Wednesday, July 7, 2021

[CentOS-announce] CESA-2021:2658 Important CentOS 7 linuxptp Security Update

CentOS Errata and Security Advisory 2021:2658 Important

Upstream details at : https://access.redhat.com/errata/RHSA-2021:2658

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
5d92d36050c5d7174cd65358882ce23f7eab51af6a02070c42917f77f9dcb3fe linuxptp-2.0-2.el7_9.1.x86_64.rpm

Source:
a0aa8a92f7fc0f029559b186db4016eaab076fb34c67d1aaf9bb54143ca62a9a linuxptp-2.0-2.el7_9.1.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[USN-5006-1] PHP vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5006-1
July 07, 2021

php7.2, php7.4 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in PHP.

Software Description:
- php7.4: HTML-embedded scripting language interpreter
- php7.2: HTML-embedded scripting language interpreter

Details:

It was discovered that PHP incorrectly handled certain PHAR files. A remote
attacker could possibly use this issue to cause PHP to crash, resulting in
a denial of service, or possibly obtain sensitive information. This issue
only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-7068)

It was discovered that PHP incorrectly handled parsing URLs with passwords.
A remote attacker could possibly use this issue to cause PHP to mis-parse
the URL and produce wrong data. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, and Ubuntu 20.10. (CVE-2020-7071)

It was discovered that PHP incorrectly handled certain malformed XML data
when being parsed by the SOAP extension. A remote attacker could possibly
use this issue to cause PHP to crash, resulting in a denial of service.
This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu
20.10. (CVE-2021-21702)

It was discovered that PHP incorrectly handled the pdo_firebase module. A
remote attacker could possibly use this issue to cause PHP to crash,
resulting in a denial of service. (CVE-2021-21704)

It was discovered that PHP incorrectly handled the FILTER_VALIDATE_URL
check. A remote attacker could possibly use this issue to perform a server-
side request forgery attack. (CVE-2021-21705)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
libapache2-mod-php7.4 7.4.16-1ubuntu2.1
php7.4-cgi 7.4.16-1ubuntu2.1
php7.4-cli 7.4.16-1ubuntu2.1
php7.4-fpm 7.4.16-1ubuntu2.1

Ubuntu 20.10:
libapache2-mod-php7.4 7.4.9-1ubuntu1.2
php7.4-cgi 7.4.9-1ubuntu1.2
php7.4-cli 7.4.9-1ubuntu1.2
php7.4-fpm 7.4.9-1ubuntu1.2

Ubuntu 20.04 LTS:
libapache2-mod-php7.4 7.4.3-4ubuntu2.5
php7.4-cgi 7.4.3-4ubuntu2.5
php7.4-cli 7.4.3-4ubuntu2.5
php7.4-fpm 7.4.3-4ubuntu2.5

Ubuntu 18.04 LTS:
libapache2-mod-php7.2 7.2.24-0ubuntu0.18.04.8
php7.2-cgi 7.2.24-0ubuntu0.18.04.8
php7.2-cli 7.2.24-0ubuntu0.18.04.8
php7.2-fpm 7.2.24-0ubuntu0.18.04.8

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5006-1
CVE-2020-7068, CVE-2020-7071, CVE-2021-21702, CVE-2021-21704,
CVE-2021-21705

Package Information:
https://launchpad.net/ubuntu/+source/php7.4/7.4.16-1ubuntu2.1
https://launchpad.net/ubuntu/+source/php7.4/7.4.9-1ubuntu1.2
https://launchpad.net/ubuntu/+source/php7.4/7.4.3-4ubuntu2.5
https://launchpad.net/ubuntu/+source/php7.2/7.2.24-0ubuntu0.18.04.8

[USN-5007-1] libuv vulnerability

==========================================================================
Ubuntu Security Notice USN-5007-1
July 07, 2021

libuv1 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.10
- Ubuntu 20.04 LTS

Summary:

libuv could be made to crash or expose sensitive information if it
received a specially crafted input.

Software Description:
- libuv1: asynchronous event notification library - runtime library

Details:

Eric Sesterhenn discovered that libuv incorrectly handled certain strings.
An attacker could possibly use this issue to access sensitive information
or cause a crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
libuv1 1.40.0-1ubuntu0.1

Ubuntu 20.10:
libuv1 1.38.0-2ubuntu2.1

Ubuntu 20.04 LTS:
libuv1 1.34.2-1ubuntu1.3

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5007-1
CVE-2021-22918

Package Information:
https://launchpad.net/ubuntu/+source/libuv1/1.40.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/libuv1/1.38.0-2ubuntu2.1
https://launchpad.net/ubuntu/+source/libuv1/1.34.2-1ubuntu1.3

Orphaned packages looking for new maintainers

The following packages are orphaned and will be retired when they
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life

Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will fail to install and/or build when the affected package gets retired.

Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>

Full report available at:
https://churchyard.fedorapeople.org/orphans-2021-07-07.txt
grep it for your FAS username and follow the dependency chain.

