Monday, March 8, 2021

Orphaned packages looking for new maintainers

The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life

Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.

Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>

Full report available at:
https://churchyard.fedorapeople.org/orphans-2021-03-08.txt
grep it for your FAS username and follow the dependency chain.

For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan

Package (co)maintainers Status Change
================================================================================
CuraEngine-lulzbot orphan 0 weeks ago
arduino-builder orphan 3 weeks ago
arp-scan moceap, orphan, xmrbrz 2 weeks ago
avahi msekleta, orphan 0 weeks ago
balance lbazan, orphan 2 weeks ago
bareftp chreide, orphan 2 weeks ago
bind-to-tinydns orphan, timj 2 weeks ago
bucardo lbazan, orphan 2 weeks ago
cri-tools dwalsh, fkluknav, lsm5, 2 weeks ago
orphan, umohnani
ctorrent orphan 2 weeks ago
cura-lulzbot orphan, spot 0 weeks ago
dianara orphan 2 weeks ago
drehatlas-warender-bibliothek- orphan 2 weeks ago
fonts
drehatlas-xaporho-fonts orphan 2 weeks ago
eclipse-pydev eclipse-sig, jjohnstn, orphan 5 weeks ago
ez-ipupdate abo, jlayton, orphan 2 weeks ago
felix-bundlerepository mizdebsk, orphan 4 weeks ago
geronimo-jcdi-1.1-api orphan 4 weeks ago
geronimo-validation orphan 4 weeks ago
git-up orphan 4 weeks ago
glom orphan 3 weeks ago
gnome-clocks gnome-sig, orphan 0 weeks ago
gnome-contacts alexl, anujmore, gnome-sig, 0 weeks ago
mcrha, orphan
golang-gvisor eclipseo, elmarco, orphan 5 weeks ago
goocanvasmm orphan 3 weeks ago
goocanvasmm2 orphan 3 weeks ago
gstreamermm orphan 3 weeks ago
httpunit fnasser, mizdebsk, orphan 2 weeks ago
jakarta-messaging orphan 0 weeks ago
jboss-el-3.0-api orphan 0 weeks ago
jboss-servlet-3.1-api orphan 0 weeks ago
jfsutils fcami, orphan 2 weeks ago
jmdns mizdebsk, orphan 3 weeks ago
jomolhari-fonts orphan, pnemade 2 weeks ago
jython akurtakov, dmalcolm, 5 weeks ago
jmatthews, lkundrak, orphan,
pmackinn
kanjistrokeorders-fonts orphan 2 weeks ago
krb5-auth-dialog alexl, caolanm, gnome-sig, 2 weeks ago
mbarnes, orphan, rhughes,
rstrode, simo, ssp
lcm dcallagh, mrunge, nmarques, 5 weeks ago
orphan
libarcus-lulzbot orphan 0 weeks ago
libinfinity orphan 3 weeks ago
libmirage orphan 2 weeks ago
libnotifymm orphan 3 weeks ago
lulzbot-marlin-firmware orphan, spot 0 weeks ago
maven-verifier mizdebsk, orphan 0 weeks ago
mydns orphan 2 weeks ago
netty mizdebsk, orphan 5 weeks ago
nload cicku, fab, fale, orphan 2 weeks ago
ocaml-merlin orphan 4 weeks ago
