce] CEBA-2013:1401 CentOS 6 qemu-kvm Update

CentOS Errata and Bugfix Advisory 2013:1401

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1401.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
9a5d53661265a21e2c01437bfa501c89a97931b5d9d204f85e9ac9a237f90123 qemu-guest-agent-0.12.1.2-2.355.0.1.el6_4.9.i686.rpm

x86_64:
d7bba07262272b8d1ba80430c0aed94c66689ad2f0bc204c0d4db73d9212a28c qemu-guest-agent-0.12.1.2-2.355.0.1.el6_4.9.x86_64.rpm
927ca6ac3edc771921ac09980347a42e5fbcd1da932014a0997e0dfee0ee2104 qemu-guest-agent-win32-0.12.1.2-2.355.0.1.el6_4.9.x86_64.rpm
a40f87712412f4b6b4483f11fe8c7dbb301f1888b4d62ad172cae0b6d4ee6b28 qemu-img-0.12.1.2-2.355.0.1.el6_4.9.x86_64.rpm
031c4b40e2003851a7b062efb555382835d59a54659b396b68a4736ccd6d19b8 qemu-kvm-0.12.1.2-2.355.0.1.el6_4.9.x86_64.rpm
e8d64b86e9ae7564ae68149c8f4e9d927f1987fb816f46d9cd8caea2be2a8549 qemu-kvm-tools-0.12.1.2-2.355.0.1.el6_4.9.x86_64.rpm

Source:
5f7e087dee9073fb16ee6d3b49f6902c487d01665471ab0bfe70948d650f5449 qemu-kvm-0.12.1.2-2.355.0.1.el6_4.9.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEBA-2013:1400 CentOS 6 setup Update

CentOS Errata and Bugfix Advisory 2013:1400

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1400.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
f3baabe199eabf0c11866c1c076f0c6bc01abe0c1cab20aa3348cd8e1c967031 setup-2.8.14-20.el6_4.1.noarch.rpm

x86_64:
f3baabe199eabf0c11866c1c076f0c6bc01abe0c1cab20aa3348cd8e1c967031 setup-2.8.14-20.el6_4.1.noarch.rpm

Source:
6cd2835e633e6af4c072f1e444dc150aa91cb96bf92c1ca84321e2bed2b54377 setup-2.8.14-20.el6_4.1.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[announce] NYC*BUG Tonight

A reminder about tonight's meeting. Also, we have a box of books from
Prentice Hall to distribute.

****

Year after Sandy, Boris Kochergin
Wednesday, October 2
6:45 PM
Suspenders Bar and Restaurant
111 Broadway, Manhattan

Abstract

In October 2012, New York City was befallen by perhaps the worst natural
disaster in its history. This meeting will consist of a first-hand
account of how, situated at the heart of the crippled financial
district, with no working infrastructure for miles around, New York
Internet operated throughout the storm and its aftermath.
Media

Speaker Bio

Boris Kochergin is currently a system administrator and programmer at
New York Internet. He was a network and system administrator at
NYU-Poly`s business incubator at 160 Varick Street (consulting), network
and system administrator at EmPower Solar (consulting), network and
system administrator at Ecological, LLC (consulting), and programmer for
the Long Island Solar Energy Industries Association (consulting).
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

Tuesday, October 1, 2013

[CentOS-announce] CEBA-2013:1396 CentOS 6 squid Update

CentOS Errata and Bugfix Advisory 2013:1396

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1396.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
c20a1e3c185ef5e76780326ed2961bbd39a50bbf499c9698e1b5d5cf4c81c480 squid-3.1.10-19.el6_4.i686.rpm

x86_64:
c2278f1d2b2d6d39a88a002c06db5dbd5fc2d95208aa2b8dc89cc7bfc63a9a6c squid-3.1.10-19.el6_4.x86_64.rpm

