Friday, March 6, 2015
[USN-2522-2] ICU regression
Version: GnuPG v1
iQIcBAEBCgAGBQJU+f3LAAoJEGVp2FWnRL6Td3wP/jhqFuiMpzzcMd30RboHHpQj
XI1HU0QCOTl1vqbpeoojhnupqomngt6hQ/dIcRCScuukrO2In1ns2lY/413X9056
Eg+PASND/1x+1ajui1mkWyMupYER5sVqeVvltW44HiWRdhfdTHdWnXP9uuQGeEWV
KuTCNcIaBJ84AdFdv6s0miVKuDtxfG2zR1HPkyDBeTOtKowtM9rIwQ+FqwyvwJEp
HJahP5dn3SynhZgaSWB8I4khGHXqTueIIwK0etVCTJxneDjRWriArMPciROofXww
gWuyDJ2MuDIj6xJzDAM4L4bDMgIwzcdN0Mg6SbiOFIoTZrGX8OXcD9iCJAPrQJx6
pLx4pC7taBGSz8zc/hjD+w6P/MsWFw/5Gz17B4niM9YkC2b/45lPEdCAxFnIYWJm
2Rp7oTee5J5LQwnrf3fq2lfkqT3oFc3Qg8nxWMlEYZcLtNBIc9Mf3vKFJKCINj1R
2rc/XojRbi7gbtm+LFHwSZzZyMRkzLg4jldB0ifTJj/amC8xXgYYvd4Wcn5D0bec
yjA7VFbQYirjSrhl0NFUgyf+nlZhHrVP8f7ZFvBNvBLNLjLF8jtYhdVTQEX6hS7N
y2EF2LUQpykHbLqk1UevfcniXxewa9bS4N1PPY7gqsl6nmTX4x2CnB2Ni94qCVs7
MSL+S0xXvO7x13F2PkP5
=MtUP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2522-2
March 06, 2015
icu regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
USN-2522-1 introduced a regression in ICU.
Software Description:
- icu: International Components for Unicode library
Details:
USN-2522-1 fixed vulnerabilities in ICU. On Ubuntu 12.04 LTS, the font
patches caused a regression when using LibreOffice Calc. The patches have
been temporarily backed out until the regression is investigated.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014-6591)
It was discovered that ICU incorrectly handled memory operations when
processing regular expressions. If an application using ICU processed
crafted data, an attacker could cause it to crash or potentially execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2014-7923, CVE-2014-7926, CVE-2014-9654)
It was discovered that ICU collator implementation incorrectly handled
memory operations. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-7940)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
libicu48 4.8.1.1-3ubuntu0.4
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2522-2
http://www.ubuntu.com/usn/usn-2522-1
https://launchpad.net/bugs/1429043
Package Information:
https://launchpad.net/ubuntu/+source/icu/4.8.1.1-3ubuntu0.4
Fedora 22 Alpha status is Go, release on March 10, 2015
agreed to Go with the Fedora 22 Alpha by Fedora QA, Release Engineering
and Development.
Fedora 22 Alpha will be publicly available on Tuesday, March 10, 2015.
Meeting details can be seen here:
Minutes: http://bit.ly/17Y8Je5
Log: http://bit.ly/1Em9JXo
Thanks everyone! It's pretty solid Alpha release and on time :).
Jaroslav
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
reallost1.fbsd2233449 您好
reallost1.fbsd2233449
上海,深圳,销-售-主-管即将开课,火爆报名中!
Shanghai Beijing Shenzhen, main sale - pin - tube will begin, hot application!
附件中的内容希望对您的工作有所帮助
蓬绿香举安全之盾,防事故之患。祝您宝剑锋从磨砺出,梅花香自苦寒来。
ryhfrq
Thursday, March 5, 2015
Fedora 22 Alpha is No-Go but second sign-off try is tomorrow
Today at Fedora 22 Alpha Go/No-Go meeting it was decided that Fedora 22
Alpha is No-Go as no release candidate is available. More details in
meeting minutes [1].