For human readable dependency chains,
see https://packager-dashboard.fedoraproject.org/
For all orphaned packages,
see https://packager-dashboard.fedoraproject.org/orphan

Package (co)maintainers Status Change
================================================================================
8sync orphan 1 weeks ago
HdrHistogram acaringi, almac, hhorak, 2 weeks ago
jvanek, orphan
JSCookMenu orphan 2 weeks ago
WebCalendar orphan 2 weeks ago
automaton orphan 4 weeks ago
biboumi louizatakk, orphan 2 weeks ago
dpsearch codeblock, jam3s, orphan 5 weeks ago
erlang-riak_pipe bowlofeggs, erlang-maint-sig, 3 weeks ago
orphan
git-cal codeblock, orphan 5 weeks ago
golang-github-atotto-clipboard orphan 0 weeks ago
guile22 mlichvar, orphan 1 weeks ago
java-atk-wrapper omajid, orphan 3 weeks ago
jboss-annotations-1.2-api cfu, cipherboy, ckelley, 2 weeks ago
dmoluguw, jmagne, mharmsen,
orphan
jboss-logmanager cipherboy, dmoluguw, gil, 4 weeks ago
jmagne, lef, orphan
jmc almac, orphan, sasiddiq 2 weeks ago
jmc-core almac, orphan, sasiddiq 2 weeks ago
js-gl-matrix orphan 1 weeks ago
luit ajax, ofourdan, orphan 4 weeks ago
lz4-java orphan 2 weeks ago
mate-applet-softupd orphan 2 weeks ago
mvel orphan 2 weeks ago
owasp-java-encoder almac, orphan, sasiddiq 2 weeks ago
perl-Debug-Client orphan, ppisar 4 weeks ago
perl-MooX-Types-MooseLike orphan 1 weeks ago
perl-Padre orphan, ppisar 4 weeks ago
php-PHPMailer orphan, remi 2 weeks ago
php-captchaphp orphan 2 weeks ago
php-hkit orphan 2 weeks ago
php-pear-Auth-Yubico orphan 2 weeks ago
php-rmccue-requests orphan 3 weeks ago
python-aiozmq orphan 1 weeks ago
python-fn codeblock, orphan 5 weeks ago
python-glusterfs-api humble, orphan 3 weeks ago
python-jsonrpcserver orphan 1 weeks ago
python-nose-cov orphan 1 weeks ago
python-nss jmagne, orphan 2 weeks ago
python-pytest-helpers-namespace orion, orphan, python-sig 0 weeks ago
python-pytest-relaxed orphan 3 weeks ago
python-setuptools-lint orphan 1 weeks ago
python-tempita kylev, orphan 2 weeks ago
python-urlobject orphan 1 weeks ago
qtile cicku, orphan 1 weeks ago
qtpass marcindulak, orphan, vascom 6 weeks ago
rubygem-ditz orphan 5 weeks ago
rubygem-expression_parser orphan 1 weeks ago
rubygem-fssm orphan 1 weeks ago
rubygem-mono_logger orphan 5 weeks ago
rubygem-redis-namespace orphan 5 weeks ago
rubygem-resque orphan 5 weeks ago
rubygem-sdoc orphan 4 weeks ago
rubygem-thin mmagr, orphan, valtri, 4 weeks ago
vondruch
rubygem-trollop orphan 5 weeks ago
rubygem-vegas orphan 5 weeks ago
stax2-api cfu, ckelley, java-maint-sig, 2 weeks ago
jmagne, mharmsen, mizdebsk,
orphan
vim-syntastic orphan 2 weeks ago
woodstox-core cfu, ckelley, java-maint-sig, 3 weeks ago
jmagne, mharmsen, mizdebsk,
orphan

The following packages require above mentioned packages:
Report too long, see the full version at
https://churchyard.fedorapeople.org/orphans-2021-07-07.txt

See dependency chains of your packages at
https://packager-dashboard.fedoraproject.org/
See all orphaned packages at https://packager-dashboard.fedoraproject.org/orphan

