Tuesday, May 31, 2016

[FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-16:20.linux

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-SA-16:20.linux Security Advisory
The FreeBSD Project

Topic: Kernel stack disclosure in Linux compatibility layer

Category: core
Module: linux(4)
Announced: 2016-05-31
Credits: CTurt
Affects: All supported versions of FreeBSD.
Corrected: 2016-05-31 16:57:42 UTC (stable/10, 10.3-STABLE)
2016-05-31 16:55:50 UTC (releng/10.3, 10.3-RELEASE-p4)
2016-05-31 16:55:45 UTC (releng/10.2, 10.2-RELEASE-p18)
2016-05-31 16:55:41 UTC (releng/10.1, 10.1-RELEASE-p35)
2016-05-31 16:58:00 UTC (stable/9, 9.3-STABLE)
2016-05-31 16:55:37 UTC (releng/9.3, 9.3-RELEASE-p43)

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I. Background

FreeBSD is binary-compatible with the Linux operating system through a
loadable kernel module/optional kernel component. The support is provided
for amd64 and i386 machines.

II. Problem Description

The implementation of the TIOCGSERIAL ioctl(2) does not clear the output
struct before copying it out to userland.

The implementation of the Linux sysinfo() system call does not clear the
output struct before copying it out to userland.

III. Impact

An unprivileged user can read a portion of uninitialised kernel stack data,
which may contain sensitive information, such as the stack guard, portions
of the file cache or terminal buffers, which an attacker might leverage to
obtain elevated privileges.

IV. Workaround

No workaround is available, but systems not using the Linux binary
compatibility layer are not vulnerable.

The Linux compatibility layer is not included in the default GENERIC kernel.

The following command can be used to test if the Linux binary compatibility
layer is loaded:

# kldstat -m linuxelf

V. Solution

Perform one of the following:

1) Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date.

Reboot is required.

2) To update your vulnerable system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

Reboot is required.

3) To update your vulnerable system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/SA-16:20/linux.patch
# fetch https://security.FreeBSD.org/patches/SA-16:20/linux.patch.asc
# gpg --verify linux.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile your kernel as described in
<URL:https://www.FreeBSD.org/handbook/kernelconfig.html> and reboot the
system.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/9/ r301055
releng/9.3/ r301049
stable/10/ r301054
releng/10.1/ r301050
releng/10.2/ r301051
releng/10.3/ r301052
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:http://cturt.github.io/compat-info-leaks.html>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-16:20.linux.asc>
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJXTcSOAAoJEO1n7NZdz2rnjSMP/AsGK5jda/QlrRrpvKyd3HGr
qVsTzro+a2ed2ZlUCamM/JICXfbAit+dOioui+CIN1IKai/mxNPMpIWcPRx1AhDr
3y52MmSzkCqK6QT3tvwYYaG4uOZ3/wbWAJ8EKz2qqYlZ4hkmy24BdvTCGB2SGDgo
Nz1P60NWxaqafCwFyb0xz7Lful52txSLIr9mWZzTcSgwNNEscGiMgzXiY64GlWfQ
r20udpFrPG5+OOwpFAdR4IImQA7B0AYD064NbzN9A+mJlbhtGguDS3oTkbVBVIbF
ldLgDkrFeIv/Jyhvij1q85xfuOxT6eaVJe7qGUaV8v6qQx17VhH8j0sVzn6nh0w9
kly4FB0osyZRQJ7bV7c+FVGECUWRyzSpeo7lx6ICXECuyzcX9U4IxC0oxPcokD3o
CEOJkQEjLtMSfKdE143lbyPCtZUMSXtp/CLEUxW7eDCbW89O7p7pv6xTiNLdopVT
cpUcF+Y0KepwMrg+jXH8i07yF6QgqRWVziA16821OJ4ThD0RN4MRrWUizl/1J2iD
LFGxK8l2U3hP5dhXpYpEHsI2xkU94Lojp0SfngFoylo4Z8UjpQeaR9NG+F3+uR45
Q8aGB3CQe84JZUzFfVN6292AE/4ZMg13iRzKUawV8JBUEWG+MnrtU6a7zwIRVM2F
zT2f1EP7488fCSxbmicf
=bohu
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

