Friday, September 7, 2018

Heads Up: python2 is marked as deprecated

In line with the "Mass Python 2 Package Removal" Fedora 30 Change [0],
we've just marked python2 and all it's subpackages as deprecated in
rawhide [1].

No new packages can depend on python2 except renames and FESCo/FPC
exceptions. See more info in the Guidelines for Deprecating Fedora
Packages [2].

[0] https://fedoraproject.org/wiki/Changes/Mass_Python_2_Package_Removal
[1]
https://src.fedoraproject.org/rpms/python2/c/0052c9fa9d76e1706d96a17460ad26f331a4e0fe?branch=master
[2] https://fedoraproject.org/wiki/Packaging:Deprecating_Packages
--
Miro HronĨok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Thursday, September 6, 2018

[USN-3761-1] Firefox vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEERN//5MGgCOgyKeIFYR+97NWUbg8FAluRnu8ACgkQYR+97NWU
bg/Diwf/exz1/UuQMJHWMjr6JVLsPCZF6lraDm/vSUi0jVWoZ0pSTi11TYh3aNSp
vcwbsymUqZO7NICbYb1JPaiCopX1bCWuXVmAS6akLFeB9fwwS+t064Zt/yUcoJTz
drya6ZuiLoHFJYyN39ZxNe4mRNCwjjbjT49V9NS5hGqSaEdjREGBDPBYLMD8Pn33
Q83ZvwCnyG1X19s2MjYKChxE7SxWDQMHEA5Ns5d89rXSc6yh4CiowkUBlmHGZpvY
/2DdjhZ+cRx3mujIcISh4QPjNpOI2NpV6xygtMev2zSw3KwJDD2ChDCe78lvm9sO
OmLuu1uKhqw0Ai9pfua29IzqlAg4YA==
=7Rw+
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3761-1
September 06, 2018

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, or execute
arbitrary code. (CVE-2018-12375, CVE-2018-12376, CVE-2018-12377,
CVE-2018-12378)

It was discovered that if a user saved passwords before Firefox 58 and
then later set a master password, an unencrypted copy of these passwords
would still be accessible. A local user could exploit this to obtain
sensitive information. (CVE-2018-12383)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
firefox 62.0+build2-0ubuntu0.18.04.3

Ubuntu 16.04 LTS:
firefox 62.0+build2-0ubuntu0.16.04.3

Ubuntu 14.04 LTS:
firefox 62.0+build2-0ubuntu0.14.04.3

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3761-1
CVE-2018-12375, CVE-2018-12376, CVE-2018-12377, CVE-2018-12378,
CVE-2018-12383

Package Information:
https://launchpad.net/ubuntu/+source/firefox/62.0+build2-0ubuntu0.18.04.3
https://launchpad.net/ubuntu/+source/firefox/62.0+build2-0ubuntu0.16.04.3
https://launchpad.net/ubuntu/+source/firefox/62.0+build2-0ubuntu0.14.04.3

[USN-3760-1] transfig vulnerability

==========================================================================
Ubuntu Security Notice USN-3760-1
September 06, 2018

transfig vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

transfig could be made to execute arbitrary code if it received a
specially crafted FIG file.

Software Description:
- transfig: Utilities for converting XFig figure files

Details:

It was discovered that transfig incorrectly handled certain FIG files.
An attacker could possibly use this to execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  transfig                        1:3.2.5.e-5ubuntu0.1

Ubuntu 14.04 LTS:
  transfig                        1:3.2.5.e-1ubuntu1.1

In general, a standard system update will make all the necessary
changes.

References:
  https://usn.ubuntu.com/usn/usn-3760-1
  CVE-2018-16140

Package Information:
  https://launchpad.net/ubuntu/+source/transfig/1:3.2.5.e-5ubuntu0.1
  https://launchpad.net/ubuntu/+source/transfig/1:3.2.5.e-1ubuntu1.1

Fedora 29 Beta Release Readiness meeting

Dear all,

Join us on irc.freenode.net in #fedora-meeting-1 for the Fedora 29
Beta Release Readiness meeting. This meeting will be held on Thursday,
2018-09-13 at 19:00 UTC.

We will meet to make sure we are coordinated and ready for the Beta
release of Fedora 29. Please note that this meeting will be held even
if the release is delayed at the Go/No-Go meeting on the same day two
hours earlier.

You may receive this message several times in order to open this
meeting to the teams and to raise awareness, so hopefully more team
representatives will come to this meeting. This meeting works best
when we have representatives from all of the teams.

