Monday, June 4, 2018

[USN-3664-2] Apport vulnerability

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlsVe8sACgkQZWnYVadE
vpMtLQ//cX4KN1fqUJCf2my/trO7ldXXTWqoBoJZWdUpREOgz/ugggnAeYQJEEQ0
HlaCJkOk6TU4MfwW7vkAsbErdQM6eLXEgN2MLIFZpjTvk9KA/PKqmzZ5wmmlX1Jm
0VeibY8xnHTphSq4hnScYA4GXoO7SkLfGcw4ug73gt+yfLfp0zS1jsJfH6WrPqYB
gkQS+AUzIptovstKkaFpmpLM+/x+wi1dZn+T2pBJ0baOWoqq3WuydjUP5kp9io/b
+bXqaySGKzG74pmk2iV3z72aOw1e49r/rR1QFoAHLREncANqCxRANW/dmV0BLOXP
tOIsg5TRZYiYFt8EJ4LU3qhTbQYMzWmBxPRHwcrhoGR9TxFNgtf06xpyeTIxrKUs
EtuxYxj/WC7hcsrwxl3p3AEP8+ggiA2Zf/CRuMsTevQoSPPaAJPXTvA8XBAluK1m
6W/qmYfgh2KsU5LiEOwMb20kUAhht56d6RmZMIUlw10kdv50z3kFW5DR4Ii+3d8c
o7luUB4kVKHkbei1f1OWaJ2r+nIECPL0ZREFprwm3K5FWqc80YNbaCDHlBpy9+J/
fpkvxmzesC6m5vnSyjVqSU7RBZlZHPpG7FYy+iKE+7ziTB9s56qqjQZxxwLhp4ot
6/t7JOosSXheXPFth9Tk5xHiDPfeYbuYIAInpZu6mm8fyAfGHCs=
=I8Rm
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3664-2
June 04, 2018

apport vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 LTS

Summary:

Apport could be tricked into causing a denial of service or escalate
privileges.

Software Description:
- apport: automatically generate crash reports for debugging

Details:

USN-3664-1 fixed a vulnerability in Apport. Sander Bos reported that Ubuntu
14.04 LTS was also vulnerable to this issue, but was incorrectly omitted
from the previous updates. This update provides the corresponding update
for Ubuntu 14.04 LTS.

Original advisory details:

Sander Bos discovered that Apport incorrectly handled core dumps when
certain files are missing from /proc. A local attacker could possibly use
this issue to cause a denial of service, gain root privileges, or escape
from containers.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
apport 2.14.1-0ubuntu3.29

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3664-2
https://usn.ubuntu.com/usn/usn-3664-1
CVE-2018-6552

Package Information:
https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.29

[USN-3668-1] Exempi vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlsVQa0ACgkQZWnYVadE
vpMFrhAAjDXMZGADpBwIxPYYYvSz0GzoU9mGWvRBBHuFZ/tCbWd0AKaW36gFLCe5
Vcdf7/rqV/JzWW3rkYAtyiDuqwR2/sIY/ByyuhvlicG1dAzlcLTpiFp6jz4x7cHD
l4wUMEmt7AtUfPttcEi9j8h9OL13I3jeaHSTNtf9cTFuMve9wphAwrHrt/z/ghjG
lPlKDiqNyJlVPTNYSBvGF/zhxs/simRtrobNP9cpacBMgkER68mD09XM5ZHvlD6g
FqcclpvkCclyLVxuMj5IM1czMvBQLl4emx78kFJJUl5AoZOHmdlqHaCs9AJVCvl8
4ByAL5UDW7/x8WLGCNH4OmSKCAU0+X7XrEoACvXHomKeu2LsA8iOf2dKi6boRUN8
vJ6CuCxaH4G9iKU9aLbC0y7Y2OAdxQN449D9xzJItEy2++2V4iwvZT7+IfuGgk61
vm+oSI5eTv66yHMzsIG8aZtuCSi/Vue58mLj77K1Wij7Cr8K3UaJ5K3kw4I/VL/T
v/T+aOBmhPOXBS6BrlIxIt4GvVe2fXXiilw9/jbk7iEoFnwt8FhYorEtcXnAQu2F
RyYU0ADkP2jLDXTxpTxVo4+ziYVa+QXK/Sw4/NqLfSH9V9ZLIUwpLTT8q9658cQm
GxRCuZjAhnEOOQJzWZWJX6vN6M+A8arRfakZZZwx6IbzN71WcdI=
=aENP
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3668-1
June 04, 2018

exempi vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 17.10
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Exempi could be made to crash or run programs if it opened a specially
crafted file.

