Tuesday, March 10, 2015
[USN-2524-1] eCryptfs vulnerability
Ubuntu Security Notice USN-2524-1
March 11, 2015
ecryptfs-utils vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
Sensitive information in encrypted home and Private directories could be
exposed if an attacker gained access to your files.
Software Description:
- ecryptfs-utils: eCryptfs cryptographic filesystem utilities
Details:
Sylvain Pelissier discovered that eCryptfs did not generate a random salt when
encrypting the mount passphrase with the login password. An attacker could use
this issue to discover the login password used to protect the mount passphrase
and gain unintended access to the encrypted files.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
ecryptfs-utils 104-0ubuntu1.14.10.3
libecryptfs0 104-0ubuntu1.14.10.3
Ubuntu 14.04 LTS:
ecryptfs-utils 104-0ubuntu1.14.04.3
libecryptfs0 104-0ubuntu1.14.04.3
Ubuntu 12.04 LTS:
ecryptfs-utils 96-0ubuntu3.4
libecryptfs0 96-0ubuntu3.4
Ubuntu 10.04 LTS:
ecryptfs-utils 83-0ubuntu3.2.10.04.6
libecryptfs0 83-0ubuntu3.2.10.04.6
After a standard system update you need to log out of all sessions and then log
back in to make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2524-1
CVE-2014-9687
Package Information:
https://launchpad.net/ubuntu/+source/ecryptfs-utils/104-0ubuntu1.14.10.3
https://launchpad.net/ubuntu/+source/ecryptfs-utils/104-0ubuntu1.14.04.3
https://launchpad.net/ubuntu/+source/ecryptfs-utils/96-0ubuntu3.4
https://launchpad.net/ubuntu/+source/ecryptfs-utils/83-0ubuntu3.2.10.04.6
[USN-2522-3] ICU vulnerabilities
Version: GnuPG v1
iQIcBAEBCgAGBQJU/1IXAAoJEGVp2FWnRL6ToykP/RQf3HSGSZ1YSTQKJYODlqKW
ArK8gAA5FYsReU0GmZ+5GNFePYHyDdnbQ5xOvwDyiKOdOperNPIF4yQ6ytYog3mn
h/jOYvDRpAPPR0mXOkvV2Awq/32pzlj4oOpyq/eKw1t59DsYVMekB2RU1G6yebZy
/0pjIJy2TZJuFBM+JRD4WAg9NKM58TPwNsv+sFeNLJDat8RGWvBbFn0mxK281w00
uRFyUIXxmAk2a3Ywl0MUqmUAyrtPVO8Yd4j4qynwPjzhO69lyS30kGDOttxdXq0f
W1+qqdKkdYHVxjRtR0xaS/MEiBWG/1QSAArMLBMsDRkHrpuT9R7MGKGUm+FSBtTx
WpSJBln5j9nUfVG12kV571o5Gs76mLVM0BrZIaPKEZg3BrdR9RvLyJHpML7CckLX
qcTYY6TE1Q+nfiK13lmRfHKdULPWQEVxE+AY/cKEX3GNMLuyHliGtgKL/WtsHoTO
mFJamAqc0icbb6q50RhhvNVAYDyOSgi7W8fZ1yywdunYFarnyDrDv6z6+noSC3KN
jJvjPRND9Ocyx4wX4TRkj9n19OPTWVXY1wND5O6bCZ3WrKleTpXMsicvvitfUkpl
Ct1CzneQRl68vu0g2/gPqNAuJW5/HahfbsZEHWRUtezjbY8peajo8IydIxOt4maU
L/5X7hBlEKWrOD+OSTkX
=NRwq
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2522-3
March 10, 2015
icu vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
ICU could be made to crash or run programs as your login if it processed
specially crafted data.
Software Description:
- icu: International Components for Unicode library
Details:
USN-2522-1 fixed vulnerabilities in ICU. On Ubuntu 12.04 LTS, the font
patches caused a regression when using LibreOffice Calc. The patches have
now been updated to fix the regression.
We apologize for the inconvenience.
Original advisory details:
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. This issue only affected
Ubuntu 12.04 LTS. (CVE-2013-1569, CVE-2013-2383, CVE-2013-2384,
CVE-2013-2419)
It was discovered that ICU incorrectly handled memory operations when
processing fonts. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-6585,
CVE-2014-6591)
It was discovered that ICU incorrectly handled memory operations when
processing regular expressions. If an application using ICU processed
crafted data, an attacker could cause it to crash or potentially execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2014-7923, CVE-2014-7926, CVE-2014-9654)
It was discovered that ICU collator implementation incorrectly handled
memory operations. If an application using ICU processed crafted data, an
attacker could cause it to crash or potentially execute arbitrary code with
the privileges of the user invoking the program. (CVE-2014-7940)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.04 LTS:
libicu48 4.8.1.1-3ubuntu0.5
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2522-3
http://www.ubuntu.com/usn/usn-2522-1
CVE-2013-1569, CVE-2013-2383, CVE-2013-2384, CVE-2013-2419,
CVE-2014-6585, CVE-2014-6591
Package Information:
https://launchpad.net/ubuntu/+source/icu/4.8.1.1-3ubuntu0.5
[Guidelines change] Changes to the packaging guidelines
The documentation section of the guidelines has been updated to include
a prohibition on using both %doc and direct installation of files into
%_pkgdocdir.
