Wednesday, October 28, 2015

[USN-2786-1] PHP vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWMNZrAAoJEGVp2FWnRL6TGhUP/RbdEygSl9prIt3SfxoXgoQn
FuDXWw7FUj6yf6R2WPfhkiP0000r4tDPxB1XH7La9PF8NRs8Rp0u/Tnj6co6Kaqs
glJ5Lrxv6NYhfRDXP4Z6edsDbHm5vDxPBgox6NIPwvwCPmU/eh8k53OQJarwsZRI
QrEhvM2KD/LFWG8eBiRhhpkMWeg97BEfls/g6xqOO5TQr0bml5QDKl6OXUPMHKXn
phgrCzV7E6tCmfMDakJs3OeZCjXJ5DBT0zoft6IFbJWSQY4nZb/lLP3bntG/YxPi
+34R5IU5++ObmpsTKJydSkc+mGbjMlXUNJELfyijbx29eE40evZMFnLI6ePgkkuh
bzff2a6g9zNhshIViv+hD2+7nrIHloeNulUbEcBdM+W+e1Q1CZc0rpN9nZIsWGFk
EA+NcBoanPxVPIFfwfdbduVE6UFEl1JdTRcIhPcWNM+2vVKu//5N7qHbz04qsK0n
SnQ4opNJHwXRD0nBgK4CAsF5zzYg8KgEOHo5a1DzngKw0IPvjPhW0djUGotU1jza
N+MYSBhDcXTXC6fCcLHgBSJD0clZqFMwmz2oLBZUVnkY3h6fAGnih6In3eEmLe0D
s+2Gpej/m7TJchgONyxz4pLs/48weB522477xp+ihLVhWZ9HxqqFVFIeNw7h/gbj
NHyUjqbg+GGP07wyy0hd
=cTZL
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2786-1
October 28, 2015

php5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

PHP could be made to crash if it processed a specially crafted file.

Software Description:
- php5: HTML-embedded scripting language interpreter

Details:

It was discovered that the PHP phar extension incorrectly handled certain
files. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service. (CVE-2015-7803, CVE-2015-7804)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
libapache2-mod-php5 5.6.11+dfsg-1ubuntu3.1
php5-cgi 5.6.11+dfsg-1ubuntu3.1
php5-cli 5.6.11+dfsg-1ubuntu3.1
php5-fpm 5.6.11+dfsg-1ubuntu3.1

Ubuntu 15.04:
libapache2-mod-php5 5.6.4+dfsg-4ubuntu6.4
php5-cgi 5.6.4+dfsg-4ubuntu6.4
php5-cli 5.6.4+dfsg-4ubuntu6.4
php5-fpm 5.6.4+dfsg-4ubuntu6.4

Ubuntu 14.04 LTS:
libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.14
php5-cgi 5.5.9+dfsg-1ubuntu4.14
php5-cli 5.5.9+dfsg-1ubuntu4.14
php5-fpm 5.5.9+dfsg-1ubuntu4.14

Ubuntu 12.04 LTS:
libapache2-mod-php5 5.3.10-1ubuntu3.21
php5-cgi 5.3.10-1ubuntu3.21
php5-cli 5.3.10-1ubuntu3.21
php5-fpm 5.3.10-1ubuntu3.21

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2786-1
CVE-2015-7803, CVE-2015-7804

Package Information:
https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.1
https://launchpad.net/ubuntu/+source/php5/5.6.4+dfsg-4ubuntu6.4
https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.14
https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.21

[CentOS-announce] CESA-2015:1943 Moderate CentOS 7 qemu-kvm Security Update

CentOS Errata and Security Advisory 2015:1943 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1943.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
dd94816402a1d6ba50110b2b714fe76e4da7624094fe2bbda431b14de57ea15d libcacard-1.5.3-86.el7_1.8.i686.rpm
015b9cafdab4091e7ca54cab05261db4740b554f2e66236c9b67eed4b0c15598 libcacard-1.5.3-86.el7_1.8.x86_64.rpm
a09a4ba70f24149e52c7331b5dd3f5f4077da2c7412490e8b5fecfe243eaf6bb libcacard-devel-1.5.3-86.el7_1.8.i686.rpm
4e1ca0fc8b286a78411952c2cc511e189949e8a0269813123965cc13cf273a07 libcacard-devel-1.5.3-86.el7_1.8.x86_64.rpm
be53857ce4dbd8d58ca584959a33d42b45e26d5e86e55d5c0e1a21cb10b10bba libcacard-tools-1.5.3-86.el7_1.8.x86_64.rpm
244a5a113e5d6e53acd1d8ac7ed8f95bbb78f8b55eacb81613462a3b18a97488 qemu-img-1.5.3-86.el7_1.8.x86_64.rpm
b08974a473cb3243a0286d43b5b114af0b593ab859ecec328806a28e06d44f4f qemu-kvm-1.5.3-86.el7_1.8.x86_64.rpm
14890a3fa1ca8397c4cfadee79f26e9d7afcd5b725926a8a81f7830d95f29510 qemu-kvm-common-1.5.3-86.el7_1.8.x86_64.rpm
be4fba970abf0dc7150a90f34d7efec190d21daabb09b937a7aa80c7b68ebbff qemu-kvm-tools-1.5.3-86.el7_1.8.x86_64.rpm