[USN-2987-1] GD library vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXTbWCAAoJEGVp2FWnRL6TXd8P/01TM1s+kG/Bs4MHWR03K5uy
BqvG84osWhM0eTXjTUmAbXz5DeqbPfnxZ4ujWjJHs3d38uiCFy1+XikgBND6+VMt
mxk93vygP5t6BZqs+1d915tH4Yiax9LCLrrUvJIHIs8b2Zd55pnQTrsrxvbddtAz
v8KaMpFqFfZ8LTsqKA5r3Oa4hG42VD9TQ45vYC5hKG688aMarqHeRixLxMsdubk9
DzUiFmXOc/aHDEaCCVBFErqxhGlz8/uh7/cC687IgT7+JSA3fa6dnF7jSV7jakbJ
HouRaITPLcp4OO8TlCCC0L1nelUaK8SwybcTvnA+2CIe+QWEgaobVqG48vDSnuFJ
/0JGWUMWROVrsN1rpdBEN2bCR6TCMl0QioqcpW+LJ7OB/Z4GZRh3rLfuUXPHc4R2
nVjlAV3T7UM38VySRulkcZ7o6uqxmVb96uBKzDrM51T7kdQebUW/I0ZpFF+Ixdef
fmJocXwmhBfuMAuK/tt08lJcgvvqXFkwfHNnbK8Hf0tOMQ+/bH1B1viduQJhCPE8
ucsQ9/35peD1q1TzMrp7fE3/xqOGCSAbN3wpdKpbTLQjfHYlSJgIPXkWDymhqsWf
9Pn40gB/5JxJGc++bay74nr3/zTXypSG6DRAZaG1aLJFQvnG2NL4I97WJovKQPeR
MVZq+v/QGRhJD4NIY15R
=nH9U
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2987-1
May 31, 2016

libgd2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

The GD library could be made to crash or run programs if it processed a
specially crafted image file.

Software Description:
- libgd2: GD Graphics Library

Details:

It was discovered that the GD library incorrectly handled certain color
tables in XPM images. If a user or automated system were tricked into
processing a specially crafted XPM image, an attacker could cause a denial
of service. This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2014-2497)

It was discovered that the GD library incorrectly handled certain malformed
GIF images. If a user or automated system were tricked into processing a
specially crafted GIF image, an attacker could cause a denial of service.
This issue only affected Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
(CVE-2014-9709)

It was discovered that the GD library incorrectly handled memory when using
gdImageFillToBorder(). A remote attacker could possibly use this issue to
cause a denial of service. (CVE-2015-8874)

It was discovered that the GD library incorrectly handled memory when using
gdImageScaleTwoPass(). A remote attacker could possibly use this issue to
cause a denial of service. This issue only applied to Ubuntu 14.04 LTS,
Ubuntu 15.10 and Ubuntu 16.04 LTS. (CVE-2015-8877)

Hans Jerry Illikainen discovered that the GD library incorrectly handled
certain malformed GD images. If a user or automated system were tricked
into processing a specially crafted GD image, an attacker could cause a
denial of service or possibly execute arbitrary code. (CVE-2016-3074)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
libgd3 2.1.1-4ubuntu0.16.04.1

Ubuntu 15.10:
libgd3 2.1.1-4ubuntu0.15.10.1

Ubuntu 14.04 LTS:
libgd3 2.1.0-3ubuntu0.1

Ubuntu 12.04 LTS:
libgd2-noxpm 2.0.36~rc1~dfsg-6ubuntu2.1
libgd2-xpm 2.0.36~rc1~dfsg-6ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2987-1
CVE-2014-2497, CVE-2014-9709, CVE-2015-8874, CVE-2015-8877,
CVE-2016-3074

