Saturday, June 4, 2016

Updated Debian 8: 8.5 released

------------------------------------------------------------------------
The Debian Project https://www.debian.org/
Updated Debian 8: 8.5 released press@debian.org
June 4th, 2016 https://www.debian.org/News/2016/20160604
------------------------------------------------------------------------


The Debian project is pleased to announce the fifth update of its stable
distribution Debian 8 (codename "jessie"). This update mainly adds
corrections for security problems to the stable release, along with a
few adjustments for serious problems. Security advisories were already
published separately and are referenced where available.

Please note that this update does not constitute a new version of Debian
8 but only updates some of the packages included. There is no need to
throw away old "jessie" CDs or DVDs but only to update via an up-to-date
Debian mirror after an installation, to cause any out of date packages
to be updated.

Those who frequently install updates from security.debian.org won't have
to update many packages and most updates from security.debian.org are
included in this update.

New installation media and CD and DVD images containing updated packages
will be available soon at the regular locations.

Upgrading to this revision online is usually done by pointing the
aptitude (or apt) package tool (see the sources.list(5) manual page) to
one of Debian's many FTP or HTTP mirrors. A comprehensive list of
mirrors is available at:

https://www.debian.org/mirror/list



Miscellaneous Bugfixes
----------------------

This stable update adds a few important corrections to the following
packages:

+-------------------------+-------------------------------------------+
| Package | Reason |
+-------------------------+-------------------------------------------+
| autofs [1] | Remove stray debugging output in log |
| | files |
| | |
| bareos [2] | Fix GnuTLS backend initialization, TLS |
| | negotiation for passive filedaemons |
| | |
| base-files [3] | Update for the point release |
| | |
| chrony [4] | Fix CVE-2016-1567: Restrict |
| | authentication of server/peer to |
| | specified key; remove /var/lib/chrony on |
| | purge only; rework postrotate log |
| | rotation script |
| | |
| clamav [5] | New upstream release |
| | |
| cyrus-imapd-2.4 [6] | Drop broken caldav support |
| | |
| debian-edu [7] | Add libdns-mdns to tasks/desktop-other |
| | and tasks/main-server to make CUPS |
| | browsing really functional; add avahi- |
| | discover, mdns-scan, avahi-autoipd and |
| | kdnssd to tasks/main-server as suggested |
| | packages |
| | |
| debian-edu-config [8] | Backport various bug fixes |
| | |
| debian-edu-doc [9] | Update wheezy and jessie documentation |
| | |
| debian-edu-install [10] | Update version number to 8+edu0 |
| | |
| debian-installer [11] | Rebuild against proposed-updates; add |
| | sata-modules for arm64 - some machines do |
| | have SATA CD |
| | |
| debian-installer- | Rebuild against new debian-installer; |
| netboot-images [12] | swap the d-i Built-Using with the |
| | installer fetching, to fail on version |
| | mismatches earlier |
| | |
| dpkg [13] | Add more Conflicts for removed packages |
| | expecting dpkg to ship install-info; |
| | remove trailing space before handling |
| | blank line dot-separator in |
| | Dpkg::Control::HashCore. Regression |
| | introduced in dpkg 1.17.25; only use the |
| | SHELL environment variable for |
| | interactive shells; move tar option --no- |
| | recursion before -T in dpkg-deb; |
| | initialize Config-Version also for |
| | packages previously in triggers-pending |
| | state; fix memory leak in dpkg infodb |
| | format upgrade logic; fix physical file |
| | offset comparison in dpkg; add kfreebsd- |
| | armhf support to ostable and |
| | triplettable; add NIOS2 support to |
| | cputable |
| | |
| evince [14] | Fix crashes when document has pages |
| | removed and is reloaded, and when a |
| | recent document fails to load |
| | |
| ext4magic [15] | Fix an issue which makes impossible to |
| | recover or examine Ext4 filesystems |
| | |
| fusionforge [16] | Disable mediawiki plugin, as mediawiki is |
| | being removed |
| | |
| gitolite3 [17] | Enable repository paths without '~/' in |
| | git-annex-shell |
| | |
| glusterfs [18] | Add missing glusterd hook script to |
| | glusterfs-server package |
| | |
| gosa [19] | Several bugfixes |
| | |
| gpa [20] | Fix check of dialog return values |
| | |
| groovy [21] | Fix remote execution of untrusted code |
| | and possible DoS vulnerability [CVE-2015- |
| | 3253] |
| | |
| hexchat [22] | Verify hostnames when ssl is in use |
| | |
| hivex [23] | Fix ruby-hivex installation |
| | |
| icedove [24] | Fix build failure on mips; fix build on |
| | arm{el,hf} |
| | |
| icedtea-web [25] | New upstream release, fixes CVE-2015-5235 |
| | and CVE-2015-5234 |
| | |
| initramfs-tools [26] | Include drivers/nvme in block driver |
| | modules; create ORDER files even if there |
| | are no valid scripts |
| | |
| libcrypto++ [27] | Fix Rijndael timing attack counter |
| | measure [CVE-2016-3995] |
| | |
| libdatetime-timezone- | Update to tzdata 2016d |
| perl [28] | |
| | |
| libksba [29] | Do not abort on decoder stack overflow |
| | [CVE-2016-4353]; fix integer overflow in |
| | the BER decoder (CVE-2016-4354 CVE-2016- |
| | 4355), encoding of invalid utf-8 strings |
| | in dn.c [CVE-2016-4356], OOB read access |
| | in _ksba_dn_to_str, possible read access |
| | beyond the buffer [CVE-2016-4579] |
| | |
| libreoffice [30] | Fix build failure on ppc64el due to |
| | changes in OpenJDK; fix logic to not |
| | install sound files |
| | |
| linux [31] | Revert some changes in 3.16.7-ckt25-1 |
| | which caused issues on some systems with |
| | Radeon graphics cards and when inserting |
| | a USB device |
| | |
| lvm2 [32] | Set default pid directory to /run |
| | |
| mathematica-fonts [33] | Update for new upstream file version |
| | (10); only TrueType fonts are now |
| | available; add missing dependency on wget |
| | |
| nam [34] | Build-Depend on tcl / tk >= 8.6 |
| | |
| ngspice [35] | Run lyx with a temporary -userdir to not |
| | rely on $HOME |
| | |
| nlpsolver [36] | Add missing Depends: on libreoffice-java- |
| | common |
| | |
| nmap [37] | Fix versioned breaks/replaces; deal with |
| | unuseable socks proxy; ignore |
| | unenumerable interfaces; move ndiff.py |
| | from zenmap to ndiff |
| | |
| opam [38] | Fix insecure certificate handling |
| | |
| openjdk-7 [39] | Fix build failure on arm{el,hf} |
| | |
| openssl [40] | Update expired certificates used by test |
| | suite; update to 1.0.1t stable release; |
| | use alternate trust chains; use correct |
| | digest when exporting keying material; |
| | security fixes [CVE-2015-3197 CVE-2015- |
| | 1793] |
| | |
| pepperflashplugin- | Update Google public key; remove 32 bit |
| nonfree [41] | support |
| | |
| perl [42] | Apply selected bug-fix patches taken from |
| | 5.20.3; fix debugperl crashes with XS |
| | modules; CVE-2015-8853 fix regexp engine |
| | hang on illegal UTF8 input; fix UTF8- |
| | related regexp engine crash |
| | |
| postgresql-9.1 [43] | New upstream release |
| | |
| postgresql-9.4 [44] | New upstream release |
| | |
| quota [45] | Change invocation of quota services, so |
| | systemd takes over most of the work |
| | |
| redmine [46] | Load all database drivers for all Redmine |
| | instances |
| | |
| tklib [47] | Fixed typo in Plotchart version which |
| | prevented its loading |
| | |
| tzdata [48] | New upstream release |
| | |
| wmforecast [49] | Update for new Yahoo! weather API |
| | |
| xapian-core [50] | Fix possible database corruption, |
| | especially with recoll |
| | |
| xarchiver [51] | Fix crash when attempting to cancel |
| | "extract here" in Thunar plugin |
| | |
| xscreensaver [52] | Remove warning about "outdated" version |
| | |
| zendframework [53] | Fix regression from ZF2015-08: binary |
| | data corruption; fix ZF2016-01: Potential |
| | Insufficient Entropy Vulnerability in ZF1 |
| | |
+-------------------------+-------------------------------------------+