Source:
306db1cd0a5cb661a106ffa33c9d084719264f9b9565fa1bf932d3cc7c51a482 qemu-kvm-1.5.3-86.el7_1.8.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[USN-2784-1] OpenJDK 7 vulnerabilities

==========================================================================
Ubuntu Security Notice USN-2784-1
October 28, 2015

openjdk-7 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in OpenJDK 7.

Software Description:
- openjdk-7: Open Source Java implementation

Details:

Multiple vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker
could exploit these to cause a denial of service or expose sensitive
data over the network. (CVE-2015-4805, CVE-2015-4835, CVE-2015-4843,
CVE-2015-4844, CVE-2015-4860, CVE-2015-4868, CVE-2015-4881,
CVE-2015-4883)

A vulnerability was discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit
this to expose sensitive data over the network. (CVE-2015-4806)

A vulnerability was discovered in the OpenJDK JRE related to data
integrity. An attacker could exploit this expose sensitive data over
the network. (CVE-2015-4872)

Multiple vulnerabilities were discovered in the OpenJDK JRE related
to information disclosure. An attacker could exploit these to expose
sensitive data over the network. (CVE-2015-4734, CVE-2015-4840,
CVE-2015-4842, CVE-2015-4903)

Multiple vulnerabilities were discovered in the OpenJDK JRE related
to availability. An attacker could exploit these to cause a denial of
service. (CVE-2015-4803, CVE-2015-4882, CVE-2015-4893, CVE-2015-4911)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
icedtea-7-jre-jamvm 7u85-2.6.1-5ubuntu0.15.10.1
openjdk-7-jre 7u85-2.6.1-5ubuntu0.15.10.1
openjdk-7-jre-headless 7u85-2.6.1-5ubuntu0.15.10.1
openjdk-7-jre-lib 7u85-2.6.1-5ubuntu0.15.10.1
openjdk-7-jre-zero 7u85-2.6.1-5ubuntu0.15.10.1

Ubuntu 15.04:
icedtea-7-jre-jamvm 7u85-2.6.1-5ubuntu0.15.04.1
openjdk-7-jre 7u85-2.6.1-5ubuntu0.15.04.1
openjdk-7-jre-headless 7u85-2.6.1-5ubuntu0.15.04.1
openjdk-7-jre-lib 7u85-2.6.1-5ubuntu0.15.04.1
openjdk-7-jre-zero 7u85-2.6.1-5ubuntu0.15.04.1

Ubuntu 14.04 LTS:
icedtea-7-jre-jamvm 7u85-2.6.1-5ubuntu0.14.04.1
openjdk-7-jre 7u85-2.6.1-5ubuntu0.14.04.1
openjdk-7-jre-headless 7u85-2.6.1-5ubuntu0.14.04.1
openjdk-7-jre-lib 7u85-2.6.1-5ubuntu0.14.04.1
openjdk-7-jre-zero 7u85-2.6.1-5ubuntu0.14.04.1

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to restart any
Java applications or applets to make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2784-1
CVE-2015-4734, CVE-2015-4803, CVE-2015-4805, CVE-2015-4806,
CVE-2015-4835, CVE-2015-4840, CVE-2015-4842, CVE-2015-4843,
CVE-2015-4844, CVE-2015-4860, CVE-2015-4868, CVE-2015-4872,
CVE-2015-4881, CVE-2015-4882, CVE-2015-4883, CVE-2015-4893,
CVE-2015-4903, CVE-2015-4911

Package Information:
https://launchpad.net/ubuntu/+source/openjdk-7/7u85-2.6.1-5ubuntu0.15.10.1
https://launchpad.net/ubuntu/+source/openjdk-7/7u85-2.6.1-5ubuntu0.15.04.1
https://launchpad.net/ubuntu/+source/openjdk-7/7u85-2.6.1-5ubuntu0.14.04.1