Source:
e124af48589c41b2cac464897581450dcf51c0fbcacd19545a0195e83ad053db squid-3.1.10-19.el6_4.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[USN-1986-1] Network Audio System (NAS) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSSwlHAAoJEGVp2FWnRL6TvpcP/2VNa7w7HM/qbbXCJpxWkkjT
RNwGJDu8VwS6ahNrivp7Wn9GHFoXYVTVp+6NywGwqiNUvZLNgfSxsQeUihhVZeR9
tQGD2kv/jAWrvX1BPtHJl7ATQHiYLv9Wp/xBnRGXzlqVymMLq1Hc8OVvFKvNRQh8
D/t5gJNCHq3bU5ENHUasMgPDptkzKvO+6TQ3bBdYFOYR5GKiSzV7qvX9NU4doRPI
bF8wEEx9J2i8JhWUlhRgNgzIrDmmT4/KxtdelE038O0A3iAeh+lhzprZlX5mE2ax
JpF9DTBp9jho3Eu0KOK/0W9swsbPSVDVBdEMQhjvBcQH+Gg6iaNBWTUi3+SkY4s0
jViPQUFhM/Mg513S3QPVf+IWHIvp4Tdp3ZW/pNeejmWEof9ZL1SaJy+nD4Vv0RLe
x8iy587QMMFJuz1c5OYDCaOvF54mIqe53g18fL4CMb3GznxNRP7CIlpIjPyQLdTk
vKtTe9w3ckWZqdfCq75KceuoiG3minYrk+mUNs1cO4V8tj77WxYtlYrZ32F8qLcQ
DLRi4n7GHhiiyc6+jlhmXgBqFVfvQWyK+1mgeZR52hqNpUJ5LK9bSY0mX/ABETMo
1NeNHu6k24EH3UZ/EDvFcrlX/Di1S45yhBQ0fSOBBI3i71AvpfDm4BmZxk9bMXWO
CxmglghLoB+9tedzdk8z
=FRmT
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1986-1
October 01, 2013

nas vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Network Audio System (NAS).

Software Description:
- nas: Network Audio System

Details:

Hamid Zamani discovered multiple security issues in the Network Audio
System (NAS) server. An attacker could possibly use these issues to cause a
denial of service or execute arbitrary code. (CVE-2013-4256, CVE-2013-4257)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
nas 1.9.3-5ubuntu0.13.04.1

Ubuntu 12.10:
nas 1.9.3-5ubuntu0.12.10.1

Ubuntu 12.04 LTS:
nas 1.9.3-4ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1986-1
CVE-2013-4256, CVE-2013-4257

Package Information:
https://launchpad.net/ubuntu/+source/nas/1.9.3-5ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/nas/1.9.3-5ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/nas/1.9.3-4ubuntu0.1

[USN-1985-1] Python 3.3 vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSSu1oAAoJEGVp2FWnRL6TlCMP/A2C8rQO9Qy3/KpkLP2gmbeA
fFN9Cho7H0/mh5AM/hdz5DOzd/mwus4Rw+d/ATEu5Jf/eJiggH4leruRIACI35jR
FRDUvz5aNyxGzrGipiAVVIOMZMT53+wRVJwaO6VsZKYWdVcuG3YIrX7Nv3NgJy3G
a6A7vErE/N5HNZWs4nrcjQXH8b4fR0X5icUTDQHWk/06LPgzxRMjc/EaTO14PNOF
gJL/E4z1PPfrUPZ35KMzDA/tcu/nf/p3R0kguJS9Bn54YcEslTNFi58KP9ybUxgg
qWqZ2diSiwGQGienxnk1Hj3z2m5h3VDbFT+25RpHRS8EjNqwm4l4sSIfLCiEn6iP
m/54mLMPyUIlZJOrCOP2DQR3PlQ4tBqkKTkl2Y8TJtUTSOY6TS+2dp8KtlZY2oty
z0q+PatOnOXjZcHLlpWDw/zuwW/Xksgu5kU7G6lSly5r3gHwSphZ42yFIazX10L2
QDwxLKNx2/96KYX0jHKuKxjcXLpMz2KS83PwJO+HgUzhJYfHm9YAH6GXQ6Hijt3n
Vx1V64Yg6y1NTdpchdH6yOmOfKKbSOyiOA5vrgb9we7JeFtAbzGP+BTyfdc4rgRJ
FJRB5907XIsBW2irTtRaMzjaXgJ7jnIOFUjy3tgXWw4+wRcu1ZZIb/Jn0VsYiQYg
NholAivWFmRjNMVksIkm
=z2cZ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1985-1
October 01, 2013

python3.3 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10

Summary:

Several security issues were fixed in Python.

