Tuesday, December 3, 2013

[USN-2043-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjfFAAoJEAUvNnAY1cPYNH0QAL29FHee4+jWxx4uW9c86nta
5LFFXli9dkkGe5KcoFpMdZct2OUj0s5A3DKznQQK8nBrcIE6sfCLIqY4dadlZeq7
HsA8z4MIvEJQ842KOwTD8x092rnWcENIK4xFFoz2eJXwLjbp2fyfo7Z60cYWFGRS
RWMqovG0/DEe1742in8DQ/nu5/rHbm+v2u07CCBCDVEi2bIBXHf5pJkN7iSNrgJp
hhgzDEZe4mhkIhhOpdlWhNlJDY1dr/D/2yprxhrFq6UUqlojPau5j4NELWfsqUT4
/BmdKn19b7CsMECAhQhM/mNIdriO3qtNkLZD45s2ithPrEc+cxIgtil9M9nZvfsx
CgqOhil2Xb0aQbCEafHK93hRYzKoT3dmSRJexeaY2HlDApQZXsR6bQvxJwUnrMY5
9YbhhwtA8RzeB/u8SlpCtKipu7aOdJiw19aWsOGoJ1/2jI+pe82dC5k3rMKM4so5
qm0tw69B4PadI1sKRlxOfSJ4cUNePg1gP+x2OFQqWo9UtOi26gXGAtPrzE3d0pDQ
m5mNi3FS1kOQ9YXu+T3OOgvSCZClOejJ1k4sR0tzt0MBSb6nzKv1c5F97bz5KCrm
1ufiLPJLzIhRPu5LQxT1deQ50pv3yJJCxdsAl4GLAd4akvyN7mAKzTi/dCF+wPs+
vDc7dBLUKOONfhv6jwdg
=5koZ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2043-1
December 03, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)

Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmenttation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
linux-image-3.5.0-44-generic 3.5.0-44.67
linux-image-3.5.0-44-highbank 3.5.0-44.67
linux-image-3.5.0-44-omap 3.5.0-44.67
linux-image-3.5.0-44-powerpc-smp 3.5.0-44.67
linux-image-3.5.0-44-powerpc64-smp 3.5.0-44.67

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2043-1
CVE-2013-4299, CVE-2013-4470

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.5.0-44.67

[USN-2042-1] Linux kernel (Saucy HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjelAAoJEAUvNnAY1cPYIx0QAJzLSd8eP6QPhlCPz7wmoRPE
kg/QgeBxfL3IIgKnqBER2AhTx1wQkOzMoWgWNUZcMVW1HZpgOga6aACbEkglK/Nc
KsiBedOvVyLI2cxI054PIwFtHxN0+IWWkuozfGjgadBQO8wLiiq6aNUV30Ldj2qF
msxuxtdJX2+cqnmTTpx2BaaHz9qzxLTFFAA0oZpfys2p1btns7Ut2pcMjSp2s5Jf
ceSkZNkq6pebnW5c6+98m8GKCbgWkOmFy+l8XhOf+h8gwCNYR5TuDdMTnMxk5TUF
lQNsZg3xW+YOCtIGktUE8sg30GtfEeR8dJ82nxLVknYjO9L4GR9bIWAeuXzWaj2w
vLQMAdemzUzeK/ySM5z+GOsdCoo3Z76QrYcIO694JaP44B0QwV8r4HM6+fZEfzfp
ueU1qWW585XNkEhe3yiqgN4tU/1RbqPDgnmLBFBf08t1OiTaKNlyEyVHW4WAHPFA
dzYoRUCFaPTHSzNMevbdHe1jTJwfbbYyV84NnOi2gu91BRjt7dL/rRNo+X3NRz+H
mGeoH9+pf5wQrgM60XfP4hQKLdJLle+zJQJiDPLPgDl6k4AH0BKAxqSBctSf5PC0
NenoOtY4nE0Nhz2JwrO4od9U/ok6hE/r0WvJfdzirQ+LCcDga5PZvff0RSIeBaQd
UPSB/WY+biNnYKVXJZNy
=SgfW
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2042-1
December 03, 2013

linux-lts-saucy vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-saucy: Linux hardware enablement kernel from Saucy

Details:

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)

Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmenttation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.11.0-14-generic 3.11.0-14.21~precise1
linux-image-3.11.0-14-generic-lpae 3.11.0-14.21~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2042-1
CVE-2013-4299, CVE-2013-4470

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-saucy/3.11.0-14.21~precise1

[USN-2041-1] Linux kernel (Raring HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjeBAAoJEAUvNnAY1cPYeRoQAKk1AkzMuHXl87900bzxCFmX
muHKEzc0TWwWa5udyS0+9+Z4qv3PTAZpb53qb6tzTs4bLxSpqV2gzQstgNL1VPiQ
TivJ/1YX8Uop/6BmSjom6iNEv4a2k76AUby33VHXs/XNXjnIkotMdduJG9YrKsn9
oL4e964MIy6tDZHLaP9QhHLzdmeDuc7e8fEJIjEBlZYem2xN8W9inIyxSUY0csRj
oYoPZmRXMoqsBGRaAvkrCWWciAP41AMVXBSMXIDSpyaqvagXRS33bvPg8QxW7rYo
Ka1P+4D8uT4uoP+hWtWKo5EUvnPES6eyR92ukz4UZc9yDFBqSV466+gykRxPj/mc
kx8jNRZsf+rILf4CXgdAJu6ii1oEyMC49u7LcyDenPsKvBulA7XdtiA+Trvpb7kM
BNHzhm7wW8oXVsIOoSXhvq9HYUAgbTGLHNGBYJLQaF0WslLnWNHQlHIF3nlNl3zF
DyoUysF6jzPC48SoWFJTB2wqI7DbIApagyTl7rGA7QP2LKCq5h8t8GkcxPKaBoiL
lcTJONwAu14/HRcZyAEc3VzY9oZ7xi+e2h5TQ5P7dDy5gAuMRfTG6+28RGcFL/tw
pi7vENs67R9js/ZbUDmmN3K5tTJV884liUHFv4mUhpX7UWP9pAaAMvwEHbLTJiEW
yfPo3x1wA1aj4GNh+dP5
=jCQu
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2041-1
December 03, 2013

linux-lts-raring vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-raring: Linux hardware enablement kernel from Raring