But as we're looking pretty good and RC1 compose is undergoing right
now (estimate delivery is 3:00 UTC on Friday), we decided to try the
seconnd Go/No-Go meeting tomorrow. Earlier to give rel-eng chance to
prepare the content for mirroring.
The next Go/No-Go meeting is on Friday, Mar 06 8:30 AM CST/14:30 UTC
#fedora-meeting-2 channel.
[1] http://bit.ly/1H0LMmC
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[USN-2522-1] ICU vulnerabilities
Version: GnuPG v1
iQIcBAEBCgAGBQJU+F41AAoJEGVp2FWnRL6Txt4P/2gMBD8VcD7kcSNeyXqXAAjY
3lSIuFW8dIDoW6t5cOI1IbeZ30bYoLvjKXyqN7TDyfra2aBRnM3hjo+WxVi+xjTb
EiNv9lObPYUlmbYLsIrIbmhz15txG70RbxUNhh0P8wxdt0ZzYlRmzfvJWSW9p3us
WYvyN7ZrR7Ty3oWCoY5vcniEl9HfPjHzDE8nMMQtYOzH/UPSrRbpk8iuQ2RWXygf
wAllWI47sElQMmNgxOpD7OhtG7wdVH00uG77veBQsgHaNZiTijwl0evx6hEJuyq/
UsSFrcBZDw3DA+3TvVlUiCrR3OHDcEp/bir1WFDbqT+IAhdZ49JgL3wtVpVbont7
UsCoq+9DgcdzixRMOhCVo/07hNB49uYHqF45fgV8fOqDi41WI55Z/GHrUOA01gKQ
WKA8Nwi+FuZwBsMXyRXPs+qlbtBW0jRMGvvgAE9jBkK8ZlxQcItpQilcU1OE8Hrw
ylfKY6F2bjedotXFeVhOshYmWDQPoV3QQ0UtCtnDSm/g450KwAQ6ZqRuwJEIujyI
4NCWfAuFRVLdO6ZMeyCNfAXB0uwSRHk2wTTE3eG1jrevmgHHMkUo8KKRqcUWrzDE
XCPwaqwSG7/RZrHjVPALfGam/+QeG+c0DbmP1YyrBisuDS2sNO/ZFsvQDbzWlEhy
yg9YIDobfGQD8W8LLvuW
=PF6e
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2522-1
March 05, 2015
icu vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
ICU could be made to crash or run programs as your login if it processed
specially crafted data.
Software Description:
- icu: International Components for Unicode library
Details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014-6591)
It was discovered that ICU incorrectly handled memory operations when
processing regular expressions. If an application using ICU processed
crafted data, an attacker could cause it to crash or potentially execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2014-7923, CVE-2014-7926, CVE-2014-9654)
It was discovered that ICU collator implementation incorrectly handled
memory operations. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-7940)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
libicu52 52.1-6ubuntu0.2
Ubuntu 14.04 LTS:
libicu52 52.1-3ubuntu0.2
Ubuntu 12.04 LTS:
libicu48 4.8.1.1-3ubuntu0.3
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2522-1
CVE-2013-1569, CVE-2013-2383, CVE-2013-2384, CVE-2013-2419,
CVE-2014-6585, CVE-2014-6591, CVE-2014-7923, CVE-2014-7926,
CVE-2014-7940, CVE-2014-9654
Package Information:
https://launchpad.net/ubuntu/+source/icu/52.1-6ubuntu0.2
https://launchpad.net/ubuntu/+source/icu/52.1-3ubuntu0.2
https://launchpad.net/ubuntu/+source/icu/4.8.1.1-3ubuntu0.3
[CentOS-announce] Release for CentOS Linux 7 Rolling media Feb 2015
Hash: SHA1
I am pleased to announce general availability of the Feb 2015 snapshot
for CentOS Linux. Todays release includes CentOS Linux 7 iso based
install media, Generic Cloud images, Atomic Host and Docker containers.
CentOS Linux rolling builds are point in time snapshot media rebuild
from original release time, to include all updates pushed to
mirror.centos.org's repositories. This includes all security, bugfix,
enhancement and general updates for CentOS Linux. Machines installed
from this media will have all these updates pre-included and will look
no different when compared with machines installed with older media
that have been yum updated to the same point in time. All rpm/yum
repos remain on mirror.centos.org with no changes in either layout or
content.
