Monday, December 5, 2016

FESCo and Council elections - December 2016/January 2017

Greetings,

FESCo and Council elections are now open and we're looking for new
candidates: https://fedoraproject.org/wiki/Elections

For FESCo we have opened five seats:
https://fedoraproject.org/wiki/Development/SteeringCommittee/Nominations

For Council we have opened one seat:
https://fedoraproject.org/wiki/Council/Nominations

The Elections schedule is as follows:
* December 06 - December 12: Nomination period open (closes promptly
at 23:59 UTC on December 12th)
* December 13 - January 09: Campaign period. Individual blog posts,
etc. encouraged. We will also have an interview with answers published
on the Fedora Community Blog.
* January 10 - January 16: Voting open (closes promptly at 23:59 UTC
on January 16th)
* January 17: Results announcement

The Campaign period has been prolonged, in these Elections, as it is
expected to have people in many countries away from keyboards during
the Christmas period.

Elections Questionnaire needs more questions for email/Community blog
interviews! If you have anything you would like to ask candidates to
FESCo or to Council, please add it to the wiki.
http://fedoraproject.org/wiki/Elections/Questionnaire

Read more about the FESCo at:
http://fedoraproject.org/wiki/Development/SteeringCommittee
and about the Council at: http://fedoraproject.org/wiki/Council

Thanks for your support,
Jan
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org

F26 System Wide Change: Enable coredumpctl by default

= System Wide Change: Enable coredumpctl by default =
https://fedoraproject.org/wiki/Changes/coredumpctl

Change owner(s):
* Michael Catanzaro <mcatanzaro AT gnome DOT org>

Enable coredumpctl by default. Core dumps will be stored in the system
journal rather than created in the crashing process's current working
directory by ABRT.


== Detailed Description ==
coredumpctl will be enabled by default. Core dumps will now be stored
in the systemd journal, rather than created in the crashing process's
current working directory by ABRT. Currently abrt-ccpp.service
installs its own core pattern to /proc/sys/kernel/core_pattern that
overrides the core pattern set by systemd. We will simply disable
abrt-ccpp.service in the Fedora systemd presets to avoid this. This is
of course only a change in default behavior. It will still be possible
and easy to revert to the previous Fedora behavior by enabling and
starting abrt-ccpp.service, or to traditional Linux behavior by
overriding the sysctl variable kernel.core_pattern.

Note that coredumpctl is intended as a developer tool, not as an
automatic bug reporting tool nor as a replacement for ABRT. ABRT will
continue to automatically report C and C++ crashes to the Fedora
Analysis Framework (FAF), and users will still be able to manually
report crashes to Red Hat Bugzilla using ABRT's Problem Reporting
application. Nor does coredumpctl replace ABRT's ability to catch
non-C/C++ issues like Java exceptions, Python exceptions, or machine
check events. ABRT remains an important component of Fedora, and will
continue to function largely as before as it has support for
retrieving core files from the system journal using
abrt-vmcore.service. However, it must be admitted that ABRT's feature
set will be slightly smaller with abrt-ccpp.service disabled. Notably,
crash-time stacktraces will no longer be available as all stacktraces
will be generated from core files extracted from the system journal.
This could result in reduced-quality for the truncated stacktraces
that are used in FAF and the first comment in Bugzilla, but it will
not affect the detailed stacktraces that are uploaded as Bugzilla
attachments.


== Scope ==
* Proposal owners:
We will disable abrt-ccpp.service in our systemd presets. That's it.

* Other developers:
We request some assistance from SELinux developers to address an
incompatibility between SELinux and coredumpctl that was introduced in
Fedora 24, RHBZ #1341829.

* Release engineering: No changes needed

* List of deliverables: No changes needed

* Policies and guidelines: No changes needed

* Trademark approval: Not needed for this change
--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org

Saturday, December 3, 2016

[CentOS-announce] CESA-2016:2843 Critical CentOS 6 firefox Security Update

CentOS Errata and Security Advisory 2016:2843 Critical

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-2843.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
4272182e4744591510d2a8f695c4514ba5cd48ea53d1f4b730fea917ced95046 firefox-45.5.1-1.el6.centos.i686.rpm

x86_64:
4272182e4744591510d2a8f695c4514ba5cd48ea53d1f4b730fea917ced95046 firefox-45.5.1-1.el6.centos.i686.rpm
ec698684b1a62b6e27173e7a025cb354ab2f0f7a2f5ff19d76e0f410b4e18575 firefox-45.5.1-1.el6.centos.x86_64.rpm

Source:
d174016bedb5dc9b22630ceb8f15eb3ba11c2114baf4a5ba87bdf9fd9a4dd53c firefox-45.5.1-1.el6.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:2843 Critical CentOS 5 firefox Security Update