Details:

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.8.0-34-generic 3.8.0-34.49~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2041-1
CVE-2013-4299, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-raring/3.8.0-34.49~precise1

[USN-2040-1] Linux kernel (Quantal HWE) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjdkAAoJEAUvNnAY1cPYmQ0P/i2gmMxphjUd530tWgkl1ETs
GA3/m4f+VwH0tk0MmTb88u9eeH4Hg/qNC9AF7hNGntx1BFoheKLvk0pUNX23G2Sc
swfsnRgVFWPeOSM2N8jVdocsIXlQaEACxBmdQIIKVZstgY7gTmhvBd2AiKfH/6gI
3puqH4eczdwVUbVl23R+siOa38JID5/zAy32pd0LOkHPcMFI/y6JLq1KFvkUZYI4
gkdTQeCR452ZpLgfhg/HUG9Jd4i7g2pzb2qP0JI7qUsW43U9Ds50IFL+LnhV8pIz
ZaX9k8EGOrF3YbHT8HfzyOPEupPgZnUi8zSWYn7Ha9XagUxjNlv7fMCE79SEb1fz
MMYZvhyL/fIlg7zdz/XkM61nbrAkf/W1lgLBTxrQh9/YqCmKLJbP1s/271RiLn2z
9THZhp0ZtlqB5i8+EvMdfeqFlPBtt0NTX35S8dZFdXS1uugr7qoJ/1+dsmxpL6vB
FqJksyF1P2u3adsMpv6kqOX8SDVJUZ1dUkg8bZ5cQHTepYwEOAzArx8hghTgI0EA
KsQxc4Da5US1qScDhPDkpDWVkSoiBeL4odIaS2iibn0Zp3Y7e3o9mGo25OD5JYzG
XzbCtrIu5a3YHBODpx+Ant6HkrH/Y6BxSXZXN5KH/+vfGZOb0fBKd+smhxNrXCOf
sCgNgRoTC0lRiH4Dw1fS
=9L7R
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2040-1
December 03, 2013

linux-lts-quantal vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-lts-quantal: Linux hardware enablement kernel from Quantal

Details:

A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)

Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmenttation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.5.0-44-generic 3.5.0-44.67~precise1

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2040-1
CVE-2013-4299, CVE-2013-4470

Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-quantal/3.5.0-44.67~precise1

[USN-2039-1] Linux kernel (OMAP4) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjdIAAoJEAUvNnAY1cPYXtAP/2xrdYgqxtHStf1OjHk6yT9T
PlknYftFQbk/61XcCpAaJwqdDawqnpFLmtEPqXWr9g8V4TLoRljp/kYw6Tdqs7dX
9r3J9pX7z3wHyb23BA0BBSd6c8h5pGS3PxLwWryzkYrV5QW1TQuIqvSBPBAwLu8q
BuCCZLrevH3beIHSwM811K5Pm5yutryFNTXjXUdAh4fAhh6vDwBUEISGnPwVzacd
Y/AgGDvKIF3QXdh5eABnSsSQvBeiY9AQRzPDWXe5vZ2rGcRnw+Xp31ppANueLCFo
NVOXfX1VX0oSo3877TAnlmqVPtrLp4072Nv/yLTUAk3S9zLLvi3nDjfM24PAsud2
Kxmm6s3bvk+xC95/3wwBJPK8C3ZA+98IUbXgKcFws6ve0+MCi0qwzRxiamORRGsO
kEbBRM5WlQODRKPRx+CWABQAU5J+cUgx+AdoD5RfSpodeFbiO2rm2nZq23cHtvMM
pbExUYeFqso7UewDW9kRiJkP8G2Tw/qOwXKzUF6WyG7shV83iZI9IC64CbdOXJLK
S36Kx+xzpSwjFjhv9iM6RGTsNNeaGN6UczKS+QSVrDrNcaBMl3G7/QdDbsJBCXYg
cQciGZnNXdiYWNtG94hc9rYjl8NTH4CpKy9VW6M4Nuf/LtNi8tthu7JGfe0dJaoV
AEb5Av5ptayZNGU7yvkR
=5E3T
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2039-1
December 03, 2013

linux-ti-omap4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ti-omap4: Linux kernel for OMAP4

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-1441-omap4 3.2.0-1441.60

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2039-1
CVE-2013-0343, CVE-2013-2140, CVE-2013-2888, CVE-2013-2889,
CVE-2013-2892, CVE-2013-2893, CVE-2013-2895, CVE-2013-2896,
CVE-2013-2897, CVE-2013-2899, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux-ti-omap4/3.2.0-1441.60

[USN-2038-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjcqAAoJEAUvNnAY1cPYy9oP/3MTnl2ShUvmrcaV1vKyof5X
zx1Am8QrayhWrkG9HjnDy2mEkulkZu+OmgVCzOXXv8b1j2djEDLv8mnSOodoOSPi
/J+htTdrNNj9wfi07/g5zmLFM3TS7yn7pibStyw0ZtSBXxdrAPW7qugcdTzRwGN1
9VLXbO1nJlw5hJXcjqUxdjcxPCo2cuqhpKXvRkJzGCKXOen7fU52rwqanXC1PgVu
TEYVJdVT1p/r1DhHRp2UJyAQP/lFwBrEzUx1Ji9oPu4fT0oEtPK4CuBH5o9d78E8
0yzkFtZN4ZkHUIHcdQtcv4KWlC9MkxP+gX3K5pGlgKQOzfZAmZiVkpcOtFLGeCL+
me6++RvdDxIN2qQUUn/P9t4zRVMzwUOKxk/oHjBxQsodkO4rXnLEkgrhu391gcei
SabhnV8Chou3PeBeh4zCKm6V421Ne2/6JW+NIsEsgIiM6coKehVer1sDlzNLuNH4
802NXBkdPlQil+/5dd302vTQ5VzWvoIJoMVxETaXCqCJQD3vaGNj5+cbZ2rbLrKz
mlCiofygxeQicg6tQqNe69oorMV+h+PJvllQKbdRchrArlm7tKx64Ljf62lDd2Ia
43oJ4rraOKjSsxcdC4zgGREzJPBH6KsS224sQUE5KUKvduKx4O8rAsiBQU2fzKRt
vB2/OsBh6pHcmdTb5//r
=/oMB
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2038-1
December 03, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)