* https://fedoraproject.org/wiki/Packaging:Guidelines#Documentation
* https://fedoraproject.org/w/index.php?title=Packaging%3AGuidelines&diff=405928&oldid=405492
* https://fedorahosted.org/fpc/ticket/338
-----
The Python guidelines were modified to clarify the use of unversioned
macros (%__python instead of %__python2 or %__python3, for example).
* https://fedoraproject.org/wiki/Packaging:Python
* https://fedoraproject.org/w/index.php?title=Packaging%3APython&diff=406053&oldid=405394
* https://fedorahosted.org/fpc/ticket/498
-----
Guidelines for Preupgrade Assistant packages have been added.
* https://fedoraproject.org/wiki/Packaging:PreupgradeAssistant
* https://fedorahosted.org/fpc/ticket/495
-----
Corrected a typo/logic error in the bootstrapping guidelines:
* https://fedorahosted.org/fpc/ticket/501
* https://fedoraproject.org/w/index.php?title=Packaging%3AGuidelines&diff=405381&oldid=403811
-----
If a package builds a module for multiple python interpreters, it must
be done below the source tree and not in the %{py3dir} anymore. For an
example see:
* http://fedoraproject.org/wiki/Packaging:Python#Building_more_than_once
-----
The guidelines on library bundling have been expanded to provide
information on some additional cases where the packaging committee may
grant exceptions.
* https://fedoraproject.org/wiki/Packaging:No_Bundled_Libraries#Some_reasons_you_might_be_granted_an_exception
* https://fedoraproject.org/w/index.php?title=Packaging%3ANo_Bundled_Libraries&diff=406057&oldid=383256
* https://fedorahosted.org/fpc/ticket/391#comment:13
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[USN-2521-1] Oxide vulnerabilities
Version: GnuPG v1
iQEcBAEBAgAGBQJU/w3gAAoJEGEfvezVlG4P2l8IAIJfvGLa36pt4XEqLCPXy6hZ
EE9cz7QkbtX/saP/pwH5OGsBYCaSgezX2M7LkQKh2J112GF8mFm5E7FDRPolPQle
gs8be9FUNoQvi3idh40+twXaUOLfrAef7p4V+D+pntDYC6Q6yu0yIhXxlXMNq9qq
D+DePL4mLCUb5+mFtVLbv5wuEVkLenQx6dlEgTADoEogVCkAJh1kp+dHjoLTZvyh
PLiL6OEzdy4C/ifpV4dsR/TZ303mbdMXai0qlZ78cPqFQhyRmZAw37iCg5LJ31gb
Fw5GMQdO1uovU4YE/Ogu+RbWx9KsKaX5oYfIkgFxyP9wwTRO4xYiHTanuQN+6e4=
=5SAN
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2521-1
March 10, 2015
oxide-qt vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Oxide.
Software Description:
- oxide-qt: Web browser engine library for Qt (QML plugin)
Details:
Several out-of-bounds write bugs were discovered in Skia. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash or execute arbitrary code with the privileges of the user invoking
the program. (CVE-2015-1213, CVE-2015-1214, CVE-2015-1215)
A use-after-free was discovered in the V8 bindings in Blink. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2015-1216)
Multiple type confusion bugs were discovered in the V8 bindings in Blink.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit these to cause a denial of service via
renderer crash, or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2015-1217, CVE-2015-1230)
Multiple use-after-free bugs were discovered in the DOM implementation in
Blink. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via renderer crash, or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2015-1218, CVE-2015-1223)
An integer overflow was discovered in Skia. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to cause a denial of service via application crash or execute
arbitrary code with the privileges of the user invoking the program.
(CVE-2015-1219)
A use-after-free was discovered in the GIF image decoder in Blink. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via renderer
crash, or execute arbitrary code with the privileges of the sandboxed
render process. (CVE-2015-1220)
A use-after-free was discovered in Blink. If a user were tricked in to
opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service via renderer crash, or execute
arbitrary code with the privileges of the sandboxed render process.