opendbx orphan 2 weeks ago
os-maven-plugin mizdebsk, orphan 5 weeks ago
pen cicku, danniel, orphan 2 weeks ago
perl-DBIx-Safe orphan 2 weeks ago
perl-pgsql_perl5 orphan 2 weeks ago
pg_activity orphan 2 weeks ago
pg_top orphan 2 weeks ago
php-deepdiver-zipstreamer orphan 0 weeks ago
php-opencloud-openstack orphan 0 weeks ago
php-pecl-ssh2 orphan, remi 2 weeks ago
phpwapmail orphan 1 weeks ago
pidgin-logviewer orphan 4 weeks ago
plotmm orphan 3 weeks ago
pokerth orphan 2 weeks ago
powermock jerboaa, lef, neugens, orphan 0 weeks ago
puppetlabs-stdlib gchamoul, orphan 5 weeks ago
python-django-registration orphan 4 weeks ago
python-flask-assets orphan, pjp, sundaram 4 weeks ago
python-flask-babelex devrim, orphan 2 weeks ago
python-flask-gravatar devrim, orphan 2 weeks ago
python-flask-htmlmin devrim, orphan 2 weeks ago
python-flask-mail devrim, orphan 2 weeks ago
python-flask-migrate jkaluza, orphan, ralph 2 weeks ago
python-flask-oauth orphan, pjp, sundaram 4 weeks ago
python-flask-paranoid devrim, orphan 2 weeks ago
python-flask-pymongo orphan 2 weeks ago
python-flask-security devrim, orphan 2 weeks ago
python-flask-sphinx-themes devrim, orphan 2 weeks ago
python-pytest4 churchyard, mrunge, orphan, 0 weeks ago
python-sig, radez, thm
python-setuptools_hg orphan 4 weeks ago
python-shadowsocks orphan 3 weeks ago
python-shapely jcp, orphan 0 weeks ago
python-sshtunnel orphan 2 weeks ago
python-uranium-lulzbot orphan 0 weeks ago
python-vcversioner fab, orphan 2 weeks ago
python-webassets dcallagh, orphan, pjp, 4 weeks ago
sundaram
qroneko orphan 4 weeks ago
redir orphan 2 weeks ago
reiserfs-utils cicku, orphan 2 weeks ago
saxpath akurtakov, mizdebsk, orphan 0 weeks ago
simple-jndi orphan 4 weeks ago
sofia-sip orphan 2 weeks ago
sumwars orphan 2 weeks ago
sushi gnome-sig, orphan 0 weeks ago
sylpheed cicku, cwickert, orphan, 2 weeks ago
sharkcz
tibetan-machine-uni-fonts orphan 2 weeks ago
tlomt-junction-fonts orphan 2 weeks ago
tmw-music orphan 4 weeks ago
trac-batchmodify-plugin orphan 5 weeks ago
trac-navadd-plugin orphan 5 weeks ago
trac-privateticketsplugin orphan 1 weeks ago
trac-themeengine-plugin orphan 5 weeks ago
trac-tocmacro-plugin orphan 5 weeks ago
trac-vatar-plugin orphan 5 weeks ago
trac-workflowadmin-plugin orphan 5 weeks ago
transmission-remote-gtk orphan, tingping 4 weeks ago
ttyd orphan 2 weeks ago
ubuntu-title-fonts orphan 2 weeks ago
vollkorn-fonts orphan 2 weeks ago
wput orphan 2 weeks ago
xmlrpc kdaniel, mizdebsk, orphan 5 weeks ago
xmonad-log-applet dcallagh, orphan 5 weeks ago
yanone-tagesschrift-fonts orphan 2 weeks ago