Software Description:
- python3.3: An interactive high-level object-oriented language

Details:

Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service.
(CVE-2013-2099)

Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a man in the middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python3.3 3.3.1-1ubuntu5.2
python3.3-minimal 3.3.1-1ubuntu5.2

Ubuntu 12.10:
python3.3 3.3.0-1ubuntu0.1
python3.3-minimal 3.3.0-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1985-1
CVE-2013-2099, CVE-2013-4238

Package Information:
https://launchpad.net/ubuntu/+source/python3.3/3.3.1-1ubuntu5.2
https://launchpad.net/ubuntu/+source/python3.3/3.3.0-1ubuntu0.1

[USN-1983-1] Python 2.7 vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSSulVAAoJEGVp2FWnRL6TA1MQAJhLak6+KtdKItVVJQWNmh4t
fxdL4q/BhMWwXHKG+RBmHjgW42K0Dd9AF3xPlnvOeBb8KPJxjMtoSxkcFxq0bBGw
zXIyZUIcL0LocdNm37ncWktlekzFDCK8GJDEmn4JU6X1QjFmsd1MEbHWCMhi79+N
eUem3Z1T8tb4MvIwqmiZc9UdBo9pdVcr8mitEwKXNKBvkiDnGV6PkHGAYO9DB3w4
OIe9zX7eWvZ1m1x2rK4+PDR5JgyIH7dD+KalwSfxwvm9mf1rLEKNEi77buG0vZwW
+9AI3oipcRcbZ5vbXq8uvjM9CKo3H59YUDaqSzE7aPyle1EeprUrDIzJX9pIgPal
4FnGsXbOG4MbwmcTAoNil1n2mGPJXhbwo9/0xt5gbsCgEFVyi8ECktifQoiPT7pl
jnELP0rJP9DRWCDPL/8AsfZbjvCkrk7XPAU5NMpCQYXqqwIIf6gHgCi35PID3jsy
Klc8ch7u6VEkxaxfheQNt+DSGVwKi33YvA9Ij3OAb9fGoOj9D8hxg71e91aqBSaf
uI/MtiPII0X+7aBYQi0EinTWlPgOmS+Q045h5ZMPP/7w1Fd+HWGodw14vo4NHl+y
JGk7yUXhKaK5HypAcKHVTOHVUid9gzWjWd+2w148qyWPgsyEOg9QHYOQ0RCVlCRR
CUxTOVMj5IO3mJqzyTu1
=wQIP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1983-1
October 01, 2013

python2.7 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Python.

Software Description:
- python2.7: An interactive high-level object-oriented language

Details:

Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service. This
issue only affected Ubuntu 13.04. (CVE-2013-2099)

Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a man in the middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python2.7 2.7.4-2ubuntu3.2
python2.7-minimal 2.7.4-2ubuntu3.2

Ubuntu 12.10:
python2.7 2.7.3-5ubuntu4.3
python2.7-minimal 2.7.3-5ubuntu4.3

Ubuntu 12.04 LTS:
python2.7 2.7.3-0ubuntu3.4
python2.7-minimal 2.7.3-0ubuntu3.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1983-1
CVE-2013-2099, CVE-2013-4238

Package Information:
https://launchpad.net/ubuntu/+source/python2.7/2.7.4-2ubuntu3.2
https://launchpad.net/ubuntu/+source/python2.7/2.7.3-5ubuntu4.3
https://launchpad.net/ubuntu/+source/python2.7/2.7.3-0ubuntu3.4

