Sunday, May 29, 2016
libcrypto errata update
ASN.1 elements over 16kb.
Patches for OpenBSD are available. Updated LibreSSL-portable releases
will be available later.
http://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/009_crypto.patch.sig
http://ftp.openbsd.org/pub/OpenBSD/patches/5.8/common/015_crypto.patch.sig
Friday, May 27, 2016
Fedora 24 Final Freeze (2016-05-31)
Tuesday May 31st 2016 is an important day on the Fedora 24 schedule[1], with
significant cut-offs.
Tuesday is the Final Freeze[2]. This means that only packages which
fix accepted blocker or freeze exception bugs[3][4] will be marked as
'stable' and included in the Final composes. Other builds will remain
in updates-testing until the Final release is approved, at which point
the Final freeze is lifted and packages can move to the 'updates' repository,
pending updates will be pushed before final release as zero day updates.
The final stable push before freeze will happen shortly after 2016-05-31
00:00:00 Please get all updates you want included requested for stable in
bodhi[5] before then.
Regards
Dennis
[1] https://fedoraproject.org/wiki/Releases/24/Schedule
[2] https://fedoraproject.org/wiki/Milestone_freezes
[3] https://fedoraproject.org/wiki/QA:SOP_blocker_bug_process
[4] https://fedoraproject.org/wiki/QA:SOP_freeze_exception_bug_process
[5] https://bodhi.fedoraproject.org/
Planned Outage: database outage - 2016-05-27 21:00 UTC
There will be an outage starting at 2016-05-27 21:00 UTC, which will
last approximately 1 hour or less.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2016-05-27 21:00 UTC'
Reason for outage:
We need to add disk space to one of our primary database servers. This
will ensure it has sufficient space for the upcoming ramp up to Fedora
24 Final release. This outage should be very short.
Affected Services:
fedocal
fedora tagger
kerneltest
mailman3/hyperkitty
koschei
mirrormanager web interface
fedora notifications service
nuancier
pdc
pkgdb2
badges
Services not listed are not affected by this outage.
Contact Information: https://fedorahosted.org/fedora-
infrastructure/ticket/5327
Ticket Link:
Please join #fedora-admin or #fedora-noc on irc.freenode.net or add
comments to the ticket for this outage above.
F25 Self Contained Change: Koji Generates Installation Media
https://fedoraproject.org/wiki/Changes/KojiInstallMedia
Change owner(s):
* Jay Greguske <jgregusk with the usual red hat domain>
Extend Koji with a new feature that allows users to create
installation media for various architectures.
== Detailed Description ==
This is a significant enabler for generating DVD media, other ISOs,
and images more efficiently. It also allows other tools such as mash
or pungi to offload much of the heavy-lifting to the build system.
Longer term, we may be able to reduce the number of tools needed to
manufacture Fedora releases.
== Scope ==
Proposal owners:
* to implement this change
Release engineering:
* This feature does require coordination with release engineering
(e.g. changes to installer image generation or update package
delivery.)
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org
Thursday, May 26, 2016
reallost1.fbsd2233449:全 能 型 车 间 主 任 50650
全 能 型 车 间 主 任 -- 实战技能训练
【参加对象】 企业厂长、制造业生产总监、生产经理、车间主任及生产制造主管及一线干部
【时间地点】 2016年6月04-05上海
【授课方式】 讲师讲授 + 视频演绎 + 案例研讨 +角色扮演 + 讲师点评
【学习费用】 3200/人(含课程讲义、午餐、茶点等)
垂询热线:上海:021-31006787 189-1787 0808 许先生
QQ/微信:320588808
注:如不需此类信件信息,请转发送"删除"至tuiding02@163.com,我们会及时处理,谢谢您的理解。
课程背景:
《全能型车间主任实战技能训练》课程在全国推广五年以来,深受国内外企业的菁莱。在全国成功举办公开课近百场次,并被很多企业引进为内训课程,尤其是中字头企业和装备制造业。在举办过程中,学员对该课程和讲师的评价可综合为六个字"实在"、"实用"、"实战"。四年的发展、四年的发现、四年的变化,使该课程的开发者――陈志华老师有了更多的感悟与提升。为了进一步加强该课程的实用性、系统性和科学性,陈志华老师对课程作了更一步的完善。现在您看到的是2013版《全能型车间主任实战技能训练》课程大纲。
2014版《全能型车间主任实战技能训练》以科学管理为纲、以系统化为领、以鲜活的现状为例,助力广大学员改变用"习惯性思维"做管理,凭"过往经验"办事情的风格。学习和掌握科学的理念、系统、方法、工具,并灵活地运用到实际工作中去。从此改变车间工作忙而乱,类似问题天天有,不同问题相同对策的格局。
课程大纲:
第一讲 基层领导角色认知与管理认知
问题讨论
为什么我们总是很忙?