Tuesday, October 27, 2015

如何轻松掌握培训师必备的现场演绎技巧和控场能力---reallost1.fbsd2233449

reallost1.fbsd2233449   您好

附件中的内容希望对您的工作和学习有所帮助

公祝您工作顺利,生活愉快。

公璨钦

rbyvr

 

[USN-2783-1] NTP vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWL7BRAAoJEGVp2FWnRL6T7mQP/2AtQGg9vpIkFdB2Ou7Gkyzj
aASrTqAFuMpubaoZEvlnmfREEaJkrwvVA4EscGHlOyqD/ZZys6W+Yy9NSmcXwIZV
/Exj9XiCPbeVbs3OT7z5UrafiMp9k6p9KaVzGZWPFCejwabHhtuC8nmfIZ0DxLN5
TNGNaN1Q1n0WKOdgGthr94dJSWemUQtSb10XhLAlvHg9EjbmVec//JqyONs0K15F
vxwtWOTXOsf56/5idJxFjxpH+0nBTuXrxmkzgnzuqbRardCra3gfDycD638WOg0O
jEdmVDT6cK5wkrtmJ5+o+CcAtCGQ4744sbRlammFT7SzVm7wH1K1HXbon9RlLyVf
/M+o4xPioz5rTcytuMHPaft5JSEyKxIa4nciDfh0NFKt4imattRqEq5tMqIewiMQ
UI1WA6fd3JQdYSYi0KfmvE+gbCPMks+t+p9Ucw5sCUp3CNTEpZfgmtxI9C2XYwzD
VSBjTGxvJybprPIizKIs1HgHiqlr8cSDNzr/mYdPpHRjZuedXLJ6ZxSUIAIsXoHZ
mWuNe8Uut+YeCokwJDXBIS8Z5Fc5bIwug4IIFwjaGuWdphddKs194klJJKN01uVS
CBnk7rMbp9mUka7gAMTxKBROAD7XWbmIfqSiCxNRi9SUkjh0ceM8Gpe5VlYEAGi/
SwbiJhaNpUXP9x7ZCwy/
=Gr64
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2783-1
October 27, 2015

ntp vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in NTP.

Software Description:
- ntp: Network Time Protocol daemon and utility programs

Details:

Aleksis Kauppinen discovered that NTP incorrectly handled certain remote
config packets. In a non-default configuration, a remote authenticated
attacker could possibly use this issue to cause NTP to crash, resulting in
a denial of service. (CVE-2015-5146)

Miroslav Lichvar discovered that NTP incorrectly handled logconfig
directives. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5194)

Miroslav Lichvar discovered that NTP incorrectly handled certain statistics
types. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service. (CVE-2015-5195)

Miroslav Lichvar discovered that NTP incorrectly handled certain file
paths. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to crash, resulting in a denial
of service, or overwrite certain files. (CVE-2015-5196, CVE-2015-7703)

Miroslav Lichvar discovered that NTP incorrectly handled certain packets.
A remote attacker could possibly use this issue to cause NTP to hang,
resulting in a denial of service. (CVE-2015-5219)

Aanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP
incorrectly handled restarting after hitting a panic threshold. A remote
attacker could possibly use this issue to alter the system time on clients.
(CVE-2015-5300)

It was discovered that NTP incorrectly handled autokey data packets. A
remote attacker could possibly use this issue to cause NTP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-7691, CVE-2015-7692, CVE-2015-7702)

It was discovered that NTP incorrectly handled memory when processing
certain autokey messages. A remote attacker could possibly use this issue
to cause NTP to consume memory, resulting in a denial of service.
(CVE-2015-7701)

Aanchal Malhotra, Isaac E. Cohen, and Sharon Goldberg discovered that NTP
incorrectly handled rate limiting. A remote attacker could possibly use
this issue to cause clients to stop updating their clock. (CVE-2015-7704,
CVE-2015-7705)

Yves Younan discovered that NTP incorrectly handled logfile and keyfile
directives. In a non-default configuration, a remote authenticated attacker
could possibly use this issue to cause NTP to enter a loop, resulting in a
denial of service. (CVE-2015-7850)

Yves Younan and Aleksander Nikolich discovered that NTP incorrectly handled
ascii conversion. A remote attacker could possibly use this issue to cause
NTP to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2015-7852)

Yves Younan discovered that NTP incorrectly handled reference clock memory.
A malicious refclock could possibly use this issue to cause NTP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2015-7853)

John D "Doug" Birdwell discovered that NTP incorrectly handled decoding
certain bogus values. An attacker could possibly use this issue to cause
NTP to crash, resulting in a denial of service. (CVE-2015-7855)

Stephen Gray discovered that NTP incorrectly handled symmetric association
authentication. A remote attacker could use this issue to possibly bypass
authentication and alter the system clock. (CVE-2015-7871)

In the default installation, attackers would be isolated by the NTP
AppArmor profile.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
ntp 1:4.2.6.p5+dfsg-3ubuntu8.1

Ubuntu 15.04:
ntp 1:4.2.6.p5+dfsg-3ubuntu6.2

Ubuntu 14.04 LTS:
ntp 1:4.2.6.p5+dfsg-3ubuntu2.14.04.5

Ubuntu 12.04 LTS:
ntp 1:4.2.6.p3+dfsg-1ubuntu3.6

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2783-1
CVE-2015-5146, CVE-2015-5194, CVE-2015-5195, CVE-2015-5196,
CVE-2015-5219, CVE-2015-5300, CVE-2015-7691, CVE-2015-7692,
CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704,
CVE-2015-7705, CVE-2015-7850, CVE-2015-7852, CVE-2015-7853,
CVE-2015-7855, CVE-2015-7871

Package Information:
https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu8.1
https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu6.2
https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p5+dfsg-3ubuntu2.14.04.5
https://launchpad.net/ubuntu/+source/ntp/1:4.2.6.p3+dfsg-1ubuntu3.6

[USN-2782-1] Apport vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWL3l2AAoJEGVp2FWnRL6T9owQAKykqYJqWE8Pzr5tbvxvbko0
UTcCn7FN6SeNq1uo5ygaOWIF6QYWKD/6c+W1z5TuoGmAkcCe8Uq83KmjmEqDsXNC
qlD2DGLEiTbYaJIHngRoAOn2YrJeneJmLKr/ZHmwFPrl3frh9LBY4Iim7yLXKh15
Ied+2asXBee7vdk0JHaxBBwcs0fkofQoWmCd8pl/leki3/R/f6zVmKXhklyneGDL
3gASKovm+FVnix9+940u4WLwN//bszXPeTp3m9XlHxRi3k4Z4o8Z2Yqa2BciPvA+
HZkjGCEN+e2YFUG+NFsCSou6U6It47wt0BJKnSYSh+gST3kX6TV250E1lrZuEkFf
oZBHVcKwhkh1YIDCfz3jjkrbUNn5FnEKzTIlVyZflg4vmMQbiYyEyr62u1VXRomf
8jkb9h2lExyVlIUp3zrt6nz2IXQonoLmVq5gVao2mjqz/GB/JMB7n5O/SSl1AhEi
AQtDVD/aSPRlT0pehKnTth2HuLIaNGNAhTyaQDWceJmBk+jCE3D9ZBIgboelBDS1
5WdY35cFD+UMcT/cgkVEFzW8yEg0E5UmAHJ7UhAy33YT7GG7ou9QE1BnLI5RHlby
4kA4MDmuJluHLDw5Dt/83iDgbW9fSC7A9Hiw6y/hZgSnbRJ8eZZBQIhRKBpucr+f
H9XPbaRzhThT9i27YVzC
=BikZ
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2782-1
October 27, 2015

apport vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Apport could be made to run programs as an administrator.

Software Description:
- apport: automatically generate crash reports for debugging

Details:

Gabriel Campana discovered that Apport incorrectly handled Python module
imports. A local attacker could use this issue to elevate privileges.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
apport 2.19.1-0ubuntu4

Ubuntu 15.04:
apport 2.17.2-0ubuntu1.7

Ubuntu 14.04 LTS:
apport 2.14.1-0ubuntu3.18

Ubuntu 12.04 LTS:
apport 2.0.1-0ubuntu17.13

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2782-1
CVE-2015-1341

Package Information:
https://launchpad.net/ubuntu/+source/apport/2.19.1-0ubuntu4
https://launchpad.net/ubuntu/+source/apport/2.17.2-0ubuntu1.7
https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.18
https://launchpad.net/ubuntu/+source/apport/2.0.1-0ubuntu17.13

