Saturday, May 5, 2018

LibreSSL 2.7.3 Released

We have released LibreSSL 2.7.3, which will be arriving in the LibreSSL
directory of your local OpenBSD mirror soon. This is the first bugfix
release from the 2.7 series, which includes the following changes from 2.7.2:

* Removed incorrect NULL checks in DH_set0_key(). Reported by Ondrej Sury.

* Limited tls_config_clear_keys() to only clear private keys.
This was inadvertently clearing the keypair, which includes the OCSP staple
and pubkey hash - if an application called tls_configure() followed by
tls_config_clear_keys(), this would prevent OCSP staples from working.

* Fixed an issue normalizing CPU architecture in the configure script,
which disabled assembly optimizations on platforms that get detected
as 'amd64', opposed to 'x86_64'.

The LibreSSL project continues improvement of the codebase to reflect modern,
safe programming practices. We welcome feedback and improvements from the
broader community. Thanks to all of the contributors who helped make this
release possible.

Friday, May 4, 2018

[arch-announce] js52 52.7.3-2 upgrade requires intervention

Due to the SONAME of `/usr/lib/libmozjs-52.so` not matching its file name, ldconfig created an untracked file `/usr/lib/libmozjs-52.so.0`. This is now fixed and both files are present in the package.

To pass the upgrade, remove `/usr/lib/libmozjs-52.so.0` prior to upgrading.

URL: https://www.archlinux.org/news/js52-5273-2-upgrade-requires-intervention/
_______________________________________________
arch-announce mailing list
arch-announce@archlinux.org
https://lists.archlinux.org/listinfo/arch-announce

Wednesday, May 2, 2018

[LSN-0037-1] Linux kernel vulnerability

==========================================================================
Kernel Live Patch Security Notice LSN-0037-1
May 02, 2018

linux vulnerability
==========================================================================

A security issue affects these releases of Ubuntu:

| Series | Base kernel | Arch | flavors |
|------------------+--------------+----------+------------------|
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | lowlatency |

Summary:

Several security issues were fixed in the kernel.

Software Description:
- linux: Linux kernel

Details:

Jann Horn discovered that the Berkeley Packet Filter (BPF) implementation
in the Linux kernel improperly performed sign extension in some situations.
A local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-16995)

It was discovered that a race condition leading to a use-after-free
vulnerability existed in the ALSA PCM subsystem of the Linux kernel. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2017-0861)

It was discovered that a use-after-free vulnerability existed in the
network namespaces implementation in the Linux kernel. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2017-15129)

It was discovered that the netfilter component of the Linux did not
properly restrict access to the connection tracking helpers list. A local
attacker could use this to bypass intended access restrictions.
(CVE-2017-17448)

It was discovered that the netfilter passive OS fingerprinting (xt_osf)
module did not properly perform access control checks. A local attacker
could improperly modify the system-wide OS fingerprint list.
(CVE-2017-17450)

The Linux ptrace code virtualizes access to the debug registers, and the
virtualization code has incorrect error handling. This means that if you
write an illegal value to, say, DR0, the internal state of the kernel's
breakpoint tracking can become corrupt despite the fact that the ptrace()
call will return -EINVAL.
(CVE-2018-1000199)

Mohamed Ghannam discovered a null pointer dereference in the RDS (Reliable
Datagram Sockets) protocol implementation of the Linux kernel. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-5333)

范龙飞 discovered that a race condition existed in loop block device
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2018-5344)

It was discovered that the Broadcom UniMAC MDIO bus controller driver in
the Linux kernel did not properly validate device resources. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2018-8043)

Update instructions:

The problem can be corrected by updating your livepatches to the following
versions:

| Kernel | Version | flavors |
|-----------------+----------+--------------------------|
| 4.4.0-116.140 | 37.2 | generic, lowlatency |
| 4.4.0-119.143 | 37.2 | generic, lowlatency |
| 4.4.0-121.145 | 37.2 | generic, lowlatency |
| 4.4.0-122.146 | 37.2 | generic, lowlatency |
| 4.4.0-116.140~14.04.1 | 37.2 | generic, lowlatency |
| 4.4.0-119.143~14.04.1 | 37.2 | generic, lowlatency |
| 4.4.0-121.145~14.04.1 | 37.2 | generic, lowlatency |

Additionally, you should install an updated kernel with these fixes and
reboot at your convienience.