The following packages require above mentioned packages:
Report too long, see the full version at
https://churchyard.fedorapeople.org/orphans-2021-03-08.txt

See dependency chains of your packages at
https://packager-dashboard.fedoraproject.org/
See all orphaned packages at https://packager-dashboard.fedoraproject.org/orphan

Affected (co)maintainers (either directly or via packages' dependencies):
aarem: sylpheed
abbra: avahi
abo: ez-ipupdate
adelton: python-shapely
agerstmayr: avahi
agoode: avahi
ajax: jomolhari-fonts
akurtakov: jython, netty, saxpath, os-maven-plugin
alexl: gnome-contacts, avahi, krb5-auth-dialog, jomolhari-fonts
alexlan: perl-pgsql_perl5
almac: jython, netty, os-maven-plugin
amerey: avahi
amigadave: avahi
ankursinha: python-shapely
anoopcs: avahi
anujmore: gnome-contacts
anyremote: avahi
aperezbios: avahi
arobinso: jython, netty, os-maven-plugin
asn: avahi
asrob: php-pecl-ssh2
astra: avahi
atim: gstreamermm
berrange: jomolhari-fonts
besser82: jomolhari-fonts
bkabrda: python-flask-migrate
bpeck: avahi
breilly: python-flask-migrate
bruno: gstreamermm
bsjones: avahi
caillon: jomolhari-fonts, avahi
caniszczyk: jython, netty, os-maven-plugin
caolanm: jomolhari-fonts, avahi, krb5-auth-dialog
carlwgeorge: avahi
chimosky: avahi
chreide: bareftp
churchyard: python-pytest4, python-shapely
cicku: avahi, sylpheed, pen, nload, reiserfs-utils
cosimoc: avahi
cottsay: python-shapely
cqi: python-flask-migrate
cverna: python-flask-migrate
cwickert: sylpheed
cycloptivity: php-pecl-ssh2
danniel: pen
dbhole: jython, netty, os-maven-plugin
dcallagh: lcm, xmonad-log-applet, python-webassets
dchen: avahi
deamn: jython, netty, os-maven-plugin
devrim: python-flask-paranoid, python-flask-gravatar, python-flask-security,
python-flask-sphinx-themes, python-flask-babelex, perl-pgsql_perl5,
python-flask-htmlmin, python-flask-mail
dmalcolm: jython, netty, os-maven-plugin
drsmith2: avahi
dsd: avahi
dvratil: avahi
dwalsh: cri-tools
dwrobel: python-shapely
dyfet: avahi
ebaron: jython, netty, os-maven-plugin
eclipse-sig: os-maven-plugin, jython, eclipse-pydev, netty, xmlrpc
eclipseo: golang-gvisor
elmarco: golang-gvisor, avahi
elxreno: os-maven-plugin, jython, netty, arduino-builder, jmdns
eseyman: jomolhari-fonts
evgenyz: jomolhari-fonts
fab: nload, python-vcversioner, perl-pgsql_perl5
fale: nload
fcami: jfsutils
fche: avahi
feborges: avahi
filabrazilska: jomolhari-fonts
filiperosset: jython, netty, saxpath, os-maven-plugin
fivaldi: python-flask-migrate
fkluknav: cri-tools
fnasser: httpunit
galileo: jython, netty, os-maven-plugin
gchamoul: puppetlabs-stdlib
gd: avahi
gferon: python-shapely
gnaponie: python-flask-migrate
gnome-sig: gnome-contacts, avahi, gnome-clocks, jomolhari-fonts, sushi,
krb5-auth-dialog
grover: avahi
hadess: avahi
hguemar: avahi
hubbitus: avahi
hvad: jomolhari-fonts
iboukris: avahi
infra-sig: jomolhari-fonts
ixs: avahi
jankratochvil: avahi
jarrpa: avahi
jcerny: jomolhari-fonts
jcp: python-shapely
jdekloe: python-shapely
jerboaa: jython, netty, os-maven-plugin, powermock
jgrulich: avahi
jistone: avahi
jjames: avahi
jjelen: jboss-servlet-3.1-api, jboss-el-3.0-api
jjohnstn: os-maven-plugin, jython, eclipse-pydev, netty, xmlrpc
jkaluza: python-flask-migrate
jkang: jython, netty, os-maven-plugin
jlayton: avahi, ez-ipupdate
jmatthews: jython, netty, os-maven-plugin
jmlich: perl-pgsql_perl5
jplesnik: jomolhari-fonts
jreznik: avahi, kanjistrokeorders-fonts
jridky: avahi
jskarvad: avahi
jsmith: php-pecl-ssh2
jspaleta: python-shapely
jstephen: avahi
jvanek: jython, netty, os-maven-plugin
kalev: avahi, python-flask-migrate
kdaniel: jython, netty, xmlrpc, os-maven-plugin
kde-sig: avahi, kanjistrokeorders-fonts
kevin: jomolhari-fonts, avahi
kkofler: avahi
kni: avahi
kwizart: avahi
lbazan: bucardo, balance, perl-DBIx-Safe, python-shapely
lberk: avahi
lef: jython, netty, os-maven-plugin, powermock
lennart: avahi
lholecek: python-flask-migrate
liangsuilong: jomolhari-fonts
limb: avahi, python-shapely
lkundrak: avahi, os-maven-plugin, jython, netty, jomolhari-fonts
lsedlar: python-flask-migrate
lsm5: cri-tools
lucarval: python-flask-migrate
martinkg: avahi
matyc: jomolhari-fonts
maxamillion: python-flask-migrate, perl-pgsql_perl5
mayorga: perl-pgsql_perl5
mbarabas: jomolhari-fonts
mbarnes: jomolhari-fonts, avahi, krb5-auth-dialog
mbooth: jython, netty, os-maven-plugin
mclasen: avahi
mcrha: gnome-contacts, avahi
mdomsch: opendbx
melmorabity: avahi
mgoodwin: avahi
mhlavink: avahi
mikem: python-flask-migrate
mikep: avahi
mizdebsk: httpunit, os-maven-plugin, jython, netty, xmlrpc, saxpath,
felix-bundlerepository, jmdns, maven-verifier
mjw: avahi
mlysonek: jomolhari-fonts
mmarhefk: jomolhari-fonts
moceap: arp-scan
mprahl: python-flask-migrate
mrunge: lcm, python-pytest4
msekleta: avahi
msimacek: avahi
nathans: avahi
neugens: powermock
neuro-sig: python-shapely
ngompa: avahi
nmarques: lcm
nosnilmot: avahi
nucleo: avahi
obnox: avahi
oget: jython, netty, os-maven-plugin
oholy: avahi
oliver: jython, netty, os-maven-plugin
opuk: avahi
orion: avahi
otaylor: python-flask-migrate
patches: os-maven-plugin, jython, netty, arduino-builder, jmdns
pavlix: avahi
pbrobinson: avahi
pcpa: python-flask-sphinx-themes
pemensik: avahi
perl-maint-sig: jomolhari-fonts
peter: jython, netty, os-maven-plugin
pfrields: php-pecl-ssh2
pingou: jomolhari-fonts
pjp: python-flask-oauth, python-flask-assets, python-webassets
pkubat: perl-pgsql_perl5
pmackinn: jython, netty, os-maven-plugin
pnemade: jomolhari-fonts
ppisar: jomolhari-fonts, avahi
praiskup: perl-pgsql_perl5
pvrabec: jomolhari-fonts
python-sig: python-pytest4, python-shapely
qulogic: python-shapely
qwan: python-flask-migrate
radez: python-pytest4
ralph: jomolhari-fonts, python-flask-migrate
rathann: gstreamermm
rdieter: avahi, kanjistrokeorders-fonts
remi: php-pecl-ssh2
rgrunber: jython, netty, os-maven-plugin
rhughes: jomolhari-fonts, avahi, krb5-auth-dialog
richardfearn: jython, netty, os-maven-plugin
rishi: avahi
rjones: jomolhari-fonts
rmattes: avahi
robert: avahi
robmv: jomolhari-fonts
robotics-sig: avahi
rstrode: jomolhari-fonts, avahi, krb5-auth-dialog
rtcm: avahi
sagitter: avahi
salimma: avahi
sasiddiq: jython, netty, os-maven-plugin
scenek: jomolhari-fonts
scox: avahi
sdodson: php-pecl-ssh2
sereinit: avahi
sergiomb: jomolhari-fonts
sharkcz: sylpheed
simo: avahi, krb5-auth-dialog
siwinski: php-pecl-ssh2
slaanesh: avahi
smakarov: avahi
smani: avahi, perl-pgsql_perl5
spot: cura-lulzbot, avahi, os-maven-plugin, jython, netty,
lulzbot-marlin-firmware, arduino-builder, CuraEngine-lulzbot, jomolhari-fonts,
python-uranium-lulzbot, jmdns, libarcus-lulzbot
ssp: jomolhari-fonts, avahi, krb5-auth-dialog
stefw: avahi
sundaram: python-flask-oauth, python-flask-assets, python-webassets
tagoh: jomolhari-fonts
tartina: avahi
tdecacqu: avahi
terjeros: jython, avahi, netty, os-maven-plugin
teuf: avahi
than: avahi, kanjistrokeorders-fonts
thm: python-pytest4
thofmann: avahi
thomasj: avahi
thozza: os-maven-plugin, jython, netty, arduino-builder, jmdns
timj: bind-to-tinydns
timn: avahi
tingping: transmission-remote-gtk
tkorbar: avahi
tomh: python-shapely, perl-pgsql_perl5
ttomecek: python-flask-migrate
ttorling: avahi
tuxbrewr: avahi
twaugh: avahi, python-flask-migrate
umohnani: cri-tools
vascom: os-maven-plugin, jython, netty, arduino-builder, jmdns
verdurin: avahi
victortoso: avahi
vmaljulin: python-flask-migrate
volter: python-shapely, perl-pgsql_perl5
vrutkovs: python-flask-migrate
wcohen: avahi
wsato: jomolhari-fonts
wtaymans: avahi
xavierb: jomolhari-fonts
xmrbrz: arp-scan
zdohnal: avahi
zeenix: avahi

--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Thursday, March 4, 2021

[USN-4757-2] wpa_supplicant and hostapd vulnerability

==========================================================================
Ubuntu Security Notice USN-4757-2
March 04, 2021

wpa vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

wpa_supplicant could be made to crash or run programs if it received
specially crafted network traffic.

Software Description:
- wpa: client support for WPA and WPA2

Details:

USN-4757-1 fixed a vulnerability in wpa_supplicant and hostapd. This update
provides the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that wpa_supplicant did not properly handle P2P
(Wi-Fi Direct) provision discovery requests in some situations. A
physically proximate attacker could use this to cause a denial of service
or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
wpasupplicant 2.1-0ubuntu1.7+esm4

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4757-2
https://ubuntu.com/security/notices/USN-4757-1
CVE-2021-27803

Wednesday, March 3, 2021

Fedora Linux 34 Beta Go/No-Go meeting next week

Hi everyone,

It's that time already! The Fedora Linux 34 Beta Go/No-Go[1] meeting
is scheduled for Thursday 11 March at 1700 UTC in #fedora-meeting. At
this time, we will determine the status of the F34 Beta for the 16
March preferred target date. For more information about the Go/No-Go
meeting, see the wiki[2].

[1] https://apps.fedoraproject.org/calendar/meeting/9923/
[2] https://fedoraproject.org/wiki/Go_No_Go_Meeting

--
Ben Cotton
He / Him / His
Senior Program Manager, Fedora & CentOS Stream
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

OpenBSD Errata: March 4th, 2021 (sshagent)

Errata patches for SSH have been released for OpenBSD 6.7 and 6.8.

Double free in ssh-agent(1)

Binary updates for the amd64, i386, and arm64 platforms are available via
the syspatch utility. Source code patches can be found on the respective
errata page:

https://www.openbsd.org/errata67.html
https://www.openbsd.org/errata68.html

[announce] Next NYC*BUG: Tonight!

The Next NYC*Bug Zoom meeting will be held March 3rd 18:45 EST / 23:45 UTC

Gaming on OpenBSD: Pearls, Pitfalls, Paranoia, by Thomas Frohwein

OpenBSD has had a long-standing reputation for its security focus, but
is also surprisingly good as a desktop OS once you've made it past the
initial barriers. It hasn't been known for gaming (other than
tetris(6)), leading users to play on other platforms like a Windows
box or game consoles. But now, things are changing one
emulator|sourceport|game engine at a time.

Follow thfr@ on a years-long journey to try to extend the advantages
offered by OpenBSD to more and better gaming - from hardware support
to security mitigations at play, to ultimately overcoming multiple
barriers and growing both OpenBSD's gaming library and its gaming
community.

For Zoom meeting details, email to rsvp AT lists.nycbug.org, and
details will be sent on the day of the meeting.

Speaker Biography

Thomas Frohwein is a German expat living in Montana. He has been
OpenBSD user since 2014, and developer (thfr@) since 2018. His primary
focus has been improving gaming options on OpenBSD and he maintains
the (eternally unfinished) webpage playonbsd.com with the infamous
shopping guide in an attempt to sabotage the productivity of OpenBSD
hackers and tempt them to drain their notoriously low bank accounts.
His dayjob is working as a physician which in this day and age is
almost equivalent to being an IT specialist.


More Info and Zoom invite details:
https://www.nycbug.org/index?action=view&id=10681

[USN-4757-1] wpa_supplicant and hostapd vulnerability

==========================================================================
Ubuntu Security Notice USN-4757-1
March 03, 2021

wpa vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

wpa_supplicant could be made to crash or run programs if it received
specially crafted network traffic.

Software Description:
- wpa: client support for WPA and WPA2

Details:

It was discovered that wpa_supplicant did not properly handle P2P
(Wi-Fi Direct) provision discovery requests in some situations. A
physically proximate attacker could use this to cause a denial of service
or possibly execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
wpasupplicant 2:2.9-1ubuntu8.2

Ubuntu 20.04 LTS:
wpasupplicant 2:2.9-1ubuntu4.3

Ubuntu 18.04 LTS:
wpasupplicant 2:2.6-15ubuntu2.8

Ubuntu 16.04 LTS:
wpasupplicant 2.4-0ubuntu6.8

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
https://usn.ubuntu.com/4757-1
CVE-2021-27803

Package Information:
https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu8.2
https://launchpad.net/ubuntu/+source/wpa/2:2.9-1ubuntu4.3
https://launchpad.net/ubuntu/+source/wpa/2:2.6-15ubuntu2.8
https://launchpad.net/ubuntu/+source/wpa/2.4-0ubuntu6.8

[USN-4754-4] Python 2.7 vulnerability

==========================================================================
Ubuntu Security Notice USN-4754-4
March 03, 2021

python2.7 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

Python could be made to execute arbitrary code or denial of service if it
received a specially crafted input.

Software Description:
- python2.7: An interactive high-level object-oriented language

Details:

USN-4754-1 fixed vulnerabilities in Python. Because of a regression, a
subsequent update removed the fix for CVE-2021-3177. This update reinstates
the security fix for CVE-2021-3177.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2020-27619, CVE-2021-3177)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
python2.7 2.7.17-1~18.04ubuntu1.6
python2.7-minimal 2.7.17-1~18.04ubuntu1.6

Ubuntu 16.04 LTS:
python2.7 2.7.12-1ubuntu0~16.04.18
python2.7-minimal 2.7.12-1ubuntu0~16.04.18

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4754-4
https://usn.ubuntu.com/4754-1
CVE-2021-3177

Package Information:
https://launchpad.net/ubuntu/+source/python2.7/2.7.17-1~18.04ubuntu1.6
https://launchpad.net/ubuntu/+source/python2.7/2.7.12-1ubuntu0~16.04.18

Tuesday, March 2, 2021

[CentOS-announce] CentOS Stream Container images available on quay.io

NOTE: This message was intended to go to centos-devel and centos-announce on 11-Feb-2021 but it only made it to centos-devel. Thanks to folks on IRC for mentioning that this never made it to the proper announcement channels.