Files marked as 20150228_01 indicate that it includes all content
released to mirror.centos.org upto ( and including ) the 28th of Feb
2015.
Since there is a need to test these images, the release will always
lag few days behind the datestamp ( and therefore content included )
in the release. My aim is to automate as much of this as possible
going forward to reduce this time lag as much as possible, however we
might not be able to remove the lag completely.
Other content formats like containers and vendor specific images will
aim to start with the same cycle as the main CentOS Linux media, but
might move to a more frequent build and release cycle if needed.
Special Interest Groups ( http://wiki.centos.org/SpecialInterestGroup)
wanting to do media and installer releases should also consider using
the rolling timelines to sync with.
- -----------
CentOS Linux distro installer media:
File: CentOS-7-x86_64-DVD-20150228_01.iso
Sha256sum:
8e1195b922def89f4d5846726f3bb1eaecd8bbfcb7a6e415d54a1ed6260ac21d
File: CentOS-7-x86_64-Everything-20150228_01.iso
Sha256sum:
09f76128a9d613ebc2ec0c6ad1313e78f0ce349dc669b2714e4e9f694c5c569b
File: CentOS-7-x86_64-Minimal-20150228_01.iso
Sha256sum:
c4da447eba9806d50d8a6369f44d5f847f0da4fd49144e5900227e0ca66ae3b2
Symlinks are provided that will always map to the latest released
builds, as follows ( including their current mapping )
http://buildlogs.centos.org/rolling/7/isos/x86_64/CentOS-7-x86_64-DVD.iso
- -> CentOS-7-x86_64-DVD-20150228_01.iso
http://buildlogs.centos.org/rolling/7/isos/x86_64/CentOS-7-x86_64-Everything.iso
- -> CentOS-7-x86_64-Everything-20150228_01.iso
http://buildlogs.centos.org/rolling/7/isos/x86_64/CentOS-7-x86_64-Minimal.iso
- -> CentOS-7-x86_64-Minimal-20150228_01.iso
These symlinks are updated to point at the latest tested and
released media and make for a good target in automation that requires
CentOS Linux media.
- ----------
For more information and comments please join us on the centos-devel
mailing list ( http://lists.centos.org/ )
Enjoy!
- --
Karanbir Singh,
Project Lead, The CentOS Project
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.14 (GNU/Linux)
iQEcBAEBAgAGBQJU+E2+AAoJEI3Oi2Mx7xbthVgH/21II7Wu00wLUJzU5uZn7xl6
olnu3CtTC0Nq7fm7MiP59PoaLTk1GKe4SaQFJQIuNJYdooH06XvarwiIo34SgOWq
MV/7KFRhWER0ZLpvJQIa0+r5WjL7OXuOHZ18FomC3/PqIZZaVwhXSXtFnCGgnirD
O6C3Ku6ErlTh4tF5gImw8s0FUkTBOOjfl5lL2jcqoSyXJkggs7CqBoH9LzfK/ddw
HeLqCenosk72bIXPMhZsM2JiGK8dujjBftcJ3GtvXOvXoWs3+Rl8fTsaSlHUa37/
brPfSDDaVWcp3sVMPmw7XCgT1s3RSxVKVZM1lHvvwZFNMnEj67mCeQN/XMlMdQU=
=5Dnk
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Wednesday, March 4, 2015
OpenBSD Foundation GSOC 2015
accepted as a mentoring organization for Google Summer of Code 2015.
As such if you are a student who qualifies to apply for GSOC, you will
be able to find us in Google's Summer of Code Application process.For
details on the application process and the relevant timelines please see
https://www.google-melange.com/gsoc/homepage/google/gsoc2015
We have an ideas page which is located at
http://www.openbsdfoundation.org/gsoc2015.html
I will repeat my usual disclaimer here on behalf of the foundation -
doing anything with GSOC does *not* guarantee the result will end up
in OpenBSD or any related project. That having been said
we hope to be able to put some mentors together with students to
accomplish things that may become useful to the community at large.