References:
CVE-2017-0861, CVE-2017-15129, CVE-2017-16995, CVE-2017-17448,
CVE-2017-17450, CVE-2018-1000199, CVE-2018-5333, CVE-2018-5344,
CVE-2018-8043

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

[CentOS-announce] CESA-2018:1124 Critical CentOS 6 python-paramiko Security Update

CentOS Errata and Security Advisory 2018:1124 Critical

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1124

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
b3d780db118ae3d20d0b42094fbb9568f2392ab1d1fda44c5a706137e89c57c7 python-paramiko-1.7.5-4.el6_9.noarch.rpm

x86_64:
b3d780db118ae3d20d0b42094fbb9568f2392ab1d1fda44c5a706137e89c57c7 python-paramiko-1.7.5-4.el6_9.noarch.rpm

Source:
516f2f3da754fde2dddef3baa1f44b2fc8eb058c6b22d7731a336165c77b42b7 python-paramiko-1.7.5-4.el6_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1188 Critical CentOS 6 java-1.8.0-openjdk Security Update

CentOS Errata and Security Advisory 2018:1188 Critical

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1188

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
3b3880acd70d462c4a7c99792ad650df5036905ee9f29903bd09a26bf887f580 java-1.8.0-openjdk-1.8.0.171-3.b10.el6_9.i686.rpm
e457c857daf516f552ad529a0d0baa591edef484318bc200472223f08e4d95f8 java-1.8.0-openjdk-debug-1.8.0.171-3.b10.el6_9.i686.rpm
eaf79a4a3eded5a956c50228fc4cbcb25f328f1b363982bd8e64eb6b4e1d4c5c java-1.8.0-openjdk-demo-1.8.0.171-3.b10.el6_9.i686.rpm
84b320acd0f3960083532090d510fa48057ac19bad387b24b3c469495eaa5bff java-1.8.0-openjdk-demo-debug-1.8.0.171-3.b10.el6_9.i686.rpm
bd608747cd424e837b8823e8dbebd39c31bc3e7b5b87b79476c0314ddd7cd3ff java-1.8.0-openjdk-devel-1.8.0.171-3.b10.el6_9.i686.rpm
ba14b04cc20ed0a6abd4e73a06874464d7ad20241fe76fcb2a6a1a3b294d0370 java-1.8.0-openjdk-devel-debug-1.8.0.171-3.b10.el6_9.i686.rpm
485bccd1b6600c42739a97ed9bd0b42adb82789b36d2259b29149594c6eaae6a java-1.8.0-openjdk-headless-1.8.0.171-3.b10.el6_9.i686.rpm
8d98014474ad927d69754b7a6b48e88127db10bddc82e7580f685938febae435 java-1.8.0-openjdk-headless-debug-1.8.0.171-3.b10.el6_9.i686.rpm
067eb162c00fb158e73774838dff1e63deacfe28712ed913b75ecbf30db28575 java-1.8.0-openjdk-javadoc-1.8.0.171-3.b10.el6_9.noarch.rpm
8a237c03e2a2a9a2a532db2224734d81aa533b486f0e70a3fe6a7d613dff121a java-1.8.0-openjdk-javadoc-debug-1.8.0.171-3.b10.el6_9.noarch.rpm
addef18119e41fa63f96a92e0c811242e7aa0ef40f20cf6f33a5f1677b9a3143 java-1.8.0-openjdk-src-1.8.0.171-3.b10.el6_9.i686.rpm
6a2d43918f1fcf87fe5d0ae9f40d2b9e80ea917ef48ca16119bd397aa211f0fe java-1.8.0-openjdk-src-debug-1.8.0.171-3.b10.el6_9.i686.rpm

