Tuesday, September 24, 2013

[USN-1967-1] Django vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSQdMgAAoJEGVp2FWnRL6TgFQP/0c30GQ2m7O6PFCE+FiGrEWh
h3x6xGKOV6zSYvKv7JhmDtxGaMoMOP9TU+RnwCsFcq6rqz9mbJwPcgJLpH9gHCTq
5d9t69wODEW/WTyBkl01p3LpbIu/0GdxgnXk9xubJQmu49TPiG3Q2ZBltqBP+50W
Z/YmQOcMeCkLneEfX/wgsbQ277/pGZsQg6p+ZR97zyUsnr5Zo55NNYM65khQFGJI
UZ3ZzYnHpbdmpoy/zWE34/YZLEoq1+wztBLkLFWXY2er2eagX5BIgQB/lzfaosph
dGMyB4Q7WFVNdlQi3fhWpiIpUAYvEXRwXi1Xa6nqn4tl1AoFKb0I5xOJysqLywF0
keWzmF/+cehBgrd+Fr2iSLEysy7Aw9B46BTCftNDVTA8B1yiN5o4cJmf1DF6nPA4
knNSBNeW4wq0Fujkql0IjGj51UrFZWMay76bn5U1UAZOEygwSPnuOZ2HX+gUgGpm
yvv3gADiigwie1hD6NplIdQTgTqtD4W9nKKjy5y31HblNFK5t3/Xm3LqWvPA2ZEu
lbjWimf5DBBeAjLGFru8C6jxrrC5pCmv6FK9ce6LjRp34ayiyvoIT2xirYJ4MFuj
n4Vl19ThsC0E7mtgIEHUeUBtmIBq2irYOaHp/gIzpRK2C9Jt2JlHhSV+gVX151Lo
NSSZLAjbrBZ1iSMrZvlR
=MAns
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1967-1
September 24, 2013

python-django vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in Django.

Software Description:
- python-django: High-level Python web development framework

Details:

It was discovered that Django incorrectly handled large passwords. A remote
attacker could use this issue to consume resources, resulting in a denial
of service. (CVE-2013-1443)

It was discovered that Django incorrectly handled ssi templates. An
attacker could use this issue to read arbitrary files. (CVE-2013-4315)

It was discovered that the Django is_safe_url utility function did not
restrict redirects to certain schemes. An attacker could possibly use this
issue to perform a cross-site scripting attack.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-django 1.4.5-1ubuntu0.1

Ubuntu 12.10:
python-django 1.4.1-2ubuntu0.4

Ubuntu 12.04 LTS:
python-django 1.3.1-4ubuntu1.8

Ubuntu 10.04 LTS:
python-django 1.1.1-2ubuntu1.9

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1967-1
CVE-2013-1443, CVE-2013-4315

Package Information:
https://launchpad.net/ubuntu/+source/python-django/1.4.5-1ubuntu0.1
https://launchpad.net/ubuntu/+source/python-django/1.4.1-2ubuntu0.4
https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.8
https://launchpad.net/ubuntu/+source/python-django/1.1.1-2ubuntu1.9

