-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUB1ltAAoJEGVp2FWnRL6TcWEP/jgaW1+UiecFa500MeICm3a4
RcRGY7LUXUCoik94rU04Q40ydjq8k3L1Qqehwj9aBTnv1gD512xa/n5RD7Yaq3o6
peaXf1WEOKwclhV5coCmgLYHOwxjKN1QtFw2Zd8nlGV25eH6zE5pucO9ZxOO5nVy
YqYwZIq5dyRxtd2jq+sZDmAXpMYqDGge9DYPb2aB81JZser1aAaChR+a+9yNtEPb
IxFA9uv6sK7/V4fHHeNFJ0pQREH6sYrnKyvEX0vds00+loU/Dcjhd092M3YLvH5l
thVC//OLXXVm+nt62Zlq+lGs/l221YGqno8qTHYd1maRNUGIQO+Auzpth90K+ldP
SsD0BfSn5MBlkOfDoQgzqhZdCbAM1+nCo5icfjbHcEFE4EtBJULEk7R191yp+Hqb
0slO4VRgc7HkzUY3xWNznILxCxBMvjfb4mnhUOeZKA1cssfCnXoFX313/oKbgb9Y
V7gomUrV1dAHuSln3YMknMV5W7GBJ07GZ0158m2BLIUrB1Qi3A3bQHTVWHuIhj7y
EBaCj6IepuwD03S9Xap93AkRBxXXbwarpsQss95VkVXVv2EMzQDuCRrRsyt/YsJp
UyVssZFW0fa6/fDlUBqY1xOx5RwFUpOUkR+FwKAwudu1Z1iuzoSJKqJtcElGCVtO
p6PFSvclblqiPqqx4Mt8
=F9IR
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2339-2
September 03, 2014
libgcrypt11 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
Libgcrypt could expose sensitive information when performing decryption.
Software Description:
- libgcrypt11: LGPL Crypto library
Details:
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that Libgcrypt was
susceptible to an adaptive chosen ciphertext attack via physical side
channels. A local attacker could use this attack to possibly recover
private keys.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
libgcrypt11 1.5.3-2ubuntu4.1
Ubuntu 12.04 LTS:
libgcrypt11 1.5.0-3ubuntu0.3
Ubuntu 10.04 LTS:
libgcrypt11 1.4.4-5ubuntu2.3
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2339-2
http://www.ubuntu.com/usn/usn-2339-1
CVE-2014-5270
Package Information:
https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.3-2ubuntu4.1
https://launchpad.net/ubuntu/+source/libgcrypt11/1.5.0-3ubuntu0.3
https://launchpad.net/ubuntu/+source/libgcrypt11/1.4.4-5ubuntu2.3
Wednesday, September 3, 2014
[USN-2339-1] GnuPG vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUB1lXAAoJEGVp2FWnRL6TFEQQALCX9CkNdxf/Th95mi1cfYNM
lIGdGfMiJcWoTFhusdznQT6kKsT7mZwZrVHw+ziDSFnsvOi5yH41DqFSjdBDnP1h
UqDru0OdHUPavEO+dL317mK7bZ46yHzPSgS8jtDt+rcWd5FadYjfrQxPxZcgMB2H
9YZ5jy86E7kJPHy0JAedFk9aY2eEFW/1BNzFLlqgFFch3iRAUyH8AXU9/00DHBoN
yBDcaLAmXXt6MZzhfrHW6Ya4z6OXMlaQ67Dvq9eW1IS+nhLbmyd3ETpG4xACfOAh
MYwAdVlO3zUve5BncbPFQzPjKd9JRLk0LcO51kPhDtjpR0yZwS2WrOn1fzx6N80d
Ugl6S3yc62vdS6zV7OnohEc8yuBjrveHd1HNhldHydkBJLt+n//iT7KCzGwnFjCS
atPzRicFB4IrgUE9wseJ9jIs4TWTSGEBb2BU3C6pNjiCVplidfBP/EWZ2KIKX1i/
2GGfov/j3l1ZyanxO6p+wSi+35eWn1Cu86E6dr6JAhN1yUUTy8AbzVopPpSI/mla
ARTu1NeZv6/AV9jTif5qEidiMblHqlnlfSrEU7TQTraevJcBIgNOhm6bmQfCTl/3
7N9HoUF5XCfhUPBrpAAaxzABoiGgxJJ7nLuqDfj9Fi6XQwldJIe+Pp+kkbpuRExv
o07u/xxhgjLmPHWTNv+W
=EEKZ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2339-1
September 03, 2014
gnupg vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
GnuPG could expose sensitive information when performing decryption.
Software Description:
- gnupg: GNU privacy guard - a free PGP replacement
Details:
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an adaptive chosen ciphertext attack via physical side
channels. A local attacker could use this attack to possibly recover
private keys.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
gnupg 1.4.11-3ubuntu2.7
Ubuntu 10.04 LTS:
gnupg 1.4.10-2ubuntu1.7
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2339-1
CVE-2014-5270
Package Information:
https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu2.7
https://launchpad.net/ubuntu/+source/gnupg/1.4.10-2ubuntu1.7
Version: GnuPG v1
iQIcBAEBCgAGBQJUB1lXAAoJEGVp2FWnRL6TFEQQALCX9CkNdxf/Th95mi1cfYNM
lIGdGfMiJcWoTFhusdznQT6kKsT7mZwZrVHw+ziDSFnsvOi5yH41DqFSjdBDnP1h
UqDru0OdHUPavEO+dL317mK7bZ46yHzPSgS8jtDt+rcWd5FadYjfrQxPxZcgMB2H
9YZ5jy86E7kJPHy0JAedFk9aY2eEFW/1BNzFLlqgFFch3iRAUyH8AXU9/00DHBoN
yBDcaLAmXXt6MZzhfrHW6Ya4z6OXMlaQ67Dvq9eW1IS+nhLbmyd3ETpG4xACfOAh
MYwAdVlO3zUve5BncbPFQzPjKd9JRLk0LcO51kPhDtjpR0yZwS2WrOn1fzx6N80d
Ugl6S3yc62vdS6zV7OnohEc8yuBjrveHd1HNhldHydkBJLt+n//iT7KCzGwnFjCS
atPzRicFB4IrgUE9wseJ9jIs4TWTSGEBb2BU3C6pNjiCVplidfBP/EWZ2KIKX1i/
2GGfov/j3l1ZyanxO6p+wSi+35eWn1Cu86E6dr6JAhN1yUUTy8AbzVopPpSI/mla
ARTu1NeZv6/AV9jTif5qEidiMblHqlnlfSrEU7TQTraevJcBIgNOhm6bmQfCTl/3
7N9HoUF5XCfhUPBrpAAaxzABoiGgxJJ7nLuqDfj9Fi6XQwldJIe+Pp+kkbpuRExv
o07u/xxhgjLmPHWTNv+W
=EEKZ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2339-1
September 03, 2014
gnupg vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
GnuPG could expose sensitive information when performing decryption.
