Tuesday, December 2, 2014
[FreeBSD-Announce] FreeBSD Foundation's 2014 Year-End Fundraising Campaign
Comment: GPGTools - http://gpgtools.org
iQEcBAEBCgAGBQJUfdzMAAoJELLsYiYPtogfSCkIAKnK29b8ZPWMQ4SAstMAZHYh
jfhFfVFJJFTos9+80E/GsuFJyNDqNcteVpOrmEA2K9lV3VpDDx7txDBjYxj/dvPK
FxHnwq0B5NCAiE2UFpZq7X5jFIXpHYsuR1ZSvOp0jxXVn9fBYHDJJJkIJ62zTa8H
7Ofyz5ymch4FIOpiuQ6ThLHtsCIBHcSqQ+VlDUJ7tnG+XdR2R/uJ+WNPV705zCiQ
yR0Sl6sq6gK0NYNO4CtX6T7HDzs7gdVhu5d78H5Mj8KFMb3RG8Yaqk0sxb0cNLpI
ykNjuc02YBYIe8ZHLjpQlNOVj0Laj2GjPEDPcni5Mun4hdOQscHNI0u3XPoxHZ4=
=h7XI
-----END PGP SIGNATURE-----
Dear FreeBSD Community,
In celebration of #GivingTuesday, we are reaching out to the FreeBSD community and asking you to consider giving back to the Foundation and FreeBSD Project by making a donation today. #GivingTuesday was created to celebrate a global day dedicated to giving back, and it's the perfect opportunity to invest in the FreeBSD Project and help us continue to grow and support FreeBSD.
Please take a moment to read our Year-End Fundraising Campaign Letter here:
http://freebsdfoundation.blogspot.com/2014/12/freebsd-foundation-2014-year-end.html
Thank you for your support!
Deb Goodkin
Executive Director
The FreeBSD Foundation
[USN-2430-1] OpenVPN vulnerability
Version: GnuPG v1
iQIcBAEBCgAGBQJUfddnAAoJEGVp2FWnRL6TL2cQAKZgQMAsJVT6O5Ea7QAh1h3q
STXQgwsRP3c/GKbNM/FTYJEv2NfBoB9Fs+bgBYX9f8YhnwZT7k34DIdltIWVY75X
8Cu7m5Qu+bkCRKkuqMAoPkb4a2z9clbmPtpDGM9UN0SmHiIxfH0mxXMvVImEkBvf
7TEYF47livxglBRCj0Br8BCqkAuUh9jpIY2UfpNzeHudPdrL0zvbINORbzfFu1G5
Kc+xIb6ZKgvDnruLYvKRAb1/swrIkQI4+mx1ishpgp1BCe/0p/Y8v8d3OVFX+LeT
JtaY/z65vNb5k622kgdmakAgd6haW4Li7yIZOTZndzVJOvsUFb4PGXHrmqXEG9T0
3ZXRQ2eiY8qCjAxIHyJrFQngwEWo+TUBzu0wwSMkI/k67j0HNMKE4Cr2nQzVH4Qu
nIV390Wz4/R+kzzHfsz1O/qq9A5fo+A8RLgLJ5QlzooqXYmPnn8rXGbYDaASXPtK
G+opZ6zzHeCIucgVfZDVZ8AgMbkUyRH4TXp6kG6v5aWKgYFw46C1/jtApwW6R+n1
vIkoH96aec4FD7g+nbXWmypHAe3LD4oJo4VrjfVBps67NlYOiZ2XCxsVs8dbh6xF
D8cnn2zPU59Qz8Ie7aCTVG8E64CQZIwopqwLwMINMSC77vwXgj/7SKpH6oxsafAL
O9W2FcuYfMl8Lso3nau7
=mc1e
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2430-1
December 02, 2014
openvpn vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
OpenVPN could be made to crash if it received specially crafted network
traffic.
Software Description:
- openvpn: virtual private network software
Details:
Dragana Damjanovic discovered that OpenVPN incorrectly handled certain
control channel packets. An authenticated attacker could use this issue to
cause an OpenVPN server to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
openvpn 2.3.2-9ubuntu1.1
Ubuntu 14.04 LTS:
openvpn 2.3.2-7ubuntu3.1
Ubuntu 12.04 LTS:
openvpn 2.2.1-8ubuntu1.4
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2430-1
CVE-2014-8104
Package Information:
https://launchpad.net/ubuntu/+source/openvpn/2.3.2-9ubuntu1.1
https://launchpad.net/ubuntu/+source/openvpn/2.3.2-7ubuntu3.1
https://launchpad.net/ubuntu/+source/openvpn/2.2.1-8ubuntu1.4
Monday, December 1, 2014
Fedora 21 Final Go/No-Go Meeting, Thursday, December 04 @ 17:00 UTC
meeting, wherein we shall determine the readiness of the Fedora 21.
Thursday, December 04, 2014 17:00 UTC (12 AM EST, 9 AM PST, 18:00 CET)
"Before each public release Development, QA and Release Engineering meet
to determine if the release criteria are met for a particular release.
This meeting is called the Go/No-Go Meeting."
"Verifying that the Release criteria are met is the responsibility of
the QA Team."
Release Candidate (RC) availability and good QA coverage are prerequisites
for the Go/No-Go decision but meeting itself is held in any case.
For more details about this meeting see:
https://fedoraproject.org/wiki/Go_No_Go_Meeting
In the meantime, keep an eye on the Fedora 21 Final Blocker list:
https://qa.fedoraproject.org/blockerbugs/milestone/21/final/buglist
Note: as I'll be already travelling to FAD Rheinland 2014, I could be
a bit late...
Jaroslav
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[announce] NYC*BUG Reminder
and Dine" starting at 7 PM.
The address is 485 10th Avenue between 37th and 38th streets.
If you're not on the RSVP list, you are unlikely to get in.
*****
There is no December meeting this Wednesday.
*****
The January 7th meeting "Designing Versatile Unix Utilities" with Eric
Radman is posted at
http://www.nycbug.org/index.cgi?action=event&do=view&id=10355#10355.
The location is TBA.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
Fedora 21 Final Release Readiness Meeting :: Thursday, Dec. 04, 19:00 UTC
date: 2014-12-04 place: irc.freenode.net in #fedora-meeting-2
time: 19:00 UTC (2 PM EST, 11 AM PST, 20:00 CET)
This Thursday, December 04, we will meet to make sure we are coordinated
and ready for the Final release of Fedora 21 on Tuesday, December 09, 2014.
Please note that this meeting will occur on December 09 even if the
release is delayed at the Go/No-Go meeting on the same day two hours
earlier.
You may received this message several times, but I was asked to open this
meeting to the teams and I'll also hope this will raise awareness and more
team representatives will come to this meeting. This meeting works best
when we have representatives from all of the teams. Also, there's a
Fedora badge for active participants!
Jaroslav
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[USN-2429-1] ppp vulnerability
Version: GnuPG v1
iQIcBAEBCgAGBQJUfI5bAAoJEGVp2FWnRL6Two8QALvtwh3m1SXEbzl79icJpIpg
823ZIOzVotw+8Xp9o6qP1tNyKPQN7KdpsvS5ojZRvn4/x2oRdSAdh5zcTIKvkgcw
Am8/RZMezA2c/z8sAgQfNzSMrBwWeR6p1jR7S0d28ZRCHeLuznyGFpUAPpQj0wBw
t/CqEaH3AKUTmXrL1aHpRL441cqA/raR3vH1vHwVOJ3bnZorVGZIJAgw/ojYa2nx
GuC0YFDmOtQMHkeD20sEwMl9IrH/YzavwCb6d6ettsYf8dnA07pQWT6wIGW7X0f9
N0CWbdj+ogtP/ZuS31r04+T11+1zQUzlF/1OUM4occ3viqOv0Nn+JN31L1up59KO
avXJP3eWv0J1OicTgsyTFgExfFBGih3H9MtMOa3q0NQMNTQWlW6wKHtVlhN4MTC9
Q2IdSr+PYAtfYjWjUCjsos0VGuZPNApPQ+kmlJT5JSff3HjdMxNKAzeZkEyXzIx1
/vr2JX6s9PhUoeVr9pFITG/hR1jPYm7ROEsOO2MXpUTs9gJTS89a3HlvKalQ7Ene
0zYT9R9V91rUNby+TwRexLNJS930bNjcC09Z2KRyZFOOtNg3rPQZq8A6AplFJ/Nb
NyO4Sd9+rM24Pv5JsyIykvRxIpkXtrxVA22rzUWv/i7jY+9cGfIcRpJOzJUsbJBM
Vbn1oJzNEdLk83faCG49
=nS3M
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2429-1
December 01, 2014
ppp vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
ppp could be made to crash or run programs as an administrator if it opened
a specially crafted file.
Software Description:
- ppp: Point-to-Point Protocol (PPP)
Details:
It was discovered that ppp incorrectly handled certain options files. A
local attacker could possibly use this issue to escalate privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
ppp 2.4.5-5.1ubuntu3.1
Ubuntu 14.04 LTS:
ppp 2.4.5-5.1ubuntu2.1
Ubuntu 12.04 LTS:
ppp 2.4.5-5ubuntu1.1
Ubuntu 10.04 LTS:
ppp 2.4.5~git20081126t100229-0ubuntu3.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2429-1
CVE-2014-3158
Package Information:
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5.1ubuntu3.1
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5.1ubuntu2.1
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5ubuntu1.1
https://launchpad.net/ubuntu/+source/ppp/2.4.5~git20081126t100229-0ubuntu3.1
[CentOS-announce] CEEA-2014:1917 CentOS 7 ibus-hangul FASTTRACK Enhancement Update
Upstream details at : https://rhn.redhat.com/errata/RHEA-2014-1917.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
4816c8d035c2966aba8812295505e0e87d3f7f86edfa4047aa16f0ddb6971cf7 ibus-hangul-1.4.2-10.el7.x86_64.rpm
Source:
453523f2015d46a26a856b3e0b57282eedf49d74ff65c12881838d4821e3ce72 ibus-hangul-1.4.2-10.el7.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CESA-2014:1912 Moderate CentOS 7 ruby Security Update
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1912.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
93c6319a06c0545dac0e0a6a1066685f07396c350a745655d27e799f0f41a9f6 ruby-2.0.0.353-22.el7_0.x86_64.rpm
86e33edbb18f7d0d8945b6f0c98fa32ccdf2699d6d440b3a00ab71f034fe873e ruby-devel-2.0.0.353-22.el7_0.x86_64.rpm
fd07cccef811c17af83f72f6f3b15739517af811190c8b051837441d02aba0d6 ruby-doc-2.0.0.353-22.el7_0.noarch.rpm
15d0f1940b5c33e0daf36ded54218e063a442b6f38f0f9511a9d299d31d0bb99 rubygem-bigdecimal-1.2.0-22.el7_0.x86_64.rpm
c060618a05f25ef1eddf2c26e4a7c8f75e458264113613965401c9d0d085667d rubygem-io-console-0.4.2-22.el7_0.x86_64.rpm
6192d1d652b260ba142fec6a24d68fb794e1e5d6ddaf15ea5cc9762ed96225cc rubygem-json-1.7.7-22.el7_0.x86_64.rpm
84e90436cd96a1f2da988aa83ed31e1d251a72b228457e66e5bebdb612a60a3e rubygem-minitest-4.3.2-22.el7_0.noarch.rpm
55d6d27b11e10c74da42c6942a768bfb955890f824cc0d173a34479868c7fcad rubygem-psych-2.0.0-22.el7_0.x86_64.rpm
589d407175e8b50ad83908488e58f95a0b3664de3b3364acd9740f71ec0350db rubygem-rake-0.9.6-22.el7_0.noarch.rpm
91386d554c388ebc53e7a14262b8f685741b90693f588839f7ee2492bad1028d rubygem-rdoc-4.0.0-22.el7_0.noarch.rpm
3028972f561fed8d9c0ce1b5fac5cb790b32e7cfbfbfaf4a4e664259e6edbb24 rubygems-2.0.14-22.el7_0.noarch.rpm
a6a26f5c1961ae818b6e13cc2d55bab5dfbc16a4e702ecd27a8d8d286c36ac1b rubygems-devel-2.0.14-22.el7_0.noarch.rpm
f1a13e18dad274233641ce4faec026500f998138e41d9ee54327977183abb58f ruby-irb-2.0.0.353-22.el7_0.noarch.rpm
183504e99b23c5aa3fbba0833cfba1b659cb12db109f28c41f5ed3128784e5ac ruby-libs-2.0.0.353-22.el7_0.i686.rpm
0c047bbd05c23c762ea64d3d8328b662d8092de39bc6f53ca28e65fde63273c8 ruby-libs-2.0.0.353-22.el7_0.x86_64.rpm
962126ae9e6dfa0def3e8300978c82377e85c83477c39084811f7d05b75b0d58 ruby-tcltk-2.0.0.353-22.el7_0.x86_64.rpm
Source:
70e4e713b67f924b5883a911dd28649c419dc2fccaac1b79ef3fe618b6ecdb26 ruby-2.0.0.353-22.el7_0.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
lists.linuxfromscratch.org mailing list memberships reminder
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.
You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.
In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.
If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!
Passwords for reallost1.fbsd2233449@blogger.com:
List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com
[CentOS-announce] CESA-2014:1911 Moderate CentOS 6 ruby Security Update
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1911.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
31d5707695b299bd4581acda718ed7b845066ba3c68b3fde46bfa1910b484546 ruby-1.8.7.374-3.el6_6.i686.rpm
93b81ec1e635b3c33f1a83e899a30ed5ad6a46c460de6b2ff371f965ff24b813 ruby-devel-1.8.7.374-3.el6_6.i686.rpm
7d10fa2773e093898074bb58a168049547da12e0b99405906782ff00136d14a2 ruby-docs-1.8.7.374-3.el6_6.i686.rpm
6954b286ff3c8f183e717b5bf9827683e440bb7702e1d8f956615f6ff6d2f2b2 ruby-irb-1.8.7.374-3.el6_6.i686.rpm
cf2ee4436dab4202ecb4441e6b43ee7b64e53d19e5cea664b23a4e709d84fb58 ruby-libs-1.8.7.374-3.el6_6.i686.rpm
eefe4e31c899d554e0dabecc15cef3ed4d015beff9e05d15f995cfff4cb5bdcf ruby-rdoc-1.8.7.374-3.el6_6.i686.rpm
551bc361956144198996fdcab5a7a97610232f962cd5e3bc0dfdd6605156a1d8 ruby-ri-1.8.7.374-3.el6_6.i686.rpm
8958034cac5db419509716d387f1df5a4722c1fba5aa6e1b331d63ea6809cf10 ruby-static-1.8.7.374-3.el6_6.i686.rpm
32cd9786acbe51cf36bf3b94578cd40055308609879069393e38e1d534a89811 ruby-tcltk-1.8.7.374-3.el6_6.i686.rpm
x86_64:
909643760630c61085fcbc1a888d532625ce3fdd2e83ab0becbd1d13a8974d32 ruby-1.8.7.374-3.el6_6.x86_64.rpm
93b81ec1e635b3c33f1a83e899a30ed5ad6a46c460de6b2ff371f965ff24b813 ruby-devel-1.8.7.374-3.el6_6.i686.rpm
813cdc7b12018f27fd0a8b9317016698f0224eee262f50d51caaf59db4756da2 ruby-devel-1.8.7.374-3.el6_6.x86_64.rpm
bd94514b57dfe24f7a0b56bdfd00f9d2b966112298c1224d58c15c434118cd16 ruby-docs-1.8.7.374-3.el6_6.x86_64.rpm
82c7d51431ae43ae88134d7f34c903fcd7286d09fdb71e7946f4bbd7ae26314e ruby-irb-1.8.7.374-3.el6_6.x86_64.rpm
cf2ee4436dab4202ecb4441e6b43ee7b64e53d19e5cea664b23a4e709d84fb58 ruby-libs-1.8.7.374-3.el6_6.i686.rpm
19313fe28cfc5ff4fc0977eb5a4589457d7c7b393ee95cd364a2cf62c2679f8e ruby-libs-1.8.7.374-3.el6_6.x86_64.rpm
fc574835d37d437c4c269725f92847a0b04af9940706d6671b9bd4429e7fe7cb ruby-rdoc-1.8.7.374-3.el6_6.x86_64.rpm
8db4efda738f4f6a1e60af15ca8afd137153e55ce81908dfb5e3c47f9ed07f66 ruby-ri-1.8.7.374-3.el6_6.x86_64.rpm
13c4fc53a8b94ab76f84c8a35d3d230a8a5be9a6fd28771e087e2fdc112a64f4 ruby-static-1.8.7.374-3.el6_6.x86_64.rpm
40b23e66b01b108a55eaf5b0f6f623e094becc1455f4ebcef4b9c138e68b96e4 ruby-tcltk-1.8.7.374-3.el6_6.x86_64.rpm
Source:
53f4584bfb59e584e7848fe11f37d228cdec6ab3509dcbd4b1c9fcdc3533f2e8 ruby-1.8.7.374-3.el6_6.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEEA-2014:1918 CentOS 6 oprofile Enhancement Update
Upstream details at : https://rhn.redhat.com/errata/RHEA-2014-1918.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0f0c9183544e6f82486346105c34a54afcd715514e13cc2ce28069102d32b057 oprofile-0.9.9-6.el6_6.i686.rpm
3fc7bf59184123d3d58fec29595f06bde27cc8013fa7788da7346a35c36fc612 oprofile-devel-0.9.9-6.el6_6.i686.rpm
e26a9af62cee1cd14bccb46dcc7aff11770f931088f29a442abc51c707e67fdb oprofile-gui-0.9.9-6.el6_6.i686.rpm
6cc09ce4e5f89e9864bb47d0098100f43d9693f33919237e3f7924c1c6440144 oprofile-jit-0.9.9-6.el6_6.i686.rpm
x86_64:
b831f62d7a85743993d2ce5a330fc83c944643667022507185ba0c1f06d3d2d6 oprofile-0.9.9-6.el6_6.x86_64.rpm
3fc7bf59184123d3d58fec29595f06bde27cc8013fa7788da7346a35c36fc612 oprofile-devel-0.9.9-6.el6_6.i686.rpm
1c47a22ad84b114e788344171305918ee08e64d4d021f1d3179382cc3ac6d198 oprofile-devel-0.9.9-6.el6_6.x86_64.rpm
507d9e274357fb29b1dfdb91517a7d6430fdd91fa8aa16b338b96ac64cfbc81b oprofile-gui-0.9.9-6.el6_6.x86_64.rpm
6cc09ce4e5f89e9864bb47d0098100f43d9693f33919237e3f7924c1c6440144 oprofile-jit-0.9.9-6.el6_6.i686.rpm
70acdcd638b6363e6f2ad044dcc09ee200cfdaf3342058b9fef8cc2edbfd627d oprofile-jit-0.9.9-6.el6_6.x86_64.rpm
Source:
0c12801fcb07266a3bf6c718b3fa5566ec0ea7e59da800effba6a536a8a93cb7 oprofile-0.9.9-6.el6_6.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