(CVE-2015-1221)
Multiple use-after-free bugs were discovered in the service worker
implementation in Chromium. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these
to cause a denial of service via application crash or execute arbitrary
code with the privileges of the user invoking the program. (CVE-2015-1222)
An out-of-bounds read was discovered in the VPX decoder implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via renderer crash. (CVE-2015-1224)
It was discovered that Blink did not initialize memory for image drawing
in some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to read
uninitialized memory. (CVE-2015-1227)
It was discovered that Blink did not initialize memory for a data
structure in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via renderer crash, or execute arbitrary code
with the privileges of the sandboxed render process. (CVE-2015-1228)
It was discovered that a web proxy returning a 407 response could inject
cookies in to the originally requested domain. If a user connected to a
malicious web proxy, an attacker could potentially exploit this to conduct
session-fixation attacks. (CVE-2015-1229)
Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2015-1231)
Multiple security issues were discovered in V8. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit these to read uninitialized memory, cause a denial of service via
renderer crash or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2015-2238)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
liboxideqtcore0 1.5.5-0ubuntu0.14.10.2
oxideqt-chromedriver 1.5.5-0ubuntu0.14.10.2
oxideqt-codecs 1.5.5-0ubuntu0.14.10.2
oxideqt-codecs-extra 1.5.5-0ubuntu0.14.10.2
Ubuntu 14.04 LTS:
liboxideqtcore0 1.5.5-0ubuntu0.14.04.3
oxideqt-chromedriver 1.5.5-0ubuntu0.14.04.3
oxideqt-codecs 1.5.5-0ubuntu0.14.04.3
oxideqt-codecs-extra 1.5.5-0ubuntu0.14.04.3
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2521-1
CVE-2015-1213, CVE-2015-1214, CVE-2015-1215, CVE-2015-1216,
CVE-2015-1217, CVE-2015-1218, CVE-2015-1219, CVE-2015-1220,
CVE-2015-1221, CVE-2015-1222, CVE-2015-1223, CVE-2015-1224,
CVE-2015-1227, CVE-2015-1228, CVE-2015-1229, CVE-2015-1230,
CVE-2015-1231, CVE-2015-2238
Package Information:
https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.10.2
https://launchpad.net/ubuntu/+source/oxide-qt/1.5.5-0ubuntu0.14.04.3
[USN-2523-1] Apache HTTP Server vulnerabilities
Version: GnuPG v1
iQIcBAEBCgAGBQJU/w2aAAoJEGVp2FWnRL6TKQsP/juziy3bOXLubWc6O0Ru32cG
QApWO2c52lxyVOUGNfKH6jiC8aHRpaRCFDvGFrZGmiYc7r0vxPbFxJokN5rAqWZq
DHdeqZ7/GSAAKnEmS+mw18mw0OR8t2OkU/3YUUa1/s139rVWnKtb62rUPf3J4Gjn
Rc8dcgNUNHPP9nXQ+7D3DzCGb/YjTXasxpBPvPG6RdlcpeUDyPVX1n5kQF0qcEOf
BPAvATj00na8MiQW8fPr+C7vmWNEZF2cMgXc8ObUBB8kr+PedIQztIbY966kwcSH
QegaDRVgoGMvLeRHETuDNddV6M4Qn6DQBibliye+ImPu63nboA8v028CUsXGJXJf
iiT2jBtsEfgiddeVZYA7IcHprFadrjpz28HftJh9L10H52SItCHavvTib4JSq/wW
IRMEbxbKDlhgNdu64fGLiQIBnxdRJUhOKDZSjWOhNQTKvnR1byV6e/MLl70C2y3p
rJclg3qzIxeuvhg8B7nINCHKbEFZi9ZIu6c00n85ndY2CpUrwm4oVfn1KgkM56Y4
D3WY7+TT0qGWsACuC2AMK92rmxscBUIF20OtY6HTK/C27IGZWDLdPQHy02dwK97M
3jrPYdqB+5em0X8ApoK2ln+wBu1/Nd5aHcVvidUhxhE9/ntmIdEmApTG1aTZ3zER
yZkI+sdwTotb0aFOwJ+e
=+CR6
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2523-1
March 10, 2015
apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS
Summary:
Several security issues were fixed in the Apache HTTP Server.
Software Description:
- apache2: Apache HTTP server
Details:
Martin Holst Swende discovered that the mod_headers module allowed HTTP
trailers to replace HTTP headers during request processing. A remote
attacker could possibly use this issue to bypass RequestHeaders directives.
(CVE-2013-5704)
Mark Montague discovered that the mod_cache module incorrectly handled
empty HTTP Content-Type headers. A remote attacker could use this issue to
cause the server to stop responding, leading to a denial of service. This
issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10. (CVE-2014-3581)
Teguh P. Alko discovered that the mod_proxy_fcgi module incorrectly
handled long response headers. A remote attacker could use this issue to
cause the server to stop responding, leading to a denial of service. This
issue only affected Ubuntu 14.10. (CVE-2014-3583)
It was discovered that the mod_lua module incorrectly handled different
arguments within different contexts. A remote attacker could possibly use
this issue to bypass intended access restrictions. This issue only affected
Ubuntu 14.10. (CVE-2014-8109)
Guido Vranken discovered that the mod_lua module incorrectly handled a
specially crafted websocket PING in certain circumstances. A remote
attacker could possibly use this issue to cause the server to stop
responding, leading to a denial of service. This issue only affected
Ubuntu 14.10. (CVE-2015-0228)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
apache2.2-bin 2.4.10-1ubuntu1.1
Ubuntu 14.04 LTS:
apache2.2-bin 2.4.7-1ubuntu4.4
Ubuntu 12.04 LTS:
apache2.2-bin 2.2.22-1ubuntu1.8
Ubuntu 10.04 LTS:
apache2.2-bin 2.2.14-5ubuntu8.15
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2523-1
CVE-2013-5704, CVE-2014-3581, CVE-2014-3583, CVE-2014-8109,
CVE-2015-0228
Package Information:
https://launchpad.net/ubuntu/+source/apache2/2.4.10-1ubuntu1.1
https://launchpad.net/ubuntu/+source/apache2/2.4.7-1ubuntu4.4
https://launchpad.net/ubuntu/+source/apache2/2.2.22-1ubuntu1.8
https://launchpad.net/ubuntu/+source/apache2/2.2.14-5ubuntu8.15
Announcing the release of Fedora 22 Alpha!