For more information, see
https://fedoraproject.org/wiki/Release_Readiness_Meetings.

I will ask for readiness from each of the teams listed below. If there
are additional teams that should be explicitly included, let me know.
All teams and contributors are welcome to provide input at the
meeting.

* Ambassadors
* Cloud WG
* Design
* Desktop
* Documentation
* Fedora Project Leader
* FESCo
* Infrastructure
* Marketing
* QA
* Release Engineering
* Server WG
* Spins
* Translations
* Websites

View the meeting on Fedocal:
https://apps.fedoraproject.org/calendar/Fedora%20release/2018/9/10/#m9337


--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Fedora 29 Beta Go/No-Go meeting

Dear all,

The Go/No-Go meeting for the Fedora 29 Beta release will be held on
Thursday, 2018-09-13 at 17:00 UTC in #fedora-meeting-1. For more
information, see: https://fedoraproject.org/wiki/Go_No_Go_Meeting

View the meeting on Fedocal at
https://apps.fedoraproject.org/calendar/Fedora%20release/2018/9/10/#m9338

--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Wednesday, September 5, 2018

[USN-3759-2] libtirpc vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3759-2
September 05, 2018

libtirpc vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in libtirpc.

Software Description:
- libtirpc: transport-independent RPC library - development files

Details:

USN-3759-1 fixed a vulnerability in libtirpc. This update provides
the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Aldy Hernandez discovered that libtirpc incorrectly handled certain
 inputs. An attacker could possibly use this issue to cause a denial of
 service. (CVE-2016-4429)

 It was discovered that libtirpc incorrectly handled certain inputs.
 An attacker could possibly use this issue to cause a denial of
 service. (CVE-2018-14622)

 It was discovered that libtirpc incorrectly handled certain strings.
 An attacker could possibly use this issue to cause a denial of
 service. (CVE-2017-8779)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libtirpc-dev                    0.2.2-5ubuntu0.1
  libtirpc1                       0.2.2-5ubuntu0.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3759-2
  https://usn.ubuntu.com/usn/usn-3759-1
  CVE-2016-4429, CVE-2017-8779, CVE-2018-14622

Fedora 30 System-Wide Change Proposal: FreeIPA Python 2 Removal

https://fedoraproject.org/wiki/Changes/FreeIPA_Python_2_Removal

== Summary ==
FreeIPA 4.8 will require Python 3.6+ and therefore no longer provide
Python 2 packages on Fedora 30.

== Owner ==
* Name: Christian Heimes (cheimes)
* Email: cheimes@redhat.com

== Detailed Description ==

On Fedora 27 to 29, FreeIPA client and server packages use Python 3
default. Additionally FreeIPA provides Python 2 packages. The Python 2
packages are not used by FreeIPA, but are merely provided for
backwards compatibility, e.g. Python 2 applications that utilize
python2-ipaclient to communicate with a FreeIPA server.

The FreeIPA upstream project is going to drop support for Python 2.7
in the upcoming FreeIPA release 4.8.0. Python 2 support is not only
causing development and testing overhead. It's also blocking
improvements like using new python-based 389-DS installer, use of new
Python features, and more. The removal of Python 2 support was
[https://lists.fedoraproject.org/archives/list/freeipa-devel@lists.fedorahosted.org/thread/KU6R2DV47DR43PBCHHPT4OYVVQJEXTVG/
announced] on the FreeIPA development on 2018-09-03.

=== Removed packages ===

* python2-ipalib
* python2-ipaclient
* python2-ipaserver
* python2-ipatests
* python2-ipa-desktop-profile-client (dependency)

== Benefit to Fedora ==

The removal of Python 2 support is in alignment with Mass Python 2
Package Removal proposal. FreeIPA depends has a large list of
dependencies. The change makes it possible to drop more Python 2
packages.

== Scope ==
* Proposal owners:
** Release FreeIPA 4.8.0 until mid January 2019
** Build and deliver FreeIPA 4.8.0 packages before 2019-01-29
** Add removed packages to ''fedora-obsolete-packages''.

* Other developers:
** Port Fleet Commander's fc-admin to Python 3 and no longer depend on
FreeIPA's Python 2 packages.
** Drop Fleet Command's Python 2 desktop profile package
** Port Ipsilion Project to Python 3 and no longer depend on FreeIPA's
Python 2 packages.

FreeIPA team is willing to help to aforementioned projects with their
port to use Python 3 FreeIPA libraries.

* Release engineering: [https://pagure.io/releng/issue/7760 #7760]
There is no releng work needed for this change.