.... Ken Westerback, The OpenBSD Foundation ....
F22 Self Contained Change: Xfce412
https://fedoraproject.org/wiki/Changes/Xfce412
Change owner(s): Kevin Fenzi <kevin@scrye.com>, Mukundan Ragavan
<nonamedotc@fedoraproject.org>, Christoph Wickert <cwickert@fedoraproject.org>
Update Xfce to the new 4.12 release with a number of bugfixes and improvements.
* This Change is announced after the Change Submission Deadline as an
exception to the process. May not be approved for proposed Fedora release. *
== Detailed Description ==
Upstream Release Date: 2015-02-28
This release will have a number of bugfixes and improvements, but no radical
changes.
== Scope ==
* Proposal owners: Update Xfce packages. Update Xfce spin with any needed
adjustments.
* Other developers: N/A (not a System Wide Change)
* Release engineering: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[announce] NYC*BUG Tonight: George Neville-Neil on DTrace
System, George Neville-Neil
18:45, Stone Creek Bar & Lounge: 140 E 27th St
no RSVPs needed, Free and Open to All
Abstract
Book Release Event for "The Design and Implementation of the FreeBSD
Operating System" with George Neville-Neil
The March meeting will be a special launch meeting for the recent
release of "The Design and Implementation of the FreeBSD Operating
System." George Neville-Neil, one of the three authors, will be speaking
on DTrace, which is covered in the book. Some introductory comments will
be made by the book's editor. Copies of the book will be for sale and
giveaway. There will be some hors d'oeuvres provided.
DTrace is the tool of choice for debugging and performance tuning
systems running on FreeBSD. Originally developed for the Solaris
operating system, DTrace was ported to FreeBSD and has been developed
and enhanced within FreeBSD ever since. Used by both systems
administrators and developers, this talk will discuss both how DTrace
works, as described in the latest edition of "The Design and
Implementation of the FreeBSD Operating System" as well as how to
effectively use the system to monitor systems and diagnose problems.
Speaker Bio
George Neville-Neil works on networking and operating system code for
fun and profit. He also teaches various courses on subjects related to
computer programming. His professional areas of interest include code
spelunking, operating systems, networking, time and security. He is the
co-author with Marshall Kirk McKusick and Robert Watson of The Design
and Implementation of the FreeBSD Operating System and is the columnist
behind ACM Queue's "Kode Vicious." He serves as a Director of the
non-profit, FreeBSD Foundation.
He earned his bachelor's degree in computer science at Northeastern
University in Boston, Massachusetts, and is a member of the ACM, the
USENIX Association and the IEEE. He is an avid bicyclist and traveler
who currently resides in New York City.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce
[USN-2516-3] Linux kernel vulnerabilities regression
Version: GnuPG v1
iQIcBAEBCgAGBQJU9scEAAoJEAUvNnAY1cPYGLQP+wRnXvZU4tQJ3uxvJMnXlYwo
kU/LiG7QpuuiVtj1MgNGc//v+LPuUAW3JnCeu7+yWVR1CStm/yHN7ydkNzqg7R7j
JqPfPvj78rHCR4oA8AgN5/5dkTuq/QoVQyIcIz78iAVs5YI1DWu/ME1vxmLVK8rD
4ez9Vj9EsTDUmHwPpua8tZ/P5eMfcjxSqgGI7CC3UnRtsX/epg0y9/gbFm/CzveA
dbRR3iUAMm9pUpJbhxsqeFiOZO6EyfAhbrfVCOIRDcpNL0za4fxklXhap6dITEoA
QJZapkS07DbGWH/aQP4B2q1x9whqV6h6kR8W1XKZ64JHr/l6sX/uJ+FyOfrrKQlM
RDvsn9OYR/9eYjJgAC/ZPhhXe8VZz+M9gEwLiBp5F1Zhp0XrY1l/mucgzVSfFpvN
ykLM92nEag/20xIuw7a3UQOsiwY1c4KXiXg6soXrWfWPdyxqcTYQsassNsG737Om
lhPgSrdf520ZT3l92fsOh45kuEm1UOXftYpBvo0XKJbEJy/2Hr8uTnpjB8CnGfUF
+Q0VWSLik+e7mZiB1JkXd6Cie0KCf+uVOpL+2IdbghFvflM2xwxNXcmj9c7i7aeQ
WLk5DG8EtD/SknaBNiJ3hiZrs9GOcQ45YuUDkvQygUEhhMQjOOgnvNzOdbMfqHcA
yEg7TU4hV8J29ghhuXB7
=Ysu7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2516-3
March 04, 2015
linux vulnerabilities regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 LTS
Summary:
USN-2516-1 introduced a regression in the Linux kernel.
Software Description:
- linux: Linux kernel
Details:
USN-2516-1 fixed vulnerabilities in the Linux kernel, and the fix in
USN-2516-2 was incomplete. There was an unrelated regression in the use of
the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A restriction bypass was discovered in iptables when conntrack rules are
specified and the conntrack protocol handler module is not loaded into the
Linux kernel. This flaw can cause the firewall rules on the system to be
bypassed when conntrack rules are used. (CVE-2014-8160)
A flaw was discovered with file renaming in the linux kernel. A local user
could exploit this flaw to cause a denial of service (deadlock and system
hang). (CVE-2014-8559)
A flaw was discovered in how supplemental group memberships are handled in
certain namespace scenarios. A local user could exploit this flaw to bypass
file permission restrictions. (CVE-2014-8989)
A flaw was discovered in how Thread Local Storage (TLS) is handled by the
task switching function in the Linux kernel for x86_64 based machines. A
local user could exploit this flaw to bypass the Address Space Layout
Radomization (ASLR) protection mechanism. (CVE-2014-9419)
Prasad J Pandit reported a flaw in the rock_continue function of the Linux
kernel's ISO 9660 CDROM file system. A local user could exploit this flaw
to cause a denial of service (system crash or hang). (CVE-2014-9420)
A flaw was discovered in the fragment handling of the B.A.T.M.A.N. Advanced
Meshing Protocol in the Linux kernel. A remote attacker could exploit this
flaw to cause a denial of service (mesh-node system crash) via fragmented
packets. (CVE-2014-9428)
A race condition was discovered in the Linux kernel's key ring. A local
user could cause a denial of service (memory corruption or panic) or
possibly have unspecified impact via the keyctl commands. (CVE-2014-9529)
A memory leak was discovered in the ISO 9660 CDROM file system when parsing
rock ridge ER records. A local user could exploit this flaw to obtain
sensitive information from kernel memory via a crafted iso9660 image.
(CVE-2014-9584)
A flaw was discovered in the Address Space Layout Randomization (ASLR) of
the Virtual Dynamically linked Shared Objects (vDSO) location. This flaw
makes it easier for a local user to bypass the ASLR protection mechanism.
(CVE-2014-9585)
Dmitry Chernenkov discovered a buffer overflow in eCryptfs' encrypted file
name decoding. A local unprivileged user could exploit this flaw to cause a
denial of service (system crash) or potentially gain administrative
privileges. (CVE-2014-9683)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 LTS:
linux-image-3.13.0-46-generic 3.13.0-46.77
linux-image-3.13.0-46-generic-lpae 3.13.0-46.77
linux-image-3.13.0-46-lowlatency 3.13.0-46.77
linux-image-3.13.0-46-powerpc-e500 3.13.0-46.77
linux-image-3.13.0-46-powerpc-e500mc 3.13.0-46.77
linux-image-3.13.0-46-powerpc-smp 3.13.0-46.77
linux-image-3.13.0-46-powerpc64-emb 3.13.0-46.77
linux-image-3.13.0-46-powerpc64-smp 3.13.0-46.77
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2516-3
http://www.ubuntu.com/usn/usn-2516-1
https://launchpad.net/bugs/1427292
Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-46.77
[USN-2515-2] Linux kernel (Trusty HWE) vulnerabilities regression
Version: GnuPG v1
iQIcBAEBCgAGBQJU9sR+AAoJEAUvNnAY1cPYIuYP/RnqIVD2CqCJrRYVGXtoTox1