A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)

Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is enabled. A physically
proximate attacker could cause a denial of service (heap out-of-bounds
write) via a specially crafted device. (CVE-2013-2892)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leverage this flaw to cause a denial of service vias
a specially crafted device. (CVE-2013-2893)

Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_LOGITECH_DJ is enabled. A
physically proximate attacker could cause a denial of service (OOPS) or
obtain sensitive information from kernel memory via a specially crafted
device. (CVE-2013-2895)

Kees Cook discovered a vulnerability in the Linux Kernel's Human Interface
Device (HID) subsystem's support for N-Trig touch screens. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2896)

Kees Cook discovered yet another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when CONFIG_HID_MULTITOUCH is enabled. A
physically proximate attacker could leverage this flaw to cause a denial of
service (OOPS) via a specially crafted device. (CVE-2013-2897)

Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kernel whe CONFIG_HID_PICOLCD is enabled. A physically
proximate attacker could exploit this flaw to cause a denial of service
(OOPS) via a specially crafted device. (CVE-2013-2899)

Alan Chester reported a flaw in the IPv6 Stream Control Transmission
Protocol (SCTP) of the Linux kernel. A remote attacker could exploit this
flaw to obtain sensitive information by sniffing network traffic.
(CVE-2013-4350)

Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
linux-image-3.2.0-57-generic 3.2.0-57.87
linux-image-3.2.0-57-generic-pae 3.2.0-57.87
linux-image-3.2.0-57-highbank 3.2.0-57.87
linux-image-3.2.0-57-omap 3.2.0-57.87
linux-image-3.2.0-57-powerpc-smp 3.2.0-57.87
linux-image-3.2.0-57-powerpc64-smp 3.2.0-57.87
linux-image-3.2.0-57-virtual 3.2.0-57.87

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2038-1
CVE-2013-0343, CVE-2013-2140, CVE-2013-2888, CVE-2013-2889,
CVE-2013-2892, CVE-2013-2893, CVE-2013-2895, CVE-2013-2896,
CVE-2013-2897, CVE-2013-2899, CVE-2013-4350, CVE-2013-4387

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.2.0-57.87

[USN-2037-1] Linux kernel (EC2) vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjcKAAoJEAUvNnAY1cPYPaMQAJyH1XejQmW9k01qWVkm+XGQ
VBtwf/ZEI25L94bNIFVmjf1o30sI9G763DyPd+SDA1GYxLtRAvpJ/uecWmKH1l4w
6/wQVZktorf+wpMIiJavM8JCROvsKjE1CEMDZojIzwow5deM1ssz4tL+E9rpjtDk
iYHOY3IsVNcqvie/6W2viOe/M2q7iPN0qpAy8Mf5JTOrMtdwKBbEOTZUKhUE93BN
AmOWrgnjglCoqhug77HPz33J24xRQxm+VfC1OG2cCnkDR6oS/Hl9MpM5DuoO2bnf
vTmP5A/4ENuvp3zBEzE+83ZgZGpUVRVdvu9RNc4TD1B6jbQBh+RhhrHx8lOj/aHo
PyJc9LyWuhrULfK3P9T/I9Cl2TkLNUYkZbmeH3NCM8pYLHsMctOWhMAQmCXHaM91
CMTfcXMhusjVO63+twfGLZfrsPZEEVJnvWt2snCFepL9NXbiSOtLDjM2K8FA5MSt
gExMJ3pPZEozPnftOOq8zxawrTYLgITJNPYNLG3HWaS6Z+31Ey2tvtOmE8Z2BPlL
9y+CtDlllRv/ZA5TiC5+zytP5lO9qIBpiK3Wrdqtlgipv+Q8DYzfh2pVnzwYkZrg
7mZG+DkDwmNl/QrEao9l3dRSpK1GAmavIBmZbFwXey+WFBzBwB6xrmISSOESqkJ4
qyjqpayC9xhRFdVTy5Wv
=wnl8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2037-1
December 03, 2013

linux-ec2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux-ec2: Linux kernel for EC2

Details:

A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)

Multiple integer overflow flaws where discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-359-ec2 2.6.32-359.72

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2037-1
CVE-2012-2121, CVE-2013-4511

Package Information:
https://launchpad.net/ubuntu/+source/linux-ec2/2.6.32-359.72

[USN-2036-1] Linux kernel vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSnjbnAAoJEAUvNnAY1cPYKpAP/A+knAbFq2Ss6ebekHAm+sW4
s2HBT2vRXYe+7nemM6JUwpd6Sy/SZLR8Logi2sb37z+1cvV4gWAIGlRUps21TXGI
h0vs+HHwkmk2GKWKa2D3S5QpoyUa3gOxqjGMyuwEo8H53BTmIz8oW+ToFm5bguZM
UzpDGRFTWlFPrkO/Ll33BHtqjrRaAXSE4bHpSp+OGY29hp1qjs6BwxSL6mQvWF5+
TEGyPf8EK5eDTPmH+oAhVNNqwdcVzuwZLobEBubfr8Kb0ybzwkbACdFOT6y37VfK
mQij7bqMYphOEbVqRKuO5eqAv4ifXaRuI8Anq9Uur6dGCFmdMlIRFUOGBSpTXVCE
vL54w2oIgfQZiash56T9xSlNJyyuNX1Co3nX4jsZc2iOZufC9AccV999F7xwfzJQ
NwYIA/hsgabsqwg9ryfLEdB6S5JilU1mPdW4yw8MweBxy7RJm53jnXfY4fluDJtT
yvmMh6/Yg76C2w9vVWIPTW8THYk4ZjgXPbKVMZfaVUWLZ2WJfrPc4bG3FX1uahKH
pgvEkj5MpGmE76pqoQiIYFbJrgR9PpXdk1u8G4tcHB1WVC8aaNvfa4mGDg2hiqdK
IWzKVkcqmbUg3xT3He0mr8GcKr6OemkLDNIfmoXXhYx2v7i7TfK08alU2GaWS2sI
339qz/5+Od/ATLaOMXlw
=8GM7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2036-1
December 03, 2013