Software Description:
- exempi: library to parse XMP metadata

Details:

It was discovered that Exempi incorrectly handled certain media files. If a
user or automated system were tricked into opening a specially crafted
file, a remote attacker could cause Exempi to hang or crash, resulting in a
denial of service, or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.10:
exempi 2.4.3-1ubuntu1.1
libexempi3 2.4.3-1ubuntu1.1

Ubuntu 16.04 LTS:
exempi 2.2.2-2ubuntu0.1
libexempi3 2.2.2-2ubuntu0.1

Ubuntu 14.04 LTS:
exempi 2.2.1-1ubuntu1.1
libexempi3 2.2.1-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3668-1
CVE-2017-18233, CVE-2017-18234, CVE-2017-18236, CVE-2017-18238,
CVE-2018-7728, CVE-2018-7729, CVE-2018-7730, CVE-2018-7731

Package Information:
https://launchpad.net/ubuntu/+source/exempi/2.4.3-1ubuntu1.1
https://launchpad.net/ubuntu/+source/exempi/2.2.2-2ubuntu0.1
https://launchpad.net/ubuntu/+source/exempi/2.2.1-1ubuntu1.1

F29 System Wide Change: NSS load p11-kit modules by default

= Proposed System Wide Change: NSS load p11-kit modules by default =
https://fedoraproject.org/wiki/Changes/NSSLoadP11KitModules


Owner(s):
* Daiki Ueno <dueno at redhat dot com>


When NSS database is created, PKCS#11 modules configured in the
system's p11-kit will be automatically registered and visible to NSS
applications.



== Detailed description ==
Fedora provides a mechanism to configure PKCS#11 modules system wide,
allowing the crypto libraries (GnuTLS and OpenSSL) to use PKCS#11
modules in a consistent manner. Until now NSS applications haven't
benefit from it as NSS uses a different configuration mechanism which
requires users to register PKCS#11 modules in NSS databases. This
change makes the manual procedure unnecessary, by registering the
p11-kit-proxy module (the aggregator of the system PKCS#11 modules) in
NSS databases with the default configuration.
See also:
* https://bugzilla.redhat.com/show_bug.cgi?id=1173577


== Scope ==
* Proposal owners:
** Enable p11-kit-proxy in the newly created NSS database, through the
crypto-policies package.
** Modify the opensc package not to register itself to the NSS
database upon installation.

* Other developers:
** Make sure that this change doesn't cause any regression with the
existing applications.

* Release engineering:
[https://pagure.io/releng/issue/7548 #7548]
** List of deliverables: N/A

* Policies and guidelines:
PackageMaintainers/PKCS11 needs changes basically to eliminate NSS
specific stuff

* Trademark approval:
N/A (not needed for this Change)
--
Jan Kuřík
JBoss EAP Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org/message/5J5SRVBJR5PDE6G6ZKOFWQG5AJ6WCFR3/

F29 System Wide Change: i686 Is For x86-64

= Proposed System Wide Change: i686 Is For x86-64 =
https://fedoraproject.org/wiki/Changes/i686_Is_For_x86-64


Owner(s):
* Florian Weimer <fweimer at redhat dot com>


Fedora builds its i686 packages for use on x86-64 systems as multi-lib RPMs.



== Detailed description ==
Currently, the i686 RPM packages are built in such a way that they are
compatible with very old i686 systems, such as the Pentium III. The
only addition over the i686/Pentium Pro baseline is a requirement to
support long NOPs, for Intel CET. However, the majority of
installations of i686 packages is for use on x86_64 systems, as
multi-lib RPMs. Furthermore, there are reports that the i686 kernel
does not run stable on old hardware which is not x86-64-capable (
https://lists.fedoraproject.org/archives/list/x86@lists.fedoraproject.org/thread/ZHV6I4IEO7GRYAZ4TUMO5VH2ZHLCNJZQ/
).
This proposal suggests to accept this reality and build the i686
packages in such a way that they require the ISA level of (early)
x86-64 CPUs.