x86_64:
18de1c67b46c2136da6950a454cb67d034f754af42e9f400d96fdacc92b1751c java-1.8.0-openjdk-1.8.0.171-3.b10.el6_9.x86_64.rpm
bb46ae508c13585350e23cde93442c78af5b3205b69215fb1700b312fa58921e java-1.8.0-openjdk-debug-1.8.0.171-3.b10.el6_9.x86_64.rpm
0647ce24d006764eb618e021482ecc5c20c50864451dd46dd3f380f12ba7471d java-1.8.0-openjdk-demo-1.8.0.171-3.b10.el6_9.x86_64.rpm
f60095ebf6e622a9bd98cadf6fedd7a5fff2d12b94c4ed8e086173642fa16b80 java-1.8.0-openjdk-demo-debug-1.8.0.171-3.b10.el6_9.x86_64.rpm
68b987230c8c678b60137237526fa00082cf6adfd74065c826ad49fcc875e9d6 java-1.8.0-openjdk-devel-1.8.0.171-3.b10.el6_9.x86_64.rpm
675d2775617c7d4c06a8c294024482c5ed16ef72e6e6684012db513682123abd java-1.8.0-openjdk-devel-debug-1.8.0.171-3.b10.el6_9.x86_64.rpm
fb2db097b0c2d6c4d1871df51226558c0475c249f20f8ff04a2baa98e660f372 java-1.8.0-openjdk-headless-1.8.0.171-3.b10.el6_9.x86_64.rpm
14afc062e1f059f2c2feedf8b7802d0bbeef6e889c68f05dd77d2666bb3909ee java-1.8.0-openjdk-headless-debug-1.8.0.171-3.b10.el6_9.x86_64.rpm
067eb162c00fb158e73774838dff1e63deacfe28712ed913b75ecbf30db28575 java-1.8.0-openjdk-javadoc-1.8.0.171-3.b10.el6_9.noarch.rpm
8a237c03e2a2a9a2a532db2224734d81aa533b486f0e70a3fe6a7d613dff121a java-1.8.0-openjdk-javadoc-debug-1.8.0.171-3.b10.el6_9.noarch.rpm
881b93d21e115824920800b0fdc992760bc911a9334a6c84771efa4fbe5e7841 java-1.8.0-openjdk-src-1.8.0.171-3.b10.el6_9.x86_64.rpm
aaa11f1aed134a9b954a394ef317cf056eb224334477d7d9e7777e81841c3d12 java-1.8.0-openjdk-src-debug-1.8.0.171-3.b10.el6_9.x86_64.rpm

Source:
ce61afe55abc160720f25a0f29a7b58cb4f04aac953b9e32f7c3292f10869afc java-1.8.0-openjdk-1.8.0.171-3.b10.el6_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1199 Important CentOS 6 patch Security Update

CentOS Errata and Security Advisory 2018:1199 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1199

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
6d4612d0d5772563ed63b20dfa2d927e7a142b1200303a1e838f82d7e5b2c429 patch-2.6-8.el6_9.i686.rpm

x86_64:
d7ee08c5cd48a92839be6fdf5e99bcc5ef48853fb5cc491a0f41e2419b0eb7b5 patch-2.6-8.el6_9.x86_64.rpm

Source:
49753d0de64e91235f20c9e17acf1c7c009fd0fea9b06734942bfdacdef20f83 patch-2.6-8.el6_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1225 Critical CentOS 6 librelp Security Update

CentOS Errata and Security Advisory 2018:1225 Critical

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1225

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
d3d3215dd4f4b41bedcdb86ec63f3a20d102e8bb7ce6b95388bec575d6ef4ba0 librelp-1.2.7-3.el6_9.1.i686.rpm
6b57c15171003905d8a623a7e3f5147e6cc4c9302ec34d0210742805ac2d6ae1 librelp-devel-1.2.7-3.el6_9.1.i686.rpm

x86_64:
d3d3215dd4f4b41bedcdb86ec63f3a20d102e8bb7ce6b95388bec575d6ef4ba0 librelp-1.2.7-3.el6_9.1.i686.rpm
3234be9e14a573d0c2073c861e16db18ddff5fb0643be3ec9794633a49a5788c librelp-1.2.7-3.el6_9.1.x86_64.rpm
6b57c15171003905d8a623a7e3f5147e6cc4c9302ec34d0210742805ac2d6ae1 librelp-devel-1.2.7-3.el6_9.1.i686.rpm
9cfc8f354a19a8669e6a3a8001c9155d8822f3920dff1abd729eef752764acfe librelp-devel-1.2.7-3.el6_9.1.x86_64.rpm

Source:
a88451ecc7b9ba1500aa95e6e5e3ba3ad5c072a86f34815d10ade9e50cbeee10 librelp-1.2.7-3.el6_9.1.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1098 Important CentOS 6 firefox Security Update

CentOS Errata and Security Advisory 2018:1098 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1098

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
02380bc2107f2a2ec19d84d2bfc49a3ea5c9cf51279a50d7f091878ef3253a24 firefox-52.7.3-1.el6.centos.i686.rpm

x86_64:
02380bc2107f2a2ec19d84d2bfc49a3ea5c9cf51279a50d7f091878ef3253a24 firefox-52.7.3-1.el6.centos.i686.rpm
5933d213ce7a34a079e2f84d1bbb08b91dd28f10daa4ef2a487b426823325474 firefox-52.7.3-1.el6.centos.x86_64.rpm

Source:
a5330e8e79305f8dbb05ecd598579827216f4e98aff93e66270378595cebfc8b firefox-52.7.3-1.el6.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1270 Important CentOS 6 java-1.7.0-openjdk Security Update

CentOS Errata and Security Advisory 2018:1270 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1270

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
141cd9631a85b702e025ba5dcdb1caea40f3d7b120624de374b5ed92984e549c java-1.7.0-openjdk-1.7.0.181-2.6.14.1.el6_9.i686.rpm
5c9e2415bcfac9b37cc9c0a5b859238a11a83d4e259454effff40f30f7283b5f java-1.7.0-openjdk-demo-1.7.0.181-2.6.14.1.el6_9.i686.rpm
db232b8611193c1afe8256b0f7e483d3f4944391848db28a923a6f807ffaf6fa java-1.7.0-openjdk-devel-1.7.0.181-2.6.14.1.el6_9.i686.rpm
ebec3f7167077e0573d802f468af12f31fb3b5ef3ca8e75cac71dc6ed4da5b22 java-1.7.0-openjdk-javadoc-1.7.0.181-2.6.14.1.el6_9.noarch.rpm
9ec1ea9eb404747790c2a143463937d58848281b544975cd33d9da1dc2198bd9 java-1.7.0-openjdk-src-1.7.0.181-2.6.14.1.el6_9.i686.rpm

x86_64:
548200b8396885c986d22485e1c283f95b57d182ef7e45335c544ae3a78e6b9f java-1.7.0-openjdk-1.7.0.181-2.6.14.1.el6_9.x86_64.rpm
930ab2cc8d37d5b4d175f057ce4b15e29755faf774a987c5705994e549ba6837 java-1.7.0-openjdk-demo-1.7.0.181-2.6.14.1.el6_9.x86_64.rpm
6f039f43f1331d949dc9ed6d53e53e64a25947a60dc6ff4d3257d06b96564704 java-1.7.0-openjdk-devel-1.7.0.181-2.6.14.1.el6_9.x86_64.rpm
ebec3f7167077e0573d802f468af12f31fb3b5ef3ca8e75cac71dc6ed4da5b22 java-1.7.0-openjdk-javadoc-1.7.0.181-2.6.14.1.el6_9.noarch.rpm
bd7c457813cfa716b61894b2fc1048e979da6c2c6dedc659741612c507a40d69 java-1.7.0-openjdk-src-1.7.0.181-2.6.14.1.el6_9.x86_64.rpm

Source:
6f07f83fd4627cf6e3e3f8109c46250b3d16bffc8731b9c8365c5f21e5bcbbc6 java-1.7.0-openjdk-1.7.0.181-2.6.14.1.el6_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

Tuesday, May 1, 2018

[announce] NYCBUG Social meeting Wednesday May 2nd

Hello everybody,

Since it appears that we will not be having a technical meeting on the first Wednesday in May, I propose that, as we have done a couple of times in the last year, to have a social meeting:

Suspenders
108 Greenwich St
(north of Rector St; south of WTC)
#1, R, W to Rector St; #4, 5 to Wall ST

Wednesday, May 2, 6:30 pm or so.

Thank you very much.
Jim Keenan

Fedora 28 is officially here!

It's almost Mother's Day, and that means it's time for Fedora 28,
which is officially released today.

Congratulations to everyone who contributed to this amazingly
smooth and polished release. You all are awesome.

Read the official announcement at:

* https://fedoramagazine.org/announcing-fedora-28/

or just go ahead and grab it from:

* https://getfedora.org/


--
Matthew Miller
<mattdm@fedoraproject.org>
Fedora Project Leader
_______________________________________________
announce mailing list -- announce@lists.fedoraproject.org
To unsubscribe send an email to announce-leave@lists.fedoraproject.org

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com