Hash: SHA1
Fedora 22 Alpha Release Announcement
====================================
The Fedora 22 Alpha release has arrived, with a preview of the latest
free and open source technology under development. Take a peek inside!
• Get Fedora 22 Alpha Workstation
https://getfedora.org/en/workstation/prerelease/
• Get Fedora 22 Alpha Server
https://getfedora.org/en/server/prerelease/
• Get Fedora 22 Alpha Cloud
https://getfedora.org/en/cloud/prerelease/
• Get Fedora 22 Alpha Spins
https://spins.fedoraproject.org/prerelease
What is the Alpha release?
==========================
The Alpha release contains all the exciting features of Fedora 22's
editions in a form that anyone can help test. This testing, guided by
the Fedora QA team, helps us target and identify bugs. When these bugs
are fixed, we make a Beta release available. A Beta release is
code-complete and bears a very strong resemblance to the third and
final release. The final release of Fedora 22 is expected in May.
We need your help to make Fedora 22 the best release yet, so please
take some time to download and try out the Alpha and make sure the
things that are important to you are working well. If you find a bug,
please report it – every bug you uncover is a chance to improve the
experience for millions of Fedora users worldwide.
Together, we can make Fedora 22 another rock-solid release. We have a
culture of coordinating new features and pushing fixes upstream as much
as feasible, and your feedback will help improve not only Fedora but
Linux and free software on the whole.
Fedora 22 Cloud
===============
The Fedora 22 Cloud Edition builds on the work completed during the
Fedora 21 cycle, and brings in a number of improvements that make
Fedora 22 a superb choice for running Linux in the cloud.
Ready for the Fedora 22 release, we have:
• The latest versions of rpm-ostree and rpm-ostree-toolbox. You can
even use rpm-ostree-toolbox to generate your own Atomic hosts from
a custom set of packages.
• A Vagrant image for Fedora 22 Atomic Host and Cloud Images. We're
supplying Vagrant boxes that work with KVM or VirtualBox, so users
on Fedora will be able to easily consume the Vagrant images with
KVM, and users on Mac OS X or Windows can use the VirtualBox image.
• Tunir: A new, lightweight Continuous Integration (CI) tool for
rapid testing of cloud images. While being driven by the need for
simple CI for the Cloud Working Group, it's generic enough to be
used by anyone to configure and run jobs/tests on their local
system.
Fedora 22 Server
================
The Fedora 22 Server Edition brings several changes that will improve
Fedora for use as a server in your environment.
• Database Server Role: Fedora 21 introduced Rolekit, a daemon for
Linux systems that provides a stable D-Bus interface to manage
deployment of server roles. The Fedora 22 release adds onto that
work with a database server role based on PostgreSQL.
• Cockpit Updates: The Cockpit Web-based management application has
been updated to the latest upstream release which adds many new
features as well as a modular design for adding new functionality.
Fedora 22 Workstation
=====================
As always, Fedora carries a number of improvements to make life better
for its desktop users! Here's some of the goodness you'll get in Fedora
22 Workstation edition.
Enhancements:
• The GNOME Shell notification system has been redesigned and
subsumed into the calendar widget.
• The Terminal now notifies you when a long running job completes.
• The login screen now uses Wayland by default. This is a step
towards replacing X with Wayland, and users should not actually
notice the difference.
• Installation of GStreamer codecs, fonts, and certain document types
is now handled by Software, instead of gnome-packagekit.
• The Automatic Bug Reporting Tool (ABRT) now features better
notifications, and uses the privacy control panel in GNOME to
control information sent.
Appearance:
• The Nautilus file manager has been improved to use GActions, from
the deprecated GtkAction APIs, for a better, more consistent
experience.
• The GNOME Shell has a refreshed theme for better usability.
• The Qt/Adwaita theme is now code complete, and Qt notifications
have been improved for smoother experience using Qt-based apps in
Workstation.
Under the covers:
• The libinput library is now used for both X11 and Wayland for
consistent input device handling.
Spins
• Plasma 5, the successor to KDE Plasma 4, is now the default
workspace in the Fedora KDE spin.
• The Xfce spin has been updated to Xfce 4.12 just in time for the
Alpha release. This release has an enormous number of improvements,
including HiDPI support, improvements to window tiling, support for
Gtk3 plugins, and many improvements for multi-monitor support.
Issues and Details
==================
This is an Alpha release. As such, we expect that you may encounter
bugs or missing features. To report issues encountered during testing,
contact the Fedora QA team via the test mailing list or in #fedora-qa
on freenode.
As testing progresses, common issues are tracked on the Common F22 Bugs
page: https://fedoraproject.org/wiki/Common_F22_bugs
For tips on reporting a bug effectively, read "how to file a bug
report:" https://fedoraproject.org/wiki/How_to_file_a_bug_report
Release Schedule
================
The full release schedule is available on the Fedora wiki:
https://fedoraproject.org/wiki/Releases/22/Schedule
The current schedule calls for a beta release in the middle of April,
and a final release in the second half of May.