Package Information:
https://launchpad.net/ubuntu/+source/libgd2/2.1.1-4ubuntu0.16.04.1
https://launchpad.net/ubuntu/+source/libgd2/2.1.1-4ubuntu0.15.10.1
https://launchpad.net/ubuntu/+source/libgd2/2.1.0-3ubuntu0.1
https://launchpad.net/ubuntu/+source/libgd2/2.0.36~rc1~dfsg-6ubuntu2.1

[USN-2986-1] dosfstools vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXTbVaAAoJEGVp2FWnRL6Tn14QAKCf935wrDJbROOde9gKXe9T
bX1P3s0JXQ5P3MXK9JOmtnVHZucl6PDWmDkhEdCN9kqaL98VM/wNNIHV0qnZjeym
ztvYiiu3WKIB7yQMbF6AYe6bEUJ66vcMzIHkUg9+min0qwTkDcsFQfNftaAYCIyY
228xxRYWhQyuksRUY3+vcgVtRPyHmGLW/YPcI3L9tRgfeRDzd/UpGHdwW6FWSK31
ulYEqE2xETxOBrFgcZlzy/+5TvcHPttYp1xYElv0ej82B7B+W6DytZa31YK9CQTp
hKBSXq/7kWQ6CCXVwKuRkXfNLqoL8QzaRHDeb1XjlyXohx4IMaauC7iD1B7rvCP2
UERaF4LLVmRppeb6tkxAX0f6CrTcDruIRLiUN9OfQPx8wcwMyeoyaup8bzSyn7El
zLafZwX0imHve8BL1m3e3eak5F7e11LS0cq0HJahaD9CYUC3pO4q9cy8Yr5IybVG
pa9docbN9lXOGWIYJDP3u4nAkk33m241mywHEWN3l9sF2kTId8fBcBwZRFXJaU+f
kmXpwvZZRPEV6PpRCKZmUZ7Y6J3hu+lBO449t66MTU9sih/21k8mWTrgu1aDPyTy
qPMFiD3Keirg/h5HkV8v+461fkcvYBm1rG4RxLBFtTnRVgw2ChpAQuwwmW5iAVzc
rUjdJF4VY0K55P5ExeAE
=caus
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2986-1
May 31, 2016

dosfstools vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

dosfstools could be made to crash or run programs if it processed a
specially crafted filesystem.

Software Description:
- dosfstools: utilities for making and checking MS-DOS FAT filesystems

Details:

Hanno Böck discovered that dosfstools incorrectly handled certain malformed
filesystems. A local attacker could use this issue to cause dosfstools to
crash, resulting in a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
dosfstools 3.0.28-2ubuntu0.1

Ubuntu 15.10:
dosfstools 3.0.28-1ubuntu0.1

Ubuntu 14.04 LTS:
dosfstools 3.0.26-1ubuntu0.1

Ubuntu 12.04 LTS:
dosfstools 3.0.12-1ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2986-1
CVE-2015-8872, CVE-2016-4804

Package Information:
https://launchpad.net/ubuntu/+source/dosfstools/3.0.28-2ubuntu0.1
https://launchpad.net/ubuntu/+source/dosfstools/3.0.28-1ubuntu0.1
https://launchpad.net/ubuntu/+source/dosfstools/3.0.26-1ubuntu0.1
https://launchpad.net/ubuntu/+source/dosfstools/3.0.12-1ubuntu1.3

[CentOS-announce] CESA-2016:1137 Important CentOS 5 openssl Security Update

CentOS Errata and Security Advisory 2016:1137 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1137.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
631e91525505003d8b42dfc52fd9b1423aa4f62b52fe0a99b179fc7ca5d402df openssl-0.9.8e-40.el5_11.i386.rpm
91707deacf653a4c5e1ee71bfe78c312ddaf1ced22598aa0ed9364b801a95f75 openssl-0.9.8e-40.el5_11.i686.rpm
b14fb301e7bb528ac9f12862471875a8a937e557437bf5dfeeb5bf45ba62a7a0 openssl-devel-0.9.8e-40.el5_11.i386.rpm
7f74ee4c3eb94f41034d716729f5a922301984327d3c7e1398d625e3d9828071 openssl-perl-0.9.8e-40.el5_11.i386.rpm