[USN-1984-1] Python 3.2 vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSSulmAAoJEGVp2FWnRL6Txb0QAIS9CnuLnsk/Qof07zE7Vxfi
4WF23FrFS5Ypo0D1gnSRDWpkKHnLkdgp6lgMmdTlo1neidMSKjT6tNPv/LY1ibnl
8fb80eLcjDqzEIeJUWcTBXK98d2tsjllPGWdh/tmYgkdxhvGb7T2lwtaOM0BnRgJ
PbYnm//rukrjHq/Vm2mobDhNI2Ed+fbdfcVbG2qc1Ltg1F7Rz/AcXR9TTToKyv3D
t7jDH4JiW8hJ+k+PargSsyzpDBAAtWkH8zezxtQH9z/Ln/Fk9MsHpPwW5xx/HG22
XbMabybfQvG1f8YDmmsFYUblRYSybwVfaLZ1UL+YAIpYgu2/gcF+yk2VWgw8aKce
3ivEsXjCGd7b0Q3h76hC77Ay5OuYAVF6jF/1bjQRPcKU90jRtn6NqA+ZRJ6BaYNX
HOlQhWXm22paB/5eoCMNklGd/ofjyyzIwtSIsq77EICYO+2kZSWTNiUyHufF+EHY
5ndXSHOKLipdrczLJoRL0mATEQft6jENZXw2nHPYnoA03VzNK9VVbDHZlO+vCPwv
NgHYPWyFNGQUi5RlggzpI5+awpGfNlslmgJ0/Vy8udeiHxGLnGbRBjHmkCFKy3+8
yy915qBXngcJSUKR2k42UJw6MyP/x4VWeYhEM0Fbsqo+F7YFIrRlT0OtDYqykAi1
97yymXSyy+TbXN6Sjh+9
=sASB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1984-1
October 01, 2013

python3.2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Python.

Software Description:
- python3.2: An interactive high-level object-oriented language

Details:

Florian Weimer discovered that Python incorrectly handled matching multiple
wildcards in ssl certificate hostnames. An attacker could exploit this to
cause Python to consume resources, resulting in a denial of service.
(CVE-2013-2099)

Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a man in the middle attack to view sensitive
information or alter encrypted communications. (CVE-2013-4238)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
python3.2 3.2.3-6ubuntu3.4
python3.2-minimal 3.2.3-6ubuntu3.4

Ubuntu 12.04 LTS:
python3.2 3.2.3-0ubuntu3.5
python3.2-minimal 3.2.3-0ubuntu3.5

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1984-1
CVE-2013-2099, CVE-2013-4238

Package Information:
https://launchpad.net/ubuntu/+source/python3.2/3.2.3-6ubuntu3.4
https://launchpad.net/ubuntu/+source/python3.2/3.2.3-0ubuntu3.5

[USN-1982-1] Python 2.6 vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSSulBAAoJEGVp2FWnRL6TEcEQAJwOdxkG/5z4F6fvoK+p9QiK
gA7io5P8hXD+L7C4taXrjBorCTeXwraX7bQ6pn2+3rl5A0oNYypHjfVoABBt4b/t
bF1EaqiV9XefTQl0Ku7O21lkGW+ocZOesDfSUVMhDZWUQGMbszsx0OePS4XjICUq
tJzGn95wCLP2MfRjJlQwjWQ6ljuCD52FXeelCBoUAg8mXKzdwWp2niUlt4hpuxvg
86fUwsYgytktQT7OanhQ9QMmz3WqNk7yuF7/J5GeFbwh2iMoDxve3XYZ+JLr4rGb
GsiMnKTdVRzKb/7SNQ0oCu5XZ2qs600vSWfri/ZPLMLo3B7psWepifOD1jn4glmw
C6ATYxx6Pm+gx3JIKYiOay14K7vU25rBGtQpjZ6c0NQsY0TLoavSBhNZcqzZsnBm
n4ACAmR4+ZzW1+MFkQ/awHikORcJ7nl6LNAj8Rwmyi5xMkjF8dwtJTp23HVBxzTW
olmxkXm7OkdepUL7Wa6jLblztala8blxznSk+H8/NyhSh0i5g6mut7CGXRS1X/qm
4RATdBkREB5/u77I8XAOYXL8/uW3cmvhx+KB2sSO61rFM5UdiNbX9mnCVZ/hVo7G
JqLcLvN5GtSoTXigZ/eTGLcO9GhW3rz2f6hK6LhbPqgic18NhQR1tmP98ha69jFz
Ak9f40wNBbLbPU5QByfZ
=D28J
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1982-1
October 01, 2013

python2.6 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Fraudulent security certificates could allow sensitive information to
be exposed when accessing the Internet.