为什么忙的时候只知道加班、加人、加设备?
我们凭什做管理?(理念、系统、方法、工具?)
传统管理与科学管理究竟有何区别?
领导的自我认知与任务
车间主任与班长到底是不是真正的领导?
领导到底是人手还是人才?
领导的三大主要标志是什么?
领导的必备的两大基本条件是什么?
领导的三件事与两大任务?
管理的三种认识
过程与手段(管理为何与时间息息相关?)
技术与艺术(如何让部下对你的管理感兴趣?)
行为与借力(上下级与相邻部门如何借力?)
经典分享(减少超负荷加班的八大要点)
班(组)长工作力不从心的原因分析
时间有效利用率低下的八大原因分析
第二讲 工作职责神圣化与班组管理
车间主任的四种身份角色
对待企业与报酬的两种心态
对待下属与下属的三种心态
实战训练:如何管理好你的班长?
班长有哪四种不称职表现?
班长为什么总是忙而乱?
班长最喜欢的工作方式是什么?
工作技巧:班长协调的劣势与最佳范围
现场管理中的"定员定岗"有何特别要求?
为什么游离状态的作业没有工作效率?
经典分享
现场管理"三不坚守原则"决定产能释放
第三讲 钱,在哪里?怎么来!——权威观点的价值
管理者管理效率——被勿视的西瓜
管理者管理思路——一个中心两个基本点
管理者管理方法——重经验凭习惯
没有结局的结局——布局决定结局
员工的生产效率——只有强化没有改善
新产品的研发 ——没有可批量制造性
抢:抢时间永远都不犯法
省:省出的钱都是净利益
盯:盯出的效率成本最低
挖:挖出的效益最有价值
第四讲 质量与效率的分析与长效控制手法
生产效率与生产能力识别
生产方式与生产原理识别
什么是流线化与流程化?
(乱流、倒流、绕流的形成分析与对策)
什么是标准化的现场管理?
什么是标准化作业?
什么是作业标准化?
经济动作的三不原则?
经典分享:
车产物流管理的"三不政策"
平衡效率与平衡损失率的计算与意义
生产线不平衡管的十大原因分析
第五讲 后员工管理与工作教导的四阶段法
———员工为什么会犯错?
———员工为什么会流失?
———怎样才能管理好你的员工?
上司最不妥当的"八大肢体语言"
上司最不妥当的"十大口头语言"
上司尊重员工人格的"十大要点"
面对员工要胁的"五大对策"
———工作教导"四阶段法"的应用
经典分享
人的第一资产是什么以及对管理的启发?
第六讲 把握N种管理理念/体系构筑的精髓
观念:ISO9000的效用是提升企业的体质
问题:为什么只求证书不求正本?
问题讨论:
1)精益生产到底是什么?(TPS、JIT、看板生产?)
2)到底是不是精益创造了TOYOTA神话?
3)精益生产的核心思想和核心思路到底是什么?
4)为什么只能是"5S"而不是"6S、7S"
5)5S管理为什么总是一动就还原?
6)5S管理的精髓与终极目的是什么?
经典分享:
车间物品摆放的"三不管理原则"?
学员课后作业或实践(感悟与收获)
(一)感悟部份
1、对于工作中出现的问题,我们通常更多地归根于"沟通不行"、"协调不当"、"执行能力差"等问题。从表面上看确实是这些问题。只要仔细想想,也许你会悟出一些疑问:难道人与人之间就那么难以沟通吗?部门之间难道就那么难以协调吗?属下难道就不想把工作尽快完成吗?对此问题你有何感想?
2、如果说管理是一门艺术,而艺术最精华的就是创意。作为一名中基层领导者,面对新生代或者另类的员工群体,在过往的管理过程中所做的一切到底是你或你的上司感兴趣,还是先让员工感兴趣呢?管理的创意你有了吗?员工对你的管理感兴趣了吗?你打算做何努力?
3、通过该课程我们已经知道了人的第一资产是人格尊严。理解起来其实很容易,可是做起来真的很难。在今后的工作中你打算怎样去保护好员工的人格尊严。
(二)实践部份
1、尽管中国企业的一线员工其实已经很优秀了,但在工厂或车间只要出现质量问题或者是交期问题,员工还是罪责难逃。本课程完后你回到公司抽四个小时的时间站到一个视觉良好的地方观察一下你的员工作业的状态,就会明白为什么质量不稳定,为什么看上去热火朝天却总是交不出货。请你观察后找出原因并划清罪责。
2、本课程完成后请你回到公司用一张A3的纸把你的车间平面图划下来。再用半天的时间观察车间的实际人流、物流、信息流现状,并把每一次流动路线在A3纸上进行连接。请你再看看那张平面图是什么状况,并由此推断你到底出了什么问题。
3、目前中国工厂每天几乎只在为一个问题忙碌,那就是赶货!到底是订单量太大没法承受,还是的确生产能力有限,或者是生产效率太低呢?这个问题恐怕所有人都能答得上来,更恐怕没有几个人答的是对的。如果所有人都答对了,那为什么还是天天这样?对此你有何感想?