[USN-1966-1] Samba vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSQdLvAAoJEGVp2FWnRL6TLfMP/jh2c5QUA4jwlEbZZ6AWbcMl
l51o/imR9CzYSZQ6F1uB8+TpW6LO6SsRK5mOgVAapcKD5wAPXn1fJXVkcCirh5Yv
wiDQVa4eElsmhSaEhjKy9jJ2uvEaAshEv6QVgxpMX3CZMaU/OC3n/qgz/QCOpDO0
4h5u629PflcSopqTBpSzyQr70h3baacg72SQWxAufETR1hEzdNawZoCYQhyf8hZW
qS6TzTGPw90tOGyB37A+8qA0rx6KSiZajNXABWs+KCAjplIjinCE48Ya81+iy+o7
crD+y76hlk+8S+sadvUE819YtMe4HEfNrfDA5Wj9TQMEoWY0H+W3u9TmhOr80fZN
bVokSO5BRnaZlsdXSXKtZP27Wj28R2pE6L0gZyaJygaCl1kKBojit9vPH0TBWNUK
AdUJapbZwjbu1Gl+CWonvLB6AcWi5ObcMYoKxV1pfw+C4cHkEAhdyI08lbNNgok2
MuvM8GuYnmGM+xfBfN3GG8Wi8aB0VNWgvf5BpoLBMXOHsgfdIQzrvqO4TJ5Rb/Su
78c1l8EL4OA0/vUq4qYO2qtc8OZWCqfABRfIThFUlbj+PWDXF0rTjKIhrd9KdP0n
JFqvcObCpgcWWBExwnnKxOKT3IDHpIYh1pI0dGeVnMNnDd2SA+RgXSmvPzymUWH6
ttGWaHR+s/LbJB5VrTlE
=yiU7
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1966-1
September 24, 2013

samba vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

Samba could be made to hang if it received specially crafted network
traffic.

Software Description:
- samba: SMB/CIFS file, print, and login server for Unix

Details:

Jeremy Allison discovered that Samba incorrectly handled certain extended
attribute lists. A remote attacker could use this issue to cause Samba
to hang, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
samba 2:3.6.9-1ubuntu1.1

Ubuntu 12.10:
samba 2:3.6.6-3ubuntu5.2

Ubuntu 12.04 LTS:
samba 2:3.6.3-2ubuntu2.8

Ubuntu 10.04 LTS:
samba 2:3.4.7~dfsg-1ubuntu3.12

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1966-1
CVE-2013-4124

Package Information:
https://launchpad.net/ubuntu/+source/samba/2:3.6.9-1ubuntu1.1
https://launchpad.net/ubuntu/+source/samba/2:3.6.6-3ubuntu5.2
https://launchpad.net/ubuntu/+source/samba/2:3.6.3-2ubuntu2.8
https://launchpad.net/ubuntu/+source/samba/2:3.4.7~dfsg-1ubuntu3.12

Announcing the release of Fedora 20 Alpha!

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.21 (GNU/Linux)

iQIcBAEBCgAGBQJSQZrIAAoJEEs3sNgP+7teN7MQAKLU5PUXilojizgTNnRCk4lI
iEPDJ8y68cpBLKOXWkWAade3bXNwruc7tVvdwcdb4G5tj7KNQ5XJ2MOHH3wA6NOk
7zPZE9d++QbJvLabDoupgtEIuKFoISjXPuxLT5DAxw3p7AJeo+t4S5r6BUHpxcqd
ymAbaoUEQdcUTVCzQKYv/KsQ0w15mdHDIJhizzFaCfStJF8lgspzqb0OpQv6kIAu
nc9WhM646l7KuXEq5HNrhz626LI+Gko+KL/rbFVOt36lVN6xr+clf4lpIMKzEB4Z
Rhi2xd1YUX94/OIYyVmFifAHYPUjoTKycftULrr1NyDKEsTJ9z3wQ95GM10nyort
XwRXxmwG3NkL4Pr1QWLt3MiSMcAlJWCvPBfaqR3UHyh+KnJj3HCaCcgY1bPbyE2d
YMlNiZinEJ4CkRtRAdvTKp+W8SlQcR35tBKNYem+j3P1oYDI0y32BuCcwGEyq07T
iiBlqz57FBgzaKY/N43Rq6sc+s056Chk3ZP+AGW6saBSRcMAjXNsIZaU9i708tLH
XeMaJzRbGt2X+/C/sgbFG5zo4IOk2qMNeiXVWe5Gbgv10fnjAB1JnQD5RPukWSAa
ZNNcDGuru7XL+EM4rdUCpxz5+673PAVW9BiMkytVnsXV1nPjThSHFny4mzK+dSqL
cm5AiFmcSKOy1uuauwwk
=Ut5q
-----END PGP SIGNATURE-----
The Fedora 20 "Heisenbug" alpha release has arrived with a preview of
the latest fantastic, free, and open source technology currently under
development. Take a peek inside:

http://fedoraproject.org/get-prerelease

*** What is the Alpha Release? ***

The Alpha release contains all the exciting features of Fedora 20 in a
form that anyone can help test. This testing, guided by the Fedora QA
team, helps us target and identify bugs. When these bugs are fixed, we
make a Beta release available. A Beta release is code-complete and
bears a very strong resemblance to the third and final release. The
final release of Fedora 20 is expected in early December.