== Scope ==
* Proposal owners:
Adjust the redhat-rpm-config, gcc, and glibc packages to switch to the
new compiler flags. Except for mstackrealign, there is substantial
experience with this configuration downstream.

* Other developers:
Other developers can enable SSE2 optimization in their packages if
they want, where this has been a compile-time option only.

* Release engineering:
https://pagure.io/releng/issues/7543 #7543

** List of deliverables: TBD

* Policies and guidelines:
i686 is no longer a primary architecture. The Packaging Guidelines do
not currently require support for non-SSE2 x86 systems, so no change
is required there.

* Trademark approval:
N/A (not needed for this Change)
--
Jan Kuřík
JBoss EAP Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org/message/CC22ZTFDB5L3BFSQG7M3TUZUVYKFUSKP/

Friday, June 1, 2018

Debian 7 Long Term Support reaching end-of-life

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCAAdFiEEZin0RNRxg3W3fj8cTDhhvcxwa3QFAlsRhXwACgkQTDhhvcxw
a3TwDgwAy5cRFQRSXKkOmwxUqlDCId9L+rrigPheGFZ/hxKNrNScN5efMQrOVdro
bH1sAAvZWpTM+D4mDBzGPGcwdpZfw0iIKZVEcW74pzeB1nRs//x84fYkbiwJjDpI
E8pni/wmL2VEbJbf88d2pppP5owkN/IUvsJAbCxaXA5A/HWJanmN5HNPkTMO4Qsi
Sjq/hpbD4PTQMOtjcu3qqPS0p9fObnLHPsuVprx9iUlU1ySY87mtTYk4Gt3KUTGx
k7j4R8Kw6v9h2uuro9dad1Zxc0q7MgPXroIVQt646kjLvpyl107tMk70V+2LovlU
BSZLyGbwb0cqgtdWLpU2zp+PQW9mspJYow2KiYMwTGFVuzg3mUhqNVlVz2zprqZI
J4M7mu6DPXajHD3AhU4Fpzw/DxcjfqbCEE0riZRgkpaoew0tWlbWl5LuFbJo3mRn
m6MUwjb7OlP8ecNPKu8wf+kh2hbqW7ojbo66ljL+GZ1FArWjezRHWfEAbDj/08op
gx2V0twA
=f10t
-----END PGP SIGNATURE-----
------------------------------------------------------------------------
The Debian Project https://www.debian.org/
Debian 7 Long Term Support reaching end-of-life press@debian.org
June 1st, 2018 https://www.debian.org/News/2018/20180601
------------------------------------------------------------------------


The Debian Long Term Support (LTS) Team hereby announces that Debian 7
"Wheezy" support has reached its end-of-life on May 31, 2018, five years
after its initial release on May 4, 2013.

Debian will not provide further security updates for Debian 7. A subset
of Wheezy packages will be supported by external parties. Detailed
information can be found at Extended LTS [1].

1: https://wiki.debian.org/LTS/Extended

The LTS Team will prepare the transition to Debian 8 "Jessie", which is
the current oldstable release. The LTS team will take over support from
the Security Team on June 17, 2018.

Debian 8 will also receive Long Term Support for five years after its
initial release with support ending on June 30, 2020. The supported
architectures include amd64, i386, armel and armhf.

For further information about using Jessie LTS and upgrading from Wheezy
LTS, please refer to LTS/Using [2].

2: https://wiki.debian.org/LTS/Using

Debian and its LTS Team would like to thank all contributing users,
developers and sponsors who are making it possible to extend the life of
previous stable releases, and who have made this LTS a success.

If you rely on Debian LTS, please consider joining the team [3],
providing patches, testing or funding the efforts [4].

3: https://wiki.debian.org/LTS/Development
4: https://wiki.debian.org/LTS/Funding


About Debian
------------

The Debian Project was founded in 1993 by Ian Murdock to be a truly free
community project. Since then the project has grown to be one of the
largest and most influential open source projects. Thousands of
volunteers from all over the world work together to create and maintain
Debian software. Available in 70 languages, and supporting a huge range
of computer types, Debian calls itself the "universal operating system".


More Information
----------------

More information about Debian Long Term Support can be found at
https://wiki.debian.org/LTS/.