LFuj3yvHMA3NSSxDYx48SbKdNdUhUKSij4fdV6G12vxA6Iy1YKnfefiQ0w+/fSPW
FWrNT0cB6SxbduvDn6AH4rMoE8YQxVb5RJhu+x6m6gnU5dA4LdGjHi6Qxc/n1kKg
fP1jj/wYCe4DOUPa5EubI/W5BOzb9B9/QocxJt75cIMmxRnRYUuhncR6r2fwG1MT
Q2xAvYZnVp/jKtM58Je24fW44EK+APcHFDF7juvd4aVFZyykwEXxyWVh2uKUa2Ir
Ex0nSlFxPK2ghS5p0uFwdNlu6fYEsKU/wqkCeRmqH5VFcAoCahWeJcU53zuqB5V1
z+VSVnvTMmXgwnPLDseZMy4xljcICcKmGRwD7gaLFUQBwyEvVpOjjd3aYQ7MYPCn
8Hgf5LZEc3B8nJfnHgNFgKL2/CRJh96Rbb26xIue2lIayjF7XBSjkv5mLkchvmq0
6+s1jKpGdlOVrKgLfDkdloK+1BSUJnI/AoRqGjEUu6yRexhyn+TgiNX4tDXLt5A/
cB4pIrBgPrxDInbIjqUi9HVwt0W5Yz0l+JrQNgsBrGh93xscYCr6KtS4jWItcN77
L+Ucvb1cufQHB9zeF5u4mrgplQOR5XYOLUYJ2gMx6+4ulIC6Mcpwju5T3Arb3+eY
7zkSDvAOgz5QyYONDxQv
=k7e8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2515-2
March 04, 2015
linux-lts-trusty vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
USN-2515-1 introduced a regression in the Linux kernel.
Software Description:
- linux-lts-trusty: Linux hardware enablement kernel from Trusty
Details:
USN-2515-1 fixed vulnerabilities in the Linux kernel. There was an unrelated
regression in the use of the virtual counter (CNTVCT) on arm64 architectures.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
Andy Lutomirski discovered an information leak in the Linux kernel's Thread
Local Storage (TLS) implementation allowing users to bypass the espfix to
obtain information that could be used to bypass the Address Space Layout
Randomization (ASLR) protection mechanism. A local user could exploit this
flaw to obtain potentially sensitive information from kernel memory.
(CVE-2014-8133)
A restriction bypass was discovered in iptables when conntrack rules are
specified and the conntrack protocol handler module is not loaded into the
Linux kernel. This flaw can cause the firewall rules on the system to be
bypassed when conntrack rules are used. (CVE-2014-8160)
A flaw was discovered with file renaming in the linux kernel. A local user
could exploit this flaw to cause a denial of service (deadlock and system
hang). (CVE-2014-8559)
A flaw was discovered in how supplemental group memberships are handled in
certain namespace scenarios. A local user could exploit this flaw to bypass
file permission restrictions. (CVE-2014-8989)
A flaw was discovered in how Thread Local Storage (TLS) is handled by the
task switching function in the Linux kernel for x86_64 based machines. A
local user could exploit this flaw to bypass the Address Space Layout
Radomization (ASLR) protection mechanism. (CVE-2014-9419)
Prasad J Pandit reported a flaw in the rock_continue function of the Linux
kernel's ISO 9660 CDROM file system. A local user could exploit this flaw
to cause a denial of service (system crash or hang). (CVE-2014-9420)
A flaw was discovered in the fragment handling of the B.A.T.M.A.N. Advanced
Meshing Protocol in the Linux kernel. A remote attacker could exploit this
flaw to cause a denial of service (mesh-node system crash) via fragmented
packets. (CVE-2014-9428)
A race condition was discovered in the Linux kernel's key ring. A local
user could cause a denial of service (memory corruption or panic) or
possibly have unspecified impact via the keyctl commands. (CVE-2014-9529)
A memory leak was discovered in the ISO 9660 CDROM file system when parsing
rock ridge ER records. A local user could exploit this flaw to obtain
sensitive information from kernel memory via a crafted iso9660 image.