Hi folks,

CentOS Stream container images are now readily available!

podman pull quay.io/centos/centos:stream

OR

podman pull quay.io/centos/centos:stream8

## Tags·

We expect the 'stream' tag to automatically move forward to new Streams as
they come on board. This means when CentOS Stream 9 becomes the Live Stream,
quay.io/centos/centos:stream will have 9 based content.

The 'stream8' tag can be used while Stream 8 is Live, and during the overlap
period between Stream 8 and Stream 9.

A 'stream9' tag will be created at the appropriate time to serve the same purpose.

You can browse through all of the tags for the CentOS repository here:

## Next Steps

- We are still in discussions on how to push these properly to Dockerhub. Since
  CentOS is an Official Image, there are some extra requirements here that
  we're working through.

If you have questions you can find us on the centos-devel mailing list
(centos-devel@centos.org) or in #centos-stream on Freenode

Cheers!

--
Brian Stinson
On behalf of the CentOS Stream Team

[CentOS-announce] CESA-2021:0671 Important CentOS 7 bind Security Update

CentOS Errata and Security Advisory 2021:0671 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2021:0671

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
1edd338d1d20b130c1a107ea59652842ef0a8167393745468301105b2a59ca6d bind-9.11.4-26.P2.el7_9.4.x86_64.rpm
1a87cf953d16581b70a51f9c131f6f714e364e0a57dee8b2856b43aad7d89104 bind-chroot-9.11.4-26.P2.el7_9.4.x86_64.rpm
ee52c09ab7dca8a8e11fe87c0855b1ce38df1fdaef899e8ce50d80b72009b62b bind-devel-9.11.4-26.P2.el7_9.4.i686.rpm
5bc7e489f2286aea26973b124918a70b6f8f29e9936508ee68e5fa89b453002b bind-devel-9.11.4-26.P2.el7_9.4.x86_64.rpm
28d32718cac59baf9c4162573d291af2345e664d16de912661fa18de7157ca63 bind-export-devel-9.11.4-26.P2.el7_9.4.i686.rpm
a9b560ad84f4c4da2302f2f1c1581df4d699c0e0f9cf0754e125b2bab6ea4795 bind-export-devel-9.11.4-26.P2.el7_9.4.x86_64.rpm
f23ad28777ef3020a0b4c72141bc0d367c9a60a8eca144eafcef471df349d126 bind-export-libs-9.11.4-26.P2.el7_9.4.i686.rpm
6df17149302a2cb98a128880ea6df6fe1092d0cd169dda5bd470cf1dc5c73494 bind-export-libs-9.11.4-26.P2.el7_9.4.x86_64.rpm
c779ed4a8b7cd8df613f47c214050d61ac25927ab97381ffb59944fb998585ff bind-libs-9.11.4-26.P2.el7_9.4.i686.rpm
43570d8e293bd93001cb8c4cac3e4b2045b3024b7f3e08f4449735bfb9d206c6 bind-libs-9.11.4-26.P2.el7_9.4.x86_64.rpm
43a8791d748c2ca3cb5e8c1b6682319313b8373bb0e84e9e545ba09dc9e093bb bind-libs-lite-9.11.4-26.P2.el7_9.4.i686.rpm
5380ad090ba99c100379b2fc1cf54a62f85cdfe390b04b6e5e0fe4c213aa4661 bind-libs-lite-9.11.4-26.P2.el7_9.4.x86_64.rpm
4cfa5141393a1004bc9d7885fee9a606293ee21216066238700f933afd5e4598 bind-license-9.11.4-26.P2.el7_9.4.noarch.rpm
d97cd106cf9572dc73237ecabf174c9e7fd63f1831ecd180582edfe2ee993409 bind-lite-devel-9.11.4-26.P2.el7_9.4.i686.rpm
87c1a04fd7037d13c6be98a8a975ef7a41eec66aa9031b781b61eabe9107ce9b bind-lite-devel-9.11.4-26.P2.el7_9.4.x86_64.rpm
8df89d78d785928efa5b8d059e96ce33ffe0c9356663c9acb50ce3ec8c660d92 bind-pkcs11-9.11.4-26.P2.el7_9.4.x86_64.rpm
f5a544c1c54d159d63ecf02b66555411db8230d7164937c969ee12412a7b3426 bind-pkcs11-devel-9.11.4-26.P2.el7_9.4.i686.rpm
1612a4f04271f95f905580cfc4cc94695b1a11ade17803d000750d518bc0e3ac bind-pkcs11-devel-9.11.4-26.P2.el7_9.4.x86_64.rpm
86d0b148abfa317696a046ac187cb479b242ea3f9ec769e6891130395ea172a9 bind-pkcs11-libs-9.11.4-26.P2.el7_9.4.i686.rpm
40ceb41cf108321fdafc40bff1168cbc4f3e85a9ec271d6b55e946ed83697fb7 bind-pkcs11-libs-9.11.4-26.P2.el7_9.4.x86_64.rpm
b97a0e1f72d3fb43f706975f8e02ff0c130ef35fc6b4763eb18db88980fcde25 bind-pkcs11-utils-9.11.4-26.P2.el7_9.4.x86_64.rpm
235100bdba26a1af51c7f66f533d9318837d01dafa0c5e822245c8e0e5469978 bind-sdb-9.11.4-26.P2.el7_9.4.x86_64.rpm
a191bcc40fb33d21a6109e116756d8999e60adb5535583f65d05f51ff3047463 bind-sdb-chroot-9.11.4-26.P2.el7_9.4.x86_64.rpm
461bf2c4280e37fa28f8577583cf56315e10dc6a8898497da766b5dffbdb1a56 bind-utils-9.11.4-26.P2.el7_9.4.x86_64.rpm

Source:
c499acbae99041e5bba4d447ec818d428bdcd477b7436f49c0499752925ce86b bind-9.11.4-26.P2.el7_9.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

Monday, March 1, 2021

[USN-4737-2] Bind vulnerability

==========================================================================
Ubuntu Security Notice USN-4737-2
March 01, 2021

bind9 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM
- Ubuntu 12.04 ESM

Summary:

Bind could be made to crash or run programs if it received specially
crafted network traffic.

Software Description:
- bind9: Internet Domain Name Server

Details:

USN-4737-1 fixed a vulnerability in Bind. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.

Original advisory details:

It was discovered that Bind incorrectly handled GSSAPI security policy
negotiation. A remote attacker could use this issue to cause Bind to crash,
resulting in a denial of service, or possibly execute arbitrary code. In
the default installation, attackers would be isolated by the Bind AppArmor
profile.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 ESM:
bind9 1:9.9.5.dfsg-3ubuntu0.19+esm4

Ubuntu 12.04 ESM:
bind9 1:9.8.1.dfsg.P1-4ubuntu0.32

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4737-2
https://usn.ubuntu.com/4737-1
CVE-2020-8625

[announce] April NYC*Bug Meeting : HardenedBSD 2021 State of the Hardened Union, by Shawn Webb

April NYC*Bug Meeting announcement:2021-04-07

HardenedBSD 2021 State of the Hardened Union, by Shawn Webb

Over the last few years, since the last State of the Hardened Union,
HardenedBSD has made strides in several areas. We're now focused as a
hardened human rights-focused operating system. This presentation will
dive into recent developments of the OS itself along with our focus on
human rights. We'll highlight some unique areas where HardenedBSD is
being used in production.
For Google meeting details, email to rsvp AT lists.nycbug.org, and details
will be sent on the day of the meeting.

More info: https://www.nycbug.org/index?action=view&id=10682
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org:8080/mailman/listinfo/announce

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com