Contact Information
-------------------

For further information, please visit the Debian web pages at
https://www.debian.org/ or send mail to <press@debian.org>.
--
Laura Arjona Reina
https://wiki.debian.org/LauraArjona

[CentOS-announce] CESA-2018:1780 Important CentOS 7 xmlrpc Security Update

CentOS Errata and Security Advisory 2018:1780 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
2bad0902c6d8582ef5bb5758c6860951f34cb646b69eda066162ed5cb83aa500 xmlrpc-client-3.1.3-9.el7_5.noarch.rpm
a47c496fc4e85d23172c9fb69e236caecfd9aa8e813ff15eeab908309b203a4f xmlrpc-common-3.1.3-9.el7_5.noarch.rpm
4b0992a8b0e3c18327635bfe9a1a6f4e946eeb8c9db62aacaf16e728ae061390 xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm
ac336edfd9e783d9a98e89d517a049e98e6bacfbc4a6564d44c1778aa6b27b69 xmlrpc-server-3.1.3-9.el7_5.noarch.rpm

Source:
6e330c0f41b9a2eb2b51a7de6242c122be29713ee6e9356fe739dbc52225ea84 xmlrpc-3.1.3-9.el7_5.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEEA-2018:1771 CentOS 7 linux-firmware Enhancement Update

CentOS Errata and Enhancement Advisory 2018:1771

Upstream details at : https://access.redhat.com/errata/RHEA-2018:1771

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
c81d039ccae2e6d9a5f8c1f63e99c0a611d489b49da73093341625ce7203fffd iwl1000-firmware-39.31.5.1-62.1.el7_5.noarch.rpm
b16d77402aaaeaab2cd27bb3c702209459aa5920bbe530687ce8867521cca73e iwl100-firmware-39.31.5.1-62.1.el7_5.noarch.rpm
f4c316d5b6277e5f80544ed82ece1c3c4194b3bf7074bcb046215cd2a3de80c9 iwl105-firmware-18.168.6.1-62.1.el7_5.noarch.rpm
85a977ba7de5d5a55865790deae6c0975e2a61ae73e5a976bdc5a6f28a3612dd iwl135-firmware-18.168.6.1-62.1.el7_5.noarch.rpm
85cd4cc32e5b47cb6d04a98b03f7cf53d00a41ed0054ea7eb3147f3b7ffac8da iwl2000-firmware-18.168.6.1-62.1.el7_5.noarch.rpm
d347fb597ac149b5910a60b0e0f1d5a81766b639b783d8cb4e64233b63c2805c iwl2030-firmware-18.168.6.1-62.1.el7_5.noarch.rpm
270d1efa9566b37a6516957d18bcb68dbe50b261751e8f8772a4c46e62c2c152 iwl3160-firmware-22.0.7.0-62.1.el7_5.noarch.rpm
c62436867e8b4fa0afa2854582c1e2ede38a25aa5c8aee63c295fb552d578d5c iwl3945-firmware-15.32.2.9-62.1.el7_5.noarch.rpm
8ae9e3a5bba2fe05c26f78cb7895fc9867d004e4147143073415bd6273bd21c3 iwl4965-firmware-228.61.2.24-62.1.el7_5.noarch.rpm
c0dd3fd97833e11345b55a973f80e575c1f2f7ac34fe5b5b64925b9d2d52c652 iwl5000-firmware-8.83.5.1_1-62.1.el7_5.noarch.rpm
f2f59820717d84bb272dd15ac691ae57e68a6795a971780e909860825ff5b026 iwl5150-firmware-8.24.2.2-62.1.el7_5.noarch.rpm
37333c605fd80feb72d7c64febce6aa3b60b04ca6834e67a9a4a67dd1b3e0bb0 iwl6000-firmware-9.221.4.1-62.1.el7_5.noarch.rpm
7520a3f8c51170c529bd78d0cbf39c396c1c547c206d437e9c219d34d857025d iwl6000g2a-firmware-17.168.5.3-62.1.el7_5.noarch.rpm
684282a662b33d35df0b41b2329058cad0ddc5ccbd23a904cdc47208b799714e iwl6000g2b-firmware-17.168.5.2-62.1.el7_5.noarch.rpm
9106613c00bf499321524b3095bc39106ada16f2c5c8aea7a7732ff348ae1898 iwl6050-firmware-41.28.5.1-62.1.el7_5.noarch.rpm
0c71a1311ca386916843bf4f04ba9d88bec808c810ed865a48da1b916e4d2f00 iwl7260-firmware-22.0.7.0-62.1.el7_5.noarch.rpm
9b64e88b312f001e47381e9204304611ecc08e0d1d0b83c085f1d0781a6e2af6 iwl7265-firmware-22.0.7.0-62.1.el7_5.noarch.rpm
f5a93f4034dc89919815bca0c650b77ff4495a9782e7544e30064ab888caae97 linux-firmware-20180220-62.1.git6d51311.el7_5.noarch.rpm