Software Description:
- python2.6: An interactive high-level object-oriented language

Details:

Ryan Sleevi discovered that Python did not properly handle certificates
with NULL characters in the Subject Alternative Name field. An attacker
could exploit this to perform a man in the middle attack to view sensitive
information or alter encrypted communications.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
python2.6 2.6.5-1ubuntu6.2
python2.6-minimal 2.6.5-1ubuntu6.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1982-1
CVE-2013-4238

Package Information:
https://launchpad.net/ubuntu/+source/python2.6/2.6.5-1ubuntu6.2

Monday, September 30, 2013

[USN-1981-1] HPLIP vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSSchDAAoJEGVp2FWnRL6TNa0P/j7BOOkHNIHlQOeXnovqCveq
jOpcvUVsmxKD0MlgRPbUbSih9wlG3gRuZ9tgOhAWrh3zJHrB5sXn7u2ra90n4paY
NaF+dnNXGhDcvMSj/I5Y1Iu0Aqnf5LIK7+80jOXt2hKe7lygKvmsAcQZ8ogN0IYr
6UOSzWrsA6lGwyUxKG/boMlVto/u+tzfDSJGWdqIzj2PmUy16dxtJ5VaQX8biqLJ
lg9eRCzSeA4xqrWu8zRJLENDamwBD/HMWW97RVPkze9af/6uUxCQQzgbsxT6mUif
BMqxUeXVRh+Uxg9c/Dc13YuEbMxElvTnhHNr172lzftXYi0uIePTW+66sFZDS9P1
QLVwa2lQb+8QUEpvX+gedxTPC/mF2ssiagm5HwpXY6zmZW8X7mJKiVeQ+b4iMzrw
cvEblQ8VyWdkYA4iP0cwRAVtDDMjN8LlXwMtlLe+AEn6LxH4f7BfFlQzlwLYPdQY
UDZ9n1LoZK/QZmvwgEv3/fmLUsbh3hU4BTtiIJwgVUl4KrVCxYgcj3jPpHTQ4sTI
cWbU476SNmYi+Wa+aaWXte3505Uy/bn4h9xk7Obopn0omvDfYMv6QknKUxTTopCo
Rn45Fc/sNe2uLScglEg7xAZwTw4fJ10upzgG+38yL89tzAKemgOBpG7D4KIin68J
cBHrs71/sWOpNDYkykAK
=To6a
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1981-1
September 30, 2013

hplip vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

HPLIP could be made to overwrite files.

Software Description:
- hplip: HP Linux Printing and Imaging System (HPLIP)

Details:

It was discovered that HPLIP incorrectly handled temporary files when using
the fax capabilities. A local attacker could possibly use this issue to
overwrite arbitrary files. This issue only applied to Ubuntu 10.04 LTS.
(CVE-2011-2722)

Tim Waugh discovered that HPLIP incorrectly handled temporary files when
printing. A local attacker could possibly use this issue to overwrite
arbitrary files. In the default installation of Ubuntu 12.04 LTS and Ubuntu
12.10, this should be prevented by the Yama link restrictions.
(CVE-2013-0200)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
hplip 3.12.6-3ubuntu4.2

Ubuntu 12.04 LTS:
hplip 3.12.2-1ubuntu3.3

Ubuntu 10.04 LTS:
hplip 3.10.2-2ubuntu2.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1981-1
CVE-2011-2722, CVE-2013-0200

Package Information:
https://launchpad.net/ubuntu/+source/hplip/3.12.6-3ubuntu4.2
https://launchpad.net/ubuntu/+source/hplip/3.12.2-1ubuntu3.3
https://launchpad.net/ubuntu/+source/hplip/3.10.2-2ubuntu2.4