* Policies and guidelines: N/A (not needed for this Change)

* Trademark approval: N/A (not needed for this Change)

== Upgrade/compatibility impact ==

The removal of Python 2 support will not affect FreeIPA server or
client systems. However 3rd party applications and scripts may be
affected. These applications and scripts must be ported to Python 3.

On upgrade from Fedora 29, previously installed ''python2-ipa*''
packages cannot be retained. All ''python[23]-ipa*'' packages have a
hard version dependency on common files with a requires line like
''Requires: freeipa-common = %{version}-%{release}''. This requires
cannot be satisfied for existing ''python2-ipa*''. Therefore
''python2-ipa*'' packages have to added to
''fedora-obsolete-packages'' package. This will ensure that the Python
2 packages are uninstalled on system upgrade.

== How To Test ==

* A fresh Fedora 30 installation will no longer have python2-ipa*
packages available.
* On upgrade from Fedora 29, all python2-ipa* packages are uninstalled.

== User Experience ==

N/A

== Dependencies ==

* fedora-obsolete-packages
* ipsilon-tools-ipa
* python2-ipa-desktop-profile-client
* fleet-commander-admin

== Contingency Plan ==

* Contingency mechanism: Keep shipping FreeIPA 4.7
* Contingency deadline: 2019-01-31
* Blocks release? No
* Blocks product? N/A

== Documentation ==
This page is the main documentation.

Also see https://pythonclock.org/ and
https://fedoraproject.org/wiki/Changes/Mass_Python_2_Package_Removal .

== Release Notes ==

FreeIPA no longer supports Python 2. All ''python2-ipa*'' packages and
''python-ipa*'' aliases are discontinued.

--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

[USN-3759-1] libtirpc vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3759-1
September 05, 2018

libtirpc vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in libtirpc.

Software Description:
- libtirpc: transport-independent RPC library - development files

Details:

Aldy Hernandez discovered that libtirpc incorrectly handled certain
inputs. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04
LTS. (CVE-2016-4429)

It was discovered that libtirpc incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-14622)

It was discovered that libtirpc incorrectly handled certain strings.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2017-8779)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  libtirpc-dev                    0.2.5-1.2ubuntu0.1
  libtirpc1                       0.2.5-1.2ubuntu0.1

Ubuntu 16.04 LTS:
  libtirpc-dev                    0.2.5-1ubuntu0.1
  libtirpc1                       0.2.5-1ubuntu0.1

Ubuntu 14.04 LTS:
  libtirpc-dev                    0.2.2-5ubuntu2.1
  libtirpc1                       0.2.2-5ubuntu2.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3759-1
  CVE-2016-4429, CVE-2017-8779, CVE-2018-14622

Package Information:
  https://launchpad.net/ubuntu/+source/libtirpc/0.2.5-1.2ubuntu0.1
  https://launchpad.net/ubuntu/+source/libtirpc/0.2.5-1ubuntu0.1
  https://launchpad.net/ubuntu/+source/libtirpc/0.2.2-5ubuntu2.1

Tuesday, September 4, 2018

[FreeBSD-Announce] FreeBSD 11.1 end-of-life

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Dear FreeBSD community,

As of September 30, 2018, FreeBSD 11.1 will reach end-of-life and will no
longer be supported by the FreeBSD Security Team. Users of FreeBSD 11.1 are
strongly encouraged to upgrade to a newer release as soon as possible.

The currently supported branches and releases and their expected
end-of-life dates are:

+--------------------------------------------------------------------------+
| Branch | Release | Type | Release Date | Estimated EoL |
+-----------+------------+--------+----------------+-----------------------+
|stable/10 |n/a |n/a |n/a |October 31, 2018 |
+-----------+------------+--------+----------------+-----------------------+
|releng/10.4|10.4-RELEASE|Normal |October 3, 2017 |October 31, 2018 |
+--------------------------------------------------------------------------+
|stable/11 |n/a |n/a |n/a |September 30, 2021 |
+-----------+------------+--------+----------------+-----------------------+
|releng/11.1|11.1-RELEASE|n/a |July 26, 2017 |September 30, 2018 |
+-----------+------------+--------+----------------+-----------------------+
|releng/11.2|11.2-RELEASE|n/a |June 28, 2018 |11.3-RELEASE + 3 months|
+--------------------------------------------------+-----------------------+

As a reminder, FreeBSD changed the support model as of 11.0-RELEASE.
For additional information, please see
https://lists.freebsd.org/pipermail/freebsd-announce/2015-February/001624.html

Please refer to https://security.freebsd.org/ for an up-to-date list of
supported releases and the latest security advisories.

- --
The FreeBSD Security Team
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEE/A6HiuWv54gCjWNV05eS9J6n5cIFAluPFJ5fFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEZD
MEU4NzhBRTVBRkU3ODgwMjhENjM1NUQzOTc5MkY0OUVBN0U1QzIACgkQ05eS9J6n
5cJhKhAAp/Q6p2CxzWTNmpZQ7no8eYpxIO0UQVLmxooqp2h8wYVRz6e1ZJAocQIE
LGvR0KI+64rZdA9bIXwdixHA9HwvO04MKkyg3iaE+en37Vy6SOdM0qRTwo7PeLIg
bwXz5KbePDvpEjHJxBBeFm4U/2D5VKm2OEux4yaikr/v3TD2jLwo96STyfV6iFmN
ESlWPS2fnraYJXQOaXdSEAiSrdD2X51cfBGo8d7fJmltQNrrk6uShwD6xDrUzc7K
jN9WLG6n//g42rzLlRdgCrLciX2QT8sqi1D/2Bz0Br3zqd7GynGUKBRywoxaq9iU
KTifOxNgw4KgPn3M55KQItxmIvVKyoVu3XHIlx8g3CWPMu7DpZYEXVJDeFfd0JLD
qiLcUmgymX/Exn/amf7neg9rGB06MPEXAJOSzbkryCMDLo6RKt9+KGma/TdLN9er
27spNGfJVk23DXFXenEBfBY82mRb+PaBQd/j5N+fLg1fQ8wG8g08DM5FzevSB9dq
PGUSlc9Caxs+sKsQAC2zxJTcdG0EWl5ABlDHLMg8/Nksz9MmbNOc8o+RvzsYmqU1
YxeyjqosMpL2YHQLQS/D5hNsN0wC6ueDaW/sKmvvYbsn/ny7Q3Q9uq3kYSTA95hm
7VOLEMIqBO/DtG31mIMIIzk5w+vLYn0M5oP2C2dTvI+Gx+vYceY=
=O/ib
-----END PGP SIGNATURE-----
_______________________________________________
freebsd-announce@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

New policy for orphaning/retiring packages with open security bugs

FESCo accepted [1] a new policy to handle packages with long-standing
known security bugs in a way similar to FTBFS bugs:

AGREED: If a CRITICAL or IMPORTANT security issue is currently open
against a package, or a security issue of lower severity has been
open for at least 6 months, four weeks before the branch point a
procedure similar to long-standing FTBFS will be triggered
immediately, with 8 weeks of weekly notifications to maintainers and
subsequent orphaning and then subsequent removal from distribution.
This applies to all packages, not just leaf.

This policy will apply to F30 and later. The branch point is on
2019/02/19, so somewhere around January 22 the procedure should start
with notifications being sent out. Maintainers are of course encouraged
to fix any security issues immediately. See [2] for a list of currently
open security bugs.

[1] https://pagure.io/fesco/issue/1935#comment-528180
[2] https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&keywords=SecurityTracking%2C%20&keywords_type=allwords&list_id=9337195&order=changeddate%2Cpriority%2Cbug_id&product=Fedora&query_format=advanced

Zbyszek,
on behalf of FESCo
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Saturday, September 1, 2018

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com

Thursday, August 30, 2018

[USN-3758-2] libx11 vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3758-2
August 30, 2018

libx11 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in libx11.

Software Description:
- libx11: X11 client-side library

Details:

USN-3758-1 fixed several vulnerabilities in libx11. This update
provides the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Tobias Stoeckmann discovered that libx11 incorrectly handled certain
 images. An attacker could possibly use this issue to access sensitive
 information (CVE-2016-7942)

 Tobias Stoeckmann discovered that libx11 incorrectly handled certain
 inputs. An attacker could possibly use this issue to access sensitive
 information. (CVE-2016-7943)

 It was discovered that libx11 incorrectly handled certain inputs.
 An attacker could possibly use this issue to cause a denial of
 service. (CVE-2018-14598, CVE-2018-14599, CVE-2018-14600)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libx11-6                        2:1.4.99.1-0ubuntu2.4
  libx11-dev                      2:1.4.99.1-0ubuntu2.4

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3758-2
  https://usn.ubuntu.com/usn/usn-3758-1
  CVE-2016-7942, CVE-2016-7943, CVE-2018-14598, CVE-2018-14599,
  CVE-2018-14600