Source:
2c23b4eeb2b19505867bd7786a8cb7da21d7ecd11d3a19f9de4d3e693196fcae linux-firmware-20180220-62.1.git6d51311.el7_5.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1779 Important CentOS 6 xmlrpc3 Security Update

CentOS Errata and Security Advisory 2018:1779 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
8a63dd898f19ba28ff553e34cf7e3d22690e5ad769a58ba314c29382c3dddba8 xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm
6bea1a7d98cccdf32c2f75de45b6a7346a6ba76381e4a13aa885a9081412fc94 xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm
12fa409cb17f876d5e7687d362554a64446f22731ca89d179b8a7a6b76964c2c xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm
d84de1c265757099ef0fcec691095f17af2c781275baf4e4cc6cc295e3e4d9cb xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm
1643cc58264f9a50ef79a11961d77e6c15733272db2fdca5326339f68b20a06d xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm
8a109d1ed6d4a054b8efbed1d25b6740d5316ab0d8407fe8fec715327f4bf26d xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm
d32170144a993875542024297d967cbdcbfc5348ba9e698eb86ec57ef0178d66 xmlrpc3-server-devel-3.0-4.17.el6_9.noarch.rpm

x86_64:
8a63dd898f19ba28ff553e34cf7e3d22690e5ad769a58ba314c29382c3dddba8 xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm
6bea1a7d98cccdf32c2f75de45b6a7346a6ba76381e4a13aa885a9081412fc94 xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm
12fa409cb17f876d5e7687d362554a64446f22731ca89d179b8a7a6b76964c2c xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm
d84de1c265757099ef0fcec691095f17af2c781275baf4e4cc6cc295e3e4d9cb xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm
1643cc58264f9a50ef79a11961d77e6c15733272db2fdca5326339f68b20a06d xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm
8a109d1ed6d4a054b8efbed1d25b6740d5316ab0d8407fe8fec715327f4bf26d xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm
d32170144a993875542024297d967cbdcbfc5348ba9e698eb86ec57ef0178d66 xmlrpc3-server-devel-3.0-4.17.el6_9.noarch.rpm

Source:
3ffd2f90bf7ddd055de393d3344152cc0fbde63a3298cbb12a7de3e7067f895c xmlrpc3-3.0-4.17.el6_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2018:1777 Important CentOS 6 procps Security Update

CentOS Errata and Security Advisory 2018:1777 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
5088ad1f19a26726e8847982bdca51ff071b8bf9d48202f26a713052c2527785 procps-3.2.8-45.el6_9.3.i686.rpm
dd01689106c323bea94b4f56f3416482629dd2ce6137921f13258e102ef960f0 procps-devel-3.2.8-45.el6_9.3.i686.rpm

x86_64:
5088ad1f19a26726e8847982bdca51ff071b8bf9d48202f26a713052c2527785 procps-3.2.8-45.el6_9.3.i686.rpm
ba2b604c6da10bf7d2df547760c5db6f91bef6644716c3cd708597c0a80d2179 procps-3.2.8-45.el6_9.3.x86_64.rpm
dd01689106c323bea94b4f56f3416482629dd2ce6137921f13258e102ef960f0 procps-devel-3.2.8-45.el6_9.3.i686.rpm
9310f7af0fd82d64736c7b837a5ed4776418c2c45bd74e1d8df540f3916b2dfc procps-devel-3.2.8-45.el6_9.3.x86_64.rpm

Source:
828effa30b5895235b5db5f2fce5c8f56525e3dbc31d49e90a12741ffc4480de procps-3.2.8-45.el6_9.3.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEEA-2018:1774 CentOS 6 microcode_ctl Enhancement Update