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)

Multiple integer overflow flaws where discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
linux-image-2.6.32-54-386 2.6.32-54.116
linux-image-2.6.32-54-generic 2.6.32-54.116
linux-image-2.6.32-54-generic-pae 2.6.32-54.116
linux-image-2.6.32-54-ia64 2.6.32-54.116
linux-image-2.6.32-54-lpia 2.6.32-54.116
linux-image-2.6.32-54-powerpc 2.6.32-54.116
linux-image-2.6.32-54-powerpc-smp 2.6.32-54.116
linux-image-2.6.32-54-powerpc64-smp 2.6.32-54.116
linux-image-2.6.32-54-preempt 2.6.32-54.116
linux-image-2.6.32-54-server 2.6.32-54.116
linux-image-2.6.32-54-sparc64 2.6.32-54.116
linux-image-2.6.32-54-sparc64-smp 2.6.32-54.116
linux-image-2.6.32-54-versatile 2.6.32-54.116
linux-image-2.6.32-54-virtual 2.6.32-54.116

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manually uninstalled the standard kernel metapackages (e.g. linux-generic,
linux-server, linux-powerpc), a standard system upgrade will automatically
perform this as well.

References:
http://www.ubuntu.com/usn/usn-2036-1
CVE-2012-2121, CVE-2013-4511

Package Information:
https://launchpad.net/ubuntu/+source/linux/2.6.32-54.116

Monday, December 2, 2013

[FreeBSD-Announce] Faces of FreeBSD - Reid Linnemann

Dear FreeBSD Community,

Thank you to everyone who has helped us raise $467,485 so far this year. We have 29 days left to reach our goal of raising $1,000,000 for 2013!
It's been heartwarming seeing so many people spreading the word about our fundraising campaign. You can help by telling your friends
on social media about our campaign as well as asking your company to make a donation.

We are excited to share our third Faces of FreeBSD story for 2013. This is a
chance for us to spotlight different people who contribute to FreeBSD in various ways.

Let us introduce you to Reid Linnemann. He was first introduced to FreeBSD in 1999. He just joined SpectraLogic, here in Boulder
Colorado, finally fulfilling his dream of working professionally with FreeBSD.

You can read his story here:
http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-reid-linnemann.html


Please consider making a donation to help us continue and increase our
support of the FreeBSD Project and community worldwide! To make a
donation go to:

http://www.freebsdfoundation.org/donate/

Thank You,

The FreeBSD Foundation
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

Fedora 20 Final Go/No-Go Meeting, Thursday, December 05 @ 17:00 UTC

Join us on irc.freenode.net in #fedora-meeting-2 for this important
meeting, wherein we shall determine the readiness of the Fedora 20.

Thursday, December 05, 2013 17:00 UTC (12 PM EST, 9 AM PST, 18:00 CET)

"Before each public release Development, QA and Release Engineering meet
to determine if the release criteria are met for a particular release.
This meeting is called the Go/No-Go Meeting."

"Verifying that the Release criteria are met is the responsibility of
the QA Team."

For more details about this meeting see:
https://fedoraproject.org/wiki/Go_No_Go_Meeting

In the meantime, keep an eye on the Fedora 20 Final Blocker list:
http://qa.fedoraproject.org/blockerbugs/milestone/20/final/buglist
For more details, see Adam's wrap up from the last Thursday [1].
Please, help us to deliver the release on time!

The Readiness meeting follows the Go/No-Go meeting two hours later.

Jaroslav

[1] https://lists.fedoraproject.org/pipermail/devel/2013-November/192527.html
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce

Sunday, December 1, 2013

俞婷瑞 如何处理劳动争议

            新《劳动合同法》、《社会保险法》、《工伤保险条例》
           
        实操应对策略与有效调岗调薪、裁员解雇及违纪问题员工处理技巧

【时间地点】
      2014年
      12月05-06日北京(B单元)
      12月12-13日深圳(B单元)
      12月19-20日广州(A单元)
      12月26-27日上海(A单元)
      12月30-31日北京(A单元)
  2015年1月9-10日深圳(A单元)

注明:该课程2天为一个单元,A单元与B单元内容是完全独立的不分先后顺序,客户可根据自己需求选择参
加A单元或者B单元,或AB单元均参加,可以参加完A单元再参加B单元或者先参加B单元再参加A单元均可,A
单元与B单元内容请看下面的课程大纲!!!