These dates are subject to change, pending any major bugs or issues
found during the development process.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQIcBAEBAgAGBQJU/vl4AAoJEH7ltONmPFDRK6sP/1dLHhetrjwNHFwQiZqwEH1A
wur8X0EVfzGLKlsf/MHACVV95LdeL6DozPaIs+a5PZZ+KVGvp3vBND24uqQEzKqz
la9hSKXccnb4ck80wRh3FN9lsEN/Dr1s7E18p5flEJYbgY4JLDJM+wj7tkReoKsF
I1eUhUvBeHREgNdf1dX5EUc3PzKbWvpf83NsZeS7zoH7rFCo6nW7zY4s1HkSeBbw
UZeEkdPCDfw1bpgJpeshE14MsezWSlR7NpiIKf9eGi5XGlD8B4KbLZvnks7A9eUX
Hm1ZBVMn2a4JlAZAD1H67xrV5V+F2oNgj6tty0fjUoKLEvGQObcVm8r4+57mTfXz
Onjou/65+9boiOMpCO78cHbPafCvaQYs7LoWpnteTCWxPaXSQFJWQUW624pL88nd
P+TpMFUG0h8Euuhig7VEz66taLz2EuhICERERMO+H3q+5Te3D05XcOFUdCbxNfkA
fcdvRIqYp7nOspnVdgiiP1jv4AeIZ/yBbqtyYOG/t9prz2vr1eOhvieZ+J0XNMpA
3RPihtRQD0hrpv/3BZ7/Xv2Uel7gg8ODA2MNL9I0tkmHW08I8qfFOUgMuRpeArSR
uPHvZod+CxmeZK6wUMqLLLj9pv/a/FXhT6T+7O+Mo6I23FqTbKVRIPQ7hVhUYpkk
pWLC0CMq1Yth9MW4QhKV
=NCvz
-----END PGP SIGNATURE-----
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
Monday, March 9, 2015
Planned Outage: Server reboots - 2015-03-11 21:00 UTC
There will be an outage starting at 2015-03-11 21:00 UTC, which will
last approximately 4 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2015-03-11 21:00 UTC'
Reason for outage:
We will be rebooting servers to apply pending updates. Downtime for any
one service should be minimal, but services may be up and down during
the outage window.
Affected Services:
Ask Fedora - http://ask.fedoraproject.org/
Badges - https://badges.fedoraproject.org/
BFO - http://boot.fedoraproject.org/
Blockerbugs - https://qa.fedoraproject.org/blockerbugs/
Bodhi - https://admin.fedoraproject.org/updates/
Buildsystem - http://koji.fedoraproject.org/
GIT / Source Control - pkgs.fedoraproject.org
Darkserver - https://darkserver.fedoraproject.org/
DNS - ns-sb01.fedoraproject.org, ns02.fedoraproject.org,
ns04.fedoraproject.org, ns05.fedoraproject.org
Docs - http://docs.fedoraproject.org/
Elections - https://admin.fedoraproject.org/voting
Email system
Fedmsg busmon - http://apps.fedoraproject.org/busmon
Fedora Account System - https://admin.fedoraproject.org/accounts/
Fedora Community - https://admin.fedoraproject.org/community/
Fedora Calendar - https://apps.fedoraproject.org/calendar/
Fedora Hosted - https://fedorahosted.org/
Fedora OpenID - https://id.fedoraproject.org/
Fedora People - http://fedorapeople.org/
Main Website - http://fedoraproject.org/
Mirror List - https://mirrors.fedoraproject.org/
Mirror Manager - https://admin.fedoraproject.org/mirrormanager/
Package Database - https://admin.fedoraproject.org/pkgdb/
QA Services
Secondary Architectures
Spins - http://spins.fedoraproject.org/
Start - http://start.fedoraproject.org/
Torrent - http://torrent.fedoraproject.org/
Wiki - http://fedoraproject.org/wiki/
Contact Information:
Ticket Link: https://fedorahosted.org/fedora-infrastructure/ticket/4681
Please join #fedora-admin or #fedora-noc on irc.freenode.net or add
comments to the ticket for this outage above.
如何明确中坚力量在企业的定位 reallost1.fbsd2233449
< 中坚力量6堂课 >
【时间地点】 2015年03月28-29深圳 03月21-22上海 04月25-26广州
【参加对象】 企业副总、各部门经理、主管、各级中层管理人员、新提拔的、从专业人才转型到管理的、进一步想提高管理绩效的、晋升到高层管理以及其它预备管理人员
【授课方式】 讲师讲授 + 视频演绎 + 案例研讨 +角色扮演 + 讲师点评
【学习费用】 3600元/1人,5800元/2人(含课程讲义、午餐、茶点等)
垂·询·热·线:上海:021-31006787、北京:010-5129-9910,深圳:0755-6128-0006 转吕小姐
在·线·QQ·微信:1368751945 189-189-58501 吕小姐
课程背景:
当今中国企业的中层干部,很多是半路出家。原先是业务骨干、技术能手,后来时势造化被推到"管理"这个位置,从业务一把好手,到承上启下、带领一帮人把一摊子事情做好,这个角色转换并不容易。
对薛灿宏老师,我和我的中层干部都不陌生,听他的课程好几年了。他培训的最大特点就是务实。薛灿宏老师不拘泥于中层干部所面临的"事",更多谈了中层干部所面临的"人",上司是人,同僚是人,下属也是人,中层干部整天就是跟人打交道;做事是基础,为人是根本,做事的本领再强,但为人失败,是中层干部最大的失败。
薛灿宏老师的课程,讲述了一些职场潜规则。潜规则不是公司制度里所能找到的,也绝非大学课堂里讲授的,摸清潜规则,并按潜规则做事、为人,才有可能让上司赏识你,同僚配合你,下属尊重你,你的职场生涯才能顺利发展,否则,即使干劲冲天,也有可能里外不讨好、四面楚歌。
我们需要怎样的中层干部?这个课程给出了答案。
——远东集团董事长 蒋锡培 为《中层经理怎样当》序
讲师介绍:【薛灿宏】
清华大学总裁班特聘讲师
曾任红豆集团管理顾问
曾任江苏科行集团管理顾问
讲师著作:
著有《中层经理怎样当》(经济日报出版社)、《中层变革》(北京大学出版社,光盘)、《执掌团队》(经济日报出版社)
学员评价:
从实践中来,到实践中去,一切从实际出发,很实用,这是薛灿宏老师的鲜明特点。
—— 江苏光芒集团董事长范朝洪
有理论的高度,有实战的深度,言之有据,诙谐幽默,引人入胜,所以我们两个月里请薛老师讲了三次。
—— 山西经纬纺机党委书记库冠群
古今中外,信手拈来,鲜活的案例,生动的故事,很过瘾。
—— 中建五局土木工程公司总经理姚子辉
当我们打算给中层干部做培训时,对国内的培训师进行了筛选,并找来最后看好的几位培训师的音像资料,比较以后选择了薛老师。事实证明,我们的眼光是对的。
—— 厦门象屿集团人力资源部经理邓鸿雁
课程大纲:
第一堂课 明确自己在企业的定位
1、企业的汉堡结构(高层要有决策力,基层要有行动力,中层需要执行力)
2、为什么会有中层(什么叫执行力?三个字:做到位)
3、中层的三大难关(上司认可、同僚支持、下属推崇)
4、中层的两大罪过(群众领袖、小国之君)
5、中层的一大软肋:推卸责任(员工可以跳槽,老板只能跳楼)
6、中层不同阶段的定位(做经理、坐经理、作经理)
案例讨论:
⑴领导责骂,下属嘲讽,中层"夹板气"是怎么造成的?
⑵我这个人力资源部经理,怎么就吃力不讨好?
第二堂课 如何得到领导认可
1、领导都是对的:坚决执行(与领导的意见不一致时,第一服从,第二沟通)
2、不议论领导是非:承上启下(而不仅仅上传下达,更不能欺上瞒下)
3、维护领导威信:自我退后(长用者多批评,短用者多表扬)
4、用数字说话:结果至上(汇报工作谈结果,请示工作说方案)
5、请领导做选择题:勤于思考(问答题永远留给自己)
6、让领导做好人:勇于担当(没有坏人就没有好人,没有坏人就没有执行力)
案例讨论:
⑶处处小心,还是屡屡受挫,我一个空降新经理如何是好?
⑷员工罢工,老板发怒,我一个中层干部怎么办?
第三堂课 如何进行跨部门协作
1、惜缘:因为看法不同,所以必有冲突(没有冲突就没有改善)
2、尊重:面子第一,道理第二(面子决定好感,好感决定成败)
3、内敛:高调做事,低调做人(孙悟空是不是好经理?)
4、克己:让于名利,无欲则刚(勤奋做事,简单做人)
5、助人:予人玫瑰,手有余香(妥协、忍让、隐藏,是优秀职业经理人必不可少的素养)
案例讨论:
⑸协作不力,如何应对公司内部的派系之争?
⑹有职无权,别的部门不买我的帐,怎么办?
第四堂课 如何调动下属工作热情
1、金钱激励:很重要但不唯一(不谈薪水,是愚民政策;光谈薪水,是害民政策)
2、晓之以利:弄清楚为谁而工作(与其抱怨薪水少,不如检讨岗位价值低)
3、引而不发:让他人说出你的想法(把自己的意见变成他人的意见,把他人的意见变成大
家的意见)
4、多头并举:从不花钱的表扬开始(人人需要兴奋,表扬就是兴奋剂)
5、防微杜渐:一切从工作积极性出发(优秀的管理者,应该是激励高手)
案例讨论:
⑺员工擅自跟客户吃饭,这笔钱该不该报销?
⑻黄金季节来了,员工闹情绪,我该怎么办?
⑼月工资800的大学生撞塌工棚使公司损失3万,如何处理?
第五堂课 如何管好部门绩效
1、角色转换:做教练而不做警察(好的管理者就是好教练)
2、灌输数字:修"路"而不是修"人"( 与其责怪下属太笨,不如反思为啥教不好)
3、聚焦绩效:多谈行为,少下结论(就事论事,不妄加结论,是改善员工行为的法则)
4、抓住关键:重视什么,就得到什么(程序清晰、数字明确,像麦当劳一样教员工)
5、目标管理:控制过程才能控制结果(目标绩效管理是照妖镜,是探照灯)
6、迫使进化:追求快乐,逃避痛苦(下属的素质差,不是你的错;不能提升下属的素质,是你的大错)
案例讨论:
⑽临阵换将,烂摊子怎么快速出绩效?
⑾员工私捞好处,漏洞怎么堵?
⑿考核,考出员工集体围攻考核主管 该怎么办?
第六堂课 如何带出优秀团队
1、团队为王:做英雄还是做领袖?(管理,就是运用他人的努力实现目标)
2、讲清规则:游戏也得先说玩法(游戏规则,是为了解决公平问题、效率问题)
3、同舟共济:一起营造安全感、归属感(员工心态出现问题,是管理者的责任)
4、双管齐下:一手抓制度,一手抓文化(万达是军队,万达是学校,万达是家庭;万达的
企业文化,把我们想说的都说了)
5、基业长青:好员工是培训出来的(培训是第二生产力)
案例讨论:
⒀怎样面对"老油条下属"?
⒁怎么应对"又臭又硬"的下属?
⒂表现良好的员工身上"有味道",怎么处理?
注:如不需此类信件信息,请转发送"删除"至qytuixin@163.com,我们会及时处理,谢谢您的理解。
[USN-2505-2] Firefox regression
Version: GnuPG v1
iQEcBAEBAgAGBQJU/eMKAAoJEGEfvezVlG4PPu0IAIKOd2j8vapmDVSweRvieLu5
H45TrjIezppWdoxYCdT+V+W67wNS9ya/iRRS3Clk543iKt+v9M700gIijvxZHs8v
O3JSWd14ikaSvDfSwaybFmNwbdbKNdAF+hAD8DPMkUW8n/G/+Xn6Zvb6k+DEcQo8
jK8hnL+Qe2c2O7IFLv4lmkfhajPeodMM5N79FkcLEOlsj5LJQWcW7llmUaIuc1Gn
DakUSG2L6SN4EZsHDtB7+VQw3pEfF0pM/mPJT9GgDs4eRQzQxjNXGNQ8HXN2UNQ8
xQHnmqhSP4Gc14LgvJrjNjPGv5xMQ239WMYt18004tIgl/BlDFWMEwo9bZni2ZA=
=NPpJ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2505-2
March 09, 2015
firefox regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
USN-2505-1 introduced a regression in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
USN-2505-1 fixed vulnerabilities in Firefox. This update removed the
deprecated "-remote" command-line switch that some older software still
depends on. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Matthew Noorenberghe discovered that whitelisted Mozilla domains could
make UITour API calls from background tabs. If one of these domains were
compromised and open in a background tab, an attacker could potentially
exploit this to conduct clickjacking attacks. (CVE-2015-0819)
Jan de Mooij discovered an issue that affects content using the Caja
Compiler. If web content loads specially crafted code, this could be used
to bypass sandboxing security measures provided by Caja. (CVE-2015-0820)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to bypass security restrictions. (CVE-2015-0821)
Armin Razmdjou discovered that contents of locally readable files could
be made available via manipulation of form autocomplete in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to obtain sensitive
information. (CVE-2015-0822)
Atte Kettunen discovered a use-after-free in the OpenType Sanitiser (OTS)
in some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash. (CVE-2015-0823)
Atte Kettunen discovered a crash when drawing images using Cairo in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service. (CVE-2015-0824)
Atte Kettunen discovered a buffer underflow during playback of MP3 files
in some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to obtain
sensitive information. (CVE-2015-0825)
Atte Kettunen discovered a buffer overflow during CSS restyling in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2015-0826)
Abhishek Arya discovered an out-of-bounds read and write when rendering
SVG content in some circumstances. If a user were tricked in to opening
a specially crafted website, an attacker could potentially exploit this
to obtain sensitive information. (CVE-2015-0827)
A buffer overflow was discovered in libstagefright during video playback
in some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-0829)
Daniele Di Proietto discovered that WebGL could cause a crash in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service. (CVE-2015-0830)
Paul Bandha discovered a use-after-free in IndexedDB. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-0831)
Muneaki Nishimura discovered that a period appended to a hostname could
bypass key pinning and HSTS in some circumstances. A remote attacker could
potentially exloit this to conduct a Man-in-the-middle (MITM) attack.