CentOS Errata and Enhancement Advisory 2018:1774

Upstream details at : https://access.redhat.com/errata/RHEA-2018:1774

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
e931f163e9536a55e4ce801be0a99e186664f8133888edaf7ade5846824f4422 microcode_ctl-1.17-25.7.el6_9.i686.rpm

x86_64:
c458d93f0a6aab4ab68c11304c8c3d5dd9972bf97d497539e2459a0cca9aed0f microcode_ctl-1.17-25.7.el6_9.x86_64.rpm

Source:
55c74ae1211a4790d87dcd9b4b363bd5e1c09e5cb81b4d17bfef5c9dcf7faa20 microcode_ctl-1.17-25.7.el6_9.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com

F29 System Wide Change: Strong crypto settings: phase 2

= Proposed System Wide Change: Strong crypto settings: phase 2 =
https://fedoraproject.org/wiki/Changes/StrongCryptoSettings2


Owner(s):
* Tomáš Mráz <tmraz at redhat dot com>


We update the current system-wide crypto policy to further disable
legacy cryptographic protocols (TLS 1.0 and TLS 1.1) and weak
Diffie-Hellman key exchange sizes (1024 bit)



== Detailed description ==
Fedora includes several cryptographic components who's security
doesn't remain constant over time. Algorithms such as (cryptographic)
hashing and encryption typically have a lifetime after which they are
considered either too risky to use or plain insecure. That would mean
we need to phase out such algorithms from the default settings, or
completely disable if they could cause irreparable issue.
While in the past we did not disable algorithms in a consistent way
(different applications utilized different policies), today we have a
system-wide policy followed by a large part of Fedora components. That
allows us to move consistently and deprecate algorithms system-wide.
For rationale see RFC 7457 for a more complete list of attacks taking
advantage of legacy crypto algorithms.

The changes for default policy are:
* Keep only TLS 1.2 (and TLS 1.3 when available) as enabled protocols
and move the TLS 1.x, x<=1 to legacy level.
* Require finite field parameters (RSA, Diffie-Hellman) of 2048 and
more in the default settings
That is a policy of:

LEGACY
MACs: All HMAC with SHA1 or better + all modern MACs (poly1305 etc)
Curves: all prime >= 255 bits (including bernstein curves)
Signature algorithms: SHA-1 hash or better (not RIPEMD)
Ciphers: all available > 112-bit key, >= 128-bit block (no rc4, but with 3DES)
key exchange: ECDHE, RSA, DHE
DH params size: >=1023
RSA params size: >=1023
TLS protocols: TLS >= 1.0

DEFAULT
MACs: All HMAC with SHA1 or better + all modern MACs (poly1305 etc)
Curves: all prime >= 255 bits (including bernstein curves)
Signature algorithms: with SHA-1 hash or better (not DSA)
Ciphers: >= 128-bit key, >= 128-bit block (aes, camellia, chacha20,
including aes-cbc)
key exchange: ECDHE, RSA, DHE
DH params size: >= 2048
RSA params size: >= 2048
TLS protocols: TLS >= 1.2

FUTURE
MACs: All HMAC with SHA256 or better + all modern MACs (poly1305 etc)
Curves: all prime >= 384 bits (including bernstein curves)
Signature algorithms: SHA-384 hash or better (not DSA)
Ciphers: >= 256-bit key, >= 128-bit block, only Authenticated
Encryption (AE) ciphers
key exchange: ECDHE, DHE
DH params size: >= 3072
RSA params size: >= 3072
TLS protocols: TLS >= 1.2



== Scope ==
* Proposal owners:
The policies include in crypto-policies package need to be updated.

* Other developers:
* Crypto policies are updated to the settings above
* https://bugzilla.redhat.com/show_bug.cgi?id=1487607 OpenSSL is
updated to allow setting policies for TLS versions

* Release engineering:
Copied from F28 change - no impact
https://pagure.io/releng/issue/7235 #7235

** List of deliverables:
* Crypto policies are updated to the settings above
* OpenSSL, NSS, GnuTLS and all applications covered under the Fedora
Crypto Policies follow the new crypto settings.

* Policies and guidelines:
No changes to packaging or other guidelines is needed.

* Trademark approval:
N/A (not needed for this Change)
--
Jan Kuřík
JBoss EAP Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org/message/B4YAC3KZOJUT4V6B3EVYZIDKHELU5NRA/