x86_64:
91707deacf653a4c5e1ee71bfe78c312ddaf1ced22598aa0ed9364b801a95f75 openssl-0.9.8e-40.el5_11.i686.rpm
4b01840b72a7ee82f9a3eb20df16106e3c0fdfcd0fb83457487a740fb4774413 openssl-0.9.8e-40.el5_11.x86_64.rpm
b14fb301e7bb528ac9f12862471875a8a937e557437bf5dfeeb5bf45ba62a7a0 openssl-devel-0.9.8e-40.el5_11.i386.rpm
e2fd36a8953c239a4526ee747fcef4faf0e52ba5c8c3a870bf3d05895ee19e72 openssl-devel-0.9.8e-40.el5_11.x86_64.rpm
3bad2a15cbbb096392eb97d9a414aae6b05edacc290ae266b2bbc47a875cf0b2 openssl-perl-0.9.8e-40.el5_11.x86_64.rpm

Source:
603c7be208dc0cb4de26b9db6a29d6aa9bf796d0227ee58d81a0c07038ef1bfe openssl-0.9.8e-40.el5_11.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:1139 Moderate CentOS 7 squid Security Update

CentOS Errata and Security Advisory 2016:1139 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1139.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
431c4c5b1d7c4795b0597f7a655c44e03db6cd573082375d28bb9eac9e527f4e squid-3.3.8-26.el7_2.3.x86_64.rpm
1c04bd54d4b10395d2c3e78a6e00ef49a7123a4347edf5aa70f57e71a87528c1 squid-sysvinit-3.3.8-26.el7_2.3.x86_64.rpm

Source:
fa239d6add7aeb21c9bceb300207e173ce7dbca3a6bd73c52266571d58e7ec91 squid-3.3.8-26.el7_2.3.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:1141 Moderate CentOS 7 ntp Security Update

CentOS Errata and Security Advisory 2016:1141 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1141.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
afb3dfae974c95e885c4f6335cd06f21263224ae21bff8bd2a5c54d5dde44d00 ntp-4.2.6p5-22.el7.centos.2.x86_64.rpm
46cc107c74c97c07bbbf1275133cc0e1b6a5598fa53bb34650e7f7559a49a36e ntpdate-4.2.6p5-22.el7.centos.2.x86_64.rpm
f916317311a69c1fc27d297a15df69002e0a92ae91f290bed52ac99bf3ff3dab ntp-doc-4.2.6p5-22.el7.centos.2.noarch.rpm
aad649a9c029e0fc173d24eaa3e548524f3cbe7271128ebd571d9535b2a9d38a ntp-perl-4.2.6p5-22.el7.centos.2.noarch.rpm
d2c4d2d7472eb1a732e68cec9f7e60bc17d356bc879e3b23a69faf607793a995 sntp-4.2.6p5-22.el7.centos.2.x86_64.rpm

Source:
ccbc05d3874452e7c1e9b72fac58c4fc5f69d9a37cf77c5b7ffe34d6416acfe2 ntp-4.2.6p5-22.el7.centos.2.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:1141 Moderate CentOS 6 ntp Security Update

CentOS Errata and Security Advisory 2016:1141 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1141.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
8cb6eac95c0d760035a5b251c4f6f72920d0c23766e98c845885ea91d4a69f08 ntp-4.2.6p5-10.el6.centos.1.i686.rpm
45f7a3ef55eff1448bdc1e6dd7e7d8db030461562643b6df33d82f59b3eb20da ntpdate-4.2.6p5-10.el6.centos.1.i686.rpm
27f007b3249dcb28a17938d3d09ef2534c30c9106b21515849a44dada7aebdbd ntp-doc-4.2.6p5-10.el6.centos.1.noarch.rpm
f9cb8483b4f76c243ab2b3dd60b37d43444425fd9df60f46c01c720cd04774fc ntp-perl-4.2.6p5-10.el6.centos.1.i686.rpm

x86_64:
e4177b6e3734069c1ee814bd358b92c9fb81d66b80ce02b687df4579174d8abe ntp-4.2.6p5-10.el6.centos.1.x86_64.rpm
7179b002333ae35af41f07b70c1d6c87407d446645038ec70f401fc178fc69f2 ntpdate-4.2.6p5-10.el6.centos.1.x86_64.rpm
27f007b3249dcb28a17938d3d09ef2534c30c9106b21515849a44dada7aebdbd ntp-doc-4.2.6p5-10.el6.centos.1.noarch.rpm
281370467116872d146d319ee7687896e59db493724b51ed3b9fac10b6d1787d ntp-perl-4.2.6p5-10.el6.centos.1.x86_64.rpm

Source:
f8d4b4a86e65c984352cd0c1b79bbbb518f986112f8ee91a2e2d953c270fc307 ntp-4.2.6p5-10.el6.centos.1.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:1140 Moderate CentOS 6 squid34 Security Update

CentOS Errata and Security Advisory 2016:1140 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1140.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
8b20601c95dc356ab1bb2b087331ee432f10cc567eb7503bef2e37891e18f03d squid34-3.4.14-9.el6_8.3.i686.rpm

x86_64:
50ccde2efa8f46ef1c4dabba442427aa812ce24ecdf202e1390346dc190659b7 squid34-3.4.14-9.el6_8.3.x86_64.rpm

Source:
304814481410fe9686f28f996c09882e794901d99aa3b509e92753ee683abf4c squid34-3.4.14-9.el6_8.3.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:1138 Moderate CentOS 6 squid Security Update

CentOS Errata and Security Advisory 2016:1138 Moderate

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-1138.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
e47c5002da71e2ae26beb75c5606d5014c2d9bd6c9e2372ab770a73af0194567 squid-3.1.23-16.el6_8.4.i686.rpm

x86_64:
d4a0380af389fc303e5db2764893651d0f8f320e22af7e240346e99379213a01 squid-3.1.23-16.el6_8.4.x86_64.rpm

Source:
17e493babcd6f109e5feb8087ebbc60e5d4c938cb8a071343e134204cedb4079 squid-3.1.23-16.el6_8.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

Monday, May 30, 2016

OpenNTPD 6.0p1 available

OpenNTPD 6.0p1 has just been released. It will be available from the mirrors
listed at http://www.openntpd.org/ shortly.

OpenNTPD is a FREE, secure, and easy to use implementation of the Network Time
Protocol. It provides the ability to sync the local clock to remote NTP servers
and can act as NTP server itself, redistributing the local clock.

Changes since OpenNTPD 5.9p1
============================

* Fixed a link failure on older Linux distributions and a build
failure on FreeBSD.
* Set MOD_MAXERROR to avoid unsynced time status when using
ntp_adjtime.
* Fixed HTTP Timestamp header parsing to use strptime in a more
portable fashion.
* Hardened TLS for ntpd constraints, enabling server name
verification. Thanks to Luis M. Merino.

The libtls library, as shipped with LibreSSL 2.3.2 or later, is
required to use the HTTPS constraint feature, though it is not
required to use OpenNTPD.

For detailed changes, see the changes either in the OpenBSD CVS repository or
the GitHub mirror.

Checksums:
==========

SHA256 (openntpd-6.0p1.tar.gz) = b1ab80094788912adb12b33cb1f251cc58db39294c1b5c6376972f5f7ba577e8

Reporting Bugs:
===============

General bugs may be reported to tech@openbsd.org

Portable bugs may be filed at https://github.com/openntpd-portable/openntpd-portable/

reallost1.fbsd2233449:管理的目的是什么?


                    新任经理、部门经理全面管理技能提升训练

【时间地点】 2016年6月17-18深圳


【参加对象】 新上任主管、经理,储备人员,部门经理/主管,职能经理,技术经理,企业中高层...
【学习费用】 3200   /人, (含课程讲义、午餐、茶点等)
垂·询·热·线:0755-61280006 、189-1787-0808     许先生      QQ/微信:320588808     
   注:如不需此类信件信息,请转发送"删除"至tuiding02@163.com,我们会及时处理,谢谢您的理解。

课程背景:
  企业的发展壮大,需要管理干部的快速成长;面对越来越激烈的市场竞争,需要管理干部的管理水平快上台阶。许多企业的中层管理干部,尤其是新任的主管经理,从专业岗位转换为主管经理后,对管理工作及管理角色的认识不到位,管理工作片面而被动,没有真正把管理的责任担当起来。有些中层管理干部虽然具有管理意识,但缺思路,缺方法,缺动作,管事带人效果不佳,事情没做好,人员没留住,团队不成型,积极性不高,凝聚力不够,归属感不强,干部自身忙而累,累而烦,久而久之麻木倦怠! 
  新任经理全面管理技能提升训练培训帮助新任经理、主管等企业管理干部,系统理解管理的逻辑性,站在整体角度,把握管理角色,理解人事管理的相辅相成,分析问题,梳理思路,探讨方法,演练工具,帮助缩短中层干部的成长周期,减少管理失误,提高管理效率,以适应市场竞争形势和企业的快速发展!

培训收益:
1、建立对管理的整体和系统思维,理解从问题,思路,系统,方法,到动作的管理线索
2、理解中层管理者在企业里应承担的责任,角色身份,应表现出的态度和意识
3、掌握把工作管好的方法和技巧 – 计划,组织,控制,创新
4、掌握带人带团队的方法 – 培养训练,沟通互动,团队氛围营造,激励设计
5、促进自我提升 – 有效管理时间,职业认识,个人修炼

课程大纲:
第一部分 自我管理
一、管理与角色认知
从专业走向管理后,如何实现角色转换?
管理的目的是什么?
中基层管理者,要承担哪些管理责任?
中基层管理者如何确立自己对上,对下,对中的身份定位?
中层管理者如何避免角色行为误区?
【讨论互动】: 你是如何理解管理及角色的?
二、管理者工作方法
时间管理与工作统筹
时间分析:我的时间用的有效吗?
时间管理的四个象限
四个象限的策略和目标
管理者如何识别轻重缓急?
好钢用在刀刃上 – 如何抓住工作的重中之重?
管理者如何做好工作统筹?
其他常用工作方法
结构分解法
项目管理法
目标管理法
PDCA
5W3H
SMART

第二部分 工作管理
一、工作管理 – 工作计划
计划为何重要?
制定计划的步骤
如何做工作分解?
工作评估与安排
【工具演练】:用WBS工具做工作策划与分解
【工具模板】:WBS参考模板
二、工作管理 – 工作组织
什么是工作组织?组织的目的是什么?
企业组织设计
企业工作组织
企业工作组织中的问题
工作组织原则
三、工作管理 – 执行控制
企业执行力差的管理因素
【讨论互动】:执行不力的管理因素
工作执行控制的策略
工作控制方法与工具
分段控制法
三要素控制法
稽核控制法
【工具演练】:控制卡设计练习
【参考工具】:三要素控制卡
【案例分析】: 三要素控制卡工具的应用
【案例分析】: 分段控制法应用
【案例分析】:稽核控制法应用
目标管理与绩效考核法
什么是目标管理?
目标来自哪里?
结果可衡量性?
考核规则?
目标共识性?
绩效考核的关键问题
数据的真实准确性?
考核与面谈注意事项
奖惩合理性
四、工作管理 – 工作改善
改进,变革与创新意识
建立创新机制

第三部分 人员与团队管理
一、沟通技能
对上沟通
了解上司
接受命令,请示建议,汇报工作
如何配合上司?
平行沟通协调
案例分析:工作协作协调中的首要问题是什么?
平级关系沟通中应切记的三条原则
如何应对办公室政治?
沟通方法技巧
沟通如何准备?
倾听的技巧
表达的技巧
赞美的技巧
二、团队管理 – 领导力发挥
什么是领导力?
领导与管理的区别
领导力来源于什么?
管理者如何提升领导力素质,发挥领导作用?
什么样的品质更受下属敬重?
什么样的行为要以身作则?
哪些能力必须修炼?
心智修炼
三、团队管理 – 员工管理
员工管理策略
打破盲人摸象式的员工管理思维!
管不住事能管好人吗?
如何应用原则性与灵活性结合?
推拉帮管组合拳
什么是德主刑辅的管理思维?
员工管理案例分析讨论:
新任主管的挑战?
个性专家员工?
老油条,有后台?
如何处理法不责众?
在下属面前没有威信怎么办?
四、团队管理 – 员工培育
1、抓思想
如何使员工认同企业?
工作中的意识问题?
引导员工的职业观,企业观,人生价值观?
调整员工心态与情绪?
2、带作风
如何带出一支雷厉风行,敢打硬仗的队伍?
如何训练良好的行为习惯?
3、提升能力
如何帮助员工建立职业理想?
管不住事能管好人吗?
如何让员工在工作中成长?
【案例分析】:华为,海尔的晋升通道与任职资格体系
【模板参考】:岗位能力分析
五、团队管理 -- 团队环境建设
1、团队环境建设与团队文化建设
2、环境对人的影响
3、优秀团队的环境特征
4、如何塑造团队环境?
价值观宣传
领导骨干的作用
制度与平台
环境建设的管理策略
六、员工管理 – 员工激励
马斯洛需求层次理论在员工需求中的体现?
如何把握员工需求?
激励员工的方法措施
物质激励是基础 – 公正评价,合理报酬,帮助员工增加收入!
让员工成长 – 个性化的培养
放大感受价值 – 关注感受与感情!
【案例分析】:企业员工激励方案和措施若干
如何激发员工 – 激励员工的12剧场
【模板工具】:12剧场激励设计方法

讲师介绍:【曹礼明】
强调落地的动作化训练导师!
中山大学MBA,中国首批PMP认证资格人员,知名企业管理培训导师。
20多年的企业工作与管理实践经验,先后在国企、合资、外资、民企担任研发经理、部门经理、人力资源总监、生产及运营总监、常务副总等职。
从事企业管理咨询顾问5年,帮助企业进行管 理变革和管理干部队伍训练。曹老师融合中西方管理理念和方法,擅长将西方管理理论与中国企业实际相结合,以结果和管理有效性为导向,注重方法、策略、措施与实际情况相结合,追求对企业产生实际效果。
  曹礼明老师认为企业管理干部管理知识和思维固然重要,如果不能落地,不能应用在工作中解决问题,那么价值有限,事倍功半!
  企业要解决管理上的"最后一公里"问题,必须在如何落地,如何做管理动作上下工夫!曹老师的训练强调找问题,做动作,追求学用结合!
  曹礼明老师在企业执行力提升,中高层领导力,团队打造,团队文化建设,干部管理技能训练等方面有丰富经验。他曾主持了多家企业的管理咨询辅导,使企业从管理混乱失控、业绩停滞不前、人员自由涣散的状态,逐步改变成制度规范、流程控制有效、企业业绩显著提升、企业凝聚力增强的崭新企业。
  曹礼明老师自从事企业管理培训以来,内外训课程数百场,受训人数上万人,其中《新任经理全面管理技能提升训练》公开课二百余期,《MTP中层管理训练》内 训上百期,内训结合企业实际情况和解决学员问题而深受好评。

主要课程:
《新任经理全面管理技能提升训练》、《中层管 理MTP训练》、《中高层领导力》、《中层执行力》、《中层选用育留》、《中层带团队》、《管理沟通与协调》、《中层核心工作能力提升》、《团队管理与人员激励》、《生产经理、主管实战管理技能提升训练》等课程。

Sunday, May 29, 2016

libcrypto errata update

A bug in the previous libcrypto errata caused an error when reading
ASN.1 elements over 16kb.

Patches for OpenBSD are available. Updated LibreSSL-portable releases
will be available later.

http://ftp.openbsd.org/pub/OpenBSD/patches/5.9/common/009_crypto.patch.sig

http://ftp.openbsd.org/pub/OpenBSD/patches/5.8/common/015_crypto.patch.sig