(CVE-2015-0832)
Alexander Kolesnik discovered that Firefox would attempt plaintext
connections to servers when handling turns: and stuns: URIs. A remote
attacker could potentially exploit this by conducting a Man-in-the-middle
(MITM) attack in order to obtain credentials. (CVE-2015-0834)
Carsten Book, Christoph Diehl, Gary Kwong, Jan de Mooij, Liz Henry, Byron
Campen, Tom Schuster, Ryan VanderMeulen, Christian Holler, Jesse Ruderman,
Randell Jesup, Robin Whittleton, Jon Coppeard, and Nikhil Marathe
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-0835, CVE-2015-0836)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.10:
firefox 36.0.1+build2-0ubuntu0.14.10.1
Ubuntu 14.04 LTS:
firefox 36.0.1+build2-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox 36.0.1+build2-0ubuntu0.12.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2505-2
http://www.ubuntu.com/usn/usn-2505-1
https://launchpad.net/bugs/1425972, https://launchpad.net/bugs/1429115
Package Information:
https://launchpad.net/ubuntu/+source/firefox/36.0.1+build2-0ubuntu0.14.10.1
https://launchpad.net/ubuntu/+source/firefox/36.0.1+build2-0ubuntu0.14.04.1
https://launchpad.net/ubuntu/+source/firefox/36.0.1+build2-0ubuntu0.12.04.1
Saturday, March 7, 2015
reallost1.fbsd2233449
reallost1.fbsd2233449
企业竞争日趋激烈,如何跟上时代发展的脚步,?
附件中的内容希望对贵公司的发展有所帮助。包淋美祝您生活愉快。
91ob2
Friday, March 6, 2015
[lfs-announce] LFS 7.7-systemd is released
Version: GnuPG v2
iQIcBAEBAgAGBQJU+ldVAAoJEMxyaRAVyqJO32oP/R8lz4vwxS/ZFhixZVjI2L3W
kpzevAwdRn173Mu4VBcIR4W74LsvLJS0kWLQKGMIsl78KEY1zM0YuM+BpCUDpNFb
+ZS1tF8wQoE4f5v0RjsZSr9wwa9zVhGa7PEq1Q0sUBWgK7+Dkx9nkLRPJkpy2yEp
4HvpXrjTLFzvhu71fAfHJoq27zXHHL/EOPvQRkkthoZCfbun8wUgQRHTU5o6AVh1
juW/bd0Scr1x0MnlIAI5pahSlPmvvKs5ePBpI3pP3x5HpywwFATuyAUda0Akykbk
k/3aQuK28gvCtMwHaBXvB5Eb6ZikHUe6zzm7A8fcr/+3zhrVxYTIgmzTeQEcbnQQ
UEwfosMuoGYXGW8/+/dYtpiOpOP2iDKorS7oQ7FYKTgqiFvmNn56G9JDB7SYrApx
rrZg2fJQvIxcWYCrTQ4ai/hKmyeal6rHJMDFpsXnrC+tB7De4mBT5INdjlyzDJIW
fahdDcNZtTDYx6TQpKchsWYrpD0YwLL+2AS7Iv3JQ612u5CzGGCc2NftudawCr/n
BDouEMZR2CCUJUQrPSseJHsuS9oqmTOv4P89lY4JQU7jNXlRL7CQcYgVRQHFMVG2
elvbEh9T2lnPzxINhzFKHEDwKMB/Pvc2IcrZVEHifTgB0RMMrAaDWT2vHpWgTPqG
Y0K1vEHlbSspV/AWsKOu
=bftt
-----END PGP SIGNATURE-----
Hi everyone,
I am proud to announce a new stable release of the Linux From Scratch systemd
Edition, a LFS Book variant that offers systemd as the default init system.
For a summary of changes, please conslut the annoucement for the release
candidate available at [1]. No significat changes happened since then.
Two security issues were addressed in e2fsprogs and grep and a bugfix that
would cause some programs to segfault on an i686 system was included for
glibc. There were also some minor text updates.
You can read the book online [2] or download it from [3] to read it locally.
Once again, all credit goes to Bruce Dubbs for doing all the work for the
main LFS book, without which the systemd book wouldn't exist.
-- Armin K., LFS systemd Maintainer.
www.linuxfromscratch.org
[1] http://lists.linuxfromscratch.org/pipermail/lfs-dev/2015-February/069895.html
[2] http://www.linuxfromscratch.org/lfs/view/7.7-systemd/
[3] http://www.linuxfromscratch.org/lfs/downloads/7.7-systemd/
--
Note: My last name is not Krejzi.
[lfs-announce] LFS and BLFS Version 7.7 is released
Version 7.7 and BLFS Version 7.7.
This release is a major update to both LFS and BLFS.
The LFS release includes updates to glibc-2.21, binutils-2.25, and gcc-4.9.2. In
total, 30 packages were updated, fixes made to bootscripts, and changes to text
have been made throughout the book.
The BLFS version includes approximately 750 packages beyond the base Linux From
Scratch Version 7.7 book. This release has over 710 updates from the previous
version including numerous text and formatting changes.
You can read the books online[0]-[1], or download[2]-[3] to read locally.
Please direct any comments about this release to the LFS development
team at lfs-dev@linuxfromscratch.org or blfs-dev@linuxfromscratch.org.
Registration for the mailing lists is required to avoid junk email.
-- Bruce Dubbs
LFS
[0] http://www.linuxfromscratch.org/lfs/view/7.7/
[1] http://www.linuxfromscratch.org/blfs/view/7.7/
[2] http://www.linuxfromscratch.org/lfs/downloads/7.7/
[3] http://www.linuxfromscratch.org/blfs/downloads/7.7/
--
http://lists.linuxfromscratch.org/listinfo/lfs-announce
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page