讲师介绍:【陈志华】
工商管理硕士,国内制造管理专家师
工作经历:
曾在全球最大的线圈制造商胜美达(SUMIDA)、日本卡西欧电子(CASIO)任职达13年,历任生产主管、品质主管,生产经理、制造总经理等;曾师从小川一也(日本能率协会管理中心专家, 日本WF&IE研究第一人,日本制造业研究的国宝级人物)专门研习标准工时与动作研究曾先后多次被派往日本和新加坡进修及培训(丰田JIT生产方式,对NPS有系统及深入研究和实践), 陈老师尤其擅长现场一体化管理(计划,成本,纳期,质量,技术,人员)
主讲课程:
《构筑高精度标准工时ST管理系统》、《多技能员工培养体系》、《多批少量生产方式实务》、《微利时代的精细化现场管理》、《全能班组长训练》等,主要出版物《反省中国式工厂管理》、《挑战80后管理》等。
[USN-2985-2] GNU C Library regression
Ubuntu Security Notice USN-2985-2
May 26, 2016
eglibc, glibc regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
USN-2985-1 introduced a regression in the GNU C Library.
Software Description:
- glibc: GNU C Library
- eglibc: GNU C Library
Details:
USN-2985-1 fixed vulnerabilities in the GNU C Library. The fix for
CVE-2014-9761 introduced a regression which affected applications that
use the libm library but were not fully restarted after the upgrade.
This update removes the fix for CVE-2014-9761 and a future update
will be provided to address this issue.
We apologize for the inconvenience.
Original advisory details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE-2014-9761)
Arjun Shankar discovered that in certain situations the nss_dns code in the
GNU C Library did not properly account buffer sizes when passed an
unaligned buffer. An attacker could use this to cause a denial of service
or possibly execute arbitrary code. (CVE-2015-1781)
Sumit Bose and Lukas Slebodnik discovered that the Name Service
Switch (NSS) implementation in the GNU C Library did not handle long
lines in the files databases correctly. A local attacker could use
this to cause a denial of service (application crash) or possibly
execute arbitrary code. (CVE-2015-5277)
Adam Nielsen discovered that the strftime function in the GNU C Library did
not properly handle out-of-range argument data. An attacker could use this
to cause a denial of service (application crash) or possibly expose
sensitive information. (CVE-2015-8776)
Hector Marco and Ismael Ripoll discovered that the GNU C Library allowed
the pointer-guarding protection mechanism to be disabled by honoring the
LD_POINTER_GUARD environment variable across privilege boundaries. A local
attacker could use this to exploit an existing vulnerability more easily.
(CVE-2015-8777)
Szabolcs Nagy discovered that the hcreate functions in the GNU C Library
did not properly check its size argument, leading to an integer overflow.
An attacker could use to cause a denial of service (application crash) or
possibly execute arbitrary code. (CVE-2015-8778)
Maksymilian Arciemowicz discovered a stack-based buffer overflow in the
catopen function in the GNU C Library when handling long catalog names. An
attacker could use this to cause a denial of service (application crash) or
possibly execute arbitrary code. (CVE-2015-8779)
Florian Weimer discovered that the getnetbyname implementation in the GNU C
Library did not properly handle long names passed as arguments. An attacker
could use to cause a denial of service (stack exhaustion leading to an
application crash). (CVE-2016-3075)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.10:
libc-bin 2.21-0ubuntu4.3
libc6 2.21-0ubuntu4.3
libc6-dev 2.21-0ubuntu4.3
Ubuntu 14.04 LTS:
libc-bin 2.19-0ubuntu6.9
libc6 2.19-0ubuntu6.9
libc6-dev 2.19-0ubuntu6.9
Ubuntu 12.04 LTS:
libc-bin 2.15-0ubuntu10.15
libc6 2.15-0ubuntu10.15
libc6-dev 2.15-0ubuntu10.15
After a standard system update you need to reboot your computer to
make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2985-2
http://www.ubuntu.com/usn/usn-2985-1
https://launchpad.net/bugs/1585614
Package Information:
https://launchpad.net/ubuntu/+source/glibc/2.21-0ubuntu4.3
https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.9
https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.15
Wednesday, May 25, 2016
[USN-2985-1] GNU C Library vulnerabilities
Ubuntu Security Notice USN-2985-1
May 25, 2016
eglibc, glibc vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in the GNU C Library.
Software Description:
- glibc: GNU C Library
- eglibc: GNU C Library
Details:
Martin Carpenter discovered that pt_chown in the GNU C Library did not
properly check permissions for tty files. A local attacker could use this
to gain administrative privileges or expose sensitive information.