(CVE-2014-9584)
A flaw was discovered in the Address Space Layout Randomization (ASLR) of
the Virtual Dynamically linked Shared Objects (vDSO) location. This flaw
makes it easier for a local user to bypass the ASLR protection mechanism.
(CVE-2014-9585)
Dmitry Chernenkov discovered a buffer overflow in eCryptfs' encrypted file
name decoding. A local unprivileged user could exploit this flaw to cause a
denial of service (system crash) or potentially gain administrative
privileges. (CVE-2014-9683)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
linux-image-3.13.0-46-generic 3.13.0-46.77~precise1
linux-image-3.13.0-46-generic-lpae 3.13.0-46.77~precise1
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2515-2
http://www.ubuntu.com/usn/usn-2515-1
https://launchpad.net/bugs/1427297
Package Information:
https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-46.77~precise1
Tuesday, March 3, 2015
LibreSSL 2.1.4 released
directory of your local OpenBSD mirror soon.
This release adds a number of new security features, makes building
privilege-separated programs simpler, and improves the libtls API.
This release also includes a binary package for convenience integrating
LibreSSL on Windows platforms, and the latest source tarball is signed
with GPG and signify for easier integration into existing build systems.
Feedback is welcome. Bugs, patches, and features requests can be
reported to tech@openbsd.org or at
https://github.com/libressl-portable/portable/issues
As the OpenBSD 5.7 development effort comes to a close, so does the
LibreSSL 2.1.x branch. The next release will begin the 2.2.x development
branch.
User-visible features:
* Improvements to libtls:
- a new API for loading CA chains directly from memory instead of a
file, allowing verification with privilege separation in a chroot
without direct access to CA certificate files.
- Ciphers default to TLSv1.2 with AEAD and PFS.
- Improved error handling and message generation
- New APIs and improved documentation
* Added X509_STORE_load_mem API for loading certificates from memory.
This facilitates accessing certificates from a chrooted environment.
* New AEAD "MAC alias" allows configuring TLSv1.2 AEAD ciphers by
using 'TLSv1.2+AEAD' as the cipher selection string.
* New openssl(1) command 'certhash' replaces the c_rehash script.
* Server-side support for TLS_FALLBACK_SCSV for compatibility with
various auditor and vulnerability scanners.
Code improvements:
* Dead and disabled code removal including MD5, Netscape workarounds,
non-POSIX IO, SCTP, RFC 3779 support, "#if 0" sections, and more.
* The ASN1 macros are expanded to aid readability and maintainability.
* Various NULL pointer asserts removed in favor of letting the OS/signal
handler catch them.
* Refactored argument handling in openssl(1) for consistency and
maintainability.
* Support for building with OPENSSL_NO_DEPRECATED
* Dozens of issues found with the Coverity scanner fixed.
Security updates:
- Fix a minor information leak that was introduced in t1_lib.c
r1.71, whereby an additional 28 bytes of .rodata (or .data) is
provided to the network. In most cases this is a non-issue since
the memory content is already public. Issue found and reported by
Felix Groebert of the Google Security Team.
- Fixes for the following low-severity issues were integrated into
LibreSSL from OpenSSL 1.0.1k:
CVE-2015-0205 - DH client certificates accepted without
verification
CVE-2014-3570 - Bignum squaring may produce incorrect results
CVE-2014-8275 - Certificate fingerprints can be modified
CVE-2014-3572 - ECDHE silently downgrades to ECDH [Client]
Reported by Karthikeyan Bhargavan of the PROSECCO team at INRIA.
The following CVEs were fixed in earlier LibreSSL releases:
CVE-2015-0206 - Memory leak handling repeated DLTS records
CVE-2014-3510 - Flaw handling DTLS anonymous EC(DH) ciphersuites.
The following CVEs did not apply to LibreSSL:
CVE-2014-3571 - DTLS segmentation fault in dtls1_get_record
CVE-2014-3569 - no-ssl3 configuration sets method to NULL
CVE-2015-0204 - RSA silently downgrades to EXPORT_RSA
The LibreSSL project continues improvement of the codebase to reflect
modern, safe programming practices. We welcome feedback and improvements
from the broader community. Thanks to all of the contributors who helped
make this release possible.