【参加对象】 董事长、总经理、副总经理、人力资源总监/经理/专员及人事行政管理人员、工会干部、法
             务人员及相关管理人员、相关律师等。

【授课方式】 讲师讲授 + 视频演绎 + 案例研讨 +角色扮演 + 讲师点评

【学习费用】 参加A单元:2800/1人,5000/2人;参加B单元:2800/1人,5000/2人
                          参加AB单元:5000/人,(含课程讲义、午餐/茶点等)

垂·询·热·线:上海:021-31006787、北京:010-5129-9910,深圳:0755-6128-0006 

在·线·QQ·微信:1368751945    133-8181-1919  吕小姐

课程背景:
  2008年,国家出台了《劳动合同法》、《劳动合同法实施条例》、《劳动争议调解仲裁法》、《职工带
薪年休假条例》、《企业职工带薪年休假实施办法》;2009年,国家出台了《劳动人事争议仲裁办案规则》
;2010年,国家出台了《劳动争议司法解释(三)》及修改了《工伤保险条例》;2011年,国家出台了《社
会保险法》及《实施<社会保险法>若干规定》;2012年,国家出台了《企业民主管理规定》、《女职工劳动
保护特别规定》及修改了《职业病防治法》;2013年,国家出台了《劳动争议司法解释(四)》、《劳务派
遣若干规定》;2014年……
  上述法律法规政策的持续实施,客观上要求企业精打细算,否则无法承受与日俱增的用工成本;客观上
要求用人单位做到"精细化"管理,否则难以证明劳动者"不合格、不胜任、严重失职、严重违纪违规",
也难以进行合法有效的"调岗调薪、裁员解雇"。如果用人单位依然实施"传统式、粗放式、随便式"的管
理,那么用人单位必将面临巨大的用工风险和赔偿责任,其管理权威也将受到严峻的挑战!
  为帮助广大企事业单位了解相关政策法律法规,掌握防范用工风险和化解劳动争议的技能技巧,以实现
低风险、低成本、高绩效的人力资源管理目标,特邀请我国知名的劳动法与员工关系管理实战专家钟永棣老
师主讲此课程。欢迎企事业单位积极组织相关人员参加此培训课程!

培训收益:
1、全面了解劳动用工过程的法律风险;
2、理解与劳动用工有关的政策法律法规;
3、培养预测、分析劳动用工法律风险的思维;
4、掌握预防和应对风险的实战技能及方法工具……

课程特色:
稀缺性:此课程将劳动法体系和薪酬绩效管理体系紧密相结合,国内极少出现此类课程。
针对性:课程内容精选了过去5年来主讲老师亲自处理过的且在不少用人单位内部也曾发生过的代表性案例
        ,这些案例完全符合中国现阶段的大环境大气候,极具参考性和启发性。
实战性:实战沙盘演练,学员深入思考与充分互动,老师毫不保留倾囊相授;学员把错误留在课堂,把正确
        的观点、方法、工具、技能带回去。

讲师介绍:【钟永棣】


资深劳动法专家

教育背景:
    国内著名劳动法与员工关系管理实战专家、劳动仲裁员、企业劳动争议预防应对专家、高级人力资源管
理师、高级劳动关系协调师,国内第一批倡导、传播、实施"国家劳动法与企业薪酬绩效有机整合"的先行
者;国内原创型、实战型、顾问型的培训师。
  现任"劳律通(中国)顾问中心"、中华创世纪培训网首席顾问,上海成通律师事务所投资合伙人;兼任
时代光华管理学院、深圳外商投资企业协会、广州市劳动保障学会、广州市人力资源市场服务中心、广东省
人力资源管理协会、香港工业总会、中山大学、浙江大学等100多家培训公司、行业协会、有关机构的签约
讲师、特聘顾问。

讲师擅长:
    钟老师精通劳动政策法律法规和劳动仲裁、诉讼程序,擅长劳动用工风险的有效预防与劳动争议案件的
精准应对,善于把劳动法律法规与企业人力资源管理有机整合,通晓企业劳动争议防范机制的构建和劳动用
工管理体系的修正完善。钟老师经常在客户办公现场、培训现场为客户、学员即时起草、审查、修改相关制
度、合同、文书,或分析具体案件的应对思路;钟老师独到的现场的专业功底,每次都赢得广大客户、学员
发自内心的好评与100%的信服!

讲师经历:
    钟老师曾任专职劳动仲裁员,曾获"广州市优秀劳动仲裁员"称号,期间审裁劳动争议案件400多宗;
多年来累积代理劳动争议500多宗,参与或主持薪酬绩效咨询项目20多个,审查完善400多家企业的人力资源
管理规章制度。个人长期担任30多家(累计200多家)企业的人力资源管理法律顾问;以钟老师领衔的专家
队伍,长期为企事业单位提供劳动法常年顾问及各种劳资专项咨询服务,客户满意度高达95%。
    2004年开始钟老师全国各地巡讲劳动法、劳动关系课程,受益企业达30000家,直接受益学员70000多人
,培训地点涉及20多个省会城市及沿海地区大城市。钟老师将枯燥的劳动政策法规溶入实际管理案例当中,
将人力资源管理与劳动法有机地整合在一起;课程内容80%为真实案例、20%为必备的重点法条;学员参与讨
论、互动,课程生动有趣,深入浅出,实战型超强,让学员即时学以致用!课程满意度高达95%,众多学员
均表示:"第一次听到如此实战、
实用、实效的劳动法课程!钟老师非常务实、不说教、没有商业味道,终于听到了让我不再后悔的精彩课程
!"
    钟老师先后在《广州日报》、《南方都市报》、《中国社会科学报》、《人力资源》、《香港工业总会
月刊》等报刊、杂志、媒体发表专业文章或采访稿50多篇。

课程大纲:
A单元内容(共2天,15个以上经典案例)
专题一:招聘入职
1.如何预防劳动者的"应聘欺诈",如何证明劳动者的"欺诈"?
2.招收应届毕业生,应注意哪些细节问题?
3.招用达到法定退休年龄的人员,应注意哪些细节问题?
4.招用待岗、内退、停薪留职的人员,应注意哪些细节问题?
5.入职体检需注意哪些细节问题?
6.入职前后用人单位应告知劳动者哪些情况,如何保留证据?
7.《入职登记表》如何设计,才能起到预防法律风险的作用?
8.劳动者无法提交《离职证明》,该怎么办?
9.企业如何书写《录用通知书》,其法律风险有哪些?