Affected (co)maintainers (either directly or via packages' dependencies):
abbra: rubygem-thin, guile22, python-tempita
abompard: python-tempita
acardace: guile22
acaringi: HdrHistogram, guile22
adalloz: guile22
adeza: python-tempita
adrian: guile22
aegorenk: guile22
aglitke: rubygem-thin
ahughes: HdrHistogram, jmc, owasp-java-encoder, jmc-core
ajax: luit
akurtakov: HdrHistogram, jmc, owasp-java-encoder, jmc-core
alakatos: guile22
alexl: guile22
alexlan: guile22
almac: HdrHistogram, jmc, owasp-java-encoder, jmc-core
amerey: rubygem-thin
andreamanzi: python-tempita
andymenderunix: guile22
ankursinha: guile22
anoopcs: rubygem-thin, guile22, python-tempita
ansasaki: guile22
aperezbios: guile22
apevec: python-tempita
arobinso: HdrHistogram, jmc, owasp-java-encoder, jmc-core
asn: rubygem-thin, guile22, python-tempita
asosedkin: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
asrob: guile22
athmane: guile22
atikhonov: guile22
atim: HdrHistogram, jmc, owasp-java-encoder, jmc-core
avagin: guile22
bbockelm: rubygem-thin
bcl: guile22
bcotton: rubygem-thin
bengal: guile22
berrange: rubygem-thin, guile22, python-tempita
besser82: guile22, python-tempita
bkearney: rubygem-thin
bonzini: rubygem-thin, guile22, python-tempita
bowlofeggs: erlang-riak_pipe
bpepple: guile22
branto: python-tempita
buc: guile22
caillon: guile22
caniszczyk: HdrHistogram, jmc, owasp-java-encoder, jmc-core
caolanm: guile22
catanzaro: guile22
cfeist: rubygem-thin
cfu: stax2-api, jboss-annotations-1.2-api, woodstox-core
cheeselee: guile22
chkr: guile22
cicku: guile22, qtile
cipherboy: jboss-annotations-1.2-api, jboss-logmanager
ckelley: stax2-api, jboss-annotations-1.2-api, woodstox-core
clalance: rubygem-thin, guile22, python-tempita
clumens: guile22
cockpit: rubygem-thin, guile22
codeblock: git-cal, python-fn, dpsearch
corsepiu: perl-MooX-Types-MooseLike
cosimoc: guile22
cra: guile22
crobinso: rubygem-thin, guile22, python-tempita
crypto-team: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
cverna: python-tempita
cwickert: guile22
czanik: guile22
dang: rubygem-thin, python-tempita
danw: guile22
davidsch: guile22
dbhole: HdrHistogram, jmc, owasp-java-encoder, jmc-core
dcallagh: python-tempita
dcavalca: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
dcbw: guile22
deamn: HdrHistogram, jmc, owasp-java-encoder, jmc-core
defolos: guile22
deji: guile22
devos: rubygem-thin, guile22, python-tempita
djdelorie: guile22
dmick: python-tempita
dmoluguw: jboss-annotations-1.2-api, jboss-logmanager
dns-sig: guile22
dperpeet: guile22
drsmith2: rubygem-thin
dwmw2: rubygem-thin, guile22, python-tempita
dyfet: guile22
dyoung: guile22
ebaron: HdrHistogram, jmc, owasp-java-encoder, jmc-core
eclipse-sig: HdrHistogram, jmc, owasp-java-encoder, jmc-core
eclipseo: rubygem-thin, golang-github-atotto-clipboard, guile22, python-tempita
eerlands: rubygem-thin
ehabkost: rubygem-thin, guile22, python-tempita
ekkis: guile22
ellert: python-tempita, php-PHPMailer
elmarco: rubygem-thin, guile22
enslaver: guile22
erack: guile22
ericb: rubygem-thin, guile22
erlang-maint-sig: erlang-riak_pipe
eseyman: perl-MooX-Types-MooseLike
f1ash: rubygem-thin
fab: rubygem-thin, guile22
fale: guile22
fbo: python-tempita
fche: rubygem-thin
feborges: rubygem-thin
fgiudici: guile22
fidencio: rubygem-thin, guile22
filbranden: guile22
filiperosset: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
fjanus: guile22
flepied: guile22
fschwarz: guile22
galileo: HdrHistogram, jmc, owasp-java-encoder, jmc-core
gbcox: guile22
gchamoul: guile22, python-tempita
gd: rubygem-thin, guile22, python-tempita
giallu: python-tempita, php-PHPMailer
gil: jboss-logmanager
gnat: guile22
gnome-sig: rubygem-thin, guile22
go-sig: golang-github-atotto-clipboard, python-tempita
green: guile22
grover: rubygem-thin, python-tempita
guidograzioli: guile22
harald: guile22
herrold: guile22
hguemar: guile22
hhorak: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
hubbitus: guile22
humble: rubygem-thin, python-glusterfs-api
huzaifas: guile22
iarnell: perl-MooX-Types-MooseLike
iboukris: rubygem-thin, guile22, python-tempita
idevat: rubygem-thin
ignatenkobrain: guile22, python-tempita
imcleod: rubygem-thin
infra-sig: python-tempita
isimluk: guile22
iucar: HdrHistogram, jmc, owasp-java-encoder, jmc-core
ixs: guile22
jadahl: guile22
jam3s: dpsearch
janfrode: guile22
jarrpa: rubygem-thin, guile22, python-tempita
java-maint-sig: woodstox-core, jmc-core, HdrHistogram, jmc, stax2-api,
owasp-java-encoder
java-sig: woodstox-core, jmc-core, HdrHistogram, jmc, stax2-api, owasp-java-encoder
jaymzh: golang-github-atotto-clipboard
jcaratzas: python-tempita
jenslody: HdrHistogram, jmc, owasp-java-encoder, jmc-core
jerboaa: HdrHistogram, jmc, owasp-java-encoder, jmc-core
jforbes: rubygem-thin, guile22, python-tempita
jgorig: guile22
jgrulich: guile22
jgu: guile22
jhrozek: guile22
jiffintt: rubygem-thin, python-tempita
jistone: rubygem-thin
jjanco: HdrHistogram, jmc, owasp-java-encoder, jmc-core
jjelen: guile22
jjohnstn: HdrHistogram, jmc, owasp-java-encoder, jmc-core
jkastner: guile22
jklimes: guile22
jlayton: rubygem-thin, guile22, python-tempita
jmagne: woodstox-core, python-nss, stax2-api, jboss-annotations-1.2-api,
jboss-logmanager
jorton: guile22
jpacner: guile22
jpena: python-tempita
jplesnik: rubygem-thin, perl-MooX-Types-MooseLike
jpokorny: guile22
jruzicka: guile22
jskala: guile22
jskarvad: guile22
jsteffan: rubygem-thin
jstephen: rubygem-thin, guile22, python-tempita
jstribny: rubygem-thin
jsynacek: guile22
jtaylor: guile22
jvanek: woodstox-core, jmc-core, HdrHistogram, jmc, stax2-api, owasp-java-encoder
jwrdegoede: guile22
kalev: guile22
kdaniel: HdrHistogram, jmc, owasp-java-encoder, jmc-core
kde-sig: rubygem-thin
kdudka: guile22
ke4qqq: python-tempita
kengert: HdrHistogram, jmc, owasp-java-encoder, jmc-core
kevin: rubygem-thin, guile22, python-tempita, python-nss
kkeithle: rubygem-thin, python-tempita
kkoukiou: rubygem-thin
ktdreyer: python-tempita
kwenning: guile22
kwizart: guile22
kylev: python-tempita
laine: rubygem-thin, guile22, python-tempita
landgraf: guile22
lbazan: python-tempita
lberk: rubygem-thin
lef: jmc-core, HdrHistogram, jmc, owasp-java-encoder, jboss-logmanager
lennart: guile22
libvirt-maint: rubygem-thin, guile22, python-tempita
limb: guile22
ljavorsk: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
lkundrak: rubygem-thin, guile22, python-tempita
lmacken: python-tempita
lnie: rubygem-thin
lnykryn: guile22
lon: guile22
louizatakk: biboumi
lslebodn: guile22
lupinix: guile22
maha: guile22
marcindulak: qtpass
martinkg: guile22
martinpitt: rubygem-thin, guile22
marx: rubygem-thin, guile22
matt: rubygem-thin
matyas: rubygem-thin
mbacovsk: python-tempita
mbarnes: guile22
mbooth: HdrHistogram, jmc, owasp-java-encoder, jmc-core
mcermak: rubygem-thin
mclasen: guile22
mdarade: guile22
mdbooth: rubygem-thin
mharmsen: stax2-api, jboss-annotations-1.2-api, woodstox-core
mhlavink: rubygem-thin, guile22
michaelc: rubygem-thin, python-tempita
michalvala: HdrHistogram, jmc, owasp-java-encoder, jmc-core
michich: guile22
mikep: jmc-core, HdrHistogram, jmc, rubygem-thin, owasp-java-encoder
mitr: python-nss
mizdebsk: woodstox-core, jmc-core, HdrHistogram, jmc, stax2-api, owasp-java-encoder
mjakubicek: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
mjw: rubygem-thin
mkrizek: rubygem-thin
mlichvar: guile22
mlisik: rubygem-thin
mlombard: rubygem-thin, python-tempita
mmagr: rubygem-thin
mmarusak: rubygem-thin, guile22
mmuzila: guile22
moceap: guile22
moezroy: guile22
mohammedisam: HdrHistogram, jmc, owasp-java-encoder, jmc-core
monnerat: guile22
mooninite: guile22
mrunge: python-tempita
mruprich: guile22
mschorm: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
mschwendt: guile22
msekleta: guile22
msivak: rubygem-thin
mstevens: guile22
mtasaka: guile22
myoung: guile22
mzidek: guile22
nalin: guile22
nb: guile22
neuro-sig: python-tempita
ngompa: rubygem-thin, guile22, python-tempita
niveusluna: guile22
nmav: guile22
nonamedotc: guile22
notting: guile22
nucleo: guile22
oalbrigt: rubygem-thin, guile22
obnox: rubygem-thin, guile22, python-tempita
odubaj: HdrHistogram, jmc, owasp-java-encoder, jmc-core
ofourdan: luit
oget: HdrHistogram, jmc, owasp-java-encoder, jmc-core
oliver: HdrHistogram, jmc, owasp-java-encoder, jmc-core
omajid: jmc-core, java-atk-wrapper, jmc, HdrHistogram, owasp-java-encoder
omular: rubygem-thin
ondrejj: python-tempita
openstack-sig: python-tempita
orion: python-pytest-helpers-namespace, guile22
osier: rubygem-thin, guile22, python-tempita
otaylor: guile22
panovotn: guile22
pawsa: guile22
pbrezina: guile22
pemensik: guile22
peter: erlang-riak_pipe, guile22
pfrankli: guile22
pghmcfc: guile22
phatina: guile22
phracek: guile22
phrdina: rubygem-thin
pmikova: HdrHistogram, jmc, owasp-java-encoder, jmc-core
pmkovar: guile22
ppisar: guile22, perl-Debug-Client, perl-Padre, perl-MooX-Types-MooseLike
praiskup: guile22
psabata: guile22
pwalter: guile22
pwouters: guile22
python-sig: python-pytest-helpers-namespace
qa-tools-sig: rubygem-thin
quintela: rubygem-thin, guile22, python-tempita
radekmanak: HdrHistogram, jmc, owasp-java-encoder, jmc-core
radez: python-tempita
rakesh: guile22
ralph: guile22, python-tempita
raphgro: rubygem-thin
rathann: guile22
rdieter: guile22
remi: php-PHPMailer
reznik: guile22
rgrunber: HdrHistogram, jmc, owasp-java-encoder, jmc-core
rhughes: guile22
richardfearn: HdrHistogram, jmc, owasp-java-encoder, jmc-core
ricky: python-tempita
rishi: guile22
rjones: rubygem-thin, guile22, python-tempita
rlescak: guile22
robert: guile22
rombobeorn: guile22
rrankin: guile22
rrelyea: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
rsroka: guile22
rstrode: guile22
rtcm: guile22
ruben: rubygem-thin
ruby-packagers-sig: rubygem-thin
sagitter: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
sailer: guile22
salimma: guile22
sandeen: python-tempita
sasiddiq: jmc, owasp-java-encoder, HdrHistogram, jmc-core
sbonazzo: rubygem-thin
sbose: guile22
scottt: HdrHistogram, jmc, owasp-java-encoder, jmc-core
scox: rubygem-thin
sergiodj: guile22
sergiomb: guile22
sgallagh: guile22
sgordon: guile22
sgros: guile22
sgrubb: guile22
sham1: guile22
sharkcz: guile22
shlomif: perl-MooX-Types-MooseLike
simo: rubygem-thin, guile22, python-tempita
simonm: python-tempita
skoduri: rubygem-thin, python-tempita
slaanesh: guile22, perl-MooX-Types-MooseLike
smakarov: rubygem-thin
smani: guile22, perl-MooX-Types-MooseLike
smilner: python-tempita
spot: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
ssahani: guile22
ssp: guile22
sssd-maintainers: guile22
stefanb: guile22
stefanberger: guile22
stefw: guile22
steve: rubygem-thin, guile22, python-tempita, perl-MooX-Types-MooseLike
steved: guile22
stevetraylen: rubygem-thin
stingray: guile22, python-tempita
svashisht: guile22
swt2c: guile22
systemd-maint: guile22
tartare: guile22
tbabej: guile22
tdawson: rubygem-thin, rubygem-trollop
tdecacqu: python-tempita
terjeros: rubygem-thin, python-tempita
teuf: rubygem-thin, guile22
tflink: rubygem-thin
thaller: guile22
thozza: guile22
timn: guile22
tkorbar: guile22
tkrizek: guile22
tmraz: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
tojeline: rubygem-thin
totol: guile22
tpopela: jmc-core, HdrHistogram, jmc, guile22, owasp-java-encoder
tstclair: rubygem-thin
ttheisen: rubygem-thin
twaugh: guile22
ueno: guile22
ultrafredde: guile22
uraeus: guile22
uwog: guile22
valtri: rubygem-thin, rubygem-trollop
vascom: rubygem-thin, qtpass
vcrhonek: rubygem-thin
veillard: rubygem-thin, guile22, python-tempita
victortoso: rubygem-thin
virtmaint-sig: rubygem-thin, guile22, python-tempita
volter: guile22
vondruch: rubygem-thin, rubygem-trollop
wakko666: guile22
wart: guile22
wcohen: rubygem-thin
wef: guile22
wolfy: guile22
wtaymans: guile22
xaeth: rubygem-thin
xavierb: perl-MooX-Types-MooseLike
xiubli: rubygem-thin
yaneti: guile22
yuwata: guile22
zbyszek: guile22
zdohnal: guile22
zeenix: rubygem-thin
zfridric: guile22
zuul: python-tempita

--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/main/f/scripts/find_unblocked_orphans.py
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

List of long term FTBFS packages to be retired in August

Dear maintainers.

Based on the current fail to build from source policy, the following packages
will be retired from Fedora 35 approximately one week before branching (August
2021).

Policy:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

The packages in rawhide were not successfully built at least since Fedora 32.

This report is based on dist tags.

Packages collected via:
https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb

If you see a package that was built, please let me know.
If you see a package that should be exempted from the process, please let me
know and we can work together to get a FESCo approval for that.

If you see a package that can be rebuilt, please do so.

Package (co)maintainers Latest build
=============================================================================
cardpeek kalev Fedora 32
percona-xtrabackup slaanesh, slankes Fedora 32
proxyfuzz psklenar Fedora 32
sugar-view-slides callkalpa, chimosky, pbrobinson, tuxbrewr Fedora 31
zram pbrobinson Fedora 32

The following packages require above mentioned packages:
Depending on: percona-xtrabackup (1), status change: 2020-11-22 (32 weeks ago)
holland (maintained by: immanetize, jeffreyness, survient)
holland-xtrabackup-1.2.4-2.fc35.noarch requires /usr/bin/xtrabackup

Affected (co)maintainers
callkalpa: sugar-view-slides
chimosky: sugar-view-slides
immanetize: percona-xtrabackup
jeffreyness: percona-xtrabackup
kalev: cardpeek
pbrobinson: sugar-view-slides, zram
psklenar: proxyfuzz
slaanesh: percona-xtrabackup
slankes: percona-xtrabackup
survient: percona-xtrabackup
tuxbrewr: sugar-view-slides
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Tuesday, July 6, 2021

F35 Change: GHC 8.10 and Stackage lts-18 (Self-Contained Change proposal)

https://fedoraproject.org/wiki/Changes/GHC_8.10_%26_Stackage_18

== Summary ==
The GHC Haskell compiler will be updated from major version 8.8 to 8.10,
and Haskell packages will be updated from Stackage LTS 16 to LTS 18 versions.

== Owner ==
* Name: [[User:Petersen| Jens Petersen]] (Haskell SIG)
* Email: <petersen@redhat.com>


== Detailed Description ==
For Fedora 35, the GHC Haskell compiler will be updated from version
8.8.4 to the latest stable 8.10.5 release (rebasing from the ghc:8.10
module stream).
Along with this, Haskell packages in [https://www.stackage.org
Stackage] (the stable Haskell source package distribution) will be
updated from the versions in LTS 16 to latest LTS 18 release.
Haskell packages not in Stackage will be updated to the latest
appropriate version in the upstream [https://hackage.haskell.org
Hackage] package repository.

On the s390x architecture, ghc-8.10 now supports the llvm backend,
which should improve s390x performance significantly.


== Benefit to Fedora ==
Fedora users will benefit from access to the latest stable Haskell
compiler release, package tools, and current stable Haskell packages
from Stackage LTS.

GHC 8.10 features performance improvements, new language extension
features, and bugfixes (see the release notes linked in the
Documentation section for more details).

== Scope ==
* Proposal owners:
** rebase ghc to 8.10.5
** update ghc-rpm-macros to the final version for F35 [done]
** refresh packagings with the latest cabal-rpm release
** update packages to latest [https://www.stackage.org/lts-18.1
Stackage LTS 18.1] versions using cabal-rpm
** build all the packages in a Koji sidetag repo in dependency order
** When finished push all builds through Bodhi to Rawhide before the
mass rebuild

* Release engineering: N/A
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: N/A (not needed for this Change)

== Upgrade/compatibility impact ==
Any dropped packages will have obsoletes added.
Otherwise there should not be any direct upgrade impact.

Users' Haskell projects will get rebuilt with ghc-8.10 when they next
build them and might need small tweaks.

== How To Test ==
* install ghc and cabal-install
* install pandoc, ShellCheck, git-annex
* install ghc-*-devel or ghc-*-prof or ghc-*-doc
* cabal-rpm builddep <favouritepackage>; cabal install <favouritepackage>
* test upgrades of F34 Haskell packages to F35

== User Experience ==
Users will have the most recent stable major version of `ghc` and
Haskell libraries and tools available to them.
This makes it easier to build the latest versions of Haskell projects.

In particular `cabal-install` will be updated from 3.0 to 3.2 and
`stack` from 2.3 to 2.7.

== Dependencies ==
(not provided)

== Contingency Plan ==
* Contingency mechanism: (What to do? Who will do it?)
** Change owner will drop the new builds and revert back to the versions in F34.
* Contingency deadline: Beta Freeze

== Documentation ==
https://downloads.haskell.org/~ghc/8.10.5/docs/html/users_guide/8.10.1-notes.html


--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

F35 Change: tzdata-minimal (Self-Contained Change proposal)

https://fedoraproject.org/wiki/Changes/tzdata-minimal

== Summary ==
Split the tzdata package into two parts - tzdata and tzdata-minimal.
tzdata will require tzdata-minimal. tzdata-minimal provides the
minimal files needed to support UTC on containers.

== Owner ==
* Name: Patsy Griffin (Franklin)
* Email: patsy@redhat.com


== Detailed Description ==
This is the first step towards providing support for a minimal, UTC
only, version of tzdata for containers. The tzdata-minimal package
will be a stand-alone, UTC only, subset of tzdata. The tzdata package
will require tzdata-minimal.

With this framework in place, other packages can develop code to
detect a minimal tzdata installation. These packages will also need
to provide appropriate messages when users request timezone
information not available when only tzdata-minimal is installed.

== Feedback ==
We have had requests for this functionality in order to support
minimal container installations. Currently some container kickstart
installations already ad hoc remove most of the timezone information
provided by tzdata, leaving only UTC support available. This change
provides a formal method of providing this support.

Both the glibc and python teams are aware of this proposed change.
This change does not currently require changes in their code. The
goal is for those packages that currently require tzdata as part of
their build or install, move towards recommending tzdata instead.

== Benefit to Fedora ==
This change will reduce the size of base container installations.

== Scope ==
* Proposal owners: Implement the proposal.
* Other developers: Developers need to ensure that their packages
continue to build and install with the new split tzdata/tzdata-minimal
package changes.

* Release engineering: No coordination required with Release Engineering.
* Policies and guidelines: The policies and guidelines do not need to
be updated.
* Trademark approval: N/A (not needed for this Change)
* Alignment with Objectives: N/A

== Upgrade/compatibility impact ==
The only visible change will be a new package tzdata-minimal required by tzdata.


== How To Test ==
Run a dnf upgrade of tzdata and observe that tzdata-minimal is now
also installed as a dependency.


== User Experience ==
Users will see that new updates to tzdata include a new package
dependency on tzdata-minimal.


== Dependencies ==
This change does not require or depend on changes to other packages.
However, we hope that dependent packages will work towards
recommending tzdata for builds and installs rather than requiring it.


== Contingency Plan ==
* Contingency mechanism: If we are unable to complete this feature by
the final development freeze, we will revert to the shipped
configuration.
* Contingency deadline: 100% Code complete deadline
* Blocks release? No

== Documentation ==
No documentation changes are needed at this time.


== Release Notes ==
The tzdata package is now divided into a UTC only package,
tzdata-minimal, and tzdata.



--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Re: F35 Change: Disable SHA1 In OpenDNSSec (Self-Contained Change proposal)

Hi Paul, all,

On Tue, Jun 29, 2021 at 1:40 AM Paul Wouters <paul@nohats.ca> wrote:
>
> On Mon, 28 Jun 2021, Ben Cotton wrote:
>
> > https://fedoraproject.org/wiki/Change/DisableSHA1InOpenDNSSec
>
> > == Detailed Description ==
> >
> > OpenDNSSec changed the default behavior to not include SHA1 DS by
> > default, and added the -sha1 knob as an immediately-deprecated
> > compatibility knob in version 2.1.0 (2017-2): "OPENDNSSEC-552: By
> > default 'ods-enforcer key export –ds' included the SHA1 version of the
> > DS. SHA1 use is discouraged in favour of SHA256. To get the SHA1 DS
> > use the –sha1 flag. This flag is immediately deprecated and will be
> > removed from future versions of OpenDNSSEC." (see ChangeLog:
> > https://www.opendnssec.org/archive/releases/ ).
> >
> > The proposal is to disable the -sha1 knob in Fedora. I will also open
> > an issue upstream to remove all the sha1-related code.
>
> This change makes me a bit nervous, and I'm the author of RFC 8624 that
> recommennds not using SHA-1 for DS/CDS records anymore.
>
> https://datatracker.ietf.org/doc/html/rfc8624#section-3.3
>
> > Supporting statement
> > [https://www.icann.org/en/blogs/details/its-time-to-move-away-from-using-sha-1-in-the-dns-24-1-2020-en
> > [from ICANN] (2020-1-24): "Now is the time for administrators of zones
> > at all levels of the DNS to stop using SHA-1 and change to algorithms
> > using stronger hashes."
>
> While this is true, the order of where things need to change are:
>
> 1 Discourage, but not block, the use of SHA-1. Eg remove it from the default set.
> 2 Ensure the migration of SHA-1 based records to SHA-256 is taking place
> 3 remove support for SHA-1
>
> This plan assumes we are in phase3. I would say we are in phase2.
>
> Remember, any domain that depends on SHA-1 is going to be more secure
> than being marked as insecure because SHA-1 is rejected. This is somewhat
> different from like SHA-1 support for authentication where the rejection
> of a weaker algorithm forces the use of a stronger algorithm.
>
> The DNSSEC fallback when an algorithm is not supported is to go insecure,
> not insist on a more secure SHA-2 that is not there. With DNSSEC,
> there is not client-server exchange like with TLS or IPsec. There is
> a producer on one end, and a consumer on the other end. The two do not
> negotiate crypto parameters.
>
> > == Benefit to Fedora ==
> > * This change makes sure OpenDNSSec in Fedora follows ICANN's
> > guidelines and does not propose SHA1 DS. This is is needed given the
> > [https://sha-mbles.github.io/ latest attacks against SHA-1]. More
> > in-depth articles are available
> > [https://www.dns.cam.ac.uk/news/2020-01-09-sha-mbles.html there] and
> > [https://mailarchive.ietf.org/arch/msg/dnsop/hA4Ur9qxRJIUo13Pjpmrm_va7cs/
>
> I know that a few people believe that shambles can in theory be abused
> with DNSSEC, but a lot of people also believe the constrains of DNS
> RRsets make this impossible. But even _if_ it is possible, it would
> only affect multiple domains that share the same private key that made
> the SHA-1 signature. And then we are talking about RRSIG records and
> not, as in this proposal, the DS/CDS RDATA content.
>
> > Patch the enforcer so that bsha1 is not honored anymore:
>
> I don't think fedora should move faster than upstream opendnssec. I
> believe the people at the IETF and the software developers of the DNS
> software are more aware of where we are in the migration path than
> individual Fedora developers.

Thanks a lot for your input. I am withdrawing the change proposal now
as it makes no sense indeed to have Fedora move faster than upstream
on this.

Regards,
François



> > == Upgrade/compatibility impact ==
> > Zones with SHA-1 signatures can be migrated to SHA-256 by re-signing the zone.
>
> The RRSIG signature is not related to the DS signature. Zone resigning
> is something completely different from the DS/CDS records. Those records
> are signed by the parent zone, and use whatever algorithm the parent
> zone uses, which the child zone cannot dictate.
>
> > This change might break (very old) clients that only recognize SHA-1
> > but these should already be broken (on the Internet at least) because
> > the root zone is signed with SHA-256 only.
>
> The root zone has no DS record, so this statement does not make sense.
> The RRSIG signature algorithm is unrelated to the DS/CDS record RRdata
> that contains a hash of the child's public key, where the hash is created
> with SHA-1 or SHA-2.
>
> > == User Experience ==
> >
> > OpenDNSSec in Fedora can currently be used to sign zones with SHA1.
> > With this change, this will no longer be possible. The migration from
> > SHA1 is underway anyway.
>
> So there are two things that really need to be clarified for this
> proposal. Is it talking about DS/CDS signature algorithm as per IANA
> registry http://www.iana.org/assignments/ds-rr-types, or are we talking
> about DNSKEY signature algorithm, that is responsble for signing all
> the zone data, that uses a hash algorithm or SHA-1 or better. Based on
> the description, I am a bit worried that it is not entirely clear what
> the proposed change actually is.
>
> Please feel free to reach out to me directly to talk about this feature
> request.
>
> Paul
> _______________________________________________
> devel mailing list -- devel@lists.fedoraproject.org
> To unsubscribe send an email to devel-leave@lists.fedoraproject.org
> Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org
> Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

Monday, July 5, 2021

[announce] July 7 NYC*BUG: Why Privacy/Security (usually) Needs Anonymity

Why Privacy/Security (usually) Needs Anonymity, George Rosamond
2021-07-07 @ 18:45 EDT - Zoom
https://www.nycbug.org/index?action=view&id=10685

IMPORTANT: For Zoom meeting details, email to rsvp AT lists.nycbug.org
by noon EDT, and details will be sent on the day of the meeting. Q&A
will be via IRC on libera.chat, channel #nycbug

In an uncensored and unleashed version of an ISSA Privacy SIG
presentation from June, George will be making a strong declaration
relevant to the times: why privacy and security (usually) need anonymity.

As privacy finally becomes an acceptable and even popular service and
product feature, its sibling anonymity is still carries nefarious
connotations. Privacy advocates onced faced questions like "do you have
something to hide?" Similar retorts are now posed to anonymity advocates.

But creating privacy solutions without anonymity means ignoring a core
aspect of (corporate,nation-state) surveillance: metadata. Knowing who
talked to whom, when did they talk and for how long, makes the actual
content of the communications less relevant in an era of mass surveillance.

Cut down to the basics and unfettered, we'll look at the changing
environment of privacy, relating it to anonymity then approach some of
the basic ingredients necessary for adapting anonymity to technical
solutions today.

And yes, the relevance of BSD Unix will be woven throughout, somehow,
someway.

We encourage questions and even wildly incorrect opinions before the
meeting on the talk@ mailing list and on IRC at libera.net #nycbug.

For Zoom meeting details, email to rsvp AT lists.nycbug.org, and details
will be sent on the day of the meeting. Q&A will be via IRC on
libera.chat, channel #nycbug

Speaker Biography

George Rosamond is a founder and long-time admin@ member of NYC*BUG.
He's the co-founder and CTO of ClearOPS, a privacy and security
technology startup.

A sysadmin by trade with citizenship in BSD Unix land, his area of
interest and expertise lies with privacy enhancing technologies, most
importantly with the Tor Project. He thrives on creating and designing
unorthodox solutions to ordinary problems, but so do most other people
in the *BSD community.
_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org:8080/mailman/listinfo/announce

[USN-5005-1] DjVuLibre vulnerability

==========================================================================
Ubuntu Security Notice USN-5005-1
July 05, 2021

djvulibre vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM

Summary:

DjVuLibre could be made to crash or execute arbitrary code if it
opened a specially crafted file.

Software Description:
- djvulibre: DjVu image format library and tools

Details:

It was discovered that DjVuLibre incorrectly handled certain djvu files.
An attacker could possibly use this issue to execute arbitrary code or
cause a crash.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libdjvulibre21 3.5.27.1-8ubuntu0.4

Ubuntu 16.04 ESM:
libdjvulibre21 3.5.27.1-5ubuntu0.1+esm2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5005-1
CVE-2021-3630

Package Information:
https://launchpad.net/ubuntu/+source/djvulibre/3.5.27.1-8ubuntu0.4

Planned Outage - System upgrades - 2021-07-06 19:00 UTC

Planned Outage - System upgrades - 2021-07-06 19:00 UTC

There will be an outage starting at 2021-07-06 19:00UTC,
which will last approximately 4 hours.

To convert UTC to your local time, take a look at
http://fedoraproject.org/wiki/Infrastructure/UTCHowto
or run:

date -d '2021-07-06 19:00UTC'

Reason for outage:

We will be applying updates and rebooting servers into new kernels. During the outage window some services may be up and down, but we will try and keep downtime as minimal as possible.

Affected Services:

Most services may be affected for times during the outage window.

Ticket Link:

https://pagure.io/fedora-infrastructure/issue/10068

Please join #fedora-admin or #fedora-noc on irc.freenode.net
or add comments to the ticket for this outage above.


Mark

Friday, July 2, 2021

armv7 maintainer test instances back online

Greetings.

I'm happy to announce that:

armv7-test01.fedorainfracloud.org
armv7-test02.fedorainfracloud.org

are back online for packager maintainers to use to test and debug
packages. They are setup the same as the armv7 koji builders with the
same resources and on the same underlying hardware.

For more information and a list of all maintainer test instances, please
see:
https://fedoraproject.org/wiki/Test_Machine_Resources_For_Package_Maintainers

For any issues or problems with the instances, please file a
infrastructure ticket:

https://pagure.io/fedora-infrastructure/issues/

Thanks and happy debugging.

kevin