Software Description:
- gnupg: GNU privacy guard - a free PGP replacement
Details:
Daniel Genkin, Adi Shamir, and Eran Tromer discovered that GnuPG was
susceptible to an adaptive chosen ciphertext attack via physical side
channels. A local attacker could use this attack to possibly recover
private keys.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
gnupg 1.4.11-3ubuntu2.7
Ubuntu 10.04 LTS:
gnupg 1.4.10-2ubuntu1.7
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2339-1
CVE-2014-5270
Package Information:
https://launchpad.net/ubuntu/+source/gnupg/1.4.11-3ubuntu2.7
https://launchpad.net/ubuntu/+source/gnupg/1.4.10-2ubuntu1.7
[announce] NYC*BUG RSVP for tonight
2014-09-03 18:45, about.com (1500 Broadway, 43rd Street, 6th Floor)
Notice: RSVP to rsvp at nycbug.org and bring photo ID. RSVPs must be
received by 2 PM, day-of.
This month's meeting will be a discussion about the status of last
month's OpenBSD porting, plus a short presentation on the deprecation of
FreeBSDs pkg_* tools and its replacement with pkgng.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
Notice: RSVP to rsvp at nycbug.org and bring photo ID. RSVPs must be
received by 2 PM, day-of.
This month's meeting will be a discussion about the status of last
month's OpenBSD porting, plus a short presentation on the deprecation of
FreeBSDs pkg_* tools and its replacement with pkgng.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
[CentOS-announce] CEBA-2014:1141 CentOS 6 openscap BugFix Update
CentOS Errata and Bugfix Advisory 2014:1141
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1141.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
b952c73cee7845e66dbb71a4614880421e7cb68268fe8390dafc45de1a338dca openscap-1.0.8-1.0.1.el6.centos.1.i686.rpm
b11e63144b33e7c3fad0ac8e70b620182248ca432f712acd339d94b341bcc488 openscap-content-1.0.8-1.0.1.el6.centos.1.noarch.rpm
33d2b3145bd7262ecbf4fa00d2043d0f4b19e1f9a6efc3c34f04ca8b89897984 openscap-devel-1.0.8-1.0.1.el6.centos.1.i686.rpm
aa38c6b0ec87dd5a1bbdc85f83b524001f344340abfd667d066f0e84634c9869 openscap-engine-sce-1.0.8-1.0.1.el6.centos.1.i686.rpm
f5273b81332ee36249cdf6302df3dfa75c67559cf1f44123859780ad398a0b05 openscap-engine-sce-devel-1.0.8-1.0.1.el6.centos.1.i686.rpm
79db9503fefe926460296ff702ecce8dfb4d754c80a68e5201c9f872a8535ade openscap-extra-probes-1.0.8-1.0.1.el6.centos.1.i686.rpm
43e395f6147e0695292e927cac39176cc64502cb9f5e761d41806c45ca17afa2 openscap-python-1.0.8-1.0.1.el6.centos.1.i686.rpm
2d0106475962791049d25917dff713fb7dd55561a606937b8ffecdec56536c1b openscap-utils-1.0.8-1.0.1.el6.centos.1.i686.rpm
x86_64:
b952c73cee7845e66dbb71a4614880421e7cb68268fe8390dafc45de1a338dca openscap-1.0.8-1.0.1.el6.centos.1.i686.rpm
b5f6929543e4a4b0a71cec64cab82927979eb41060b37663b09068156af12b94 openscap-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
b11e63144b33e7c3fad0ac8e70b620182248ca432f712acd339d94b341bcc488 openscap-content-1.0.8-1.0.1.el6.centos.1.noarch.rpm
33d2b3145bd7262ecbf4fa00d2043d0f4b19e1f9a6efc3c34f04ca8b89897984 openscap-devel-1.0.8-1.0.1.el6.centos.1.i686.rpm
9b4c47c9f51632f24a9b2d3fe9f6938543d48c93b2d212cf48be2277be3f4170 openscap-devel-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
392a96503cb3ebe0006da1423be493990290b477403ce5b53d74b462ae7cbd62 openscap-engine-sce-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
6d8d7bdf60b774cbdce2e72d31fe8775745bfb6823a8b386b6851c6b40849bb9 openscap-engine-sce-devel-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
cb13943b31fea43a146da3b7007f47bbc995a806df2ac1bbb09ba6d4a1582e65 openscap-extra-probes-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
c33c4004eb15a8401993db229a0771953ea69a7f91ba2d659d2fb54c3b8f45b6 openscap-python-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
f7c3819e0a354273b5b462405f4f33a5319d17c1cb74699447e22d367add6175 openscap-utils-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
Source:
3cb945f4861eea30b3b289487c51cfcaab2fecde8590a8ad426823ada86812b3 openscap-1.0.8-1.0.1.el6.centos.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1141.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
b952c73cee7845e66dbb71a4614880421e7cb68268fe8390dafc45de1a338dca openscap-1.0.8-1.0.1.el6.centos.1.i686.rpm
b11e63144b33e7c3fad0ac8e70b620182248ca432f712acd339d94b341bcc488 openscap-content-1.0.8-1.0.1.el6.centos.1.noarch.rpm
33d2b3145bd7262ecbf4fa00d2043d0f4b19e1f9a6efc3c34f04ca8b89897984 openscap-devel-1.0.8-1.0.1.el6.centos.1.i686.rpm
aa38c6b0ec87dd5a1bbdc85f83b524001f344340abfd667d066f0e84634c9869 openscap-engine-sce-1.0.8-1.0.1.el6.centos.1.i686.rpm
f5273b81332ee36249cdf6302df3dfa75c67559cf1f44123859780ad398a0b05 openscap-engine-sce-devel-1.0.8-1.0.1.el6.centos.1.i686.rpm
79db9503fefe926460296ff702ecce8dfb4d754c80a68e5201c9f872a8535ade openscap-extra-probes-1.0.8-1.0.1.el6.centos.1.i686.rpm
43e395f6147e0695292e927cac39176cc64502cb9f5e761d41806c45ca17afa2 openscap-python-1.0.8-1.0.1.el6.centos.1.i686.rpm
2d0106475962791049d25917dff713fb7dd55561a606937b8ffecdec56536c1b openscap-utils-1.0.8-1.0.1.el6.centos.1.i686.rpm
x86_64:
b952c73cee7845e66dbb71a4614880421e7cb68268fe8390dafc45de1a338dca openscap-1.0.8-1.0.1.el6.centos.1.i686.rpm
b5f6929543e4a4b0a71cec64cab82927979eb41060b37663b09068156af12b94 openscap-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
b11e63144b33e7c3fad0ac8e70b620182248ca432f712acd339d94b341bcc488 openscap-content-1.0.8-1.0.1.el6.centos.1.noarch.rpm
33d2b3145bd7262ecbf4fa00d2043d0f4b19e1f9a6efc3c34f04ca8b89897984 openscap-devel-1.0.8-1.0.1.el6.centos.1.i686.rpm
9b4c47c9f51632f24a9b2d3fe9f6938543d48c93b2d212cf48be2277be3f4170 openscap-devel-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
392a96503cb3ebe0006da1423be493990290b477403ce5b53d74b462ae7cbd62 openscap-engine-sce-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
6d8d7bdf60b774cbdce2e72d31fe8775745bfb6823a8b386b6851c6b40849bb9 openscap-engine-sce-devel-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
cb13943b31fea43a146da3b7007f47bbc995a806df2ac1bbb09ba6d4a1582e65 openscap-extra-probes-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
c33c4004eb15a8401993db229a0771953ea69a7f91ba2d659d2fb54c3b8f45b6 openscap-python-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
f7c3819e0a354273b5b462405f4f33a5319d17c1cb74699447e22d367add6175 openscap-utils-1.0.8-1.0.1.el6.centos.1.x86_64.rpm
Source:
3cb945f4861eea30b3b289487c51cfcaab2fecde8590a8ad426823ada86812b3 openscap-1.0.8-1.0.1.el6.centos.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2014:1139 CentOS 6 initscripts BugFix Update
CentOS Errata and Bugfix Advisory 2014:1139
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1139.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
49590027129104bcc310c7b6e446822017c39c4f616988fb02e2fd96138f64b2 debugmode-9.03.40-2.el6.centos.4.i686.rpm
a582e569a2f6c90ff88c4483415d740a9beb5dcd03d16ad9ea937892b13dd871 initscripts-9.03.40-2.el6.centos.4.i686.rpm
x86_64:
1b7d40f31554c23de9d5870afe6e6adcd738c76e59253b945e8da89d6b35e3a7 debugmode-9.03.40-2.el6.centos.4.x86_64.rpm
ecc8f81159fd9aa33fdeffec25f494e80d4b40eb7b4ed09626da3c7f103beff4 initscripts-9.03.40-2.el6.centos.4.x86_64.rpm
Source:
f443e00191de82590a8933c9561954f5d88ca4bdec449595211062a246c78a13 initscripts-9.03.40-2.el6.centos.4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1139.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
49590027129104bcc310c7b6e446822017c39c4f616988fb02e2fd96138f64b2 debugmode-9.03.40-2.el6.centos.4.i686.rpm
a582e569a2f6c90ff88c4483415d740a9beb5dcd03d16ad9ea937892b13dd871 initscripts-9.03.40-2.el6.centos.4.i686.rpm
x86_64:
1b7d40f31554c23de9d5870afe6e6adcd738c76e59253b945e8da89d6b35e3a7 debugmode-9.03.40-2.el6.centos.4.x86_64.rpm
ecc8f81159fd9aa33fdeffec25f494e80d4b40eb7b4ed09626da3c7f103beff4 initscripts-9.03.40-2.el6.centos.4.x86_64.rpm
Source:
f443e00191de82590a8933c9561954f5d88ca4bdec449595211062a246c78a13 initscripts-9.03.40-2.el6.centos.4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2014:1140 CentOS 6 avahi BugFix Update
CentOS Errata and Bugfix Advisory 2014:1140
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1140.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
c05c0eb98850d7593eec0089f6d64c2a81df5bdf2e0cce873cc1b4666dee1191 avahi-0.6.25-12.el6_5.3.i686.rpm
2c50f0628744b47f86a89dfb4f283e6cd56ac611aec8712539fad14538100c1d avahi-autoipd-0.6.25-12.el6_5.3.i686.rpm
83c3e0768d5fcf1a0a4bb0188bfc0249ccc4410aedc3a5b9c191fc2d5e9abf40 avahi-compat-howl-0.6.25-12.el6_5.3.i686.rpm
77c57e79803d17f2740987963484dae2289df53ed7f9b13b6e2ab86d6ccc86e1 avahi-compat-howl-devel-0.6.25-12.el6_5.3.i686.rpm
adf9582d2f1dce306949df07ce752c9e647dd2f66df34e7cf35c7323c2ba6f92 avahi-compat-libdns_sd-0.6.25-12.el6_5.3.i686.rpm
b4493e6f26c2b36827bbfbd21a83e58b2ecf964bd0e52601be977388fea91948 avahi-compat-libdns_sd-devel-0.6.25-12.el6_5.3.i686.rpm
667edbf1a9dd2f5dd406a130b079d74579188a3c11b4d1afdcf58282c23c282a avahi-devel-0.6.25-12.el6_5.3.i686.rpm
5d4e6ef4db89d0c0b072b9767e6b30000ad869b049666455258c25a68e77f19e avahi-dnsconfd-0.6.25-12.el6_5.3.i686.rpm
216535bd6fe030b6deacd12ccb95ddc365eadb0ffb74a41ca7c78b47a51d9e9a avahi-glib-0.6.25-12.el6_5.3.i686.rpm
07f2f7f1755f336f675695c57f3f51ab4b273362c410ace22e1552060da7cc5e avahi-glib-devel-0.6.25-12.el6_5.3.i686.rpm
cd2e4fa6203c297efe34360f8e9bee83124e9df9fa647b26f9d7f321de2a63ae avahi-gobject-0.6.25-12.el6_5.3.i686.rpm
598def41091267cbbc54ae5a79b26747ae5af3549a9c7d4976cab81b709e6af0 avahi-gobject-devel-0.6.25-12.el6_5.3.i686.rpm
9f27a8630f7bfd4cd7e8302aca8be7c8b91af6361a6aa0d8ee07f3e8fe7eee97 avahi-libs-0.6.25-12.el6_5.3.i686.rpm
8feba5d7ce0fb18cd4b8e9b242c64fec6d32b9f98792127a3c52cc2f0ad8b236 avahi-qt3-0.6.25-12.el6_5.3.i686.rpm
a84e07e8fa097d28d6c7f9a03659cad949dfd5d40db0a9f4f2c0f3c02ec5d5e3 avahi-qt3-devel-0.6.25-12.el6_5.3.i686.rpm
6a3b7648e16e15b78c48b6bda78ab332c6b8f456395078e0c32fbdbedc8b557d avahi-qt4-0.6.25-12.el6_5.3.i686.rpm
6de0ee5928a105c5f0e848461f9c3b7a585a2ca166f69e74080483078d7474ed avahi-qt4-devel-0.6.25-12.el6_5.3.i686.rpm
f7dfdc24723aee6c564ec232fe78974d0358c9f754393eb56d176403433abd7b avahi-tools-0.6.25-12.el6_5.3.i686.rpm
1f327f102c73cacd9ebee9858f656d0503977e233dc60b4fa4fd1f7e7cf140d9 avahi-ui-0.6.25-12.el6_5.3.i686.rpm
c473c308f351a5fa78c2a7108c3298e30aed607311d3134035e0a88d107d54ff avahi-ui-devel-0.6.25-12.el6_5.3.i686.rpm
21b467e10f2069c0b83de8f6fb6c5c2cea4b3c227408747cdf11995511092715 avahi-ui-tools-0.6.25-12.el6_5.3.i686.rpm
x86_64:
c05c0eb98850d7593eec0089f6d64c2a81df5bdf2e0cce873cc1b4666dee1191 avahi-0.6.25-12.el6_5.3.i686.rpm
a85601e7d415f90ef47648c57dedc0f1a6d09e9b3c07f97c409a33819d313814 avahi-0.6.25-12.el6_5.3.x86_64.rpm
86a6b1adef765b851db4336d6d80517b419a7de2bde12784670e979ed4a1566c avahi-autoipd-0.6.25-12.el6_5.3.x86_64.rpm
83c3e0768d5fcf1a0a4bb0188bfc0249ccc4410aedc3a5b9c191fc2d5e9abf40 avahi-compat-howl-0.6.25-12.el6_5.3.i686.rpm
da6e09af3ee6c1afedf597b419cd46c28dff0b56688bb39fe3d94413f13bf2b0 avahi-compat-howl-0.6.25-12.el6_5.3.x86_64.rpm
77c57e79803d17f2740987963484dae2289df53ed7f9b13b6e2ab86d6ccc86e1 avahi-compat-howl-devel-0.6.25-12.el6_5.3.i686.rpm
69d15dec25fa31ec75af4d8069f144faf9890f9972edcafe533f952ff8e462c5 avahi-compat-howl-devel-0.6.25-12.el6_5.3.x86_64.rpm
adf9582d2f1dce306949df07ce752c9e647dd2f66df34e7cf35c7323c2ba6f92 avahi-compat-libdns_sd-0.6.25-12.el6_5.3.i686.rpm
48d9db96596c2d9b73cda609ba89ddba12907fc0a680aa0256e5a718f0fa0c62 avahi-compat-libdns_sd-0.6.25-12.el6_5.3.x86_64.rpm
b4493e6f26c2b36827bbfbd21a83e58b2ecf964bd0e52601be977388fea91948 avahi-compat-libdns_sd-devel-0.6.25-12.el6_5.3.i686.rpm
4f8954a76ffefadb864bda10e9ab614b52d89a439cb0ea02543fe27e2e921de3 avahi-compat-libdns_sd-devel-0.6.25-12.el6_5.3.x86_64.rpm
667edbf1a9dd2f5dd406a130b079d74579188a3c11b4d1afdcf58282c23c282a avahi-devel-0.6.25-12.el6_5.3.i686.rpm
ae23b436451ce4e5df07937ed4c0cf272b410f8539097ca9bba7c4ff2a0c849c avahi-devel-0.6.25-12.el6_5.3.x86_64.rpm
ef791578781fa1827a4f029b01ee44b4d5782a8388ad4c2c3da6877ea306275b avahi-dnsconfd-0.6.25-12.el6_5.3.x86_64.rpm
216535bd6fe030b6deacd12ccb95ddc365eadb0ffb74a41ca7c78b47a51d9e9a avahi-glib-0.6.25-12.el6_5.3.i686.rpm
de1e412d47e0c6d72dcdd286941a0a7e4f6e39f68431cbda6ec0995dc4f0604b avahi-glib-0.6.25-12.el6_5.3.x86_64.rpm
07f2f7f1755f336f675695c57f3f51ab4b273362c410ace22e1552060da7cc5e avahi-glib-devel-0.6.25-12.el6_5.3.i686.rpm
b7f774cddffd5699809ef0834d9cd67a0ca49dc645d943904efa43087cbf5c5c avahi-glib-devel-0.6.25-12.el6_5.3.x86_64.rpm
cd2e4fa6203c297efe34360f8e9bee83124e9df9fa647b26f9d7f321de2a63ae avahi-gobject-0.6.25-12.el6_5.3.i686.rpm
39295162433218e3ab65a7c825478fd1d4970156a9890a509c4be15cdd4e3f4e avahi-gobject-0.6.25-12.el6_5.3.x86_64.rpm
598def41091267cbbc54ae5a79b26747ae5af3549a9c7d4976cab81b709e6af0 avahi-gobject-devel-0.6.25-12.el6_5.3.i686.rpm
0dea5eaeb27e2eba9e25723e339a078b92f7e6c9645cbc149e8970507671725f avahi-gobject-devel-0.6.25-12.el6_5.3.x86_64.rpm
9f27a8630f7bfd4cd7e8302aca8be7c8b91af6361a6aa0d8ee07f3e8fe7eee97 avahi-libs-0.6.25-12.el6_5.3.i686.rpm
9e894833badd52c9ac08bc3334a4be480bb0ea96bcebf2021079febea8465be5 avahi-libs-0.6.25-12.el6_5.3.x86_64.rpm
8feba5d7ce0fb18cd4b8e9b242c64fec6d32b9f98792127a3c52cc2f0ad8b236 avahi-qt3-0.6.25-12.el6_5.3.i686.rpm
7dbfd56b8df2751f4acef4cf337c954da39278402772d9512a42c9d01462455c avahi-qt3-0.6.25-12.el6_5.3.x86_64.rpm
a84e07e8fa097d28d6c7f9a03659cad949dfd5d40db0a9f4f2c0f3c02ec5d5e3 avahi-qt3-devel-0.6.25-12.el6_5.3.i686.rpm
d9010311995430fd1d02c82acaa5817cb3341f9d79588b8a10def8beb1901f84 avahi-qt3-devel-0.6.25-12.el6_5.3.x86_64.rpm
6a3b7648e16e15b78c48b6bda78ab332c6b8f456395078e0c32fbdbedc8b557d avahi-qt4-0.6.25-12.el6_5.3.i686.rpm
e2defa69b2906cf02e3d5f8db3cb60ba99d20f74d4583c574161e2616610d4c6 avahi-qt4-0.6.25-12.el6_5.3.x86_64.rpm
6de0ee5928a105c5f0e848461f9c3b7a585a2ca166f69e74080483078d7474ed avahi-qt4-devel-0.6.25-12.el6_5.3.i686.rpm
192290bd31ed17c56eb756cc8ce8f6cd444f7155a8c681577a3d3c639e37e80d avahi-qt4-devel-0.6.25-12.el6_5.3.x86_64.rpm
cc89218162114f6d45d2572d08d7b614cb60c3abe905e60ceebf32e3650c7fdc avahi-tools-0.6.25-12.el6_5.3.x86_64.rpm
1f327f102c73cacd9ebee9858f656d0503977e233dc60b4fa4fd1f7e7cf140d9 avahi-ui-0.6.25-12.el6_5.3.i686.rpm
69461e9cb7c999d4e1d2b25b3490ec70f68422a90451d5dce8aba161d5aa2bee avahi-ui-0.6.25-12.el6_5.3.x86_64.rpm
c473c308f351a5fa78c2a7108c3298e30aed607311d3134035e0a88d107d54ff avahi-ui-devel-0.6.25-12.el6_5.3.i686.rpm
b76a694d90a3a11e4bdece9b4f2bae05aaa6bcf00e8d351e2b7f47ff724d0bb8 avahi-ui-devel-0.6.25-12.el6_5.3.x86_64.rpm
6a720fae78e7b26a9686f54ae8f54793a36d55bfee57a18a9dd0751448207765 avahi-ui-tools-0.6.25-12.el6_5.3.x86_64.rpm
Source:
b0ee191710d2c4046ddf2c21bac93edddca3c93452f52cdf36febbc56c239e31 avahi-0.6.25-12.el6_5.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1140.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
c05c0eb98850d7593eec0089f6d64c2a81df5bdf2e0cce873cc1b4666dee1191 avahi-0.6.25-12.el6_5.3.i686.rpm
2c50f0628744b47f86a89dfb4f283e6cd56ac611aec8712539fad14538100c1d avahi-autoipd-0.6.25-12.el6_5.3.i686.rpm
83c3e0768d5fcf1a0a4bb0188bfc0249ccc4410aedc3a5b9c191fc2d5e9abf40 avahi-compat-howl-0.6.25-12.el6_5.3.i686.rpm
77c57e79803d17f2740987963484dae2289df53ed7f9b13b6e2ab86d6ccc86e1 avahi-compat-howl-devel-0.6.25-12.el6_5.3.i686.rpm
adf9582d2f1dce306949df07ce752c9e647dd2f66df34e7cf35c7323c2ba6f92 avahi-compat-libdns_sd-0.6.25-12.el6_5.3.i686.rpm
b4493e6f26c2b36827bbfbd21a83e58b2ecf964bd0e52601be977388fea91948 avahi-compat-libdns_sd-devel-0.6.25-12.el6_5.3.i686.rpm
667edbf1a9dd2f5dd406a130b079d74579188a3c11b4d1afdcf58282c23c282a avahi-devel-0.6.25-12.el6_5.3.i686.rpm
5d4e6ef4db89d0c0b072b9767e6b30000ad869b049666455258c25a68e77f19e avahi-dnsconfd-0.6.25-12.el6_5.3.i686.rpm
216535bd6fe030b6deacd12ccb95ddc365eadb0ffb74a41ca7c78b47a51d9e9a avahi-glib-0.6.25-12.el6_5.3.i686.rpm
07f2f7f1755f336f675695c57f3f51ab4b273362c410ace22e1552060da7cc5e avahi-glib-devel-0.6.25-12.el6_5.3.i686.rpm
cd2e4fa6203c297efe34360f8e9bee83124e9df9fa647b26f9d7f321de2a63ae avahi-gobject-0.6.25-12.el6_5.3.i686.rpm
598def41091267cbbc54ae5a79b26747ae5af3549a9c7d4976cab81b709e6af0 avahi-gobject-devel-0.6.25-12.el6_5.3.i686.rpm
9f27a8630f7bfd4cd7e8302aca8be7c8b91af6361a6aa0d8ee07f3e8fe7eee97 avahi-libs-0.6.25-12.el6_5.3.i686.rpm
8feba5d7ce0fb18cd4b8e9b242c64fec6d32b9f98792127a3c52cc2f0ad8b236 avahi-qt3-0.6.25-12.el6_5.3.i686.rpm
a84e07e8fa097d28d6c7f9a03659cad949dfd5d40db0a9f4f2c0f3c02ec5d5e3 avahi-qt3-devel-0.6.25-12.el6_5.3.i686.rpm
6a3b7648e16e15b78c48b6bda78ab332c6b8f456395078e0c32fbdbedc8b557d avahi-qt4-0.6.25-12.el6_5.3.i686.rpm
6de0ee5928a105c5f0e848461f9c3b7a585a2ca166f69e74080483078d7474ed avahi-qt4-devel-0.6.25-12.el6_5.3.i686.rpm
f7dfdc24723aee6c564ec232fe78974d0358c9f754393eb56d176403433abd7b avahi-tools-0.6.25-12.el6_5.3.i686.rpm
1f327f102c73cacd9ebee9858f656d0503977e233dc60b4fa4fd1f7e7cf140d9 avahi-ui-0.6.25-12.el6_5.3.i686.rpm
c473c308f351a5fa78c2a7108c3298e30aed607311d3134035e0a88d107d54ff avahi-ui-devel-0.6.25-12.el6_5.3.i686.rpm
21b467e10f2069c0b83de8f6fb6c5c2cea4b3c227408747cdf11995511092715 avahi-ui-tools-0.6.25-12.el6_5.3.i686.rpm
x86_64:
c05c0eb98850d7593eec0089f6d64c2a81df5bdf2e0cce873cc1b4666dee1191 avahi-0.6.25-12.el6_5.3.i686.rpm
a85601e7d415f90ef47648c57dedc0f1a6d09e9b3c07f97c409a33819d313814 avahi-0.6.25-12.el6_5.3.x86_64.rpm
86a6b1adef765b851db4336d6d80517b419a7de2bde12784670e979ed4a1566c avahi-autoipd-0.6.25-12.el6_5.3.x86_64.rpm
83c3e0768d5fcf1a0a4bb0188bfc0249ccc4410aedc3a5b9c191fc2d5e9abf40 avahi-compat-howl-0.6.25-12.el6_5.3.i686.rpm
da6e09af3ee6c1afedf597b419cd46c28dff0b56688bb39fe3d94413f13bf2b0 avahi-compat-howl-0.6.25-12.el6_5.3.x86_64.rpm
77c57e79803d17f2740987963484dae2289df53ed7f9b13b6e2ab86d6ccc86e1 avahi-compat-howl-devel-0.6.25-12.el6_5.3.i686.rpm
69d15dec25fa31ec75af4d8069f144faf9890f9972edcafe533f952ff8e462c5 avahi-compat-howl-devel-0.6.25-12.el6_5.3.x86_64.rpm
adf9582d2f1dce306949df07ce752c9e647dd2f66df34e7cf35c7323c2ba6f92 avahi-compat-libdns_sd-0.6.25-12.el6_5.3.i686.rpm
48d9db96596c2d9b73cda609ba89ddba12907fc0a680aa0256e5a718f0fa0c62 avahi-compat-libdns_sd-0.6.25-12.el6_5.3.x86_64.rpm
b4493e6f26c2b36827bbfbd21a83e58b2ecf964bd0e52601be977388fea91948 avahi-compat-libdns_sd-devel-0.6.25-12.el6_5.3.i686.rpm
4f8954a76ffefadb864bda10e9ab614b52d89a439cb0ea02543fe27e2e921de3 avahi-compat-libdns_sd-devel-0.6.25-12.el6_5.3.x86_64.rpm
667edbf1a9dd2f5dd406a130b079d74579188a3c11b4d1afdcf58282c23c282a avahi-devel-0.6.25-12.el6_5.3.i686.rpm
ae23b436451ce4e5df07937ed4c0cf272b410f8539097ca9bba7c4ff2a0c849c avahi-devel-0.6.25-12.el6_5.3.x86_64.rpm
ef791578781fa1827a4f029b01ee44b4d5782a8388ad4c2c3da6877ea306275b avahi-dnsconfd-0.6.25-12.el6_5.3.x86_64.rpm
216535bd6fe030b6deacd12ccb95ddc365eadb0ffb74a41ca7c78b47a51d9e9a avahi-glib-0.6.25-12.el6_5.3.i686.rpm
de1e412d47e0c6d72dcdd286941a0a7e4f6e39f68431cbda6ec0995dc4f0604b avahi-glib-0.6.25-12.el6_5.3.x86_64.rpm
07f2f7f1755f336f675695c57f3f51ab4b273362c410ace22e1552060da7cc5e avahi-glib-devel-0.6.25-12.el6_5.3.i686.rpm
b7f774cddffd5699809ef0834d9cd67a0ca49dc645d943904efa43087cbf5c5c avahi-glib-devel-0.6.25-12.el6_5.3.x86_64.rpm
cd2e4fa6203c297efe34360f8e9bee83124e9df9fa647b26f9d7f321de2a63ae avahi-gobject-0.6.25-12.el6_5.3.i686.rpm
39295162433218e3ab65a7c825478fd1d4970156a9890a509c4be15cdd4e3f4e avahi-gobject-0.6.25-12.el6_5.3.x86_64.rpm
598def41091267cbbc54ae5a79b26747ae5af3549a9c7d4976cab81b709e6af0 avahi-gobject-devel-0.6.25-12.el6_5.3.i686.rpm
0dea5eaeb27e2eba9e25723e339a078b92f7e6c9645cbc149e8970507671725f avahi-gobject-devel-0.6.25-12.el6_5.3.x86_64.rpm
9f27a8630f7bfd4cd7e8302aca8be7c8b91af6361a6aa0d8ee07f3e8fe7eee97 avahi-libs-0.6.25-12.el6_5.3.i686.rpm
9e894833badd52c9ac08bc3334a4be480bb0ea96bcebf2021079febea8465be5 avahi-libs-0.6.25-12.el6_5.3.x86_64.rpm
8feba5d7ce0fb18cd4b8e9b242c64fec6d32b9f98792127a3c52cc2f0ad8b236 avahi-qt3-0.6.25-12.el6_5.3.i686.rpm
7dbfd56b8df2751f4acef4cf337c954da39278402772d9512a42c9d01462455c avahi-qt3-0.6.25-12.el6_5.3.x86_64.rpm
a84e07e8fa097d28d6c7f9a03659cad949dfd5d40db0a9f4f2c0f3c02ec5d5e3 avahi-qt3-devel-0.6.25-12.el6_5.3.i686.rpm
d9010311995430fd1d02c82acaa5817cb3341f9d79588b8a10def8beb1901f84 avahi-qt3-devel-0.6.25-12.el6_5.3.x86_64.rpm
6a3b7648e16e15b78c48b6bda78ab332c6b8f456395078e0c32fbdbedc8b557d avahi-qt4-0.6.25-12.el6_5.3.i686.rpm
e2defa69b2906cf02e3d5f8db3cb60ba99d20f74d4583c574161e2616610d4c6 avahi-qt4-0.6.25-12.el6_5.3.x86_64.rpm
6de0ee5928a105c5f0e848461f9c3b7a585a2ca166f69e74080483078d7474ed avahi-qt4-devel-0.6.25-12.el6_5.3.i686.rpm
192290bd31ed17c56eb756cc8ce8f6cd444f7155a8c681577a3d3c639e37e80d avahi-qt4-devel-0.6.25-12.el6_5.3.x86_64.rpm
cc89218162114f6d45d2572d08d7b614cb60c3abe905e60ceebf32e3650c7fdc avahi-tools-0.6.25-12.el6_5.3.x86_64.rpm
1f327f102c73cacd9ebee9858f656d0503977e233dc60b4fa4fd1f7e7cf140d9 avahi-ui-0.6.25-12.el6_5.3.i686.rpm
69461e9cb7c999d4e1d2b25b3490ec70f68422a90451d5dce8aba161d5aa2bee avahi-ui-0.6.25-12.el6_5.3.x86_64.rpm
c473c308f351a5fa78c2a7108c3298e30aed607311d3134035e0a88d107d54ff avahi-ui-devel-0.6.25-12.el6_5.3.i686.rpm
b76a694d90a3a11e4bdece9b4f2bae05aaa6bcf00e8d351e2b7f47ff724d0bb8 avahi-ui-devel-0.6.25-12.el6_5.3.x86_64.rpm
6a720fae78e7b26a9686f54ae8f54793a36d55bfee57a18a9dd0751448207765 avahi-ui-tools-0.6.25-12.el6_5.3.x86_64.rpm
Source:
b0ee191710d2c4046ddf2c21bac93edddca3c93452f52cdf36febbc56c239e31 avahi-0.6.25-12.el6_5.3.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[USN-2338-1] Lua vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJUBxxCAAoJEGVp2FWnRL6TTRcP/ihNJjnIMdb6p4SD5hUGXikB
YvDPAec3AzDJ1cR48savqM2puqm/Y+o5aGnl+NRtavi2e+3nxnHUxU9Nx73tkbN3
ZnPHoc1t3InRvD0m7nexRQT7uhavyNLUdhRjt6uwlPMsQ2CVeDRU/OA0Eh+2K/Tr
JK2Kr5uR7g3H499uClZDOldLJjHBAcV5eQ/op35rcZUYY7s44A5hO0htxzsiJVU8
S2B/QgZCFT+vq4Pd6Q/XrUEBglbMjSdH5KEZNSjj4TzBzdzGxiap+H10B2m3JZYB
R8XqHd3cWj4BfJbnNUvY5BH/jsSh7Mff3NqraMAQchhVJdqkrnrJV6hjQ6sMjvsb
5bDDrBxQOM8LnTkN01tqW4WEhGb9hTjEQqO6c8paabyCWi4IAgiTzIMMSTwtSK8n
qhoNPhX3IOI1pAZAvwQtLPVtX1UuwAzLouwgAXwb4b/TnyhhzoW9esLX4i2ATgtL
C3X5ljz1hxYeuNzPxzXpJ3S1R1Acj/VBElX7Rx3kuE0oFHHAP0/BEKfyhJKbn2tV
uGyu4sXuxinhnQoDsBmtp0p9AS0RCMaDXfaKl2YDvsZE0d3F6xayIb79B6I5AzRL
yqaL9B9BSB4EnCKYeUqWMfj6WUSO0YTQ2W8SxuXyVZADtJgAEjJMvanrnGSB0tv9
oIKccayYzXmWabHsyvqF
=Tug6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2338-1
September 03, 2014
lua5.1 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Lua could be made to crash or run programs.
Software Description:
- lua5.1: Simple, extensible, embeddable programming language
Details:
It was discovered that Lua incorrectly handled certain vararg functions
with a large number of fixed parameters. An attacker could use this issue
to cause Lua applications to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
liblua5.1-0 5.1.5-5ubuntu0.1
lua5.1 5.1.5-5ubuntu0.1
Ubuntu 12.04 LTS:
liblua5.1-0 5.1.4-12ubuntu1.1
lua5.1 5.1.4-12ubuntu1.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2338-1
CVE-2014-5461
Package Information:
https://launchpad.net/ubuntu/+source/lua5.1/5.1.5-5ubuntu0.1
https://launchpad.net/ubuntu/+source/lua5.1/5.1.4-12ubuntu1.1
Version: GnuPG v1
iQIcBAEBCgAGBQJUBxxCAAoJEGVp2FWnRL6TTRcP/ihNJjnIMdb6p4SD5hUGXikB
YvDPAec3AzDJ1cR48savqM2puqm/Y+o5aGnl+NRtavi2e+3nxnHUxU9Nx73tkbN3
ZnPHoc1t3InRvD0m7nexRQT7uhavyNLUdhRjt6uwlPMsQ2CVeDRU/OA0Eh+2K/Tr
JK2Kr5uR7g3H499uClZDOldLJjHBAcV5eQ/op35rcZUYY7s44A5hO0htxzsiJVU8
S2B/QgZCFT+vq4Pd6Q/XrUEBglbMjSdH5KEZNSjj4TzBzdzGxiap+H10B2m3JZYB
R8XqHd3cWj4BfJbnNUvY5BH/jsSh7Mff3NqraMAQchhVJdqkrnrJV6hjQ6sMjvsb
5bDDrBxQOM8LnTkN01tqW4WEhGb9hTjEQqO6c8paabyCWi4IAgiTzIMMSTwtSK8n
qhoNPhX3IOI1pAZAvwQtLPVtX1UuwAzLouwgAXwb4b/TnyhhzoW9esLX4i2ATgtL
C3X5ljz1hxYeuNzPxzXpJ3S1R1Acj/VBElX7Rx3kuE0oFHHAP0/BEKfyhJKbn2tV
uGyu4sXuxinhnQoDsBmtp0p9AS0RCMaDXfaKl2YDvsZE0d3F6xayIb79B6I5AzRL
yqaL9B9BSB4EnCKYeUqWMfj6WUSO0YTQ2W8SxuXyVZADtJgAEjJMvanrnGSB0tv9
oIKccayYzXmWabHsyvqF
=Tug6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2338-1
September 03, 2014
lua5.1 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Lua could be made to crash or run programs.
Software Description:
- lua5.1: Simple, extensible, embeddable programming language
Details:
It was discovered that Lua incorrectly handled certain vararg functions
with a large number of fixed parameters. An attacker could use this issue
to cause Lua applications to crash, resulting in a denial of service, or
possibly execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
liblua5.1-0 5.1.5-5ubuntu0.1
lua5.1 5.1.5-5ubuntu0.1
Ubuntu 12.04 LTS:
liblua5.1-0 5.1.4-12ubuntu1.1
lua5.1 5.1.4-12ubuntu1.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2338-1
CVE-2014-5461
Package Information:
https://launchpad.net/ubuntu/+source/lua5.1/5.1.5-5ubuntu0.1
https://launchpad.net/ubuntu/+source/lua5.1/5.1.4-12ubuntu1.1
[CentOS-announce] The epel-release package is now available via Extras
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
The CentOS project is pleased to announce that the epel-release
package is now included in the CentOS Extras repositories for all
current versions of CentOS.
In order to use packages from the EPEL repository, users may 'yum
install epel-release'
NOTE: This does not change the existing support structure for either
EPEL or CentOS. If you encounter a bug with a package from EPEL,
please file the bug with EPEL. CentOS will continue to provide best
effort support for distribution packages.
- --
Jim Perrin
The CentOS Project | http://www.centos.org
twitter: @BitIntegrity | GPG Key: FA09AD77
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iQIcBAEBAgAGBQJUBxOmAAoJEBbHyC76Ca13Jz0QAMLzbG2BOYe+5E06uhAIgw72
tAoLudNTjjs3XLQCbHIjZNrr3RaugX2lxLk5CAHq4VnuVOqv1vBalbb49LJJJlft
3RbdXowASNWU4yihqQjO5STsqIEHX7hfqqBjkWadeQAxA1iZhXT+x5eFsgz84iF6
hN1mUwlr6vv6EW6wKMD1M61LihNM8uqWRyyigD8g6RxmHAdw1Ernr8pXV6U0pbU4
Rk9jAlI6xeYP+m0QVs4ppNnRowk9P6O761pi4wThtrpETJAptWf67aNfLzGHR3zA
1VVoBDKUzMFYcqBczVL/JblHebB0oTfKq7iQF+W7mK6YlaaK/YFRTrcL1kIbpIT/
he6aSJjVC8DGpKLu5kI3shxU1UoI7jmB0IQ0oF/RuX3L1fD/T/pe6dFwQb4n3AEw
zzlU6I6+bIZMsjXdWaREFXMFbeGiAQqYFOfUY5GxYAj1HzNWU0zg4duhB7/nfxm8
XOooAp05bnh5U7jFoNkba6zh5b65cXQHBvJn9J9MD7VdKrSNvazaWrrf7tZ2LIXl
9Ci27JUg/PWcWz7fVzcRXGMdIa/9dWQqLhvVaCQAtGog7CZ9cxUTgINYZFkU3wDg
7pvuSpe994tLIEd4ubvOynkgF7BnS3Z369JTUrVkPY3hylL5nn/q3OpzGqOb12YO
8jxBMl9DKWbPEicl8Qth
=fA85
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Hash: SHA1
The CentOS project is pleased to announce that the epel-release
package is now included in the CentOS Extras repositories for all
current versions of CentOS.
In order to use packages from the EPEL repository, users may 'yum
install epel-release'
NOTE: This does not change the existing support structure for either
EPEL or CentOS. If you encounter a bug with a package from EPEL,
please file the bug with EPEL. CentOS will continue to provide best
effort support for distribution packages.
- --
Jim Perrin
The CentOS Project | http://www.centos.org
twitter: @BitIntegrity | GPG Key: FA09AD77
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iQIcBAEBAgAGBQJUBxOmAAoJEBbHyC76Ca13Jz0QAMLzbG2BOYe+5E06uhAIgw72
tAoLudNTjjs3XLQCbHIjZNrr3RaugX2lxLk5CAHq4VnuVOqv1vBalbb49LJJJlft
3RbdXowASNWU4yihqQjO5STsqIEHX7hfqqBjkWadeQAxA1iZhXT+x5eFsgz84iF6
hN1mUwlr6vv6EW6wKMD1M61LihNM8uqWRyyigD8g6RxmHAdw1Ernr8pXV6U0pbU4
Rk9jAlI6xeYP+m0QVs4ppNnRowk9P6O761pi4wThtrpETJAptWf67aNfLzGHR3zA
1VVoBDKUzMFYcqBczVL/JblHebB0oTfKq7iQF+W7mK6YlaaK/YFRTrcL1kIbpIT/
he6aSJjVC8DGpKLu5kI3shxU1UoI7jmB0IQ0oF/RuX3L1fD/T/pe6dFwQb4n3AEw
zzlU6I6+bIZMsjXdWaREFXMFbeGiAQqYFOfUY5GxYAj1HzNWU0zg4duhB7/nfxm8
XOooAp05bnh5U7jFoNkba6zh5b65cXQHBvJn9J9MD7VdKrSNvazaWrrf7tZ2LIXl
9Ci27JUg/PWcWz7fVzcRXGMdIa/9dWQqLhvVaCQAtGog7CZ9cxUTgINYZFkU3wDg
7pvuSpe994tLIEd4ubvOynkgF7BnS3Z369JTUrVkPY3hylL5nn/q3OpzGqOb12YO
8jxBMl9DKWbPEicl8Qth
=fA85
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Tuesday, September 2, 2014
[USN-2326-1] Oxide vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAEBAgAGBQJUBjSnAAoJEGEfvezVlG4Pjf0H/jsHcV2yrF6q8/6wWzCl8B6W
nCx7pi3T2aj3Vzw5OAS09dcS4VSiYJC+Ub5/tLKQDvwYY9gAeg1j+So7lG9IQPKE
GUPuKPq17NYW7YIhKHKuag59zagDnYKVOpiMASvzdt2oNa5cGaOar+V1CDkIMYi7
f9tnNd6iMedtc11hKgGJaLqCeRyrM9j4u6QPjf6LHOtKmkIclPTMrMDni8JlqWyV
6lCNn77rpNJyIxhgUXuQM5B5cEgFTw6R9TQSXH3eRCVSlLOLDdXLLKoQ4lb/9954
GGb7chSNeJzVGBVUc9+AYpMut2WZzc2SDqGMSPCPoooEhbt3CWHq6aFGVGrUdOE=
=vFYR
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2326-1
September 02, 2014
oxide-qt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Oxide.
Software Description:
- oxide-qt: Web browser engine library for Qt (QML plugin)
Details:
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3168)
A use-after-free was discovered in the DOM implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3169)
A use-after-free was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-3171)
It was discovered that WebGL clear calls did not interact properly with
the state of a draw buffer. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service. (CVE-2014-3173)
A threading issue was discovered in the Web Audio API during attempts to
update biquad filter coefficients. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service. (CVE-2014-3174)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3175)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
liboxideqtcore0 1.1.2-0ubuntu0.14.04.1
oxideqt-codecs 1.1.2-0ubuntu0.14.04.1
oxideqt-codecs-extra 1.1.2-0ubuntu0.14.04.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2326-1
CVE-2014-3168, CVE-2014-3169, CVE-2014-3171, CVE-2014-3173,
CVE-2014-3174, CVE-2014-3175
Package Information:
https://launchpad.net/ubuntu/+source/oxide-qt/1.1.2-0ubuntu0.14.04.1
Version: GnuPG v1
iQEcBAEBAgAGBQJUBjSnAAoJEGEfvezVlG4Pjf0H/jsHcV2yrF6q8/6wWzCl8B6W
nCx7pi3T2aj3Vzw5OAS09dcS4VSiYJC+Ub5/tLKQDvwYY9gAeg1j+So7lG9IQPKE
GUPuKPq17NYW7YIhKHKuag59zagDnYKVOpiMASvzdt2oNa5cGaOar+V1CDkIMYi7
f9tnNd6iMedtc11hKgGJaLqCeRyrM9j4u6QPjf6LHOtKmkIclPTMrMDni8JlqWyV
6lCNn77rpNJyIxhgUXuQM5B5cEgFTw6R9TQSXH3eRCVSlLOLDdXLLKoQ4lb/9954
GGb7chSNeJzVGBVUc9+AYpMut2WZzc2SDqGMSPCPoooEhbt3CWHq6aFGVGrUdOE=
=vFYR
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2326-1
September 02, 2014
oxide-qt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Oxide.
Software Description:
- oxide-qt: Web browser engine library for Qt (QML plugin)
Details:
A use-after-free was discovered in the SVG implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3168)
A use-after-free was discovered in the DOM implementation in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2014-3169)
A use-after-free was discovered in V8. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via renderer crash, or execute arbitrary
code with the privileges of the sandboxed render process. (CVE-2014-3171)
It was discovered that WebGL clear calls did not interact properly with
the state of a draw buffer. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service. (CVE-2014-3173)
A threading issue was discovered in the Web Audio API during attempts to
update biquad filter coefficients. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service. (CVE-2014-3174)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial of
service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2014-3175)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
liboxideqtcore0 1.1.2-0ubuntu0.14.04.1
oxideqt-codecs 1.1.2-0ubuntu0.14.04.1
oxideqt-codecs-extra 1.1.2-0ubuntu0.14.04.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2326-1
CVE-2014-3168, CVE-2014-3169, CVE-2014-3171, CVE-2014-3173,
CVE-2014-3174, CVE-2014-3175
Package Information:
https://launchpad.net/ubuntu/+source/oxide-qt/1.1.2-0ubuntu0.14.04.1
[announce] NYC*BUG Wednesday Sept 3
Sorry for the delay...
2014-09-03 18:45, about.com (1500 Broadway, 43rd Street, 6th Floor)
Notice: RSVP to rsvp at nycbug.org and bring photo ID. RSVPs must be
received by 2 PM, day-of.
This month's meeting will be a discussion about the status of last
month's OpenBSD porting, plus a short presentation on the deprecation of
FreeBSDs pkg_* tools and its replacement with pkgng.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
2014-09-03 18:45, about.com (1500 Broadway, 43rd Street, 6th Floor)
Notice: RSVP to rsvp at nycbug.org and bring photo ID. RSVPs must be
received by 2 PM, day-of.
This month's meeting will be a discussion about the status of last
month's OpenBSD porting, plus a short presentation on the deprecation of
FreeBSDs pkg_* tools and its replacement with pkgng.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
Subscribe to:
Posts (Atom)