专题二:劳动合同订立
1.用人单位自行拟定的劳动合同文本是否有效,是否需要进行备案?
2.劳动者借故拖延或拒绝签订劳动合同,用人单位如何应对?
3.未签订劳动合同,需支付多长期限的双倍工资?是否受到仲裁时效的限制?
4.劳动合同期满,继续留用劳动者,但未续签合同,是否也需支付双倍工资?
5.什么时候为最佳时间,签署劳动合同、用工协议?
6.法律禁止2次约定试用期,劳动合同期限和试用期限该如何约定?
7.用人单位收购其他组织时,如何与被接收的员工签订、变更劳动合同?
8.应否与属于职业经理人的法人代表签订劳动合同?

专题三:试用期
1.可否先试用后签合同,可否单独签订试用期协议?
2.员工主动申请延长试用期,该怎样操作,才规避赔偿风险?
3.试用期满后辞退员工,最少赔2个月工资,该如何化解?
4.试用期最后一天辞退员工,赔偿概率为70%,如何化解?
5.试用期满前几天辞退员工,赔偿概率为50%,如何化解?
6.不符合录用条件的范围包括哪些,如何取证证明?
7.《试用期辞退通知书》如何书写,以避免违法解除的赔偿金?
8.出现"经济性裁员"情况,优先裁掉试用期的新员工,合法吗?

专题四:无固定期限劳动合同
1.无固定期限劳动合同到底是不是铁饭碗,会不会增加企业成本?
2.无固定期限劳动合同解除的条件、理由有哪些?
3.用人单位拒绝签订无固定期限劳动合同,有何风险?
4.签订了固定期限劳动合同的员工,期间工作累计满10年,能否要求将固定期限合同变更为无固定期限合同
  ?
5.连续订立二次固定期限劳动合同到期,用人单位能否终止合同;员工提出签订无固定期限合同,用人单位
  能否拒绝?
6.合同期满劳动者由于医疗期、三期等原因续延劳动合同导致劳动者连续工作满十年,劳动者提出订立无固
  定期限劳动合同的,用人单位能否拒绝?

专题五:特殊用工协议
1.培训服务期与劳动合同期限有何不同,劳动合同期限与服务期限发生冲突时如何适用?
2.培训服务期未到期,而劳动合同到期,用人单位终止劳动合同的,是否属于提前解除劳动合同,如何规避
  ?
3.劳动者严重过错被解雇,用人单位能否依据服务期约定要求劳动者支付违约金?
4.在什么情况下,可签署竞业限制协议?
5.在什么时候,企业更有主动权签署竞业限制协议?
6.无约定经济补偿的支付,竞业限制是否有效?
7.竞业限制的经济补偿的标准如何界定?
8.要求员工保密,企业需要支付保密工资吗?

专题六:劳动关系解除终止
1.双方协商解除劳动合同并约定支付适当的经济补偿,事后劳动者追讨经济补偿的差额部分,仲裁机构有可
  能支持劳动者的诉求,企业如何避免案件败诉?
2.能否与"三期妇女、特殊保护期间的员工"协商解除,如何规避风险?
3.员工未提前30日通知企业即自行离职,企业能否扣减其工资?
4.员工提交辞职信后的30天内,企业批准其离职,可能有风险,如何化解?
5.员工提交辞职信后的30天后,企业批准其离职,也可能有风险,如何化解?
6.对于患病员工,能否解除,如何操作才能降低法律风险?
7.实行末位淘汰制,以末位排名为由解雇员工,往往被认定非法解雇,企业该如何做,才避免案件败诉?
8.以"组织架构调整,无合适岗位安排"为由解雇员工,感觉非常符合常理,但往往被认定非法解雇,企业
  该如何做才避免风险?
9.以"经济性裁员"名义解雇员工,感觉非常符合常理,但往往被认定非法解雇,企业该如何操作?
10.《解除劳动合同通知书》如果表述不当,往往成为劳动者打赢官司的有力证据,企业该如何书写,才避
   免案件败诉而承担法律责任?
11.解除劳动合同前未通知及征求工会的意见,是否构成非法解除?
12.劳动合同到期后,经常出现该终止的忘记办理终止手续,该续签的忘记办理续签手续,其引发的风险非
   常大;那么企业该如何规避风险?

专题七:社会保险法
1.用人单位拖欠社保费,有什么法律责任?
2.用人单位不足额缴纳社会保险如何处理?
3.员工不愿意买社保,并与单位签有协议的情况下,该协议是否有效?
4.试用期间,是否必须缴纳社会保险?
5.如果无参保,劳动者因第三方责任产生的医疗费用,能否要求单位报销?
6.企业协助辞职员工骗取失业保险金,有什么法律风险?
7.女职工未婚先孕、未婚生育争议如何处理?
8.怀孕女职工提出长期休假保胎,直至修完产假,该如何协调此问题?

专题八:劳动争议处理
1.用人单位败诉的原因主要有哪些?
2.仲裁或法院在处理案件时,如何适用法律法规?
3.如何判定政策法律法规的效力等级?
4.公开审理的开庭形式,有何风险,如何避免风险?
5.申请仲裁的时效如何计算;如何理解"劳动争议发生之日"?
6.如何书写答辩书,有哪些注意事项?
7.开庭期间,质证与辩论需要注意哪些关键问题?
8.举证责任如何分配,无法举证的后果有哪些?

B单元内容(共2天,15个以上经典案例)
专题一:绩效管理与岗位调整
1.企业单方调整岗位,员工往往可被迫解除合同并索赔经济补偿,如何规避?
2.调岗时没有书面确认,员工到新岗位工作2个月后能否要求恢复到原岗位?
3.可否对"三期内"女职工进行调岗、调薪?
4.员工认同绩效结果,为什么在"不胜任工作"引发的争议中还是败诉?
5.为什么企业根据绩效结果支付员工绩效奖金,最终被认定非法克扣工资?
6.法律上如何证明劳动者"不能胜任工作"?
7.对绩效考核不合格的员工,如何合法辞退?
8.绩效正态分布往往强制划分5%的员工为不合格者,是否合法?

专题二:劳动报酬、薪酬福利
1.工资总额包括哪些工资明细?
2.新进员工薪资管理问题及处理技巧;
3.调整工作岗位后,可以调整薪资标准吗?
4.如何通过薪酬调整处理员工失职、违纪等问题?
5.值班算不算加班?
6.加班加点工资支付常见误区?
7.用人单位如何设计工资构成以降低加班费成本?
8.未经用人单位安排,劳动者自行加班的,是否需支付加班工资?
9.劳动者主张入职以来的加班费,如何应对?
10.劳动者在工作日\法定节假日加班,能否安排补休而不予支付加班费?
11.病假、年休假、婚假、产假、丧假等的享受条件及工资待遇标准?
12.离职员工往往回头追讨年终奖,有可能得到支持,如何规避该风险?

专题三:违纪违规问题员工处理
1.劳动者往往拒绝签收处分、解雇通知书,如何应对?
2.问题员工往往拒绝提交《检讨书》或否认违纪违规事实,企业该如何收集证据?
3.对于违纪员工,应该在什么时间内处理?
4.怎样理解"严重违反用人单位的规章制度"?
5.如何在《惩罚条例》中描述"一般违纪"、"较重违纪"及"严重违纪"?
6.怎样理解"严重失职,营私舞弊,给用人单位造成重大损害"?
7.如何界定"重大损害","重大损害"是否必须体现为造成直接的经济损失?
8.如何追究"严重失职、严重违纪违规"者的法律责任?
9.能否直接规定"禁止兼职,否则视为严重违纪违规"?
10.直线部门经理擅自口头辞退员工,仲裁机构往往认定企业非法解雇,企业该如何做,才避免案件败诉?
11.劳动者不辞而别、无故旷工,却主张被企业口头解雇,往往得到仲裁机构的支持,企业该如何做,才避
   免案件败诉?
12."录音录象"证据,仲裁与法院是否采信;企业内部OA系统上的资料能否作为证据使用;电子邮件、手
   机短信能否作为证据使用?

专题四:经济补偿
1.用人单位需向劳动者支付经济补偿的情形有哪些?
2.什么情况下用人单位需支付两倍的经济补偿?
3.劳动者可否同时向用人单位主张经济补偿和赔偿金?
4.经济补偿计算的基数及标准如何确定?
5.经济补偿年限最高不超过十二年的适用范围?
6.如何计算《劳动合同法》生效前后的经济补偿年限?
7.如何理解"六个月以上不满一年的,按一年计算;不满六个月的,向劳动者支付半个月工资的经济补偿"
  ?
8.劳动合同法环境下"50%额外经济补偿金"是否继续适用?

专题五:规章制度、员工手册
1.企业人力资源管理体系中哪些内容跟劳动法有必然联系?
2.人力资源、劳动用工管理制度应该包括哪些必备内容?
3.制定规章制度的程序要求给用人单位带来哪些风险,如何应对?
4.非国有用人单位如何组建"职工代表大会"?
5.无纸化、网络化办公下的公示,存在哪些风险?
6.如何公示或告知,更符合仲裁或诉讼的举证要求?
7.规章制度能否规定对员工进行经济处罚?
8.规章制度违反法律法规,劳动者可以被迫解除并索取经济补偿,如何防范?

专题六:工伤保险条例
1.属于工伤范围的情形有哪些?
2.不得认定为工伤的情形有哪些?
3.怎样理解"上下班途中",怎样控制期间的风险?
4.发生工伤事故,用人单位需承担哪些费用?
5.工伤员工借故拒绝复工,借故不断休假,如何处理?
6.对于第三方造成的工伤事故,劳动者能否要求用人单位支付工伤待遇又同时要求第三方支付人身伤害赔偿
  ?
7.用人单位能否以商业保险理赔款替代职工工伤赔偿待遇?
8.发生工伤事故,双方私下和解,补偿协议该如何签订才有效?

专题七:劳务派遣
1.劳务派遣用工模式,有何利弊,利大还是弊大?
2.劳务派遣合作协议必须注意的风险细节有哪些?
3.新法下劳务派遣面临的主要风险有哪些?
4.派遣工"第三签"时,能否要求签订无固定期限劳动合同?
5.哪些岗位可以使用派遣工,辅助性、临时性、替代性如何理解与操作?
6.新规定对于同工同酬提出哪些新要求,如何规避同工同酬风险?
7.采用劳务派遣用工方式,能否异地参保?
8.用工单位如何行使对派遣员工的退还或退换权?
9.如何处理违反用工单位规章制度的派遣员工?
10.怎样规定派遣员工的辞职程序和离职责任?
11.部分劳务公司很可能面临关闭停业,原来的派遣工的劳动关系如何处理?
12.业务外包与劳务派遣的本质区别有哪些?
13.如何筛选承包方,需考察哪些细节要点?
14.用工单位如何应对派遣合作争议和劳动争议?

注:如不需要此类信件信息,请发送"删除"至qytuixin@163.com,我们会及时处理,谢谢您的理解。

[CentOS-announce] Release for CentOS-6.5 i386 and x86_64

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

We are pleased to announce the immediate availability of CentOS-6.5
install media for i386 and x86_64 Architectures. Release Notes for 6.5
are available at http://wiki.centos.org/Manuals/ReleaseNotes/CentOS6.5 -
we recommend everyone looks through those once.

CentOS-6.5 is based on the upstream release EL 6.5 and includes packages
from all variants. All upstream repositories have been combined into
one, to make it easier for end users to work with.

There are many fundamental changes in this release, compared with the
past CentOS-6 releases, and we highly recommend everyone stufy the
Release Notes as well as the upstream Techical Notes about the changes
and how they might impact your installation.

All updates released since upstream 6.5 release are also released to the
CentOS-6.5 mirrors.

Everyone who has centos-cr repositories enabled and in use, would
already be running CentOs-6.5 as of one week ago and will notice only
the centos-release rpm update today.

+++++++++++++++++++++++
Upgrading from CentOS-4 or CentOS-5:

We recommend everyone run through a reinstall rather than attempt an
inplace upgrade from CentOS-4 or CentOS-5.

+++++++++++++++++++++++
Upgrading from CentOS-6.0 / 6.1 / 6.2 / 6.3 or 6.4

Unless you have edited your yum configs, a 'yum update' should move your
machine seamlessly from any previous CentOS-6.x release to CentOS-6.5

+++++++++++++++++++++++
Downloading CentOS-6.5 for new installs:

When possible, consider using torrents to run the downloads. Usually its
also the fastest means to download the distro.

Torrent files for the DVD's are available at :
http://mirror.centos.org/centos/6.5/isos/i386/CentOS-6.5-i386-bin-DVD1to2.torrent
http://mirror.centos.org/centos/6.5/isos/x86_64/CentOS-6.5-x86_64-bin-DVD1to2.torrent

You can also use a mirror close to you :
http://www.centos.org/modules/tinycontent/index.php?id=30

Most mirrors will allow direct DVD downloads over http, ftp and rsync.

Please keep in mind that not all mirrors are currently updated, some
might take upto another 24 hours before they have all the content.

We have also made efforts to try and ensure that most install types and
roles can be run from DVD-1 itself.

+++++++++++++++++++++++
sha1sum for the CentOS-6.5 ISOS:

i386:
67ea68068ae53d1f23431072ec0288b3e1abfe4d CentOS-6.5-i386-bin-DVD1.iso
70fe3b01ce8133fa7e6e7dbfcb9f1acdb1e9981f CentOS-6.5-i386-bin-DVD2.iso
3cf41ef12362ad363ff0650c703d3d045bcbfa7a CentOS-6.5-i386-LiveCD.iso
73d6444e2576e1169035d2444f872ff622ed85b6 CentOS-6.5-i386-LiveDVD.iso
4f900bba81d0e3c5cc5354a94984ed2fa03d4061 CentOS-6.5-i386-minimal.iso
e2e637dfbb08c04a478362733ee906ba9485771d CentOS-6.5-i386-netinstall.iso


x86_64:
32c7695b97f7dcd1f59a77a71f64f2957dddf738 CentOS-6.5-x86_64-bin-DVD1.iso
25e5de362ba6c75d793dbeb060b27ba1865cb5df CentOS-6.5-x86_64-bin-DVD2.iso
690ccc84926a46152543a3cad57d983c9004638d CentOS-6.5-x86_64-LiveCD.iso
3ac5eb9a6dcbf5f2b4cfd2432cccd84cd722840d CentOS-6.5-x86_64-LiveDVD.iso
f21a71e8e31df73297bdd1ccd4a64a36831284bd CentOS-6.5-x86_64-minimal.iso
3a9662cb65f9d59677d76acfdb73289da43b4599 CentOS-6.5-x86_64-netinstall.iso


+++++++++++++++++++++++
LiveCD and LiveDVD

LiveCD and LiveDVD media is also released into the ISOS/ directory.
You can download these from either a mirror close to you or the
torrents listed here :

http://mirror.centos.org/centos/6.5/isos/i386/CentOS-6.5-i386-LiveCD.torrent
http://mirror.centos.org/centos/6.5/isos/i386/CentOS-6.5-i386-LiveDVD.torrent

http://mirror.centos.org/centos/6.5/isos/x86_64/CentOS-6.5-x86_64-LiveCD.torrent
http://mirror.centos.org/centos/6.5/isos/x86_64/CentOS-6.5-x86_64-LiveDVD.torrent


+++++++++++++++++++++++
Cloud Images

Images for various on-preimse and off-premise Cloud environments are
currently under development for CentOS-6.5 and will be released in the
coming days. Everyone looking to join and help with the CentOS Cloud
efforts is encouraged to join the CentOS-Virt list where such issues
are discussed ( http://lists.centos.org/mailman/listinfo/centos-virt ).

+++++++++++++++++++++++
Getting Help:

The best place to start when looking for help with CentOS is at the wiki
( http://wiki.centos.org/GettingHelp ) which lists various options and
communities who might be able to help. If you think there is a bug in
the system, do report it at http://bugs.centos.org/ - but keep in mind
that the bugs system is *not* a support mechanism.

+++++++++++++++++++++++
Metups and training sessions

The next CentOS Dojo is going to take place at Austin, TX, USA on the
6th December 2013. Details on the day, venue and registration are
available at http://wiki.centos.org/Events/Dojo/Austin2013

As 2014 comes up, we've started planning for the Dojo Schedules for
the next year. If you would like to get involved in helping
organising, running, presenting or sponsoring a Dojo or even just want
more detail do get in touch with us at the CentOS Promo list
(http://lists.centos.org/mailman/listinfo/centos-promo)


+++++++++++++++++++++++
Contributing and joining the project:

We are always looking for people to join and help with various things in
the project. If you are keen to help out a good place to start is the
wiki page at http://wiki.centos.org/Contribute . If you have questions
or a specific area you would like to contribute towards that is not
covered on that page, feel free to drop in on
#centos-devel@irc.freenode.net for a chat or email the centos-devel list
(http://lists.centos.org).

+++++++++++++++++++++++
Thanks to everyone who contributed towards making CentOS 6.5, specially
the effort put in, as always, by the QA and Build team.

A special shout out to all the donors who have contributed hardware,
network connectivity, hosting and resources over the years. The CentOS
project now has a fairly well setup resource pool, purely thanks to the
donors.

Enjoy!

- --
Karanbir Singh <kbsingh@centos.org>
The CentOS Project {http://www.centos.org}
irc: z00dax@irc.freenode.net ( #centos, #centos-devel )

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlKbXc8ACgkQMA29nj4Tz1tsdACgqvWoCBaV/Eiplg28cYaxs6Jp
rsEAnjfC+qLkGr+3bArO/UZKkyGO3lav
=Qq62
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce