Monday, May 6, 2019
[USN-3966-1] GNOME Shell vulnerability
Ubuntu Security Notice USN-3966-1
May 06, 2019
gnome-shell vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.10
- Ubuntu 18.04 LTS
Summary:
GNOME Shell could be made to execute keyboard shortcuts and other
actions while the workstation was locked.
Software Description:
- gnome-shell: graphical shell for the GNOME desktop
Details:
It was discovered that the GNOME Shell incorrectly handled certain
keyboard inputs. An attacker could possibly use this issue to invoke
keyboard shortcuts, and potentially other actions while the workstation
was locked.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.10:
gnome-shell 3.30.2-0ubuntu1.18.10.2
Ubuntu 18.04 LTS:
gnome-shell 3.28.3+git20190124-0ubuntu18.04.2
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3966-1
CVE-2019-3820
Package Information:
https://launchpad.net/ubuntu/+source/gnome-shell/3.30.2-0ubuntu1.18.10.2
https://launchpad.net/ubuntu/+source/gnome-shell/3.28.3+git20190124-0ubuntu18.04.2
Sunday, May 5, 2019
Thursday, May 2, 2019
Planned Outage - src.fedoraproject.org - 2019-05-03 19:00 UTC
iQIzBAEBCgAdFiEESz7rprBJHpbnMnrQSzew2A/7u14FAlzLeswACgkQSzew2A/7
u15CJBAAqX43vbneISUiQeW3CveDnBRQByEqOdzLx/ZONnQNM9G4/526iysDbZI5
WyYmDNA6y3QTePrpbeDtlQwp1S4qTumR2OeH845fKX1XQL0AYlLi9DB2P9X6bMRp
hbGABkbTPtFPr5WUajb8Shp0JrvOoQEDUVcpL0rKX/QlDlLLVKk1MxF4Qu3rEppq
e1XpcIEzJDN/9GXUyLBeBpCXKXWykeJv0NH2R2AFHNhag7W/msXykErMi9kfw9Hv
NSuYDb9iq7sRyhyI7YRXYXDvx2J2Xm1tc0E/1xrGA8uxpFep1WTL50mci5QEOMp/
T1ls7Pucfr8Eq+coCdFGJ5JsZrrHgOB2do/PW0RRh50S4XPcRo+oim9PSX4ZOY2K
tmGdP6M9tuGgq/P9joRikab79ZxEu2IRcxNcUVF1OzllFPzgEo6E7xfuxq+ReQwn
SxKjMHZH/r1cfbB53NAXvuIS9O0AjvUjlVI2rrlzcQgFDciCI6diw+ylJieykJb6
aopBf6EJfXC6PPcY2jRlB2qXKXlhiasV/MJTAfggbZN7zs2J8UWFOWm0JWtDYNsx
VyJAr8UyWMw9CLerqYgN0nZN4hyLO3oyUq4xByzH1vndrJxCZ08LYN3y7x6Di/95
NlaCUR8P+sNPhF5PsuXem/HOoT24vrsno2xbuW+JJ0X18pyan9g=
=DQL2
-----END PGP SIGNATURE-----
Planned Outage - src.fedoraproject.org - 2019-05-03 19:00 UTC
There will be an outage starting at 2019-05-03 19:00 UTC ,
which will last approximately 1 hour.
To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:
date -d '2019-05-03 19:00UTC'
Reason for outage:
We will be adding additional disk space to src.fedoraproject.org. The
outage should be short, but the host will be down while the additional
disk is added and resized.
Affected Services:
src.fedoraproject.org
Ticket Link:
https://pagure.io/fedora-infrastructure/issue/7756
REMINDER: Fedora 28 End of Life on 2019-May-28
going to close all of the Fedora 28 bugs which remain open [1].
You have a few weeks remaining to submit updates, if you have any,
before the Fedora 28 release becomes unsupported.
[1] https://fedoraproject.org/wiki/Releases/30/HouseKeeping#Fedora_28_EOL_Closure
--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
Pronouns: he/him
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
[USN-3964-1] python-gnupg vulnerabilities
iQIzBAEBCgAdFiEEwZbe96kJeWh2OITRdyg1Qz0oXX0FAlzLE+UACgkQdyg1Qz0o
XX1laA//eVZkqukAEZrGBzJw4n/5Ba9b14/POGuCodH391D82neaSEVSACqHvdZk
7zKGwysto4dnaxKcT0XsSWx62Tc8EnDSHS2uUZATN8Zqd/DJLxi2r7cl3NQMt0sO
SV4A9YMfRfyIU9PkhHatT1vqjvt9eJ8pgMlIAbmeG9VRilIf2KHS47o4gbuxEUDL
VjMj3qJCEeU7WvmKGOrI8RWF38BWup010HxXCu9LeIz/vA6J1iaNVFdksYAjLE5C
03lPfWxy1BnwvDUXubSM6RIkk/ADf+wvaO0olzNyg7AVlNd+T5yE7WHaMzzCc9f2
96NvnOiEZE4RFf7YH0rqDWhPdoN+Cb0IFFQFYRh3mJHWJ1Bl9bgWn1XkNSOuwx3q
S4kcHhMJqmBnvfRMmmNDEUlCnu0PwqPcGgTvCkWYQelDkD8NlcA2dHzQAzK4L7SF
bU7Rr5VoVypugg3o99g6NTQ35jsaUjkmD1nxGYAc8CGD+sZZbERP0Qj5loWDRoT5
S/Zjt+0fnikabzdfYdcqVopP3yTCOlc3BjoUvrKxB4x+YUBHGr3RlN9NUZ5Ft1Xp
SprIYqBlf/eTjPmOBtgeFEazy9U06rqyVbeB5h2aapnTjuFkswzt7qJDVuzc9AIS
zvREAxGxkOmiRgFh+fv66XUBSiHAbUVwWX68tG3DopJYm2I9gkM=
=njRb
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3964-1
May 02, 2019
python-gnupg vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS
Summary:
Several security issues were fixed in python-gnupg
Software Description:
- python-gnupg: Python wrapper for the GNU Privacy Guard
Details:
Marcus Brinkmann discovered that GnuPG before 2.2.8 improperly handled certain
command line parameters. A remote attacker could use this to spoof the output of
GnuPG and cause unsigned e-mail to appear signed.
(CVE-2018-12020)
It was discovered that python-gnupg incorrectly handled the GPG passphrase. A
remote attacker could send a specially crafted passphrase that would allow them
to control the output of encryption and decryption operations.
(CVE-2019-6690)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.04:
python-gnupg 0.4.3-1ubuntu1.19.04.1
python3-gnupg 0.4.3-1ubuntu1.19.04.1
Ubuntu 18.10:
python-gnupg 0.4.1-1ubuntu1.18.10.1
python3-gnupg 0.4.1-1ubuntu1.18.10.1
Ubuntu 18.04 LTS:
python-gnupg 0.4.1-1ubuntu1.18.04.1
python3-gnupg 0.4.1-1ubuntu1.18.04.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3964-1
CVE-2018-12020, CVE-2019-6690
Package Information:
https://launchpad.net/ubuntu/+source/python-gnupg/0.4.3-1ubuntu1.19.04.1
https://launchpad.net/ubuntu/+source/python-gnupg/0.4.1-1ubuntu1.18.10.1
https://launchpad.net/ubuntu/+source/python-gnupg/0.4.1-1ubuntu1.18.04.1
Wednesday, May 1, 2019
OpenBSD Errata: May 3rd, 2019 (rip6cksum)
and 6.5.
If a userland program sets the IPv6 checksum offset on a raw socket,
an incoming packet could crash the kernel. ospf6d is such a program.
Binary updates for the amd64, i386, and arm64 platforms are available
via the syspatch utility. Source code patches can be found on the
respective errata page:
https://www.openbsd.org/errata63.html
https://www.openbsd.org/errata64.html
https://www.openbsd.org/errata65.html
As these affect the kernel, a reboot will be needed after patching.
Note that this is the last erratum for OpenBSD 6.3.
Extended Security Maintenance for Ubuntu 14.04 (Trusty Tahr) began April 25 2019
to confirm that as of April 25, 2019, Ubuntu 14.04 LTS basic support
has ended. No more package updates[1] will be accepted to the 14.04
primary archive, and any subsequent support will be done via Extended
Security Maintenance. Over the coming weeks, various images will be
archived, and the primary archive will be copied to old-releases.
Again, we remind you that for customers who can't upgrade to 16.04 or
later immediately, Canonical offers Extended Security Support for
14.04 LTS to Ubuntu Advantage customers, more info about which can
be found here:
[1] We expect one more update to the ubuntu-advantage client to
support future ESM features.
The original Extended Support warning follows, with upgrade instructions:
Ubuntu announced its 14.04 (Trusty Tahr) release almost 5 years ago, on
April 17, 2014. As with the earlier LTS releases, Ubuntu committed to
ongoing security and critical fixes for a period of 5 years. The standard
support period is now nearing its end and Ubuntu 14.04 will transition to
Extended Security Maintenance (ESM) on Thursday, April 25th, 2019.
Users are encouraged to evaluate and upgrade to our latest 18.04 LTS
release via 16.04. The supported upgrade path from Ubuntu 14.04 is via
Ubuntu 16.04. Instructions and caveats for the upgrades may be found at:
https://help.ubuntu.com/community/XenialUpgrades for Ubuntu 16.04 and
https://help.ubuntu.com/community/BionicUpgrades for Ubuntu 18.04.