(CVE-2013-2207, CVE-2016-2856)
Robin Hack discovered that the Name Service Switch (NSS) implementation in
the GNU C Library did not properly manage its file descriptors. An attacker
could use this to cause a denial of service (infinite loop).
(CVE-2014-8121)
Joseph Myers discovered that the GNU C Library did not properly handle long
arguments to functions returning a representation of Not a Number (NaN). An
attacker could use this to cause a denial of service (stack exhaustion
leading to an application crash) or possibly execute arbitrary code.
(CVE-2014-9761)
Arjun Shankar discovered that in certain situations the nss_dns code in the
GNU C Library did not properly account buffer sizes when passed an
unaligned buffer. An attacker could use this to cause a denial of service
or possibly execute arbitrary code. (CVE-2015-1781)
Sumit Bose and Lukáš Slebodník discovered that the Name Service
Switch (NSS) implementation in the GNU C Library did not handle long
lines in the files databases correctly. A local attacker could use
this to cause a denial of service (application crash) or possibly
execute arbitrary code. (CVE-2015-5277)
Adam Nielsen discovered that the strftime function in the GNU C Library did
not properly handle out-of-range argument data. An attacker could use this
to cause a denial of service (application crash) or possibly expose
sensitive information. (CVE-2015-8776)
Hector Marco and Ismael Ripoll discovered that the GNU C Library allowed
the pointer-guarding protection mechanism to be disabled by honoring the
LD_POINTER_GUARD environment variable across privilege boundaries. A local
attacker could use this to exploit an existing vulnerability more easily.
(CVE-2015-8777)
Szabolcs Nagy discovered that the hcreate functions in the GNU C Library
did not properly check its size argument, leading to an integer overflow.
An attacker could use to cause a denial of service (application crash) or
possibly execute arbitrary code. (CVE-2015-8778)
Maksymilian Arciemowicz discovered a stack-based buffer overflow in the
catopen function in the GNU C Library when handling long catalog names. An
attacker could use this to cause a denial of service (application crash) or
possibly execute arbitrary code. (CVE-2015-8779)
Florian Weimer discovered that the getnetbyname implementation in the GNU C
Library did not properly handle long names passed as arguments. An attacker
could use to cause a denial of service (stack exhaustion leading to an
application crash). (CVE-2016-3075)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.10:
libc6 2.21-0ubuntu4.2
libc6-dev 2.21-0ubuntu4.2
Ubuntu 14.04 LTS:
libc6 2.19-0ubuntu6.8
libc6-dev 2.19-0ubuntu6.8
Ubuntu 12.04 LTS:
libc6 2.15-0ubuntu10.14
libc6-dev 2.15-0ubuntu10.14
After a standard system update you need to reboot your computer to
make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2985-1
CVE-2013-2207, CVE-2014-8121, CVE-2014-9761, CVE-2015-1781,
CVE-2015-5277, CVE-2015-8776, CVE-2015-8777, CVE-2015-8778,
CVE-2015-8779, CVE-2016-2856, CVE-2016-3075
Package Information:
https://launchpad.net/ubuntu/+source/glibc/2.21-0ubuntu4.2
https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.8
https://launchpad.net/ubuntu/+source/eglibc/2.15-0ubuntu10.14
[USN-2950-5] Samba regression
Version: GnuPG v2
iQIcBAEBCgAGBQJXRer+AAoJEGVp2FWnRL6TzaIQAI+RFBoJTOdZu+abtBpY97sj
eZnNsQ8Gfp5jfQ+HYoWi4D5IlAyJybww7fxv7RgNjtzHX8g7DDsUcFdm/uffHKpB
dVh+XCBBrN+0NtzZlPrGSnudhY0riSlOUG55iiC/7GOHHjqbLfk3vEuD1Wu4j9NR
zcgkj1ebgNNoNrRC7snovlr2r8qG6IAVAuJc4iP4T6XmhX39xs6STzZzgEWycENk
MPr53RJRjN3euQL+ZoF3We5egY+lelIR2Ub0RlneF9me6fRabZnaTT8RZSgFvvQI
lFe1PawDhrL5dSXwVIH/Nbpjaom5SToD2jxfc8nLVPQIFC/9GUhxzqSHgO5n9CAQ
VP0767dLlUuJ0FtHN4eUoYbunJwDbdPzDfG+Rm0c7LIvBKYSghsUR12Xk4/xGQGR
u8HkbDEug5Y8zRIkpPlcI04CqO2CJBSLhWwOJR5nc+bS/5ytNwChzNzO3OxLX2w1
/bAZ9ee4kq7c4kDWjK9vbks/PDuIOuFeWu7IAnGm6DO6fKrSLYZXi8ouoGJlvwU6
wFKGQwk46JxkiCF4T4mLV5wdWbj84eL8XuYbTm5rBMz3oiFjSYhzV7Dd+Cr+l8Is
JAt5wVFomw718MCzuE2sK1IuzoCb33Iq4dsX10PjMBR1vU06kgoM8phLO2p23Zzs
0my88cpw89wVj1sj2Qon
=Fz1o
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2950-5
May 25, 2016
samba regression
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
Summary:
USN-2950-1 introduced a regression in Samba.
Software Description:
- samba: SMB/CIFS file, print, and login server for Unix
Details:
USN-2950-1 fixed vulnerabilities in Samba. USN-2950-3 updated Samba to
version 4.3.9, which introduced a regression when using the ntlm_auth tool.
This update fixes the problem.
Original advisory details:
Jouni Knuutinen discovered that Samba contained multiple flaws in the
DCE/RPC implementation. A remote attacker could use this issue to perform
a denial of service, downgrade secure connections by performing a man in
the middle attack, or possibly execute arbitrary code. (CVE-2015-5370)
Stefan Metzmacher discovered that Samba contained multiple flaws in the
NTLMSSP authentication implementation. A remote attacker could use this
issue to downgrade connections to plain text by performing a man in the
middle attack. (CVE-2016-2110)
Alberto Solino discovered that a Samba domain controller would establish a
secure connection to a server with a spoofed computer name. A remote
attacker could use this issue to obtain sensitive information.
(CVE-2016-2111)
Stefan Metzmacher discovered that the Samba LDAP implementation did not
enforce integrity protection. A remote attacker could use this issue to
hijack LDAP connections by performing a man in the middle attack.
(CVE-2016-2112)
Stefan Metzmacher discovered that Samba did not validate TLS certificates.
A remote attacker could use this issue to spoof a Samba server.
(CVE-2016-2113)
Stefan Metzmacher discovered that Samba did not enforce SMB signing even if
configured to. A remote attacker could use this issue to perform a man in
the middle attack. (CVE-2016-2114)
Stefan Metzmacher discovered that Samba did not enable integrity protection
for IPC traffic. A remote attacker could use this issue to perform a man in
the middle attack. (CVE-2016-2115)
Stefan Metzmacher discovered that Samba incorrectly handled the MS-SAMR and
MS-LSAD protocols. A remote attacker could use this flaw with a man in the
middle attack to impersonate users and obtain sensitive information from
the Security Account Manager database. This flaw is known as Badlock.
(CVE-2016-2118)
Samba has been updated to 4.3.8 in Ubuntu 14.04 LTS and Ubuntu 15.10.
Ubuntu 12.04 LTS has been updated to 3.6.25 with backported security fixes.
In addition to security fixes, the updated packages contain bug fixes,
new features, and possibly incompatible changes. Configuration changes may
be required in certain environments.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
samba 2:4.3.9+dfsg-0ubuntu0.16.04.2
Ubuntu 15.10:
samba 2:4.3.9+dfsg-0ubuntu0.15.10.2
Ubuntu 14.04 LTS:
samba 2:4.3.9+dfsg-0ubuntu0.14.04.3
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2950-5
http://www.ubuntu.com/usn/usn-2950-1
https://launchpad.net/bugs/1578576
Package Information:
https://launchpad.net/ubuntu/+source/samba/2:4.3.9+dfsg-0ubuntu0.16.04.2
https://launchpad.net/ubuntu/+source/samba/2:4.3.9+dfsg-0ubuntu0.15.10.2
https://launchpad.net/ubuntu/+source/samba/2:4.3.9+dfsg-0ubuntu0.14.04.3
[CentOS-announce] Release for CentOS Linux 6.8 i386 and x86_64
Version: GnuPG v2.0.22 (GNU/Linux)
iEYEARECAAYFAldFzQMACgkQTKkMgmrBY7N36wCbB0srkLACBRsscBbt7IplCYSe
At4An0cp9CCRL+8KPquyLT4z519CWDxf
=4el4
-----END PGP SIGNATURE-----
We are pleased to announce the immediate availability of CentOS Linux
6.8 and install media for i386 and x86_64 Architectures. Release Notes
for 6.8 are available at:
http://wiki.centos.org/Manuals/ReleaseNotes/CentOS6.8
We recommend everyone review these release notes.
CentOS Linux 6.8 is derived from source code released by Red Hat, Inc.
for Red Hat Enterprise Linux 6.8. All upstream variants have been
placed into one combined repository to make it easier for end users.
Workstation, server, and minimal installs can all be done from our
combined repository. All of our testing is only done against this
combined distribution.
There are many fundamental changes in this release, compared with the
past CentOS Linux 6 releases, and we highly recommend everyone study
the upstream Release Notes as well as the upstream Technical Notes
about the changes and how they might impact your installation. (See
the 'Further Reading' section if the CentOS release notes link above).
All updates since the upstream 6.8 release are also on the CentOS
mirrors as zero day updates. When installing CentOS-6.8 (or any other
version) from any of our media, you should always run 'yum update'
after the install to apply these.
Users consuming our centos-cr repositories will already be running all
the packages that make up CentOS-6.8, and all updates released since.
They will notice only the centos-release and anaconda updates today
when moving to CentOS Linux 6.8. For more information on the CR
repository for future updates, see this link:
http://wiki.centos.org/AdditionalResources/Repositories/CR
Release Announcements for all updated packages are available here:
http://bit.ly/1WOy3dB
+++++++++++++++++++++++
Upgrading From Prior Major CentOS Versions:
We recommend everyone perform a fresh reinstall rather than attempt an
inplace upgrade from other major CentOS versions (CentOS-2.1, CentOS-3.x,
CentOS-4.x, CentOS-5.x).
+++++++++++++++++++++++
Upgrading from CentOS-6.0 / 6.1 / 6.2 / 6.3 / 6.4 / 6.5 / 6.6 or 6.7
CentOS Linux is designed to automatically upgrade between releases
within a major version (in this case, CentOS-6). Unless you have
edited your yum default configuration, a 'yum update' should move your
machines seamlessly from any previous CentOS Linux 6.x release to 6.8.
We also test this in our QA cycles and have noticed no problems, any
issues would be mentioned in the Release Notes.
+++++++++++++++++++++++
Downloading CentOS Linux 6.8 for new installs:
When possible, consider using torrents to obtain our ISOs. Usually it
is also the fastest means to download the distro.
The install media is split into various formats. We have made efforts
to ensure that most install types and roles can be done from DVD-1
itself, and the minimal install ISO is only tested to deliver a
minimal install set, when used as an ISO format ( either on cd or usb
). While other forms of installs ( eg. pxe delivered ) might work from
the minimal ISO, they are neither tested not supported. The only
format where we support the entire set of install options and delivery
mechanisms is via the complete CentOS Linux 6.8 tree, wihch can also
be created by consolidating all content from DVD1 and DVD2.
We no longer produce CD size images for the entire CentOS Linux 6
distribution, however the minimal install and netinstall iso images
are small enough to fit on all CD grade media.
Torrent files for the DVD's are available at :
http://mirror.centos.org/centos/6.8/isos/i386/CentOS-6.8-i386-bin-DVD1to2.torrent
http://mirror.centos.org/centos/6.8/isos/x86_64/CentOS-6.8-x86_64-bin-DVD1to2.torrent
You can also use a mirror close to you to get any of our ISOs:
http://mirror.centos.org/centos/6.8/isos/
If you need to update a local mirror, you can choose from our mirror
network http://www.centos.org/download/mirrors/ Most mirrors will
allow downloads over http, ftp and rsync.
Note: The x86_64 ISOs (minimal, netinstall, DVD1) should install on UEFI
machines.
Secure Boot must be disabled to install CentOS 6. The Live ISOs and i386
ISOs will
not boot with UEFI.
+++++++++++++++++++++++
sha256sum for the CentOS-6.8 ISOS:
i386:
720d185fdf063383a4471657076b72fc162d3c3c3bca2e5e5ae13a25b3046519
CentOS-6.8-i386-bin-DVD1.iso
0c1a498a469214f276b4390a9ac2111fe8eb89084f7921d2eced659ada09e1a9
CentOS-6.8-i386-bin-DVD2.iso
7df6c27c0cd1186845bee4e786d43dbd3ae429258098283f9dbc2b2d20ed6a89
CentOS-6.8-i386-LiveCD.iso
7e2ace104901921ac919a390be827251727dfd04437fbd4e4d3024b6d70d8718
CentOS-6.8-i386-LiveDVD.iso
f4cf0614cc2ac451ffec5bd349ee74a1b31fd394e58561a07c38a21be5a4bdeb
CentOS-6.8-i386-minimal.iso
1668434d76e14a45a189b7810582e7e6ded686854f75b7f8ba053830a5706e57
CentOS-6.8-i386-netinstall.iso
x86_64:
dda55622614a8b43b448a72f87d6cb7f79de1eff49ee8c5881a7d9db28d4e35
CentOS-6.8-x86_64-bin-DVD1.iso
0aba869427b4ce04e100d72744daf7fea1f7be2e4be56b658095bd9e99e04e6d
CentOS-6.8-x86_64-bin-DVD2.iso
efa82d673206cb6af377b1f929a510cc2b1ce95cdb436210121ec271e056c920
CentOS-6.8-x86_64-LiveCD.iso
52a9c8c1d250de39976dda9412293473b8349efefb31b66fecdee0fdf93866d9
CentOS-6.8-x86_64-LiveDVD.iso
ec49c297d484b9da0787e5944edc38f7c70f21c0f6a60178d8e9a8926d1949f4
CentOS-6.8-x86_64-minimal.iso
56d9cc5757ed1443af7b321967622a108978328f72e58050d31bcf1998dfd162
CentOS-6.8-x86_64-netinstall.iso
+++++++++++++++++++++++
Cloud Images:
Images for various on-premise and off-premise Cloud environments are
currently under development for CentOS Linux 6.8 and will be released
in the coming days. Everyone looking to join and help with the CentOS
Cloud efforts is encouraged to join the CentOS-devel list where such
issues are discussed (
http://lists.centos.org/mailman/listinfo/centos-devel ).
+++++++++++++++++++++++
Getting Help:
The best place to start when looking for help with CentOS is at the
wiki ( http://wiki.centos.org/GettingHelp ) which lists various
options and communities who might be able to help. If you think there
is a bug in the system, do report it at http://bugs.centos.org/ - but
keep in mind that the bugs system is *not* a support mechanism. If you
need supported software with Support Level Agreements, people to call
and response times then we recommend Red Hat Enterprise Linux.
If you have questions you would like to field at us in real time, come
join the office hours on Wed or Thu of every week. You can find
details on these at http://wiki.centos.org/OfficeHours
+++++++++++++++++++++++
Meet-ups and Events:
If you would like to get involved in helping organize, run, present or
sponsor a CentOS Dojo or even just want more details then join the
CentOS Promo list:
http://lists.centos.org/mailman/listinfo/centos-promo and drop an
email introducing yourself. We are very keen to find help to run
events around the world, and also to find people who can represent
CentOS at various community events around the world.
+++++++++++++++++++++++
Contributing and joining the project:
We are always looking for people to join and help with various things
in the project. If you are keen to help out a good place to start is
the wiki page at http://wiki.centos.org/Contribute . If you have
questions or a specific area you would like to contribute towards that
is not covered on that page, feel free to drop in on #centos-devel at
irc.freenode.net for a chat or email the centos-devel list
(http://lists.centos.org).
+++++++++++++++++++++++
Thanks to everyone who contributed towards making CentOS Linux 6.8,
especially the effort put in, as always, by the QA
(http://wiki.centos.org/QaGroup) and Build teams.
A special shout out to all the donors who have contributed hardware,
network connectivity, hosting and resources over the years. The CentOS
project now has a fairly well setup resource pool, solely thanks to
the donors.
Enjoy!
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS
Tuesday, May 24, 2016
[USN-2984-1] PHP vulnerabilities
Version: GnuPG v2
iQIcBAEBCgAGBQJXRJteAAoJEGVp2FWnRL6ThaYP/1yfHv0ymzYkoX68oCrTq60w
Fr5uhhH6ter6KicPLIqJ7MlsZn6Cc3q8BCSb23nKODJdnQ8xqWy+i38Z0PCKAC7b
EpD0VLB8OvxEtCVcSDXuCoMH8hBaM04yFbol5xuS5siHpRi/IBxYWTULa0kjPf2H
s+XMg9WPH38ZoUKqD7ByYfXHvAm56chS+GAJEo27489scx3Hvf8frIlQDbttddDE
fDasbI3P0xSQ0nKvSfPMsb5DEi4fBYA2LU7r48AqAdQs/HcRXdnnTdRPt0hn657e
kVWUYPUO5ozs0iqo9FhGr0cdEJXZOuEfFx9GL5fNEhVnPXLuzyRhrCwNAnzUidXF
ox0UhlDCFjMIAU1qoSBJTHBu4vILpYfQ/lkho6NNGVTGuPN+8JFK0WXR3yQVlnDD
T4Y1f45Lr6cqTe4KXwGp0sXlywHyRX51A5PBFajZvvz8QuRF0Fy5PBd6iUBHvQ1g
qMmJpZgei+17wQqqTQq1E+CtwnCTNkD5vBzFmtXGRDIw52qBLU2Htlw0jX3CEoI6
3CHJkxL5wd4n+qf/Lp26vQZZScLn6XScyS6VnSvO6KkRy+8t+Rrhk3nX6JxnYz2i
OJOv3c19qnR4zjFIxNOmsAn+bG+Tz8VKTwwoFT8whnIAPgqLcfuIFpWiW38Vim7D
dtfmjYxUnj444llgf8ES
=C5U2
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2984-1
May 24, 2016
php5, php7.0 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS
Summary:
Several security issues were fixed in PHP.
Software Description:
- php7.0: HTML-embedded scripting language interpreter
- php5: HTML-embedded scripting language interpreter
Details:
It was discovered that the PHP Fileinfo component incorrectly handled
certain magic files. An attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS. (CVE-2015-8865)
Hans Jerry Illikainen discovered that the PHP Zip extension incorrectly
handled certain malformed Zip archives. A remote attacker could use this
issue to cause PHP to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only affected Ubuntu 16.04 LTS.
(CVE-2016-3078)
It was discovered that PHP incorrectly handled invalid indexes in the
SplDoublyLinkedList class. An attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-3132)
It was discovered that the PHP rawurlencode() function incorrectly handled
large strings. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service. This issue only affected Ubuntu
16.04 LTS. (CVE-2016-4070)
It was discovered that the PHP php_snmp_error() function incorrectly
handled string formatting. A remote attacker could use this issue to cause
PHP to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4071)
It was discovered that the PHP phar extension incorrectly handled certain
filenames in archives. A remote attacker could use this issue to cause PHP
to crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4072)
It was discovered that the PHP mb_strcut() function incorrectly handled
string formatting. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-4073)
It was discovered that the PHP phar extension incorrectly handled certain
archive files. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 15.10. (CVE-2016-4342, CVE-2016-4343)
It was discovered that the PHP bcpowmod() function incorrectly handled
memory. A remote attacker could use this issue to cause PHP to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2016-4537, CVE-2016-4538)
It was discovered that the PHP XML parser incorrectly handled certain
malformed XML data. A remote attacker could possibly use this issue to
cause PHP to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-4539)
It was discovered that certain PHP grapheme functions incorrectly handled
negative offsets. A remote attacker could possibly use this issue to cause
PHP to crash, resulting in a denial of service. (CVE-2016-4540,
CVE-2016-4541)
It was discovered that PHP incorrectly handled certain malformed EXIF tags.
A remote attacker could possibly use this issue to cause PHP to crash,
resulting in a denial of service. (CVE-2016-4542, CVE-2016-4543,
CVE-2016-4544)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
libapache2-mod-php7.0 7.0.4-7ubuntu2.1
php7.0-cgi 7.0.4-7ubuntu2.1
php7.0-cli 7.0.4-7ubuntu2.1
php7.0-fpm 7.0.4-7ubuntu2.1
Ubuntu 15.10:
libapache2-mod-php5 5.6.11+dfsg-1ubuntu3.4
php5-cgi 5.6.11+dfsg-1ubuntu3.4
php5-cli 5.6.11+dfsg-1ubuntu3.4
php5-fpm 5.6.11+dfsg-1ubuntu3.4
Ubuntu 14.04 LTS:
libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.17
php5-cgi 5.5.9+dfsg-1ubuntu4.17
php5-cli 5.5.9+dfsg-1ubuntu4.17
php5-fpm 5.5.9+dfsg-1ubuntu4.17
Ubuntu 12.04 LTS:
libapache2-mod-php5 5.3.10-1ubuntu3.23
php5-cgi 5.3.10-1ubuntu3.23
php5-cli 5.3.10-1ubuntu3.23
php5-fpm 5.3.10-1ubuntu3.23
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2984-1
CVE-2015-8865, CVE-2016-3078, CVE-2016-3132, CVE-2016-4070,
CVE-2016-4071, CVE-2016-4072, CVE-2016-4073, CVE-2016-4342,
CVE-2016-4343, CVE-2016-4537, CVE-2016-4538, CVE-2016-4539,
CVE-2016-4540, CVE-2016-4541, CVE-2016-4542, CVE-2016-4543,
CVE-2016-4544
Package Information:
https://launchpad.net/ubuntu/+source/php7.0/7.0.4-7ubuntu2.1
https://launchpad.net/ubuntu/+source/php5/5.6.11+dfsg-1ubuntu3.4
https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.17
https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.23
Friday, May 20, 2016
Planned Outage: buildsystem Server reboots - 2016-05-24 21:00 UTC
There will be an outage starting at 2016-05-24 21:00 UTC, which will
last approximately 2 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2016-05-24 21:00 UTC'
Reason for outage:
We will be updating and rebooting the servers in our build network.
Services related to building may be down and up during the outage
window.
Affected Services:
* pkgs.fedoraproject.org
* koschei
* koji
* kojipkgs
* bodhi / updates.fedoraproject.org
Services not listed are not affected by this outage.
Contact Information:
Ticket Link: https://fedorahosted.org/fedora-infrastructure/ticket/5312
Please join #fedora-admin or #fedora-noc on irc.freenode.net or add
comments to the ticket for this outage above.
Planned Outage: Server reboots - 2016-05-25 21:00 UTC
There will be an outage starting at 2016-05-25 21:00 UTC, which will
last approximately 4 hours.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2016-05-25 21:00 UTC'
Reason for outage:
We will be updating and rebooting various servers. Services may be up
and down during the outage window as particular hosts are updated and
rebooted.
Affected Services:
Most services may see some small disruption during the outage window.
Contact Information:
Ticket Link: https://fedorahosted.org/fedora-infrastructure/ticket/5313
Please join #fedora-admin or #fedora-noc on irc.freenode.net or add
comments to the ticket for this outage above.