1: https://packages.debian.org/src:autofs
2: https://packages.debian.org/src:bareos
3: https://packages.debian.org/src:base-files
4: https://packages.debian.org/src:chrony
5: https://packages.debian.org/src:clamav
6: https://packages.debian.org/src:cyrus-imapd-2.4
7: https://packages.debian.org/src:debian-edu
8: https://packages.debian.org/src:debian-edu-config
9: https://packages.debian.org/src:debian-edu-doc
10: https://packages.debian.org/src:debian-edu-install
11: https://packages.debian.org/src:debian-installer
12: https://packages.debian.org/src:debian-installer-netboot-images
13: https://packages.debian.org/src:dpkg
14: https://packages.debian.org/src:evince
15: https://packages.debian.org/src:ext4magic
16: https://packages.debian.org/src:fusionforge
17: https://packages.debian.org/src:gitolite3
18: https://packages.debian.org/src:glusterfs
19: https://packages.debian.org/src:gosa
20: https://packages.debian.org/src:gpa
21: https://packages.debian.org/src:groovy
22: https://packages.debian.org/src:hexchat
23: https://packages.debian.org/src:hivex
24: https://packages.debian.org/src:icedove
25: https://packages.debian.org/src:icedtea-web
26: https://packages.debian.org/src:initramfs-tools
27: https://packages.debian.org/src:libcrypto++
28: https://packages.debian.org/src:libdatetime-timezone-perl
29: https://packages.debian.org/src:libksba
30: https://packages.debian.org/src:libreoffice
31: https://packages.debian.org/src:linux
32: https://packages.debian.org/src:lvm2
33: https://packages.debian.org/src:mathematica-fonts
34: https://packages.debian.org/src:nam
35: https://packages.debian.org/src:ngspice
36: https://packages.debian.org/src:nlpsolver
37: https://packages.debian.org/src:nmap
38: https://packages.debian.org/src:opam
39: https://packages.debian.org/src:openjdk-7
40: https://packages.debian.org/src:openssl
41: https://packages.debian.org/src:pepperflashplugin-nonfree
42: https://packages.debian.org/src:perl
43: https://packages.debian.org/src:postgresql-9.1
44: https://packages.debian.org/src:postgresql-9.4
45: https://packages.debian.org/src:quota
46: https://packages.debian.org/src:redmine
47: https://packages.debian.org/src:tklib
48: https://packages.debian.org/src:tzdata
49: https://packages.debian.org/src:wmforecast
50: https://packages.debian.org/src:xapian-core
51: https://packages.debian.org/src:xarchiver
52: https://packages.debian.org/src:xscreensaver
53: https://packages.debian.org/src:zendframework

Security Updates
----------------

This revision adds the following security updates to the stable release.
The Security Team has already released an advisory for each of these
updates:

+----------------+------------------------+
| Advisory ID | Package |
+----------------+------------------------+
| DSA-3410 [54] | icedove-l10n [55] |
| | |
| DSA-3410 [56] | iceowl-l10n [57] |
| | |
| DSA-3410 [58] | enigmail [59] |
| | |
| DSA-3410 [60] | icedove [61] |
| | |
| DSA-3432 [62] | icedove [63] |
| | |
| DSA-3473 [64] | nginx [65] |
| | |
| DSA-3476 [66] | postgresql-9.4 [67] |
| | |
| DSA-3482 [68] | libreoffice [69] |
| | |
| DSA-3485 [70] | didiwiki [71] |
| | |
| DSA-3491 [72] | icedove [73] |
| | |
| DSA-3495 [74] | xymon [75] |
| | |
| DSA-3520 [76] | icedove [77] |
| | |
| DSA-3530 [78] | tomcat6 [79] |
| | |
| DSA-3533 [80] | openvswitch [81] |
| | |
| DSA-3535 [82] | kamailio [83] |
| | |
| DSA-3537 [84] | imlib2 [85] |
| | |
| DSA-3538 [86] | libebml [87] |
| | |
| DSA-3539 [88] | srtp [89] |
| | |
| DSA-3540 [90] | lhasa [91] |
| | |
| DSA-3542 [92] | mercurial [93] |
| | |
| DSA-3543 [94] | oar [95] |
| | |
| DSA-3544 [96] | python-django [97] |
| | |
| DSA-3545 [98] | cgit [99] |
| | |
| DSA-3546 [100] | optipng [101] |
| | |
| DSA-3549 [102] | chromium-browser [103] |
| | |
| DSA-3550 [104] | openssh [105] |
| | |
| DSA-3552 [106] | tomcat7 [107] |
| | |
| DSA-3554 [108] | xen [109] |
| | |
| DSA-3555 [110] | imlib2 [111] |
| | |
| DSA-3556 [112] | libgd2 [113] |
| | |
| DSA-3557 [114] | mysql-5.5 [115] |
| | |
| DSA-3558 [116] | openjdk-7 [117] |
| | |
| DSA-3559 [118] | iceweasel [119] |
| | |
| DSA-3560 [120] | php5 [121] |
| | |
| DSA-3561 [122] | subversion [123] |
| | |
| DSA-3562 [124] | tardiff [125] |
| | |
| DSA-3563 [126] | poppler [127] |
| | |
| DSA-3564 [128] | chromium-browser [129] |
| | |
| DSA-3565 [130] | pdns [131] |
| | |
| DSA-3565 [132] | ovito [133] |
| | |
| DSA-3565 [134] | botan1.10 [135] |
| | |
| DSA-3565 [136] | softhsm [137] |
| | |
| DSA-3565 [138] | qtcreator [139] |
| | |
| DSA-3566 [140] | openssl [141] |
| | |
| DSA-3567 [142] | libpam-sshauth [143] |
| | |
| DSA-3568 [144] | libtasn1-6 [145] |
| | |
| DSA-3569 [146] | openafs [147] |
| | |
| DSA-3570 [148] | mercurial [149] |
| | |
| DSA-3571 [150] | ikiwiki [151] |
| | |
| DSA-3572 [152] | websvn [153] |
| | |
| DSA-3573 [154] | qemu [155] |
| | |
| DSA-3574 [156] | libarchive [157] |
| | |
| DSA-3575 [158] | libxstream-java [159] |
| | |
| DSA-3576 [160] | icedove [161] |
| | |
| DSA-3577 [162] | jansson [163] |
| | |
| DSA-3578 [164] | libidn [165] |
| | |
| DSA-3579 [166] | xerces-c [167] |
| | |
| DSA-3580 [168] | imagemagick [169] |
| | |
| DSA-3581 [170] | libndp [171] |
| | |
| DSA-3582 [172] | expat [173] |
| | |
| DSA-3583 [174] | swift-plugin-s3 [175] |
| | |
| DSA-3584 [176] | librsvg [177] |
| | |
| DSA-3585 [178] | wireshark [179] |
| | |
| DSA-3586 [180] | atheme-services [181] |
| | |
| DSA-3587 [182] | libgd2 [183] |
| | |
+----------------+------------------------+

54: https://www.debian.org/security/2015/dsa-3410
55: https://packages.debian.org/src:icedove-l10n
56: https://www.debian.org/security/2015/dsa-3410
57: https://packages.debian.org/src:iceowl-l10n
58: https://www.debian.org/security/2015/dsa-3410
59: https://packages.debian.org/src:enigmail
60: https://www.debian.org/security/2015/dsa-3410
61: https://packages.debian.org/src:icedove
62: https://www.debian.org/security/2016/dsa-3432
63: https://packages.debian.org/src:icedove
64: https://www.debian.org/security/2016/dsa-3473
65: https://packages.debian.org/src:nginx
66: https://www.debian.org/security/2016/dsa-3476
67: https://packages.debian.org/src:postgresql-9.4
68: https://www.debian.org/security/2016/dsa-3482
69: https://packages.debian.org/src:libreoffice
70: https://www.debian.org/security/2016/dsa-3485
71: https://packages.debian.org/src:didiwiki
72: https://www.debian.org/security/2016/dsa-3491
73: https://packages.debian.org/src:icedove
74: https://www.debian.org/security/2016/dsa-3495
75: https://packages.debian.org/src:xymon
76: https://www.debian.org/security/2016/dsa-3520
77: https://packages.debian.org/src:icedove
78: https://www.debian.org/security/2016/dsa-3530
79: https://packages.debian.org/src:tomcat6
80: https://www.debian.org/security/2016/dsa-3533
81: https://packages.debian.org/src:openvswitch
82: https://www.debian.org/security/2016/dsa-3535
83: https://packages.debian.org/src:kamailio
84: https://www.debian.org/security/2016/dsa-3537
85: https://packages.debian.org/src:imlib2
86: https://www.debian.org/security/2016/dsa-3538
87: https://packages.debian.org/src:libebml
88: https://www.debian.org/security/2016/dsa-3539
89: https://packages.debian.org/src:srtp
90: https://www.debian.org/security/2016/dsa-3540
91: https://packages.debian.org/src:lhasa
92: https://www.debian.org/security/2016/dsa-3542
93: https://packages.debian.org/src:mercurial
94: https://www.debian.org/security/2016/dsa-3543
95: https://packages.debian.org/src:oar
96: https://www.debian.org/security/2016/dsa-3544
97: https://packages.debian.org/src:python-django
98: https://www.debian.org/security/2016/dsa-3545
99: https://packages.debian.org/src:cgit
100: https://www.debian.org/security/2016/dsa-3546
101: https://packages.debian.org/src:optipng
102: https://www.debian.org/security/2016/dsa-3549
103: https://packages.debian.org/src:chromium-browser
104: https://www.debian.org/security/2016/dsa-3550
105: https://packages.debian.org/src:openssh
106: https://www.debian.org/security/2016/dsa-3552
107: https://packages.debian.org/src:tomcat7
108: https://www.debian.org/security/2016/dsa-3554
109: https://packages.debian.org/src:xen
110: https://www.debian.org/security/2016/dsa-3555
111: https://packages.debian.org/src:imlib2
112: https://www.debian.org/security/2016/dsa-3556
113: https://packages.debian.org/src:libgd2
114: https://www.debian.org/security/2016/dsa-3557
115: https://packages.debian.org/src:mysql-5.5
116: https://www.debian.org/security/2016/dsa-3558
117: https://packages.debian.org/src:openjdk-7
118: https://www.debian.org/security/2016/dsa-3559
119: https://packages.debian.org/src:iceweasel
120: https://www.debian.org/security/2016/dsa-3560
121: https://packages.debian.org/src:php5
122: https://www.debian.org/security/2016/dsa-3561
123: https://packages.debian.org/src:subversion
124: https://www.debian.org/security/2016/dsa-3562
125: https://packages.debian.org/src:tardiff
126: https://www.debian.org/security/2016/dsa-3563
127: https://packages.debian.org/src:poppler
128: https://www.debian.org/security/2016/dsa-3564
129: https://packages.debian.org/src:chromium-browser
130: https://www.debian.org/security/2016/dsa-3565
131: https://packages.debian.org/src:pdns
132: https://www.debian.org/security/2016/dsa-3565
133: https://packages.debian.org/src:ovito
134: https://www.debian.org/security/2016/dsa-3565
135: https://packages.debian.org/src:botan1.10
136: https://www.debian.org/security/2016/dsa-3565
137: https://packages.debian.org/src:softhsm
138: https://www.debian.org/security/2016/dsa-3565
139: https://packages.debian.org/src:qtcreator
140: https://www.debian.org/security/2016/dsa-3566
141: https://packages.debian.org/src:openssl
142: https://www.debian.org/security/2016/dsa-3567
143: https://packages.debian.org/src:libpam-sshauth
144: https://www.debian.org/security/2016/dsa-3568
145: https://packages.debian.org/src:libtasn1-6
146: https://www.debian.org/security/2016/dsa-3569
147: https://packages.debian.org/src:openafs
148: https://www.debian.org/security/2016/dsa-3570
149: https://packages.debian.org/src:mercurial
150: https://www.debian.org/security/2016/dsa-3571
151: https://packages.debian.org/src:ikiwiki
152: https://www.debian.org/security/2016/dsa-3572
153: https://packages.debian.org/src:websvn
154: https://www.debian.org/security/2016/dsa-3573
155: https://packages.debian.org/src:qemu
156: https://www.debian.org/security/2016/dsa-3574
157: https://packages.debian.org/src:libarchive
158: https://www.debian.org/security/2016/dsa-3575
159: https://packages.debian.org/src:libxstream-java
160: https://www.debian.org/security/2016/dsa-3576
161: https://packages.debian.org/src:icedove
162: https://www.debian.org/security/2016/dsa-3577
163: https://packages.debian.org/src:jansson
164: https://www.debian.org/security/2016/dsa-3578
165: https://packages.debian.org/src:libidn
166: https://www.debian.org/security/2016/dsa-3579
167: https://packages.debian.org/src:xerces-c
168: https://www.debian.org/security/2016/dsa-3580
169: https://packages.debian.org/src:imagemagick
170: https://www.debian.org/security/2016/dsa-3581
171: https://packages.debian.org/src:libndp
172: https://www.debian.org/security/2016/dsa-3582
173: https://packages.debian.org/src:expat
174: https://www.debian.org/security/2016/dsa-3583
175: https://packages.debian.org/src:swift-plugin-s3
176: https://www.debian.org/security/2016/dsa-3584
177: https://packages.debian.org/src:librsvg
178: https://www.debian.org/security/2016/dsa-3585
179: https://packages.debian.org/src:wireshark
180: https://www.debian.org/security/2016/dsa-3586
181: https://packages.debian.org/src:atheme-services
182: https://www.debian.org/security/2016/dsa-3587
183: https://packages.debian.org/src:libgd2

Removed packages
----------------

The following packages were removed due to circumstances beyond our
control:

+-------------------------------+--------------------------------------+
| Package | Reason |
+-------------------------------+--------------------------------------+
| lyz [184] | Depends on to-be-removed zotero- |
| | standalone-build |
| | |
| mediawiki [185] | No longer security supported |
| | |
| mediawiki-math [186] | Depends on to-be-removed mediawiki |
| | |
| zotero-standalone-build [187] | Unusable in jessie |
| | |
+-------------------------------+--------------------------------------+

184: https://packages.debian.org/src:lyz
185: https://packages.debian.org/src:mediawiki
186: https://packages.debian.org/src:mediawiki-math
187: https://packages.debian.org/src:zotero-standalone-build

Debian Installer
----------------

URLs
----

The complete lists of packages that have changed with this revision:

http://ftp.debian.org/debian/dists/jessie/ChangeLog


The current stable distribution:

http://ftp.debian.org/debian/dists/stable/


Proposed updates to the stable distribution:

http://ftp.debian.org/debian/dists/proposed-updates


stable distribution information (release notes, errata etc.):

https://www.debian.org/releases/stable/


Security announcements and information:

https://security.debian.org/ [188]

188: https://www.debian.org/security/


About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to <press@debian.org>, or contact the
stable release team at <debian-release@lists.debian.org>.

Updated Debian 7: 7.11 released

------------------------------------------------------------------------
The Debian Project https://www.debian.org/
Updated Debian 7: 7.11 released press@debian.org
June 4th, 2016 https://www.debian.org/News/2016/2016060402
------------------------------------------------------------------------


The Debian project is pleased to announce the eleventh (and final)
update of its oldstable distribution Debian 7 (codename "wheezy"). This
update mainly adds corrections for security problems to the oldstable
release, along with a few adjustments for serious problems. Security
advisories were already published separately and are referenced where
available.

The packages from DSA 3548 are not included in this point release for
technical reasons, as are some architectures for DSA 3547, DSA 3219, DSA
3482 and DSA 3246. All other security updates released during the
lifetime of "wheezy" that have not previously been part of a point
release are included in this update.

Please note that this update does not constitute a new version of Debian
7 but only updates some of the packages included. There is no need to
throw away old "wheezy" CDs or DVDs but only to update via an up-to-date
Debian mirror after an installation, to cause any out of date packages
to be updated.

Those who frequently install updates from security.debian.org won't have
to update many packages and most updates from security.debian.org are
included in this update.

New installation media and CD and DVD images containing updated packages
will be available soon at the regular locations.

Upgrading to this revision online is usually done by pointing the
aptitude (or apt) package tool (see the sources.list(5) manual page) to
one of Debian's many FTP or HTTP mirrors. A comprehensive list of
mirrors is available at:

https://www.debian.org/mirror/list



Miscellaneous Bugfixes
----------------------

This oldstable update adds a few important corrections to the following
packages:

+--------------------------+------------------------------------------+
| Package | Reason |
+--------------------------+------------------------------------------+
| base-files [1] | Update for the point release |
| | |
| debian-installer [2] | Rebuild for the point release |
| | |
| debian-installer- | Rebuild for the point release; swap the |
| netboot-images [3] | d-i Built-Using with the installer |
| | fetching, to fail on version mismatches |
| | earlier |
| | |
| dpkg [4] | Remove trailing space before handling |
| | blank line dot-separator in |
| | Dpkg::Control::HashCore. Regression |
| | introduced in dpkg 1.16.16; only use the |
| | SHELL environment variable for |
| | interactive shells; move tar option -- |
| | no-recursion before -T in dpkg-deb; |
| | initialize Config-Version also for |
| | packages previously in triggers-pending |
| | state; fix memory leak in dpkg infodb |
| | format upgrade logic; fix physical file |
| | offset comparison in dpkg |
| | |
| groovy [5] | Fix remote execution of untrusted code |
| | and possible DoS vulnerability |
| | [CVE-2015-3253] |
| | |
| gtk+3.0 [6] | Fix integer overflow when allocating a |
| | large block of memory in |
| | gdk_cairo_set_source_pixbuf [CVE-2013- |
| | 7447] |
| | |
| highlight [7] | Avoid segfault with undefined syntax |
| | |
| icecast2 [8] | Security fix [CVE-2014-9018] |
| | |
| libcrypto++ [9] | Fix Rijndael timing attack counter |
| | measure [CVE-2016-3995] |
| | |
| libdatetime-timezone- | Update to tzdata 2016d |
| perl [10] | |
| | |
| openldap [11] | Disable the back-mdb test suite on |
| | powerpc to work around back-mdb tests |
| | failing on buildds running the jessie |
| | ppc64 kernel, which uses 64KB pages |
| | |
| optipng [12] | Fix use-after-free vulnerability |
| | [CVE-2015-7801] |
| | |
| postgresql-9.1 [13] | New upstream release |
| | |
| tzdata [14] | New upstream version |
| | |
| xapian-core [15] | Fix possible database corruption, |
| | especially with recoll |
| | |
| zendframework [16] | Fix regression from ZF2015-08: binary |
| | data corruption; fix ZF2016-01: |
| | Potential Insufficient Entropy |
| | Vulnerability in ZF1 |
| | |
+--------------------------+------------------------------------------+

1: https://packages.debian.org/src:base-files
2: https://packages.debian.org/src:debian-installer
3: https://packages.debian.org/src:debian-installer-netboot-images
4: https://packages.debian.org/src:dpkg
5: https://packages.debian.org/src:groovy
6: https://packages.debian.org/src:gtk+3.0
7: https://packages.debian.org/src:highlight
8: https://packages.debian.org/src:icecast2
9: https://packages.debian.org/src:libcrypto++
10: https://packages.debian.org/src:libdatetime-timezone-perl
11: https://packages.debian.org/src:openldap
12: https://packages.debian.org/src:optipng
13: https://packages.debian.org/src:postgresql-9.1
14: https://packages.debian.org/src:tzdata
15: https://packages.debian.org/src:xapian-core
16: https://packages.debian.org/src:zendframework

Security Updates
----------------

This revision adds the following security updates to the oldstable
release. The Security Team has already released an advisory for each of
these updates:

+----------------+---------------------------+
| Advisory ID | Package |
+----------------+---------------------------+
| DSA-2722 [17] | icedtea-web [18] |
| | |
| DSA-2727 [19] | openjdk-6 [20] |
| | |
| DSA-2768 [21] | icedtea-web [22] |
| | |
| DSA-2893 [23] | openswan [24] |
| | |
| DSA-2912 [25] | openjdk-6 [26] |
| | |
| DSA-2980 [27] | openjdk-6 [28] |
| | |
| DSA-3070 [29] | kfreebsd-9 [30] |
| | |
| DSA-3077 [31] | openjdk-6 [32] |
| | |
| DSA-3147 [33] | openjdk-6 [34] |
| | |
| DSA-3157 [35] | ruby1.9.1 [36] |
| | |
| DSA-3163 [37] | libreoffice [38] |
| | |
| DSA-3175 [39] | kfreebsd-9 [40] |
| | |
| DSA-3219 [41] | libdbd-firebird-perl [42] |
| | |
| DSA-3234 [43] | openjdk-6 [44] |
| | |
| DSA-3236 [45] | libreoffice [46] |
| | |
| DSA-3246 [47] | ruby1.9.1 [48] |
| | |
| DSA-3339 [49] | openjdk-6 [50] |
| | |
| DSA-3356 [51] | openldap [52] |
| | |
| DSA-3394 [53] | libreoffice [54] |
| | |
| DSA-3410 [55] | icedove-l10n [56] |
| | |
| DSA-3410 [57] | icedove [58] |
| | |
| DSA-3410 [59] | enigmail [60] |
| | |
| DSA-3432 [61] | icedove [62] |
| | |
| DSA-3442 [63] | isc-dhcp [64] |
| | |
| DSA-3458 [65] | openjdk-7 [66] |
| | |
| DSA-3465 [67] | openjdk-6 [68] |
| | |
| DSA-3467 [69] | tiff [70] |
| | |
| DSA-3475 [71] | postgresql-9.1 [72] |
| | |
| DSA-3480 [73] | eglibc [74] |
| | |
| DSA-3482 [75] | libreoffice [76] |
| | |
| DSA-3485 [77] | didiwiki [78] |
| | |
| DSA-3491 [79] | icedove [80] |
| | |
| DSA-3515 [81] | graphite2 [82] |
| | |
| DSA-3520 [83] | icedove [84] |
| | |
| DSA-3523 [85] | iceweasel [86] |
| | |
| DSA-3530 [87] | tomcat6 [88] |
| | |
| DSA-3534 [89] | dhcpcd [90] |
| | |
| DSA-3536 [91] | libstruts1.2-java [92] |
| | |
| DSA-3537 [93] | imlib2 [94] |
| | |
| DSA-3538 [95] | libebml [96] |
| | |
| DSA-3539 [97] | srtp [98] |
| | |
| DSA-3540 [99] | lhasa [100] |
| | |
| DSA-3541 [101] | roundcube [102] |
| | |
| DSA-3542 [103] | mercurial [104] |
| | |
| DSA-3543 [105] | oar [106] |
| | |
| DSA-3544 [107] | python-django [108] |
| | |
| DSA-3546 [109] | optipng [110] |
| | |
| DSA-3547 [111] | imagemagick [112] |
| | |
| DSA-3550 [113] | openssh [114] |
| | |
| DSA-3551 [115] | fuseiso [116] |
| | |
| DSA-3552 [117] | tomcat7 [118] |
| | |
| DSA-3553 [119] | varnish [120] |
| | |
| DSA-3555 [121] | imlib2 [122] |
| | |
| DSA-3556 [123] | libgd2 [124] |
| | |
| DSA-3559 [125] | iceweasel [126] |
| | |
+----------------+---------------------------+

17: https://www.debian.org/security/2013/dsa-2722
18: https://packages.debian.org/src:icedtea-web
19: https://www.debian.org/security/2013/dsa-2727
20: https://packages.debian.org/src:openjdk-6
21: https://www.debian.org/security/2013/dsa-2768
22: https://packages.debian.org/src:icedtea-web
23: https://www.debian.org/security/2014/dsa-2893
24: https://packages.debian.org/src:openswan
25: https://www.debian.org/security/2014/dsa-2912
26: https://packages.debian.org/src:openjdk-6
27: https://www.debian.org/security/2014/dsa-2980
28: https://packages.debian.org/src:openjdk-6
29: https://www.debian.org/security/2014/dsa-3070
30: https://packages.debian.org/src:kfreebsd-9
31: https://www.debian.org/security/2014/dsa-3077
32: https://packages.debian.org/src:openjdk-6
33: https://www.debian.org/security/2015/dsa-3147
34: https://packages.debian.org/src:openjdk-6
35: https://www.debian.org/security/2015/dsa-3157
36: https://packages.debian.org/src:ruby1.9.1
37: https://www.debian.org/security/2015/dsa-3163
38: https://packages.debian.org/src:libreoffice
39: https://www.debian.org/security/2015/dsa-3175
40: https://packages.debian.org/src:kfreebsd-9
41: https://www.debian.org/security/2015/dsa-3219
42: https://packages.debian.org/src:libdbd-firebird-perl
43: https://www.debian.org/security/2015/dsa-3234
44: https://packages.debian.org/src:openjdk-6
45: https://www.debian.org/security/2015/dsa-3236
46: https://packages.debian.org/src:libreoffice
47: https://www.debian.org/security/2015/dsa-3246
48: https://packages.debian.org/src:ruby1.9.1
49: https://www.debian.org/security/2015/dsa-3339
50: https://packages.debian.org/src:openjdk-6
51: https://www.debian.org/security/2015/dsa-3356
52: https://packages.debian.org/src:openldap
53: https://www.debian.org/security/2015/dsa-3394
54: https://packages.debian.org/src:libreoffice
55: https://www.debian.org/security/2015/dsa-3410
56: https://packages.debian.org/src:icedove-l10n
57: https://www.debian.org/security/2015/dsa-3410
58: https://packages.debian.org/src:icedove
59: https://www.debian.org/security/2015/dsa-3410
60: https://packages.debian.org/src:enigmail
61: https://www.debian.org/security/2016/dsa-3432
62: https://packages.debian.org/src:icedove
63: https://www.debian.org/security/2016/dsa-3442
64: https://packages.debian.org/src:isc-dhcp
65: https://www.debian.org/security/2016/dsa-3458
66: https://packages.debian.org/src:openjdk-7
67: https://www.debian.org/security/2016/dsa-3465
68: https://packages.debian.org/src:openjdk-6
69: https://www.debian.org/security/2016/dsa-3467
70: https://packages.debian.org/src:tiff
71: https://www.debian.org/security/2016/dsa-3475
72: https://packages.debian.org/src:postgresql-9.1
73: https://www.debian.org/security/2016/dsa-3480
74: https://packages.debian.org/src:eglibc
75: https://www.debian.org/security/2016/dsa-3482
76: https://packages.debian.org/src:libreoffice
77: https://www.debian.org/security/2016/dsa-3485
78: https://packages.debian.org/src:didiwiki
79: https://www.debian.org/security/2016/dsa-3491
80: https://packages.debian.org/src:icedove
81: https://www.debian.org/security/2016/dsa-3515
82: https://packages.debian.org/src:graphite2
83: https://www.debian.org/security/2016/dsa-3520
84: https://packages.debian.org/src:icedove
85: https://www.debian.org/security/2016/dsa-3523
86: https://packages.debian.org/src:iceweasel
87: https://www.debian.org/security/2016/dsa-3530
88: https://packages.debian.org/src:tomcat6
89: https://www.debian.org/security/2016/dsa-3534
90: https://packages.debian.org/src:dhcpcd
91: https://www.debian.org/security/2016/dsa-3536
92: https://packages.debian.org/src:libstruts1.2-java
93: https://www.debian.org/security/2016/dsa-3537
94: https://packages.debian.org/src:imlib2
95: https://www.debian.org/security/2016/dsa-3538
96: https://packages.debian.org/src:libebml
97: https://www.debian.org/security/2016/dsa-3539
98: https://packages.debian.org/src:srtp
99: https://www.debian.org/security/2016/dsa-3540
100: https://packages.debian.org/src:lhasa
101: https://www.debian.org/security/2016/dsa-3541
102: https://packages.debian.org/src:roundcube
103: https://www.debian.org/security/2016/dsa-3542
104: https://packages.debian.org/src:mercurial
105: https://www.debian.org/security/2016/dsa-3543
106: https://packages.debian.org/src:oar
107: https://www.debian.org/security/2016/dsa-3544
108: https://packages.debian.org/src:python-django
109: https://www.debian.org/security/2016/dsa-3546
110: https://packages.debian.org/src:optipng
111: https://www.debian.org/security/2016/dsa-3547
112: https://packages.debian.org/src:imagemagick
113: https://www.debian.org/security/2016/dsa-3550
114: https://packages.debian.org/src:openssh
115: https://www.debian.org/security/2016/dsa-3551
116: https://packages.debian.org/src:fuseiso
117: https://www.debian.org/security/2016/dsa-3552
118: https://packages.debian.org/src:tomcat7
119: https://www.debian.org/security/2016/dsa-3553
120: https://packages.debian.org/src:varnish
121: https://www.debian.org/security/2016/dsa-3555
122: https://packages.debian.org/src:imlib2
123: https://www.debian.org/security/2016/dsa-3556
124: https://packages.debian.org/src:libgd2
125: https://www.debian.org/security/2016/dsa-3559
126: https://packages.debian.org/src:iceweasel

Debian Installer
----------------

URLs
----

The complete lists of packages that have changed with this revision:

http://ftp.debian.org/debian/dists/wheezy/ChangeLog


The current oldstable distribution:

http://ftp.debian.org/debian/dists/oldstable/


Proposed updates to the oldstable distribution:

http://ftp.debian.org/debian/dists/oldstable-proposed-updates


oldstable distribution information (release notes, errata etc.):

https://www.debian.org/releases/oldstable/


Security announcements and information:

https://security.debian.org/ [127]

127: https://www.debian.org/security/


About Debian
------------

The Debian Project is an association of Free Software developers who
volunteer their time and effort in order to produce the completely free
operating system Debian.


Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/, send mail to <press@debian.org>, or contact the
stable release team at <debian-release@lists.debian.org>.

[FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-16:24.ntp

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

=============================================================================
FreeBSD-SA-16:24.ntp Security Advisory
The FreeBSD Project

Topic: Multiple vulnerabilities of ntp

Category: contrib
Module: ntp
Announced: 2016-06-04
Credits: Network Time Foundation and various contributors listed below
Affects: All supported versions of FreeBSD.
Corrected: 2016-06-03 08:59:21 UTC (stable/10, 10.3-STABLE)
2016-06-04 05:46:52 UTC (releng/10.3, 10.3-RELEASE-p5)
2016-06-04 05:46:52 UTC (releng/10.2, 10.2-RELEASE-p19)
2016-06-04 05:46:52 UTC (releng/10.1, 10.1-RELEASE-p36)
2016-06-03 09:03:10 UTC (stable/9, 9.3-STABLE)
2016-06-04 05:46:52 UTC (releng/9.3, 9.3-RELEASE-p44)
CVE Name: CVE-2016-4957, CVE-2016-4953, CVE-2016-4954, CVE-2016-4955
CVE-2016-4956

For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:https://security.FreeBSD.org/>.

I. Background

The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP)
used to synchronize the time of a computer system to a reference time
source.

II. Problem Description

Multiple vulnerabilities have been discovered in the NTP suite:

The fix for Sec 3007 in ntp-4.2.8p7 contained a bug that could cause ntpd to
crash. [CVE-2016-4957, Reported by Nicolas Edet of Cisco]

An attacker who knows the origin timestamp and can send a spoofed packet
containing a CRYPTO-NAK to an ephemeral peer target before any other
response is sent can demobilize that association. [CVE-2016-4953, Reported by
Miroslav Lichvar of Red Hat]

An attacker who is able to spoof packets with correct origin timestamps
from enough servers before the expected response packets arrive at the
target machine can affect some peer variables and, for example,
cause a false leap indication to be set. [CVE-2016-4954, Reported by
Jakub Prokes of Red Hat]

An attacker who is able to spoof a packet with a correct origin timestamp
before the expected response packet arrives at the target machine can
send a CRYPTO_NAK or a bad MAC and cause the association's peer variables
to be cleared. If this can be done often enough, it will prevent that
association from working. [CVE-2016-4955, Reported by Miroslav Lichvar
of Red Hat]

The fix for NtpBug2978 does not cover broadcast associations, so broadcast
clients can be triggered to flip into interleave mode. [CVE-2016-4956,
Reported by Miroslav Lichvar of Red Hat.]

III. Impact

Malicious remote attackers may be able to break time synchronization,
or cause the ntpd(8) daemon to crash.

IV. Workaround

No workaround is available, but systems not running ntpd(8) are not
affected. Network administrators are advised to implement BCP-38,
which helps to reduce the risk associated with the attacks.

V. Solution

Perform one of the following:

1) Upgrade your vulnerable system to a supported FreeBSD stable or
release / security branch (releng) dated after the correction date.

The ntpd service has to be restarted after the update. A reboot is
recommended but not required.

2) To update your vulnerable system via a binary patch:

Systems running a RELEASE version of FreeBSD on the i386 or amd64
platforms can be updated via the freebsd-update(8) utility:

# freebsd-update fetch
# freebsd-update install

The ntpd service has to be restarted after the update. A reboot is
recommended but not required.

3) To update your vulnerable system via a source code patch:

The following patches have been verified to apply to the applicable
FreeBSD release branches.

a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility.

# fetch https://security.FreeBSD.org/patches/SA-16:24/ntp.patch
# fetch https://security.FreeBSD.org/patches/SA-16:24/ntp.patch.asc
# gpg --verify ntp.patch.asc

b) Apply the patch. Execute the following commands as root:

# cd /usr/src
# patch < /path/to/patch

c) Recompile the operating system using buildworld and installworld as
described in <URL:https://www.FreeBSD.org/handbook/makeworld.html>.

Restart the applicable daemons, or reboot the system.

VI. Correction details

The following list contains the correction revision numbers for each
affected branch.

Branch/path Revision
- -------------------------------------------------------------------------
stable/9/ r301257
releng/9.3/ r301301
stable/10/ r301256
releng/10.1/ r301301
releng/10.2/ r301301
releng/10.3/ r301301
- -------------------------------------------------------------------------

To see which files were modified by a particular revision, run the
following command, replacing NNNNNN with the revision number, on a
machine with Subversion installed:

# svn diff -cNNNNNN --summarize svn://svn.freebsd.org/base

Or visit the following URL, replacing NNNNNN with the revision number:

<URL:https://svnweb.freebsd.org/base?view=revision&revision=NNNNNN>

VII. References

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4957>

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4953>

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4954>

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4955>

<URL:https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4956>

The latest revision of this advisory is available at
<URL:https://security.FreeBSD.org/advisories/FreeBSD-SA-16:24.ntp.asc>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.1.12 (FreeBSD)

iQIcBAEBCgAGBQJXUnRyAAoJEO1n7NZdz2rncMMQAIB69xMkhWqoZ+0R2R6MOPAI
UWIEPN4fLktiz4oIKP/C/xTsJdonC6+GCKbEb4h+deUOEYPaK5L1RsjvzwjqDKvI
9THtZUBoEcifALOiO1Mkum+1ntCkF+7EK2EXSuF2/wYga/ekVkCPZqLxmUEbL/KG
HEa4VCnMv0euAxEbtzix6efNTZV/9O0uUmYlU0wt8WF+YL+p15CyhBIc5YZISpWA
izugcLKU8xriFMOiyOIttnIS1pAKERu0Fh9EqlkfFhcmJXl18Oxn10L0qH6uEx/C
Rs11KzyJSuOpBl7x5NZi9jsTzlZlI6zqJ9b6Dlj2A8k82oz5p3VUf+CDyDlMZxHo
2PsRPGdYJA98w/dUFucZozt1J4K05dWOnd6oED1bY8bFEb+IhRYYOil/wqiNBJFw
Q9B6jB18Olp4PxxMZVX5kXz4j3tzqlt80wY9S/pVOIGjKcbxIHqhB5CFt1UJfsUw
BGzJTpYYBvqdS0e3ozO+4QyHBlm4Ure4JFlrb/kBXgLvnBcTfn5e2NMJKhMSvC0B
O5Ma1D7E2eYxxHgpUFTJYo+qNrfWsQHPClxOMVXbxUrz/iheEvTaed7tyHtMI5nz
vloTNWf4WNWnxYv5meOOSj2lXX5dxT+XpEA+1kmOWdWvOx8nmOWrOUYN6hM191jD
e3hZ2X6TAfHd5LIHtb2C
=ttlK
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

Friday, June 3, 2016

F25 Self Contained Change: Fedora Scale-Out Docker Registry

= Proposed Self Contained Change: Fedora Scale-Out Docker Registry =
https://fedoraproject.org/wiki/Changes/FedoraDockerRegistry

Change owner(s):
* Adam Miller <maxamillion AT fedoraproject DOT org>

This is a proposal for a change to the Fedora Infrastructure and
Fedora Release Engineering tooling to provide a scalable Docker
Registry solution for Fedora that is integrated with the Fedoar Docker
Layered Image Build Service.

== Detailed Description ==
Change Wrangler note: as the Change description is quite complex,
please check the Change page for the details.

== Scope ==
* Proposal owners
- Implement the proposed Design of a Scaled-Out Docker Registry
-- Deploy Pulp
-- Deploy Crane
-- Deploy Docker-Distribution Registry
-- Integrate with MirrorManager for content distribution
- Document the system

(Change Wrangler note: as the Scope section is quite complex, please
check the Change page for the details)
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

F25 Self Contained Change: Release Engineering Automation Workflow Engine

= Proposed Self Contained Change: Release Engineering Automation
Workflow Engine =
https://fedoraproject.org/wiki/Changes/ReleaseEngineeringAutomationWorkflowEngine

Change owner(s):
* Adam Miller <maxamillion AT fedoraproject DOT org>


Centralized entry point, logging, and dash board for pre-defined
Automated Workflow tasks used by the Release Engineering team with
delegation and self-service tasks for members of various teams who
normally depend on Release Engineering for various tasks.


== Detailed Description ==
Currently Fedora Release Engineering Automation tasks are performed by
various scripts run on various machines within the Fedora
Infrastructure with no real centralized logging. Some of these are
automated by chron jobs and some run by hand by request of various
members within the Fedora Community, normally around Fedora Test Days.
Finding information about old tasks is not always the easiest of
things to do and the delegation of tasks is currently not available.
The goal here is to provide a solution that removes those barriers.

Workflows will be executed and potentially orchestrate actions between
multiple other systems or tools such as bodhi, pungi, and koji.
Fedmsgs will be emitted with information about the start and
completion of workflows along with metadata about them.

In the event of a compose, certain fedmsg output will be picked up by
taskotron and autocloud to perform various levels of testing.

(Change Wrangler note: as the section is quite complex, please check
the Change page to get more details)

== Scope ==
* Proposal owners shall have to:
- Determine what the "Engine" will be after evaluation and working
with the Fedora RelEng and Infrastructure teams for advisement.
- Deploy RelEng Automation Workflow Engine
-- Fully automated deployment in Fedora Infrastructure Ansible
- Document Workflow Automation
-- How workflows are created
-- How to run workflows
-- How new contributors can get started

* Release engineering
- Deploy the "Engine"

* Policies and guidelines
- Need to determine who can create/run workflows
- Define guidelines for writing workflows

(Change Wrangler note: as the Scope section is quite complex, please
check the Change page to get more details)
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

reallost1.fbsd2233449:了解环境、职业健康安全法规的体系框架管理的基础

                环境健康安全法律法规

课程背景:
          面对数以万计的中国环境、安全及工业卫生法律法规及相关标准,企业如何学习并了解在实际管理中运用环境及职业健康安全法律法规及相关标准,已成为企业管理的一项专业性强、技术要求度的核心工作,并作为评判企业是否符合EHS管理体系、符合供应链EHS管控标准、符合社会责任关怀及可持续发展的重要准则。
本程课将从最新环境、职业健康安全法律法规入手,结合企业在不同发展阶段环境、安全及工业卫生的法规运用、现场实务操作展开培训,让学员对环境、安全及工业卫生律法规的实施与方法有一个详细的认知,并能有效的根据培训内容进行动作分解和活动实施落地。

课程简介:
培训对象:
EHS经理、EHS工程师、安全工程师、中高层管理者,采购经理、危险化学品库管理员、库房经理、安全员、ISO14001内审员、OHS18001内审员等 


授课形式:知识讲授、视频分析、案例展示、角色扮演、实操演练等
课程时间:6月25-26日 上海
课程费用:3200元/人 (包含:课程资料费、午餐、茶点、发票)
联系方式:021-31006787  18917870808    许先生
QQ、微信:320588808

课程特色:
互动教学模式。使用引导技术,理论结合实际案例分析来进行项目的学习与讨论。

课程收获:
1.了解环境、职业健康安全法规的体系框架管理的基础
2.掌握环境、职业健康安全法律法规管理的重点要求
3.掌握环境、职业健康安全管理的实务操作方法

课程大纲:
第一天
一、环境、安全及工业卫生法律法规基础知识
环境、安全及工业卫生法律法规在企业管理中的重要性
新版环境保护法、安全生产法及相关配套法规内容解析
在EMS、OH&S体系中对相关法律法规管理的要求

二、企业在新、改、扩建中的环境、安全及工业卫生法律法规管理
(1)环境三同时管理
环境影响评价及批复相关法规介绍
环境公众参与相关法规要求
环境三废(废水、废气、噪声)检测适用标准及判定方法
环境三同时验收管理要求
企业环境信用评价办法(试行)解读-企业环境信用评价指标及评分方法
案例:针对企业环境信用评价四个等级(绿、蓝、黄、红牌)的后果
(2)安全三同时管理
安全三同时管理相关法规解读
安全预评价、安全验收评价及安全现状评价三个类别导则的解析
危险化学品库安全评价细则要求
如何按照<安全评价通则>组织建筑项目安全三同时验收
(3)职业卫生三同时管理
职业病防治法解析
进行职业病危害评价的风险等级
职业危害预评价与职业危害控制效果评价的区别
如何开展职业危害因素检测(工作场所有害因素职业接触限值-物理或化学)
职业危害因素的申报管理
用人单位职业病防治八条规定及防治指南
(4)厂房消防验收与防雷验收管理
中华人民共和国消防法
 建筑设计防火规范解析
建筑工程消防验收评价规则
防雷减灾管理办法
防雷装置设计审批和竣工验收规定

第二天
三、企业在日常管理中的环境、安全及工业卫生法律法规的应用、实施与维护
(1) 企业日常运行过程中的环境管理法规要求
2016年实施新版大气污染防治法应对要求
废弃物管理-中华人民共和国固体废物污染环境防治法(2013修正)解析
废弃物管理-国家危废目录2014版征求意见稿变更内容及危废管理流程、废弃电器电子产品回收处理管理条例
危险化学品管理-《重点环境管理危险化学品目录》解读
环境应急管理企业突发环境事件风险评估指南(试行)解读

(2)企业日常运行过程的安全管理法规要求
危险化学品管理-2015新版危险化学目录、危险化学品分类信息表解读
基于GHS的全球化学品统一分类与标准机制、危险化学品管理条例2013版解析
消防安全管理-建筑消防设施的维护管理标准解读
特种设备管理-新版特种设备安全法及特种设备目录解析、特种作业人员安全技术培训考核
电气安全管理-用电安全导则、电气安全操作规程及手持式电动工具管理、使用、检查和维修安全技术规程
安全标志管理-工业管道基本识别色、识别符号和安全标识、2015版消防标志应用解读
交通安全管理-工业企业厂内铁路、道路运输安全规程
餐饮安全管理-餐饮业和集体用餐配送单位卫生规范
应急预案管理-生产经营单位安全事故应急预案编制导则、应急预案政府备案要求
(3)企业日常运行过程中的职业健康管理
劳保用品管理-特种劳保用品目录、个体防护装备选用规范、呼吸防护用品的选择、使用与维护
职业病体检管理与工伤保险
2015新版职业病危害因素目录
2013版职业病目录
GBZ188职业健康监护技术标准
工伤保险条例及应用细则解读
粉尘与爆炸管理-(铝镁粉加工)粉尘防爆安全规程
射线许可证或豁免制度管理-放射性同位素与射线装置安全和防护条例

讲师介绍:
    史万进先生
南京工业大学安全工程硕士
华东地区环境健康安全管理-资深培训专家
国家注册管理咨询师 、国家注册安全工程师、上海市注册安全标准化评审员
顶优咨询等国际知名培训认证机构EHS资深培训讲师
史老师曾在国内化工企业及全球知名电子制造集团任职EHS(环境及职业健康安全)主管工作, 积累了丰富的EHS现场管理经验。拥有上百家知名企业(包括数十家世界500强)环境、安全管理项目培训与辅导经验,对机械制造、电子、化工等相关行业等各类企业环境、职业健康与安全管理问题有深入的研究。
史老师设计和实施了大量的EHS培训科目,史老师的环境与安全管理课程,逻辑缜密、系统规范,强调实用、操作可行。活泼,幽默,课堂气氛活跃,擅于利用引导教学技术、善用大量情景案例、新闻事件启发学员对环境与安全管理的自我反思,参与性、互动性、实用性强。

主讲课程:

《6S实战管理培训》、《危险源辨识与风险评价》、《EHS管理体系构建与实施》、《EHS法律法规及应用管理实务》、《消防安全管理实务》、《应急准备与响应》、《中高层安全属地与安全领导力管理》、《工业卫生管理专项培训》、《GHS全球化学品统一分与标识管理》、《危险化学品管理实务》、《BBS&STOP安全观察培训程序》、《班组长安全意识提升培训》、《事故调查与分析管理》、《环境三废与废弃物废弃物管理实务》、《人机工程与安全改善》、《机械与电气防护管理》、《SCC承商包商安全认证培训》......


部分服务过的客户:

一汽、大众、华晨宝马、万向集团、乔治费歇尔汽车产品、新日铁汽车部件、万都底盘部件、瀚德汽车产品、森萨塔科技、吉凯恩工业、大赛璐安全系统、首钢冷轧薄板、浦项不锈钢、凯斯库汽车部件、高田汽车安全装置、固铂轮胎、住友橡胶、正新橡胶、双良集团、富乐压铸、华翔电子、中化集团、三美化工、化工研究院、华峰集团、大金氟化工、迈图高新材料、九州药业、长顺集团、联合利华、阿特拉斯.科普柯集团、博莱特压缩机、爱美克空气过滤器、盖茨液压技术、达涅利冶金设备、曼恩机械、莱克电气、微密科技、梅兰日兰电子、西门子听力仪器......

 

Thursday, June 2, 2016

[FreeBSD-Announce] 2016 FreeBSD Community Survey

Hi everyone,
The FreeBSD Foundation needs your input. Please help us by filling out the 2016 FreeBSD Community Survey. The survey should only take about 10 minutes, and will help us determine the direction of our efforts in supporting the Project and community. Please submit all responses by July, 7, 2016.

https://www.surveymonkey.com/r/freebsd2016

We appreciate your feedback!


Thanks
Anne

Anne Dickison
Marketing Director
FreeBSD Foundation




_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

[USN-2991-1] nginx vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXUHYgAAoJEGVp2FWnRL6TY7wQAKZNqG5kjyWOGSGBQ6Fa0K3F
/0hkhWdkwjN4aU4WNKeirWLrbAELF1iDQfMoJMUvyaF9z0G9YTGmqTegrvZ3rU6h
sflOLQZTNzTJmKA6IQhZCSx2xcA2fVXDZuRFaKKlTbwWZio43xaj42QPDJEaykjA
iHBGSro+QbRQX5ljSSSZFfwlSYZF+OhEQFHYtcoyEZbhee2YHaQYZX/ihFFXkrel
IdgFhtxVYYOEGGsa/tiqCjQqS+1HbOanbHoYLqNNpmKZ80D9VtP9xvQSodZg2IWA
n4E0uLfKrmcOz7Hgu9k9L4ANhRndbFwVEduI1Tj4SUpteN5gQdN+IaBB3cYwuBRD
JoBJYJdVLcCI9REBh2iAWIcVisEYytcicgIzV4jjzuvrMhucLQYBKiTM8tVPrBQ7
Ol/pMbx628EKrpDrfIuM3RqEjAJwdlkMO7giG5ysMMJX57VivXuwlPplRRqbW4Dm
txVwy396PGWi/B1iY1497E8uZsx1fx32ovhx9uQJDrQg/5t5v7gKLT3mhlo4605c
SvEdjTTHx487p+L0q5+NmQC9f7B1ETMJDeFFua9rSndRlNcZbITwwyjTJyvxT/v+
USY4l06ytfMX4YGpOHiVMnBcOOsHPDhj10qTrn+2mwZixqvb1nhhJmLJnQuTWhU/
MI9MZYwU5/3SkNgfmoeH
=GbCc
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2991-1
June 02, 2016

nginx vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS

Summary:

nginx could be made to crash if it received specially crafted network
traffic.

Software Description:
- nginx: small, powerful, scalable web/proxy server

Details:

It was discovered that nginx incorrectly handled saving client request
bodies to temporary files. A remote attacker could possibly use this issue
to cause nginx to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
nginx-core 1.10.0-0ubuntu0.16.04.2
nginx-extras 1.10.0-0ubuntu0.16.04.2
nginx-full 1.10.0-0ubuntu0.16.04.2
nginx-light 1.10.0-0ubuntu0.16.04.2

Ubuntu 15.10:
nginx-core 1.9.3-1ubuntu1.2
nginx-extras 1.9.3-1ubuntu1.2
nginx-full 1.9.3-1ubuntu1.2
nginx-light 1.9.3-1ubuntu1.2

Ubuntu 14.04 LTS:
nginx-core 1.4.6-1ubuntu3.5
nginx-extras 1.4.6-1ubuntu3.5
nginx-full 1.4.6-1ubuntu3.5
nginx-light 1.4.6-1ubuntu3.5

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2991-1
CVE-2016-4450

Package Information:
https://launchpad.net/ubuntu/+source/nginx/1.10.0-0ubuntu0.16.04.2
https://launchpad.net/ubuntu/+source/nginx/1.9.3-1ubuntu1.2
https://launchpad.net/ubuntu/+source/nginx/1.4.6-1ubuntu3.5

[USN-2990-1] ImageMagick vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXUDNoAAoJEGVp2FWnRL6Ti1IQAIF3M6gKtHeElwhlteeTfoL1
yFFWRXchUrLURlWzPBQ381fJ90i0mNaOkkipAJXsj6uzOAobqDmUFh4eO4+zecFA
fII2DzRxGJoOJ1eDAQ284zQkMbB5JEYudDU8rc1zAXm2qQyHsSMXYFzz8PCne8X2
QoC9AFpAsTEyqwm17KZRZRee3W/bdHtIUJm9Dwpr57w9gZggayzHIFM8I07tzR3y
pXtETlBcJYo4NWOCw+iIJjSfZCbuK23Y4E6ddDOlUBOSKN5lmh8ksMt9sKo5CY28
jO3wiN3RIVuASxmuaxFY7TlubhvDHu1IKsTTAzQwA3iJATh6654X3sgLicoNICju
GkJ/Q+Hhaq+3eoUV2KysrOdboBi1jjuf40qI1X5gxNAeFRRKPCmrk14y5wHnIShO
yRLJpzWv0lFyT0ycjB5sRf8iySmt0gH1VI0MTDdc8lxvC2sx3k/eL+2s1KNMwvs4
c5TXouaaVIiJP14dGWR82RJ8fHIas+7mA121+VSsuXzKIrdXmwUgSpeabW/vNXzI
CoFt4gdUDAjNP/gwEE+axEnTkSS+FTvGBH9Y8ygNSKIliDT8YSygDGxR9vpk6znQ
C7fDP7/HywFelqq5ytjJz3DPoD7FtBiN6V/S+GtE9k/KpwpeMo58mbLF4ubxTL5T
aV4qPu19nxuitqRdajjj
=cLRU
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2990-1
June 02, 2016

imagemagick vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in ImageMagick.

Software Description:
- imagemagick: Image manipulation programs and library

Details:

Nikolay Ermishkin and Stewie discovered that ImageMagick incorrectly
sanitized untrusted input. A remote attacker could use these issues to
execute arbitrary code. These issues are known as "ImageTragick". This
update disables problematic coders via the /etc/ImageMagick-6/policy.xml
configuration file. In certain environments the coders may need to be
manually re-enabled after making sure that ImageMagick does not process
untrusted input. (CVE-2016-3714, CVE-2016-3715, CVE-2016-3716,
CVE-2016-3717, CVE-2016-3718)

Bob Friesenhahn discovered that ImageMagick allowed injecting commands via
an image file or filename. A remote attacker could use this issue to
execute arbitrary code. (CVE-2016-5118)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
imagemagick 8:6.8.9.9-7ubuntu5.1
imagemagick-6.q16 8:6.8.9.9-7ubuntu5.1
imagemagick-common 8:6.8.9.9-7ubuntu5.1
libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.1
libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.1

Ubuntu 15.10:
imagemagick 8:6.8.9.9-5ubuntu2.1
imagemagick-6.q16 8:6.8.9.9-5ubuntu2.1
imagemagick-common 8:6.8.9.9-5ubuntu2.1
libmagick++-6.q16-5v5 8:6.8.9.9-5ubuntu2.1
libmagickcore-6.q16-2 8:6.8.9.9-5ubuntu2.1

Ubuntu 14.04 LTS:
imagemagick 8:6.7.7.10-6ubuntu3.1
imagemagick-common 8:6.7.7.10-6ubuntu3.1
libmagick++5 8:6.7.7.10-6ubuntu3.1
libmagickcore5 8:6.7.7.10-6ubuntu3.1

Ubuntu 12.04 LTS:
imagemagick 8:6.6.9.7-5ubuntu3.4
imagemagick-common 8:6.6.9.7-5ubuntu3.4
libmagick++4 8:6.6.9.7-5ubuntu3.4
libmagickcore4 8:6.6.9.7-5ubuntu3.4

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2990-1
CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717,
CVE-2016-3718, CVE-2016-5118

Package Information:
https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.1
https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-5ubuntu2.1
https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.1
https://launchpad.net/ubuntu/+source/imagemagick/8:6.6.9.7-5ubuntu3.4

Wednesday, June 1, 2016

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com

F25 Self Contained Change: The GNU C Library version 2.24

= Proposed Self Contained Change: The GNU C Library version 2.24 =
https://fedoraproject.org/wiki/Changes/GLIBC224

Change owner(s):
* Carlos O'Donell <carlos AT redhat DOT com>

Switch glibc in Fedora 25 to glibc version 2.24.

== Detailed Description ==
The GNU C Library version 2.24 will be released at the beginning of
August 2016; we have started closely tracking the glibc 2.24
development code in Fedora Rawhide and are addressing any issues as
they arise. Given the present schedule Fedora 24 will branch after the
GLIBC 2.24 upstream release.

In addition, we plan the following packaging changes:
* Split NSS (Name Service Switch) modules into separate RPM
subpackages (#1338889)
* Leave assertions enabled (#1338887)
* Use one program to implement sln and ldconfig (#1315476)
* Provide a libcrypt implementation not based on libfreebl3.so (#1324623)


== Scope ==
* Proposal owners: Update glibc to 2.24 from tested upstream release.

* Other developers: Aside from Carlos O'Donell <carlos AT redhat DOT
com>, Florian Weimer <fweimer AT redhat DOT com>, Torvald Riegel
<triegel AT redhat DOT com>, Martin Sebor <msebor AT redhat DOT com>,
and Patsy Franklin <pfrankli AT redhat DOT com>, no other developers
are required. These developers need to ensure that rawhide is stable
and ready for the Fedora 24 branch. Given that glibc is backwards
compatible and we have been testing the new glibc in rawhide it should
make very little impact when updated.

* Release engineering: In general coordination with release
engineering is not required. A mass rebuild is not required.

* Policies and guidelines: The policies and guidelines do not need to
be updated.
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/devel-announce@lists.fedoraproject.org

[USN-2989-1] Linux kernel vulnerabilities

==========================================================================
Ubuntu Security Notice USN-2989-1
June 01, 2016

linux vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Justin Yackoski discovered that the Atheros L2 Ethernet Driver in the Linux
kernel incorrectly enables scatter/gather I/O. A remote attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-2117)

Jason A. Donenfeld discovered multiple out-of-bounds reads in the OZMO USB
over wifi device drivers in the Linux kernel. A remote attacker could use
this to cause a denial of service (system crash) or obtain potentially
sensitive information from kernel memory. (CVE-2015-4004)

Andy Lutomirski discovered a race condition in the Linux kernel's
translation lookaside buffer (TLB) handling of flush events. A local
attacker could use this to cause a denial of service or possibly leak
sensitive information. (CVE-2016-2069)

Ralf Spenneberg discovered that the Linux kernel's GTCO digitizer USB
device driver did not properly validate endpoint descriptors. An attacker
with physical access could use this to cause a denial of service (system
crash). (CVE-2016-2187)

Hector Marco and Ismael Ripoll discovered that the Linux kernel would
improperly disable Address Space Layout Randomization (ASLR) for x86
processes running in 32 bit mode if stack-consumption resource limits were
disabled. A local attacker could use this to make it easier to exploit an
existing vulnerability in a setuid/setgid program. (CVE-2016-3672)

Andrey Konovalov discovered that the CDC Network Control Model USB driver
in the Linux kernel did not cancel work events queued if a later error
occurred, resulting in a use-after-free. An attacker with physical access
could use this to cause a denial of service (system crash). (CVE-2016-3951)

It was discovered that an out-of-bounds write could occur when handling
incoming packets in the USB/IP implementation in the Linux kernel. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2016-3955)

Kangjie Lu discovered an information leak in the ANSI/IEEE 802.2 LLC type 2
Support implementations in the Linux kernel. A local attacker could use
this to obtain potentially sensitive information from kernel memory.
(CVE-2016-4485)

Kangjie Lu discovered an information leak in the routing netlink socket
interface (rtnetlink) implementation in the Linux kernel. A local attacker
could use this to obtain potentially sensitive information from kernel
memory. (CVE-2016-4486)

It was discovered that in some situations the Linux kernel did not handle
propagated mounts correctly. A local unprivileged attacker could use this
to cause a denial of service (system crash). (CVE-2016-4581)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
linux-image-3.13.0-87-generic 3.13.0-87.133
linux-image-3.13.0-87-generic-lpae 3.13.0-87.133
linux-image-3.13.0-87-lowlatency 3.13.0-87.133
linux-image-3.13.0-87-powerpc-e500 3.13.0-87.133
linux-image-3.13.0-87-powerpc-e500mc 3.13.0-87.133
linux-image-3.13.0-87-powerpc-smp 3.13.0-87.133
linux-image-3.13.0-87-powerpc64-emb 3.13.0-87.133
linux-image-3.13.0-87-powerpc64-smp 3.13.0-87.133

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References:
http://www.ubuntu.com/usn/usn-2989-1
CVE-2015-4004, CVE-2016-2069, CVE-2016-2117, CVE-2016-2187,
CVE-2016-3672, CVE-2016-3951, CVE-2016-3955, CVE-2016-4485,
CVE-2016-4486, CVE-2016-4581

Package Information:
https://launchpad.net/ubuntu/+source/linux/3.13.0-87.133