Monday, October 26, 2015

reallost1.fbsd2233449:如何避免劳动纠纷

reallost1.fbsd2233449   您好

附件中的内容希望对您的工作和学习有所帮助

期待您的莅临。

岑祝您工作顺利,生活愉快。

岑玲嶬

mquzo

 

reallost1.fbsd2233449:如何高效管理研发成-本

研发室一个企业的重要部门,如何做到研发成本的高效管理,请阅览附件

[CentOS-announce] CESA-2015:1930 Important CentOS 7 ntp Security Update

CentOS Errata and Security Advisory 2015:1930 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1930.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
8f073bb7d81834cf898ba2a8561962cbc16c881b6c2738e25e487da29f00abfe ntp-4.2.6p5-19.el7.centos.3.x86_64.rpm
c8cfd910fd3a75503f31b2f923d419eb1e56b37cd6f565d512cc5c45ed06f50c ntpdate-4.2.6p5-19.el7.centos.3.x86_64.rpm
d640161a23a1bbcfd5186be2b6cad1fcf03003a165b32717bd208ceefc943d92 ntp-doc-4.2.6p5-19.el7.centos.3.noarch.rpm
d4926c9306439e023b3d5d9bfd2d38077971ac0030b0a05ec3fdc3d4ded92071 ntp-perl-4.2.6p5-19.el7.centos.3.noarch.rpm
fbfe6b88e16c8f1bab9ca194d2b234652d016c995330a5aa22cd4f39349f9de2 sntp-4.2.6p5-19.el7.centos.3.x86_64.rpm

Source:
3f2c2f3b1af0b94d01702d85e55442fb517e8747779a40339be96747650246ac ntp-4.2.6p5-19.el7.centos.3.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2015:1930 Important CentOS 6 ntp Security Update

CentOS Errata and Security Advisory 2015:1930 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1930.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
3cd9b3811298e411dfa65eb67a74b61bdee315640dfc11d1f02c28c8953af6aa ntp-4.2.6p5-5.el6.centos.2.i686.rpm
bda06af5dda320b811acf25e26950eec6476b9e2ed91cf40f32b95d8432f1780 ntpdate-4.2.6p5-5.el6.centos.2.i686.rpm
5a68ef2c168fc52f5064d75124fda27a2e0b4992242f0458ffe0207fb6164019 ntp-doc-4.2.6p5-5.el6.centos.2.noarch.rpm
74aa10fbcafbeab0d5e5fe57d7d5ac9177a175f7133eb6d84e7663796eedf700 ntp-perl-4.2.6p5-5.el6.centos.2.i686.rpm

x86_64:
24982d48079999e8be273feeda4725067c9bf74ae335aa4a18d67a7300435ffa ntp-4.2.6p5-5.el6.centos.2.x86_64.rpm
5228dc4b5af2f98f18198928fc4354484154ee1f01cc3a96d1732ed018d7bcbf ntpdate-4.2.6p5-5.el6.centos.2.x86_64.rpm
5a68ef2c168fc52f5064d75124fda27a2e0b4992242f0458ffe0207fb6164019 ntp-doc-4.2.6p5-5.el6.centos.2.noarch.rpm
ad4b6c9ca483d3e31687b730d7772df73b728a2de04c7152d470394203d48ec5 ntp-perl-4.2.6p5-5.el6.centos.2.x86_64.rpm

Source:
d32ee87acc861f4c4adeff99b7f8cdca4407173739d50b60fb3a691147fcbb32 ntp-4.2.6p5-5.el6.centos.2.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[USN-2781-1] MySQL vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWLkPxAAoJEGVp2FWnRL6TE0AQAKPYUsKwbroj7LUqeXuo/E1s
0hq4kAQa35BFB3enzjVradeFj/VgnmY0FBRu3jhTqv59chb1Wyy0FO5WcpGeqBZX
A0KYKj+XUxsmD9crVNzHPV1AvuSOrGYEAaS/zIpzexIjZyYPBHWaonPGWmac4YrZ
qobKMjkXAJ1Qr4XgclUemqwgzh3q+XafCgoRg98zU7KwUe/3c8zF8x7FXIhpX3Am
ofJhuoQ+RWs8quJwB+uCD9tldaJd9FVs86XA7IOxktWOYNhlmahoK3o/3YrwDFx5
0JyzAu2TIcntXdTaF/cqjGtknpDaw7R2rohi5qqI5MhBBnEo5BIWXA6+FKYelG+z
mtw4+gI3kiwAqX+M1XKpARvAulPznWqiSfvLV1rsRbEtYXJBYEAJ6emYcZxvF0eh
dYxbV6bSo3+2BhRVrqivFFVG/cRXDD9HSApNao8xKKTIZOWQTHqT/HWV5+Zurbk9
wifpuvB26JdZsRHaO9iUsAKU2raMKhJ/Prl52ipQV7J1Bm+aMP19hOnAx2i08s8A
7zVeuwYe2DlFgXQcosJ1+0ywdw36SAR4LKJrDjq9xmiMYpAScoxkODxHlaSUgyS9
0/dD4mPGfC2GRmEYBUfnhUim5HVtr/up1g9yPRfbG13p+vNhvZkTJByRv0s9b0+9
ObcwM9RFyaYDJMsizgdZ
=HPmm
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2781-1
October 26, 2015

mysql-5.5, mysql-5.6 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in MySQL.

Software Description:
- mysql-5.6: MySQL database
- mysql-5.5: MySQL database

Details:

Multiple security issues were discovered in MySQL and this update includes
new upstream MySQL versions to fix these issues.

MySQL has been updated to 5.5.46 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
Ubuntu 15.04 and Ubuntu 15.10 have been updated to MySQL 5.6.27.

In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes.

Please see the following for more information:
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-45.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-46.html
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-26.html
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-27.html
http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
mysql-server-5.6 5.6.27-0ubuntu1

Ubuntu 15.04:
mysql-server-5.6 5.6.27-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
mysql-server-5.5 5.5.46-0ubuntu0.14.04.2

Ubuntu 12.04 LTS:
mysql-server-5.5 5.5.46-0ubuntu0.12.04.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2781-1
CVE-2015-4730, CVE-2015-4766, CVE-2015-4792, CVE-2015-4800,
CVE-2015-4802, CVE-2015-4815, CVE-2015-4816, CVE-2015-4819,
CVE-2015-4826, CVE-2015-4830, CVE-2015-4833, CVE-2015-4836,
CVE-2015-4858, CVE-2015-4861, CVE-2015-4862, CVE-2015-4864,
CVE-2015-4866, CVE-2015-4870, CVE-2015-4879, CVE-2015-4890,
CVE-2015-4895, CVE-2015-4904, CVE-2015-4910, CVE-2015-4913

Package Information:
https://launchpad.net/ubuntu/+source/mysql-5.6/5.6.27-0ubuntu1
https://launchpad.net/ubuntu/+source/mysql-5.6/5.6.27-0ubuntu0.15.04.1
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.46-0ubuntu0.14.04.2
https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.46-0ubuntu0.12.04.2

[FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-15:25.ntp

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=============================================================================
FreeBSD-SA-15:25.ntp Security Advisory
The FreeBSD Project

Topic: Multiple vulnerabilities of ntp

Category: contrib
Module: ntp
Announced: 2015-10-26
Credits: Network Time Foundation
Affects: All supported versions of FreeBSD.
Corrected: 2015-10-26 11:35:40 UTC (stable/10, 10.2-STABLE)
2015-10-26 11:36:55 UTC (releng/10.2, 10.2-RELEASE-p6)
2015-10-26 11:37:31 UTC (releng/10.1, 10.1-RELEASE-p23)
2015-10-26 11:36:40 UTC (stable/9, 9.3-STABLE)
2015-10-26 11:42:25 UTC (releng/9.3, 9.3-RELEASE-p29)
CVE Name: CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7704,
CVE-2015-7848, CVE-2015-7849, CVE-2015-7850, CVE-2015-7851,
CVE-2015-7852, CVE-2015-7853, CVE-2015-7854, CVE-2015-7855,
CVE-2015-7871

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit https://security.FreeBSD.org/.

I. Background

The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP)
used to synchronize the time of a computer system to a reference time
source.

II. Problem Description

Crypto-NAK packets can be used to cause ntpd(8) to accept time from an
unauthenticated ephemeral symmetric peer by bypassing the authentication
required to mobilize peer associations. [CVE-2015-7871] FreeBSD 9.3 and
10.1 are not affected.

If ntpd(8) is fed a crafted mode 6 or mode 7 packet containing an unusual
long data value where a network address is expected, the decodenetnum()
function will abort with an assertion failure instead of simply returning
a failure condition. [CVE-2015-7855]

If ntpd(8) is configured to allow remote configuration, and if the
(possibly spoofed) source IP address is allowed to send remote
configuration requests, and if the attacker knows the remote
configuration password or if ntpd(8) was configured to disable
authentication, then an attacker can send a set of packets to ntpd(8) that
may cause it to crash, with the hypothetical possibility of a small code
injection. [CVE-2015-7854]

A negative value for the datalen parameter will overflow a data buffer.
NTF's ntpd(8) driver implementations always set this value to 0 and are
therefore not vulnerable to this weakness. If you are running a custom
refclock driver in ntpd(8) and that driver supplies a negative value for
datalen (no custom driver of even minimal competence would do this)
then ntpd would overflow a data buffer. It is even hypothetically
possible in this case that instead of simply crashing ntpd the
attacker could effect a code injection attack. [CVE-2015-7853]

If an attacker can figure out the precise moment that ntpq(8) is listening
for data and the port number it is listening on or if the attacker can
provide a malicious instance ntpd(8) that victims will connect to then an
attacker can send a set of crafted mode 6 response packets that, if
received by ntpq(8), can cause ntpq(8) to crash. [CVE-2015-7852]

If ntpd(8) is configured to allow remote configuration, and if the
(possibly spoofed) IP address is allowed to send remote configuration
requests, and if the attacker knows the remote configuration password
or if ntpd(8) was configured to disable authentication, then an attacker
can send a set of packets to ntpd that may cause ntpd(8) to overwrite
files. [CVE-2015-7851]. The default configuration of ntpd(8) within
FreeBSD does not allow remote configuration.

If ntpd(8) is configured to allow remote configuration, and if the
(possibly spoofed) source IP address is allowed to send remote
configuration requests, and if the attacker knows the remote
configuration password or if ntpd(8) was configured to disable
authentication, then an attacker can send a set of packets to ntpd
that will cause it to crash and/or create a potentially huge log
file. Specifically, the attacker could enable extended logging,
point the key file at the log file, and cause what amounts to an
infinite loop. [CVE-2015-7850]. The default configuration of ntpd(8)
within FreeBSD does not allow remote configuration.

If ntpd(8) is configured to allow remote configuration, and if the
(possibly spoofed) source IP address is allowed to send remote
configuration requests, and if the attacker knows the remote
configuration password or if ntpd was configured to disable
authentication, then an attacker can send a set of packets to
ntpd that may cause a crash or theoretically perform a code
injection attack. [CVE-2015-7849]. The default configuration of ntpd(8)
within FreeBSD does not allow remote configuration.

If ntpd(8) is configured to enable mode 7 packets, and if the use
of mode 7 packets is not properly protected thru the use of the
available mode 7 authentication and restriction mechanisms, and
if the (possibly spoofed) source IP address is allowed to send
mode 7 queries, then an attacker can send a crafted packet to
ntpd that will cause it to crash. [CVE-2015-7848]. The default
configuration of ntpd(8) within FreeBSD does not allow mode 7
packets.

If ntpd(8) is configured to use autokey, then an attacker can send
packets to ntpd that will, after several days of ongoing attack,
cause it to run out of memory. [CVE-2015-7701]. The default
configuration of ntpd(8) within FreeBSD does not use autokey.

If ntpd(8) is configured to allow for remote configuration, and if
the (possibly spoofed) source IP address is allowed to send
remote configuration requests, and if the attacker knows the
remote configuration password, it's possible for an attacker
to use the "pidfile" or "driftfile" directives to potentially
overwrite other files. [CVE-2015-5196]. The default configuration
of ntpd(8) within FreeBSD does not allow remote configuration

An ntpd(8) client that honors Kiss-of-Death responses will honor
KoD messages that have been forged by an attacker, causing it
to delay or stop querying its servers for time updates. Also,
an attacker can forge packets that claim to be from the target
and send them to servers often enough that a server that
implements KoD rate limiting will send the target machine a
KoD response to attempt to reduce the rate of incoming packets,
or it may also trigger a firewall block at the server for
packets from the target machine. For either of these attacks
to succeed, the attacker must know what servers the target
is communicating with. An attacker can be anywhere on the
Internet and can frequently learn the identity of the target's
time source by sending the target a time query. [CVE-2015-7704]

The fix for CVE-2014-9750 was incomplete in that there were
certain code paths where a packet with particular autokey
operations that contained malicious data was not always being
completely validated. Receipt of these packets can cause ntpd
to crash. [CVE-2015-7702]. The default configuration of ntpd(8)
within FreeBSD does not use autokey.

III. Impact

An attacker which can send NTP packets to ntpd(8), which uses cryptographic
authentication of NTP data, may be able to inject malicious time data
causing the system clock to be set incorrectly. [CVE-2015-7871]

An attacker which can send NTP packets to ntpd(8), can block the
communication of the daemon with time servers, causing the system
clock not being synchronized. [CVE-2015-7704]

An attacker which can send NTP packets to ntpd(8), can remotely crash
the daemon, sending malicious data packet. [CVE-2015-7855] [CVE-2015-7854]
[CVE-2015-7853] [CVE-2015-7852] [CVE-2015-7849] [CVE-2015-7848]

An attacker which can send NTP packets to ntpd(8), can remotely
trigger the daemon to overwrite its configuration files. [CVE-2015-7851]
[CVE-2015-5196]

IV. Workaround

No workaround is available, but systems not running ntpd(8) are not
affected. Network administrators are advised to implement BCP-38,
which helps to reduce risk associated with the attacks.

V. Solution

Perform one of the following:

1) Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date.

The ntpd service has to be restarted after the update. A reboot is
recommended but not required.

2) To update your vulnerable system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

The ntpd service has to be restarted after the update. A reboot is
recommended but not required.

3) To update your vulnerable system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

[FreeBSD 10.2]
# fetch https://security.FreeBSD.org/patches/SA-15:25/ntp-102.patch.bz2
# bunzip2 ntp-102.patch.bz2
# fetch https://security.FreeBSD.org/patches/SA-15:25/ntp-102.patch.asc
# gpg --verify ntp-102.patch.asc

[FreeBSD 10.1]
# fetch https://security.FreeBSD.org/patches/SA-15:25/ntp-101.patch.bz2
# bunzip2 ntp-101.patch.bz2
# fetch https://security.FreeBSD.org/patches/SA-15:25/ntp-101.patch.asc
# gpg --verify ntp-101.patch.asc

[FreeBSD 9.3]
# fetch https://security.FreeBSD.org/patches/SA-15:25/ntp-93.patch.bz2
# bunzip2 ntp-93.patch.bz2
# fetch https://security.FreeBSD.org/patches/SA-15:25/ntp-93.patch.asc
# gpg --verify ntp-93.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch
# find contrib/ntp -type f -empty -delete

c) Recompile the operating system using buildworld and installworld as
described in https://www.FreeBSD.org/handbook/makeworld.html.

d) For 9.3-RELEASE and 10.1-RELEASE an update to /etc/ntp.conf is recommended,
which can be done with help of the mergemaster(8) tool on 9.3-RELEASE and
with help of the etcupdate(8) tool on 10.1-RELEASE.

Restart the ntpd(8) daemon, or reboot the system.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/9/ r289998
releng/9.3/ r290001
stable/10/ r289997
releng/10.1/ r290000
releng/10.2/ r289999
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN

VII. References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7701
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7702
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7703
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7704
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7848
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7849
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7850
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7851
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7852
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7853
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7854
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7855
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7871

The latest revision of this advisory is available at
https://security.FreeBSD.org/advisories/FreeBSD-SA-15:25.ntp.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJWLhOJAAoJEO1n7NZdz2rn91wP/2GwEt1boNQq2a7nYzv/mS5D
sYKkIi7o+2yr2BLXvtc3O7c9QC3/YeGsza9DTRqndcY572SWvRgtkFstMTTm8IV/
RVlIE40gVR3tex0zo7BiD7uKUrxWxWcpwMbE5dzlE+vSybyyj0dSSkwUHJjrbJoA
RmyNuEEUhQn5sRCg6qJv/PLp2G7BcYAasKScukjm7QnLP2kq/tvM9mcqwfh2tadM
7kbf8uq+ykvsRzctaDnxQaB5+zJxBQYJjBelxQfIkNek0XGfdj3sRwISeFznbllq
mOLTIBaFiuEtHtusO7MKKavMgS5CQJOvuuvd/l3NY1MnxC6X/1SWig9KIKDIn/hv
q8dsnq7LLx+tO6Cv4Dub7EbC2ZP3xXGOC4Ie02z8bTZnbX7iwyPUidQQqtU9ra15
rxzFcZnBxu+yyMNJVsV2qVV/r9OycgKxWlEELC1wYrK9fKfvLdA5aEGjDeU1Z+s6
JS2zKr0t4F2bMrCsjYP1lQD8sHkCVjwJk+IJU/slcwSajDjBNlMH0yBxGYE1ETIZ
qMF7/PAkLe8V78pdYmXw9pcaPyhI+ihPLnNrdhX8AI2RX5jDK7IuUNJeUM04UrVB
8N+mMwgamcuCPWNNyXaL0bz21fexZOuhHmU+B8Yn3SFX5O5b/r9gGvrjo8ei8jOk
EUlBT3ViDhHNrI7PTaiI
=djPm
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"