CentOS Errata and Security Advisory 2016:2843 Critical

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-2843.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
428cdbe6535695b8770f32372f3d88f886beabec9ada487d0aca157816c5973e firefox-45.5.1-1.el5.centos.i386.rpm

x86_64:
428cdbe6535695b8770f32372f3d88f886beabec9ada487d0aca157816c5973e firefox-45.5.1-1.el5.centos.i386.rpm
c0eddc4d631809868c0409114c051170671a357eaa95a3b29a8642f8c65e5d42 firefox-45.5.1-1.el5.centos.x86_64.rpm

Source:
48ab00902da28957f5bb2ed54e684596d52c8fca825fbb24c19814786643fad4 firefox-45.5.1-1.el5.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

Friday, December 2, 2016

[announce] NYC*BUG Holiday Hang-out

Wednesday, December 7
645 PM
Suspenders at 108 Greenwich Street.

We'll meet at one end of the restaurant/bar, and keep it informal this year.

We are sorting out meetings for the new year with space reserved for:

January 4

February 1 (we need space for that date)

March 1

April 5

Those who previously expressed interest in doing a meeting, please ping
admin@ to sort out the details. You know who you are :)

_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

Thursday, December 1, 2016

[USN-3148-1] Ghostscript vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3148-1
December 02, 2016

ghostscript vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Ghostscript could be made to crash, run programs, or disclose sensitive
information if it processed a specially crafted file.

Software Description:
- ghostscript: PostScript and PDF interpreter

Details:

Tavis Ormandy discovered multiple vulnerabilities in the way that Ghostscript
processes certain Postscript files. If a user or automated system were tricked
into opening a specially crafted file, an attacker could cause a denial of
service or possibly execute arbitrary code. (CVE-2016-7976, CVE-2016-7978,
CVE-2016-7979, CVE-2016-8602)

Multiple vulnerabilities were discovered in Ghostscript related to information
disclosure. If a user or automated system were tricked into opening a specially
crafted file, an attacker could expose sensitive data. (CVE-2013-5653,
CVE-2016-7977)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
  ghostscript                     9.19~dfsg+1-0ubuntu6.2
  ghostscript-x                   9.19~dfsg+1-0ubuntu6.2
  libgs9                          9.19~dfsg+1-0ubuntu6.2
  libgs9-common                   9.19~dfsg+1-0ubuntu6.2

Ubuntu 16.04 LTS:
  ghostscript                     9.18~dfsg~0-0ubuntu2.2
  ghostscript-x                   9.18~dfsg~0-0ubuntu2.2
  libgs9                          9.18~dfsg~0-0ubuntu2.2
  libgs9-common                   9.18~dfsg~0-0ubuntu2.2

Ubuntu 14.04 LTS:
  ghostscript                     9.10~dfsg-0ubuntu10.5
  ghostscript-x                   9.10~dfsg-0ubuntu10.5
  libgs9                          9.10~dfsg-0ubuntu10.5
  libgs9-common                   9.10~dfsg-0ubuntu10.5

Ubuntu 12.04 LTS:
  ghostscript                     9.05~dfsg-0ubuntu4.4
  ghostscript-x                   9.05~dfsg-0ubuntu4.4
  libgs9                          9.05~dfsg-0ubuntu4.4
  libgs9-common                   9.05~dfsg-0ubuntu4.4

In general, a standard system update will make all the necessary changes.

References:
  http://www.ubuntu.com/usn/usn-3148-1
  CVE-2013-5653, CVE-2016-7976, CVE-2016-7977, CVE-2016-7978,
  CVE-2016-7979, CVE-2016-8602

Package Information:
  https://launchpad.net/ubuntu/+source/ghostscript/9.19~dfsg+1-0ubuntu6.2
  https://launchpad.net/ubuntu/+source/ghostscript/9.18~dfsg~0-0ubuntu2.2
  https://launchpad.net/ubuntu/+source/ghostscript/9.10~dfsg-0ubuntu10.5
  https://launchpad.net/ubuntu/+source/ghostscript/9.05~dfsg-0ubuntu4.4

[USN-3133-1] Oxide vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJYQH6qAAoJEGEfvezVlG4P9E4H/1bUWDrfUAKQ3n/CpEGAG+PO
rFIysi8MhCWDS0J5n02s4Z2B6T8XEJvL+lgEODB4y9Vov7hsjSDh19WfN3aR0N6M
Vguc5qDISjzmiVOVNORiZF7GfQn6DQ6KTN99pKWDrwTB7D2OjELfPj7/vAtTREqF
P/i9x9V4PsVf4xmwfyGOejJ1XnwCSN+IiAIQgl65JXbCfstnOAiyx4v5ZgAdMo26
ATWJVsy3y46LviSS+7YNs2Hfl9JywHti8NOZbmDJeFcrXqrEDMheSEQ0Rk8eO1mr
aNtPHul/08b1/nxvoTaXmacK/rfZxLu11mQ8C6y8GSood77B5xQI6MiRtejjxa8=
=ZpYO
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3133-1
December 01, 2016

oxide-qt vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Oxide.

Software Description:
- oxide-qt: Web browser engine for Qt (QML plugin)

Details:

Multiple security vulnerabilities were discovered in Chromium. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit these to obtain sensitive information, cause a denial
of service via application crash, or execute arbitrary code.
(CVE-2016-5198, CVE-2016-5200, CVE-2016-5202)

A heap-corruption issue was discovered in FFmpeg. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service via application crash, or
execute arbitrary code. (CVE-2016-5199)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.10:
liboxideqtcore0 1.18.5-0ubuntu0.16.10.1

Ubuntu 16.04 LTS:
liboxideqtcore0 1.18.5-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
liboxideqtcore0 1.18.5-0ubuntu0.14.04.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-3133-1
CVE-2016-5198, CVE-2016-5199, CVE-2016-5200, CVE-2016-5202

Package Information:
https://launchpad.net/ubuntu/+source/oxide-qt/1.18.5-0ubuntu0.16.10.1
https://launchpad.net/ubuntu/+source/oxide-qt/1.18.5-0ubuntu0.16.04.1
https://launchpad.net/ubuntu/+source/oxide-qt/1.18.5-0ubuntu0.14.04.1

[CentOS-announce] CEEA-2016:2832 CentOS 6 tzdata Enhancement Update

CentOS Errata and Enhancement Advisory 2016:2832

Upstream details at : https://rhn.redhat.com/errata/RHEA-2016-2832.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
94711daa2f7540f86e4313316646551596431c259771937c3331430bfd5fb6c8 tzdata-2016j-1.el6.noarch.rpm
c3592026ffc22a0209ed8c694f6d61c3e8ab9bf7b11c8c4f3e940890ab9f443a tzdata-java-2016j-1.el6.noarch.rpm

x86_64:
94711daa2f7540f86e4313316646551596431c259771937c3331430bfd5fb6c8 tzdata-2016j-1.el6.noarch.rpm
c3592026ffc22a0209ed8c694f6d61c3e8ab9bf7b11c8c4f3e940890ab9f443a tzdata-java-2016j-1.el6.noarch.rpm

Source:
269fcb2024cf95221b18ddaface194532539927534eb88a872a0c08bb27a8ad9 tzdata-2016j-1.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:2825 Important CentOS 6 thunderbird Security Update

CentOS Errata and Security Advisory 2016:2825 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-2825.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
b21002cf325311197b191b5b530f685a6501df24390836e0f2b82a0bfdb11258 thunderbird-45.5.0-1.el6.centos.i686.rpm

x86_64:
3e0df1347b13bbdbbe0e7563dd7a84bcd6c6818925b53393448e13128a359562 thunderbird-45.5.0-1.el6.centos.x86_64.rpm

Source:
dea7ceb00bc57fb4c1ff6e8d7f6d9e3acc6852d4d4b29355d2bb1de300452532 thunderbird-45.5.0-1.el6.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEEA-2016:2832 CentOS 5 tzdata Enhancement Update

CentOS Errata and Enhancement Advisory 2016:2832

Upstream details at : https://rhn.redhat.com/errata/RHEA-2016-2832.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
e11c441014d2a46d7e85ed4db026fbc2f9c0e008ad89c402696589db3f4893b0 tzdata-2016j-1.el5.i386.rpm
62b80a842298ca82ca815f649f3cb0a675d6544a77fa14756e6c15db2f7c9e50 tzdata-java-2016j-1.el5.i386.rpm

x86_64:
bcdcca7cbdc90b6d128d9f908e67159bff74b7bcd63c3245f00d6cd6593f56f1 tzdata-2016j-1.el5.x86_64.rpm
d38f22fd31f06b46012a47af034aa6098af98e59f9da9665e5047b324025f2b9 tzdata-java-2016j-1.el5.x86_64.rpm

Source:
f6f785b3ba7f4d1b9d4799d417976f839ec553efaf7fdf5bd728f0fd40fb979a tzdata-2016j-1.el5.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:2825 Important CentOS 5 thunderbird Security Update

CentOS Errata and Security Advisory 2016:2825 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-2825.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
7251f6beb26fcb00598415eeaf517c73782cd93d61546cae8fee4d0f7a4071b6 thunderbird-45.5.0-1.el5.centos.i386.rpm

x86_64:
b37fd2b77f5597775d8ad56a518b5fb35ab1c09c03b731817edd56c4a65a6e6b thunderbird-45.5.0-1.el5.centos.x86_64.rpm

Source:
89b0a355885d6a9c753eb36af7e2c58ff3fb1c05c72438af2be24f3b35f65065 thunderbird-45.5.0-1.el5.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com