Ubuntu 16.04 and 18.04 continue to be actively supported with security
updates and bug fixes. All announcements of official security updates for
Ubuntu releases are sent to the ubuntu-security-announce mailing list,
information about which may be found here:
https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Canonical provides Extended Security Maintenance for Ubuntu 14.04 LTS to
customers through Ubuntu Advantage. The announcement including details
about how and where to purchase extended support can be found here:
https://blog.ubuntu.com/2019/02/05/ubuntu-14-04-trusty-tahr
https://www.ubuntu.com/esm
Since its launch in October 2004, Ubuntu has become one of the most
highly regarded Linux distributions with millions of users in homes,
schools, businesses and governments around the world. Ubuntu is Open
Source software, costs nothing to download, and users are free to
customise or alter their software in order to meet their needs.
On behalf of the Ubuntu Release Team,
Adam Conrad
--
ubuntu-announce mailing list
ubuntu-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-announce
Extended Security Maintenance for Ubuntu 14.04 (Trusty Tahr) began April 25 2019
to confirm that as of April 25, 2019, Ubuntu 14.04 LTS basic support
has ended. No more package updates will be accepted to the 14.04
primary archive, and any subsequent support will be done via Exteded
Security Maintenance. Over the coming weeks, various images will be
archived, and the primary archive will be copied to old-releases.
Again, we remind you that for customers who can't upgrade to 16.04 or
later immediately, Canonical offers Extended Security Support for
14.04 LTS to Ubuntu Advantage customers, more info about which can
be found here:
The original Extended Support warning follows, with upgrade instructions:
Ubuntu announced its 14.04 (Trusty Tahr) release almost 5 years ago, on
April 17, 2014. As with the earlier LTS releases, Ubuntu committed to
ongoing security and critical fixes for a period of 5 years. The standard
support period is now nearing its end and Ubuntu 14.04 will transition to
Extended Security Maintenance (ESM) on Thursday, April 25th, 2019.
Users are encouraged to evaluate and upgrade to our latest 18.04 LTS
release via 16.04. The supported upgrade path from Ubuntu 14.04 is via
Ubuntu 16.04. Instructions and caveats for the upgrades may be found at:
https://help.ubuntu.com/community/XenialUpgrades for Ubuntu 16.04 and
https://help.ubuntu.com/community/BionicUpgrades for Ubuntu 18.04.
Ubuntu 16.04 and 18.04 continue to be actively supported with security
updates and bug fixes. All announcements of official security updates for
Ubuntu releases are sent to the ubuntu-security-announce mailing list,
information about which may be found here:
https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
Canonical provides Extended Security Maintenance for Ubuntu 14.04 LTS to
customers through Ubuntu Advantage. The announcement including details
about how and where to purchase extended support can be found here:
https://blog.ubuntu.com/2019/02/05/ubuntu-14-04-trusty-tahr
https://www.ubuntu.com/esm
Since its launch in October 2004, Ubuntu has become one of the most
highly regarded Linux distributions with millions of users in homes,
schools, businesses and governments around the world. Ubuntu is Open
Source software, costs nothing to download, and users are free to
customise or alter their software in order to meet their needs.
On behalf of the Ubuntu Release Team,
Adam Conrad
--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
[USN-3953-2] PHP vulnerabilities
Ubuntu Security Notice USN-3953-2
May 01, 2019
php5 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 ESM
- Ubuntu 12.04 ESM
Summary:
Several security issues were fixed in PHP.
Software Description:
- php5: HTML-embedded scripting language interpreter
Details:
USN-3953-1 fixed several vulnerabilities in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that PHP incorrectly handled certain exif tags in
JPEG images. A remote attacker could use this issue to cause PHP to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 ESM:
libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.29+esm1
php5-cgi 5.5.9+dfsg-1ubuntu4.29+esm1
php5-cli 5.5.9+dfsg-1ubuntu4.29+esm1
php5-fpm 5.5.9+dfsg-1ubuntu4.29+esm1
Ubuntu 12.04 ESM:
libapache2-mod-php5 5.3.10-1ubuntu3.35
php5-cgi 5.3.10-1ubuntu3.35
php5-cli 5.3.10-1ubuntu3.35
php5-fpm 5.3.10-1ubuntu3.35
In general, a standard system update will make all the necessary
changes.
References:
https://usn.ubuntu.com/usn/usn-3953-2
https://usn.ubuntu.com/usn/usn-3953-1
CVE-2019-11034, CVE-2019-11035
[USN-3963-1] Memcached vulnerability
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlzJomkACgkQZWnYVadE
vpNEvxAAgjwMBFVyLxSYlWwa3Jorpj6910KWdbCVpUrGn43FhTQZpQNVatKKAMXM
ev+7xXOtBrZmxtEqwPWMTVfaDpD06UhBnJQfIcRX6+zmjNqdMIw637MkFEMhc+YU
snzTkTQkH04TOnocXp7Wh7ILeAZy/eULCmH9ohdc2YhP9i+wdt6HAi0S6vxYUmZ+
u+AhlEadahdWRotCOd9SFUGHXeHSox7GgXnkd2r4rhu5hP5O7JmiP3uQO6SKTV3x
1dA/ywcvNPfRYhtGkCxkOABEZU+G6wHW2va2x8OLMz1zb/NtOk69vTUqQ0f9ubz+
U1nlrc+Tu0liBZCp2RDVEVMAGnyBreBEczoR92JX7YELw9gKWjL1JHCL8tNknAAt
I/CzWbwOArgS+/nkB1U2bMQNHWdxDRmt5EK6wY5rHAW3vqDqHfZ80vpJbRAk8Rui
tUo7hm4tozvA14tPHl+sNvvvF8TWzp1efd3TDFu7+RbbOAhp/KPpOYif+MS4fcKZ
lOeZFdYCbTiKVpWOXiZzrtlTwMcrBv++5GWj1MuBjvMMTHgojZsbXEcb4HheUpIO
8rj+VuFxcauTq9TEHRf8vpHdl2FbimZtf0RR+CMqSGoVyBEvQ+vrUmeO2kSwtD7U
a+a/Z/WqZaDV00Iubbw+GmhRxicQvCjUTtUSZWExBXUaxz3VNPY=
=mjkn
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3963-1
May 01, 2019
memcached vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 19.04
- Ubuntu 18.10
- Ubuntu 18.04 LTS
Summary:
Memcached could be made to crash if it received specially crafted network
traffic.
Software Description:
- memcached: high-performance memory object caching system
Details:
It was discovered that Memcached incorrectly handled certain lru command
messages. A remote attacker could possibly use this issue to cause
Memcached to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 19.04:
memcached 1.5.10-0ubuntu1.19.04.1
Ubuntu 18.10:
memcached 1.5.10-0ubuntu1.18.10.1
Ubuntu 18.04 LTS:
memcached 1.5.6-0ubuntu1.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3963-1
CVE-2019-11596
Package Information:
https://launchpad.net/ubuntu/+source/memcached/1.5.10-0ubuntu1.19.04.1
https://launchpad.net/ubuntu/+source/memcached/1.5.10-0ubuntu1.18.10.1
https://launchpad.net/ubuntu/+source/memcached/1.5.6-0ubuntu1.1
[CentOS-announce] IRC Meeting Changes
various Special Interest Groups (SIGs) and other projects in the #centos-devel
channel on the freenode IRC network. This has, for the most part, worked out
fairly well. However, as this is a shared channel, at times things can become
a bit hectic and confusing as people occasionally interrupt a meeting in
progress. Not only does this break the flow of the meeting but it also injects
noise into the logs that the project maintains for historical reference. This
policy was also different from most other projects which have a dedicated
"meetings" channel to be used for these purposes.
In order to address the issue the project has made the decision to transition
meetings to the #centos-meeting channel. This is a dedicated channel to be
used solely for meetings. We feel this will help alleviate any potential
issues with interruptions and other distractions.
This channel is managed by the same group of people, our IRC Ops Team, as is
#centos-devel and our channel bots are present to help as necessary. An
additional bonus of this transition will be that the meeting bot (centbot)
responsible for meeting oversight and logging will now be able to set the
channel topic to reflect meeting status. This was not previously possible due
to policy as we did not want to have the bot op'd unless absolutely necessary
in a shared channel.
We are planning this transition for June 1st in order to give the stakeholders
involved ample time to alert their communities of the change and to ensure we
have made the necessary changes on our end to ensure a smooth transition for
people who access the logs via the https://www.centos.org/minutes/ interface.
Any questions regarding this transition should be addressed either via the
centos-devel mailing list or on the #centos-devel IRC channel on freenode.
Additionally people can reach out to me personally on IRC (Bahhumbug on
freenode) or via email if they have questions or concerns regarding this or
other CentOS IRC matters.
Thanks and see you in #centos-meeting :)
--
The good-enough father is not simply a knight in shining armor galloping to
the occasional rescue; he is there through good times and bad, insisting on
and delighting in his paternity every pleasurable and painful step of the
way.
-- Victoria Secunda, American psychologist and author,
Women and Their Fathers, ch. 4 (1992)
lists.linuxfromscratch.org mailing list memberships reminder
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.
You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.
In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.
If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!
Passwords for reallost1.fbsd2233449@blogger.com:
List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com