We need your help to make Fedora 20 the best release yet, so please
take some time to download and try out the Alpha and make sure the
things that are important to you are working. If you find a bug, please
report it – every bug you uncover is a chance to improve the experience
for millions of Fedora users worldwide. Together, we can make Fedora a
rock-solid distribution. We have a culture of coordinating new features
and pushing fixes upstream as much as feasible and your feedback will
help improve not only Fedora but Linux and free software on the whole.
(See the end of this announcement for more information on how to help.)

*** Changes ***

Fedora prides itself on bringing cutting-edge technologies to users of
open source software around the world, and this release continues that
tradition. No matter what you do, Fedora 20 has the tools you need to
help you get things done.

To see how Fedora 20 is evolving from Fedora 19, see the accepted
changes here:

http://fedoraproject.org/wiki/Releases/20/ChangeSet

== 10 Years of Fedora ==

The Fedora 20 release coincides nicely with the 10th anniversary of
Fedora. The first Fedora release (then called Fedora Core 1) came out
on November 6, 2003.

Since then, the Fedora Project has become an active and vibrant
community that produces nearly a dozen "spins" that are tailor made for
desktop users, hardware design, gaming, musicians, artists, and early
classroom environments.

== ARM as a Primary Architecture ==

While Fedora has supported a number of hardware architectures over the
years, x86/x86_64 has been the default for the majority of Fedora users
and for the Linux community in general.

ARM, however, has been making massive strides. It already dominates the
mobile market, and is becoming a go-to platform for hobbyists and
makers, and is showing enormous promise for the server market as well.

In keeping with Fedora's commitment to innovation, the Fedora community
has been pushing to make ARM a primary architecture to satisfy the
needs of users and developers targeting the ARM platform.

*** Maturity and Advanced Features ***

Sometimes it's not the big new features that make a users' experience
better, it's the little enhancements or long-awaited tricky features
that really help make a new release the bee's knees.

=== NetworkManager Improvements ===

NetworkManager is getting several improvements in Fedora 20 that will
be welcome additions for power users and system administrators.

Users will now be able to add, edit, delete, activate, and de-activate
network connections via the nmcli command line tool, which will make
life much easier for non-desktop uses of Fedora.

NetworkManager is also getting support for bonding interfaces and
bridging interfaces. Bonding and bridging are used in many enterprise
setups and are necessary for virtualization and fail-over scenarios.

=== No Default Sendmail, Syslog ===

Fedora 20 removes some services that many users find unnecessary,
though (of course) they will remain available as installable packages
for users who might need them.

The systemd journal now takes the place as the default logging
solution, having been tested and able to manage persistent logging in
place of syslog.

Also, Sendmail will no longer be installed by default, as most Fedora
installs have no need of a Mail Transfer Agent (MTA).

== Cloud and Virtualization Improvements ==

The Fedora 20 release continues the Fedora tradition of adopting and
integrating leading edge technologies used in cloud computing. This
release includes a number of features that will make working with
virtualization and cloud computing much easier.

* OS Installer Support for LVM Thin Provisioning: LVM has introduced
thin provisioning technology, which provides greatly improved
snapshot functionality in addition to thin provisioning capability.
This change will make it possible to configure thin provisioning
during OS installation.

* VM Snapshot UI with virt-manager: This change will make taking VM
snapshots much easier. qemu and libvirt have all the major pieces in
place for performing safe VM snapshots/checkpoints, however there
isn't any simple discoverable UI. This feature will track adding that
UI to virt-manager, and any other virt stack bits that need to be
fixed/improved. This includes adding functionality to libvirt to
support deleting and rebasing to external snapshots.

* Role based access control with libvirt: Libvirt role based access
control will allow fine grained access control like 'user FOO can
only start/stop/pause vm BAR', but for all libvirt APIs and objects.

* ARM on x86 with libvirt/virt-manager: This change will fix running
ARM VMs on x86 hosts using standard libvirt tools libvirt virsh,
virt-manager and virt-install.

== Developer Goodness ==

As always, Fedora 20 will include several new features and updated
packages that will be of interest to all manner of developers.

* Ruby on Rails 4.0: This update will keep Fedora up-to-date and will
ensure that the current Ruby on Rails developers stay with us as they
will get support for system-packaged Ruby on Rails of the latest
version. Apart from that, Rails 4.0 also bring improved
functionality, speed. security and better modularization.

* Perl 5.18: Perl 5.18 will be shipped in Fedora 20. Perl doesn't get
as much attention these days, but it's still a vital part of many
production and development environments. Fedora will deliver the most
up-to-date Perl release so its users will be able to stay current
with the latest Perl.

*** Desktop Environments and Spins ***

= GNOME 3.10 =

Fedora 20 Alpha will have a preview of GNOME 3.10, GNOME 3.9.90. GNOME
3.10 will have a number of new applications and new features that will
please GNOME-lovers in the Fedora 20 release. This release includes a
new music application (gnome-music), a new maps application
(gnome-maps), a revamp for the system status menu, and Zimbra support
in Evolution.

There is also preliminary support in this release for running
GNOME-shell as a Wayland compositor, though Wayland may not be in the
default packages for the final Fedora 20 release.

= KDE Plasma Workspaces 4.11 =

The Fedora KDE SIG has rebased to KDE 4.11 for Fedora 20. This release
includes faster Nepomuk indexing, improvements to Kontact, KScreen
integration in KWin, Metalink/HTTP support for KGet, and much more.

= Spins =

Spins are alternate versions of Fedora. In addition to various desktop
environments for Fedora, spins are also available as tailored
environments for various types of users via hand-picked application
sets or customizations.

To see all of the Official Fedora 20 Release Spins, visit the Fedora 20
Release Spins page:

https://fedoraproject.org/wiki/Releases/20/Spins

Nightly composes of alternate Spins are available here:

http://dl.fedoraproject.org/pub/alt/nightly-composes

*** Note on Performance ***

Fedora development releases use a kernel with extra debug information
to help us understand and resolve issues faster; however, this can have
a significant impact on performance. Refer to the kernel debug strategy
page for more details:

https://fedoraproject.org/wiki/KernelDebugStrategy

You can boot with slub_debug=- or use the kernel from nodebug
repository to disable the extra debug info.

*** Issues and Details ***

Heisenbug Alpha is a testing release. To report issues encountered
during testing, contact the Fedora QA team via the test mailing list or
in #fedora-qa on freenode.

As testing progresses, common issues are tracked on the Fedora wiki:
https://fedoraproject.org/wiki/Common_F20_bugs

For tips on reporting a bug effectively, read "How to File a Bug
Report:" http://fedoraproject.org/wiki/How_to_file_a_bug_report .

You can join the Fedora QA team mailing list here:
https://lists.fedoraproject.org/mailman/listinfo/test

** Contributing ***

There are many ways to contribute beyond bug reporting. You can help
translate software and content, test and give feedback on software
updates, write and edit documentation, design and do artwork, help with
all sorts of promotional activities, and package free software for use
by millions of Fedora users worldwide. To get started, visit
http://join.fedoraproject.org today!

[CentOS-announce] CEBA-2013:1277 CentOS 5 ghostscript Update

CentOS Errata and Bugfix Advisory 2013:1277

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1277.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
906a6aceca2477f887ee3575183f13453b3dbbc86479e8566d8a74ef7d27d901 ghostscript-8.70-15.el5_9.3.i386.rpm
eb367a0fff773e34e3ff6649fd519972d0fded9c0b2fd137eac49ec5f391c2fb ghostscript-devel-8.70-15.el5_9.3.i386.rpm
e342ad31e0ff8163fa8b463fc4fe4eff25916984e01102b2cef553069bb9c778 ghostscript-gtk-8.70-15.el5_9.3.i386.rpm

x86_64:
906a6aceca2477f887ee3575183f13453b3dbbc86479e8566d8a74ef7d27d901 ghostscript-8.70-15.el5_9.3.i386.rpm
5e257787ba29ca72fd232a4b63cd9bb1569dbc2dfd4d8b088f04a693866f0014 ghostscript-8.70-15.el5_9.3.x86_64.rpm
eb367a0fff773e34e3ff6649fd519972d0fded9c0b2fd137eac49ec5f391c2fb ghostscript-devel-8.70-15.el5_9.3.i386.rpm
3a7bece574372d665912a46e650bbbc715106cee3f3168d47098fee70bf3d642 ghostscript-devel-8.70-15.el5_9.3.x86_64.rpm
134bca10c12b90200d3ff2970838b6fc7058bc9edac37cf085c4ccf948fb4d25 ghostscript-gtk-8.70-15.el5_9.3.x86_64.rpm

Source:
64dcaf5a0de30cc5d34ca79ee6e2d2bdaee1716b93f9ef5260a2fb12ca43b073 ghostscript-8.70-15.el5_9.3.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

Monday, September 23, 2013

[CentOS-announce] CEBA-2013:1276 CentOS 6 chkconfig Update

CentOS Errata and Bugfix Advisory 2013:1276

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1276.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
f2bd516b2881594e510e39b95b0fe0ae875204d80ab1f322f9624590b1db1099 chkconfig-1.3.49.3-2.el6_4.1.i686.rpm
b959bc1e4a176452f2544d8a5067bf2133d164e08b9e82ebd4ca13028406be61 ntsysv-1.3.49.3-2.el6_4.1.i686.rpm

x86_64:
bc1e754226c33a5152761d66d0b569e7cc68d16239e6e60bd6f4a7ac04a739f1 chkconfig-1.3.49.3-2.el6_4.1.x86_64.rpm
dbae3ff25340240fc45ab2c68be37a9346e8133adfb8ea4b83d247df980ee1c7 ntsysv-1.3.49.3-2.el6_4.1.x86_64.rpm

Source:
2985848e00ebff25446226f939892a474d18c1191a6818f61d2ea48067f3955b chkconfig-1.3.49.3-2.el6_4.1.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[USN-1964-1] LibRaw vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSQINdAAoJEGVp2FWnRL6TXH8P/j+HwzUaxkrghx3rsmuxkRFx
u86ogNjtNy0Tpc+dhloOWFQi9BBsW9gFZBGIqt8GJ0P28nf+/378kGQSOzDrHV2P
hi1/xpDkxtsAzVzATA2yDnnTqItyOheXG9wTpLf9pX7Q9eHYDhAHe4OpJz9YK00A
mcm+3gHpwxz5dt+NA+kqj86kWvzv1tc4azPkxxsp/zPfWWKR0AkiqenAlbtNwzpS
Bmwse9nsri+EYWubeNYnZcoUV6iwymhQtaxKpEI/zJH+OtzSnxj7X0R4lw07sXYv
+aYUcIyMi07gH3Rt5V/ElSqit1YOAUW/ybDob8m/BFdN2GKqvS7DorMUDlYJsvqS
yePUCgPvCsjb0xLUMbsiMncbrU3cV563WXDj3qixyFe2cYXtw9ilUs9MLQvyicbL
AVUuTsQknipYy+TrUDeWG6xn89SIrdIGejd/BvyC5bSijlO51A7ilYhfDaO8/zA2
6/T5ZLH+i2B0cXuVsEkcnpH8CRAlVXg/DI8YvSVc2CltSgr5tUnteqViLRM6KbU3
mmxgIYabKgerEcL3+0JObEDcKLOcjjz5i8q+K2lOh6yoqG0f//OH/tLDIDITx+iY
D/yrP2iC1YkOJwPKsTUoldg2fxZ+1yusxxlEEPLsdRZkEqs8LamTHbDjyDPs+P5f
3E32joMIKLNxt/t1/Ceo
=7rrN
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1964-1
September 23, 2013

libraw vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS

Summary:

LibRaw could be made to crash if it opened a specially crafted file.

Software Description:
- libraw: raw image decoder library

Details:

It was discovered that LibRaw incorrectly handled photo files. If a user or
automated system were tricked into processing a specially crafted photo
file, applications linked against LibRaw could be made to crash, resulting
in a denial of service. (CVE-2013-1438, CVE-2013-1439)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
libraw5 0.14.7-0ubuntu1.13.04.2

Ubuntu 12.10:
libraw5 0.14.7-0ubuntu1.12.10.2

Ubuntu 12.04 LTS:
libraw5 0.14.4-0ubuntu2.2

After a standard system update you need to restart your session to make all
the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1964-1
CVE-2013-1438, CVE-2013-1439

Package Information:
https://launchpad.net/ubuntu/+source/libraw/0.14.7-0ubuntu1.13.04.2
https://launchpad.net/ubuntu/+source/libraw/0.14.7-0ubuntu1.12.10.2
https://launchpad.net/ubuntu/+source/libraw/0.14.4-0ubuntu2.2

[USN-1965-1] pyOpenSSL vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJSQIN3AAoJEGVp2FWnRL6TVToP/061UTSbyjOZf8971nbWXZnX
GGhCH7oobDGO/I3YqHdgXcosSGN9cbBVvTZW0biesWRiV0oXrZI5HCsZkAl7V0qi
gHp42t7kOuT8gNPwcON6u/QQDxRfyECmZNwLdYkLdqhbpOtsChKfyoQ3nz4+dSLz
G1k4fiino9uatWM/ipYRr8tyLjLzbmSWjhW73LDqT1yf+1O2yKFA+4TK+W8vtXcp
0UuRa3VdaEtPNwBD3iufih9NdsWOAJbbUE9NR3HldLbcV2E+MZgoRVqmlzfH2yI4
Umq7y58OSXT5aclBwpUCvpS3w3p2gkxazMKhaAb57Zs7hxqh7zywaMf+DDcrro8c
54ZdgU/SNprfM4sL1LPA3gROEcJbEQjptdg9sGYpkkdpY4/K4P00UUFzUvhghm40
XWNhRSU8gkW7u36lwjezPo4lX4yqVH4txNIZRRcAkIfGl3l3OuJa+Ad2idVOTg/7
kpt9xv2ScXQLctWhcDtupHE5Xur+hTkq85a2cffGdsSJlliOINsMxJrvOqv1nKW8
by74IYd3oO0jxAzmnwFlUApvxL02rmsgMfvd9b+9o8g4Rz80fDOBkUvYRJHtHR9R
Fr2kqSz4HurbbWbypCp3zK6TdfIB0b/ISr+BH/5N86ZOm2iHa90Ejj5SLS9yRgaQ
dyTloaQXCt3bNzgL63Az
=x3hH
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1965-1
September 23, 2013

pyopenssl vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
- Ubuntu 10.04 LTS

Summary:

Fraudulent security certificates could allow sensitive information to be
exposed when accessing the Internet.

Software Description:
- pyopenssl: Python wrapper around the OpenSSL library

Details:

It was discovered that pyOpenSSL did not properly handle certificates with
NULL characters in the Subject Alternative Name field. An attacker could
exploit this to perform a man in the middle attack to view sensitive
information or alter encrypted communications.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
python-openssl 0.13-2ubuntu3.1
python3-openssl 0.13-2ubuntu3.1

Ubuntu 12.10:
python-openssl 0.13-2ubuntu1.1
python3-openssl 0.13-2ubuntu1.1

Ubuntu 12.04 LTS:
python-openssl 0.12-1ubuntu2.1

Ubuntu 10.04 LTS:
python-openssl 0.10-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1965-1
CVE-2013-4314

Package Information:
https://launchpad.net/ubuntu/+source/pyopenssl/0.13-2ubuntu3.1
https://launchpad.net/ubuntu/+source/pyopenssl/0.13-2ubuntu1.1
https://launchpad.net/ubuntu/+source/pyopenssl/0.12-1ubuntu2.1
https://launchpad.net/ubuntu/+source/pyopenssl/0.10-1ubuntu0.1

[CentOS-announce] CEBA-2013:1278 CentOS 6 autofs Update

CentOS Errata and Bugfix Advisory 2013:1278

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1278.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
38ba1750155bfcb08b80ed70353bc3870e9c1dc1d155ba255dd28a77bc8cc428 autofs-5.0.5-75.el6_4.i686.rpm

x86_64:
f3a945f1062a8cfa917da787a518b3b496282faebbf8411d17c543f8fd803663 autofs-5.0.5-75.el6_4.x86_64.rpm

Source:
9b3166fe5b3e24ce6fb8a143ab7ec880d526e0ac79327aa1938cd8eb070e05d1 autofs-5.0.5-75.el6_4.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CEBA-2013:1276 CentOS 6 chkconfig Update

CentOS Errata and Bugfix Advisory 2013:1276

Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1276.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
b7e728c1cb477f0464c8244ab7391216b8e48e04cc4cd1eb306896091b4ac1c8 chkconfig-1.3.49.3-2.el6_4.1.i686.rpm
70db47b60c2bf241090f147ff681266528c8741146357ff1f400104c737016ea ntsysv-1.3.49.3-2.el6_4.1.i686.rpm

x86_64:
56694998883d5606d040c0d0ce9d76078aee500aa8e640b5a1f4c8ff6ed20f7e chkconfig-1.3.49.3-2.el6_4.1.x86_64.rpm
35a80e4baffe5331ae317298b1a34c9e8b2544e755a6523997cac3e7da3dffda ntsysv-1.3.49.3-2.el6_4.1.x86_64.rpm

Source:
e00a8330d55620b91e4c16a8571b6c1ed093845e3bbce1eac7e31a60cc237d7d chkconfig-1.3.49.3-2.el6_4.1.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce

[FreeBSD-Announce] vBSDcon Registrations Only Open For 30 More Days!

Hi all,

There are only 30 more days left to register for Verisign's vBSDcon. Online registrations will become unavailable October 23, 2013. For those planning to attend, we encourage you to register soon at http://www.vbsdcon.com/. You will not want to miss this event. There will presentations by several well seasoned technologists such as Baptiste Darroussin on the subject of "PkgNG", a new packaging system for FreeBSD based system such as FreeBSD, PC-BSD, and Dragonfly BSD.

Baptiste has a background in UNIX Systems Engineering and is involved in multiple facets of the FreeBSD project including being a Ports committer for 3 years and a src committer for 2 years. His involvement also includes being a member of the Port management team. PkgNG, a new package management framework for FreeBSD, is one of Baptiste's primary roles where he is a lead developer.

In addition to plenary speakers, vBSDcon will also feature after conference hours Hacker Lounges and Doc Sprints. These sessions will be available for the entire BSD communities to include NetBSD, OpenBSD, FreeBSD, and other BSD based distributions to have a collaborative space to work and communicate with one another. Complimentary wireless internet access will also be available.

We look forward to seeing you all there for this opportunity to come together as a community. Remember, online registrations will close on October 23, 2013. Register for vBSDcon at http://www.vbsdcon.com/.

--
Vincent (Rick) Miller
Systems Engineer
vmiller@verisign.com

t: 703.948.4395 m: 703.581.3068
12061 Bluemont Way, Reston, VA 20190

http://www.vbsdcon.com/
http://www.verisigninc.com/


"This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed, and may contain information that is non-public, proprietary, privileged, confidential and exempt from disclosure under applicable law or may be constituted as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this message in error, notify sender immediately and delete this message immediately."
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"

Saturday, September 21, 2013

reallost1.fbsd2233449 alodo

昌哲敬:ninhao

附件中,教会您如何从技术走向管理

br7fhnd6f

感谢您对我们工作的理解和支持。

谢谢

哲敬 祝您工作顺利,身体健康。

 

Thursday, September 19, 2013

[CentOS-announce] CESA-2013:1273 Important CentOS 6 spice-gtk Update

CentOS Errata and Security Advisory 2013:1273 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2013-1273.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
c7bc8814163e0390fbba942451f909fd2219a985e6d7d80e20406337df9f53d7 spice-glib-0.14-7.el6_4.3.i686.rpm
21fb779dee7388ca315952a13a25863dcf8eaac78085ef7c2f6d838f3358037f spice-glib-devel-0.14-7.el6_4.3.i686.rpm
389e752a57947e83b47afd88c320f67285da0c2f2b5e9690fb89edf100705a37 spice-gtk-0.14-7.el6_4.3.i686.rpm
73c99affb153c83104504e79587bf28e6e3f57467999d94a669ff52bcba252c1 spice-gtk-devel-0.14-7.el6_4.3.i686.rpm
fe6a3b157084c07a5c3ceadd681606711d646c55f3e9743ad8d93978ba500794 spice-gtk-python-0.14-7.el6_4.3.i686.rpm
c27d2e3a7ee5597e05bf1f70fb27865d8766cc819fffb19ddd35168f68716fdc spice-gtk-tools-0.14-7.el6_4.3.i686.rpm

x86_64:
c7bc8814163e0390fbba942451f909fd2219a985e6d7d80e20406337df9f53d7 spice-glib-0.14-7.el6_4.3.i686.rpm
9b0705a9cfc12e13f63dd0fd764022acb33befbc74a5d6aeaa8eeac0e28391ef spice-glib-0.14-7.el6_4.3.x86_64.rpm
21fb779dee7388ca315952a13a25863dcf8eaac78085ef7c2f6d838f3358037f spice-glib-devel-0.14-7.el6_4.3.i686.rpm
89e8388b861f00ae72a6ce430a4a7b01e108be11c2c57d7af2a299c56d2e1253 spice-glib-devel-0.14-7.el6_4.3.x86_64.rpm
389e752a57947e83b47afd88c320f67285da0c2f2b5e9690fb89edf100705a37 spice-gtk-0.14-7.el6_4.3.i686.rpm
0387c3a49dda89e9984205bd3f253f695d3d3667f29b216a20ca659beaba0926 spice-gtk-0.14-7.el6_4.3.x86_64.rpm
73c99affb153c83104504e79587bf28e6e3f57467999d94a669ff52bcba252c1 spice-gtk-devel-0.14-7.el6_4.3.i686.rpm
c5352f17487b6b09b20b77664c6089a221f17434d89ac773c81d8b208cbf789e spice-gtk-devel-0.14-7.el6_4.3.x86_64.rpm
3df4024ef980d29f111453123c076171eed9933f7fb1e6abbe230f9d1d5a33aa spice-gtk-python-0.14-7.el6_4.3.x86_64.rpm
90a05cc18d4ec3c7ba419537aed537785f8132a718c5e213e2fc4b8b27d2378c spice-gtk-tools-0.14-7.el6_4.3.x86_64.rpm

Source:
a2415f770b600330e06d3a86f2cc10a9e4f06f41d1b342f78ac1774668de5521 spice-gtk-0.14-7.el6_4.3.src.rpm



--
Karanbir Singh
CentOS Project { http://www.centos.org/ }
irc: z00dax, #centos@irc.freenode.net

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce