-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi all,
I have just changed the starting times of the nightly branched
composes. Rawhide now kicks off 3 hours earlier at 05:15 UTC. Branched
now starts 2 hours earlier at 07:15 UTC. Releng is working to integrate
the nightly livecd composes into the automated compose process, as well
as adding nightly arm and cloud image creation.
as we stabilise the compose processes we will add a separate email with
a notification of the nightly image composition completion.
Dennis
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iQIcBAEBAgAGBQJShPFIAAoJEH7ltONmPFDRbxEQAKI1oFfh7BIMXLHP5xVMUb14
jJVMGRAgJkZxWa0a3BzXXg6aK7OdW7Q7JQTslYSrS64Vf85Ze9Fb4CdX6rhQX4yG
oBAzuJkenVhValaG/nQ5fcP9hDBIyIdbP0eJFDx5/2MZXdzDoThuIIWvgxBgXlpX
qFdBPtDDypZXjS3wiMTGa4ZnLjLnagSXmi0KLzUiWGlo4oFfi6YUsXj5lDosnj/X
LpAxc5YhFpBMwpivBc6Tq+nJqTY+1ML40Nmp15EibDnFgIPn6cto2s19iv+Svf1o
LbDltJfs/4VTpq/MSJqiYV56wYrVSMEb52ijbgXHJhR1SnxfnF3fBf31KkAtcIAr
X+XT3TU+jO9wzRPE8Pu9NsxQerZGBqKPGAXDeGzo0cpF8zCnow13wKIeHkv0PtnC
LQOlf2vDEL7f7zlA04+nxbbvRdrF2O2KNxoCP7pIEXdyKOP32ILmgcTIfY9PjmkX
Ftd8oPoccefb0NG3mJ2I/EGkmGRXU4X7iJskYkV7Kcuhg1LerltPqkdIpluQThp+
s/if2V+0AYGDVWX9kB2d4NmPW0uFKrV7NTWjvxClyGjeQgsRu8yjEtFRzkEbQZ5P
X3vfTWtEmvjPj5naVTa9lWHIzTCpO1fzwi1MBej5P5yrvjhMZFTmyEsZRDzmywZA
GvpoK1wIbzsOPfvn2olN
=L+9x
-----END PGP SIGNATURE-----
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
Thursday, November 14, 2013
Wednesday, November 13, 2013
[USN-2029-1] Apache Commons FileUpload vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSg5qwAAoJEGVp2FWnRL6T/5YQAK9hpJoO3isW+hV37Z8SzrwN
4o+TwbbI93/hfx/y1J39omvU8jaWsjruMexj+rbj7vbZ4rxKD6s0WlA7L/hpmg7+
+YYYRCPV9hITXunbiosK0Y5ZgPHLx/PosmUvuUdacUFPwyTGREJOgZEz1nif4EqH
FtaU/HDz70k0vplLEyfWBkbKhxZvaQNlvHWVMBgIrfE2vPF0r7KCW3QZtjUvxqec
XeLq0D8XuyLT9jwv9QZe61azsxIdkpOL/Qzm9cDoR4f8T+b5NAEG9+MaHT44sDxA
MvGmj4PS15cwZSFZSgxHw+kKToPAnqV3HKIGlrd3Pv5mO7YVIqCXkKlAhSSKMsw3
qSRTKK8TuExUoIKFPgl+/xkM88B0RlGqtSwbCg0PLVePcViT5p1uDWrw9thRuk0v
0GpAKEuEm0Vlzc4wwWUtDXnYZih6eZ4LvtSxGt1l/jJcs+mqrDIyw7PxuJC1wF8R
uePcpkX8C9b6IUJxiXHrDjiKmOzPNElkRW/juK2rCYui+8se3I5a+nrHgvb+O6fG
+RZRX7uZrkSpaz7PGMfNbXP19G+yF/KRKg6aR0cO4bSxL+0lE9i3/mqFWhtok8Im
BPFhwKEikhZqH7AyEdu1NDv7sQ9PPGUG0JpiGvlBQSlBj5T1YCOsA2bP2McNNTcf
TqhOxfXp3XW1G8qvbE/3
=S+OX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2029-1
November 13, 2013
libcommons-fileupload-java vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Apache Commons FileUpload could be made to overwrite files.
Software Description:
- libcommons-fileupload-java: File upload capability for servlets and web
applications
Details:
It was discovered that Apache Commons FileUpload incorrectly handled file
names with NULL bytes in serialized instances. An attacker could use this
issue to possibly write to arbitrary files.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
libcommons-fileupload-java 1.2.1-3ubuntu2.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2029-1
CVE-2013-2186
Package Information:
https://launchpad.net/ubuntu/+source/libcommons-fileupload-java/1.2.1-3ubuntu2.1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSg5qwAAoJEGVp2FWnRL6T/5YQAK9hpJoO3isW+hV37Z8SzrwN
4o+TwbbI93/hfx/y1J39omvU8jaWsjruMexj+rbj7vbZ4rxKD6s0WlA7L/hpmg7+
+YYYRCPV9hITXunbiosK0Y5ZgPHLx/PosmUvuUdacUFPwyTGREJOgZEz1nif4EqH
FtaU/HDz70k0vplLEyfWBkbKhxZvaQNlvHWVMBgIrfE2vPF0r7KCW3QZtjUvxqec
XeLq0D8XuyLT9jwv9QZe61azsxIdkpOL/Qzm9cDoR4f8T+b5NAEG9+MaHT44sDxA
MvGmj4PS15cwZSFZSgxHw+kKToPAnqV3HKIGlrd3Pv5mO7YVIqCXkKlAhSSKMsw3
qSRTKK8TuExUoIKFPgl+/xkM88B0RlGqtSwbCg0PLVePcViT5p1uDWrw9thRuk0v
0GpAKEuEm0Vlzc4wwWUtDXnYZih6eZ4LvtSxGt1l/jJcs+mqrDIyw7PxuJC1wF8R
uePcpkX8C9b6IUJxiXHrDjiKmOzPNElkRW/juK2rCYui+8se3I5a+nrHgvb+O6fG
+RZRX7uZrkSpaz7PGMfNbXP19G+yF/KRKg6aR0cO4bSxL+0lE9i3/mqFWhtok8Im
BPFhwKEikhZqH7AyEdu1NDv7sQ9PPGUG0JpiGvlBQSlBj5T1YCOsA2bP2McNNTcf
TqhOxfXp3XW1G8qvbE/3
=S+OX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2029-1
November 13, 2013
libcommons-fileupload-java vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Apache Commons FileUpload could be made to overwrite files.
Software Description:
- libcommons-fileupload-java: File upload capability for servlets and web
applications
Details:
It was discovered that Apache Commons FileUpload incorrectly handled file
names with NULL bytes in serialized instances. An attacker could use this
issue to possibly write to arbitrary files.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
libcommons-fileupload-java 1.2.1-3ubuntu2.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2029-1
CVE-2013-2186
Package Information:
https://launchpad.net/ubuntu/+source/libcommons-fileupload-java/1.2.1-3ubuntu2.1
[CentOS-announce] CEEA-2013:1516 CentOS 6 hpsa Update
CentOS Errata and Enhancement Advisory 2013:1516
Upstream details at : https://rhn.redhat.com/errata/RHEA-2013-1516.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
ab3c7899340f74c9ab48c0a5738a11b0174382840b62ff0cb09d89a1e0e127c5 kmod-hpsa-3.4.0_1_RH1-1.el6_4.i686.rpm
x86_64:
ff8ea688947819a10985a76dbec58a550824154780ed1d696a9da2e68772b19b kmod-hpsa-3.4.0_1_RH1-1.el6_4.x86_64.rpm
Source:
e2ccc0c0f0a2af623615a19238083537e3ccdd45c84aecd205ba10fe4e372388 hpsa-3.4.0_1_RH1-1.el6_4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHEA-2013-1516.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
ab3c7899340f74c9ab48c0a5738a11b0174382840b62ff0cb09d89a1e0e127c5 kmod-hpsa-3.4.0_1_RH1-1.el6_4.i686.rpm
x86_64:
ff8ea688947819a10985a76dbec58a550824154780ed1d696a9da2e68772b19b kmod-hpsa-3.4.0_1_RH1-1.el6_4.x86_64.rpm
Source:
e2ccc0c0f0a2af623615a19238083537e3ccdd45c84aecd205ba10fe4e372388 hpsa-3.4.0_1_RH1-1.el6_4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
[CentOS-announce] CEBA-2013:1517 CentOS 6 libvirt Update
CentOS Errata and Bugfix Advisory 2013:1517
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1517.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
69eefbd0356841d9bfcbdd55dcf27abf7d2782d9fb739276631b1f78e3524c72 libvirt-0.10.2-18.el6_4.15.i686.rpm
b8b6e63923708bb36b276bc0d06e33e8c97f06f0f2d6e444acb50dc3d301aade libvirt-client-0.10.2-18.el6_4.15.i686.rpm
55f16975dc8fe7fdcd1325e2c9784c31b9a4ed48bf56a9712a55f1946e307c56 libvirt-devel-0.10.2-18.el6_4.15.i686.rpm
fa2a8e1f173350d464b7ecb572428615158f3c625bd1a489d364cfc9415fe094 libvirt-python-0.10.2-18.el6_4.15.i686.rpm
x86_64:
a8f7dac16c432b0491217073939472434d0e9a23066b9dd7fc4eee5b7d61aac5 libvirt-0.10.2-18.el6_4.15.x86_64.rpm
b8b6e63923708bb36b276bc0d06e33e8c97f06f0f2d6e444acb50dc3d301aade libvirt-client-0.10.2-18.el6_4.15.i686.rpm
2bfd49eb900fe8eeffebe4979ade482a81cf0b7a5f014fce43c539fc2ee2ff2d libvirt-client-0.10.2-18.el6_4.15.x86_64.rpm
55f16975dc8fe7fdcd1325e2c9784c31b9a4ed48bf56a9712a55f1946e307c56 libvirt-devel-0.10.2-18.el6_4.15.i686.rpm
49f4c7bf99ff33b0d40483cff2da7398f8ca829bd9ca87e84e6932fd76b56429 libvirt-devel-0.10.2-18.el6_4.15.x86_64.rpm
ddda9892618a0d0d785c42216e40bb0ea59d6e3f49b4b681818b7d1436936f2b libvirt-lock-sanlock-0.10.2-18.el6_4.15.x86_64.rpm
4568330fe6f07ba850b5f7cefd2592af0914b00c3e1dab6e9ae004dadcf60ce9 libvirt-python-0.10.2-18.el6_4.15.x86_64.rpm
Source:
21c0cf5a30850bb5c759a56ca617a7c8cbebdebfaadc08adc2281a09ba684cf2 libvirt-0.10.2-18.el6_4.15.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1517.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
69eefbd0356841d9bfcbdd55dcf27abf7d2782d9fb739276631b1f78e3524c72 libvirt-0.10.2-18.el6_4.15.i686.rpm
b8b6e63923708bb36b276bc0d06e33e8c97f06f0f2d6e444acb50dc3d301aade libvirt-client-0.10.2-18.el6_4.15.i686.rpm
55f16975dc8fe7fdcd1325e2c9784c31b9a4ed48bf56a9712a55f1946e307c56 libvirt-devel-0.10.2-18.el6_4.15.i686.rpm
fa2a8e1f173350d464b7ecb572428615158f3c625bd1a489d364cfc9415fe094 libvirt-python-0.10.2-18.el6_4.15.i686.rpm
x86_64:
a8f7dac16c432b0491217073939472434d0e9a23066b9dd7fc4eee5b7d61aac5 libvirt-0.10.2-18.el6_4.15.x86_64.rpm
b8b6e63923708bb36b276bc0d06e33e8c97f06f0f2d6e444acb50dc3d301aade libvirt-client-0.10.2-18.el6_4.15.i686.rpm
2bfd49eb900fe8eeffebe4979ade482a81cf0b7a5f014fce43c539fc2ee2ff2d libvirt-client-0.10.2-18.el6_4.15.x86_64.rpm
55f16975dc8fe7fdcd1325e2c9784c31b9a4ed48bf56a9712a55f1946e307c56 libvirt-devel-0.10.2-18.el6_4.15.i686.rpm
49f4c7bf99ff33b0d40483cff2da7398f8ca829bd9ca87e84e6932fd76b56429 libvirt-devel-0.10.2-18.el6_4.15.x86_64.rpm
ddda9892618a0d0d785c42216e40bb0ea59d6e3f49b4b681818b7d1436936f2b libvirt-lock-sanlock-0.10.2-18.el6_4.15.x86_64.rpm
4568330fe6f07ba850b5f7cefd2592af0914b00c3e1dab6e9ae004dadcf60ce9 libvirt-python-0.10.2-18.el6_4.15.x86_64.rpm
Source:
21c0cf5a30850bb5c759a56ca617a7c8cbebdebfaadc08adc2281a09ba684cf2 libvirt-0.10.2-18.el6_4.15.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Tuesday, November 12, 2013
[FreeBSD-Announce] FreeBSD Foundation's Year-End Fundraising Campaign!
Dear FreeBSD Community,
Your donations have helped make FreeBSD the best open source operating system available! By investing in The FreeBSD Foundation you have helped us keep FreeBSD a high-performance, secure, and stable operating system.
Thanks to people like you, the FreeBSD Foundation has been proudly supporting the FreeBSD Project and community for over 13 years now. We are incredibly grateful for all the support we receive from you and so many individuals and organizations that value FreeBSD. As of this writing we have raised $427,000 towards our goal of raising $1,000,000. Would you consider making a gift to support our work in 2014?
Donations can easily be made here: http://www.freebsdfoundation.org/donate/.
This year your donations helped FreeBSD by:
• Funding development projects to improve FreeBSD, including: Native iSCSI kernel stack, Updated Intel graphics chipset support, Integration of Newcons, UTF-8 console support, Superpages for ARM architecture, and Layer 2 networking modernization and performance improvements.
• Hiring two more staff members to help with FreeBSD development projects, security, and release engineering.
• Educating the public and promoting FreeBSD. We are preparing the debut our new online magazine, the FreeBSD Journal. We created high-quality brochures to teach people about FreeBSD. We also visited companies to help facilitate collaboration efforts with the Project.
• Sponsoring BSD conferences and summits in Europe, Japan, Canada, and the US.
• Protecting FreeBSD IP and providing legal support to the Project.
• Purchasing hardware to build and improve FreeBSD project infrastructure.
But are you aware of the tangible benefits derived from our support of the FreeBSD community? Providing travel grants to FreeBSD volunteers is a great way to invest in the future of FreeBSD. One person we sponsored was Google Summer of Code student Mike Ma, who had the chance to present his work at EuroBSDCon. During his presentation he received valuable input that will help improve and verify his GSoC work. By attending the conference, he had the opportunity to meet passionate FreeBSD developers who inspired him to learn as much as he could about their different projects. This encouraged him to continue working with his mentor and get involved in his mentor's work as well as some lldb work.
Now that Mike's back at his university, he's been busy promoting and advocating for FreeBSD. In fact he's so passionate about the Project now that he convinced a friend who is working on programming languages to work on the clang project, because it's relevant to his own work.
This one investment helped FreeBSD by providing an environment for a student to get more involved in the Project, and bring that enthusiasm back to his university to promote FreeBSD and encourage more students to get involved. This is an investment in the next generation of FreeBSD developers.
Donate today to help us continue and increase our support of the FreeBSD Project and community worldwide! Making a donation is quick and easy. To make a donation go to: http://www.freebsdfoundation.org/donate/.
Thank you for your support!
Sincerely,
Deb Goodkin
Secretary/Treasurer
The FreeBSD Foundation
P.S. Please make your investment in FreeBSD now, by making a donation today! To make a donation, go here: http://www.freebsdfoundation.org/donate/.
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
Your donations have helped make FreeBSD the best open source operating system available! By investing in The FreeBSD Foundation you have helped us keep FreeBSD a high-performance, secure, and stable operating system.
Thanks to people like you, the FreeBSD Foundation has been proudly supporting the FreeBSD Project and community for over 13 years now. We are incredibly grateful for all the support we receive from you and so many individuals and organizations that value FreeBSD. As of this writing we have raised $427,000 towards our goal of raising $1,000,000. Would you consider making a gift to support our work in 2014?
Donations can easily be made here: http://www.freebsdfoundation.org/donate/.
This year your donations helped FreeBSD by:
• Funding development projects to improve FreeBSD, including: Native iSCSI kernel stack, Updated Intel graphics chipset support, Integration of Newcons, UTF-8 console support, Superpages for ARM architecture, and Layer 2 networking modernization and performance improvements.
• Hiring two more staff members to help with FreeBSD development projects, security, and release engineering.
• Educating the public and promoting FreeBSD. We are preparing the debut our new online magazine, the FreeBSD Journal. We created high-quality brochures to teach people about FreeBSD. We also visited companies to help facilitate collaboration efforts with the Project.
• Sponsoring BSD conferences and summits in Europe, Japan, Canada, and the US.
• Protecting FreeBSD IP and providing legal support to the Project.
• Purchasing hardware to build and improve FreeBSD project infrastructure.
But are you aware of the tangible benefits derived from our support of the FreeBSD community? Providing travel grants to FreeBSD volunteers is a great way to invest in the future of FreeBSD. One person we sponsored was Google Summer of Code student Mike Ma, who had the chance to present his work at EuroBSDCon. During his presentation he received valuable input that will help improve and verify his GSoC work. By attending the conference, he had the opportunity to meet passionate FreeBSD developers who inspired him to learn as much as he could about their different projects. This encouraged him to continue working with his mentor and get involved in his mentor's work as well as some lldb work.
Now that Mike's back at his university, he's been busy promoting and advocating for FreeBSD. In fact he's so passionate about the Project now that he convinced a friend who is working on programming languages to work on the clang project, because it's relevant to his own work.
This one investment helped FreeBSD by providing an environment for a student to get more involved in the Project, and bring that enthusiasm back to his university to promote FreeBSD and encourage more students to get involved. This is an investment in the next generation of FreeBSD developers.
Donate today to help us continue and increase our support of the FreeBSD Project and community worldwide! Making a donation is quick and easy. To make a donation go to: http://www.freebsdfoundation.org/donate/.
Thank you for your support!
Sincerely,
Deb Goodkin
Secretary/Treasurer
The FreeBSD Foundation
P.S. Please make your investment in FreeBSD now, by making a donation today! To make a donation, go here: http://www.freebsdfoundation.org/donate/.
_______________________________________________
freebsd-announce@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-announce
To unsubscribe, send any mail to "freebsd-announce-unsubscribe@freebsd.org"
[USN-2028-1] Apache XML Security for Java vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgm83AAoJEGVp2FWnRL6TYlIP/2dmRLLFFEG56M1b7UG0s1i0
IAAs+iDEbdLBi9dLIY3KnoTVKnYlYGPVofON9m+Gs76G2TZFNrFuXfm/K8P2MVzi
YkbssrZAWC0HoFHFxS03BrNTFFVBA9tcdNCyesvnP/WXQjrqmYOl3yjeMfFoJqWN
ghpWkYq3YEWY7d1wsCja4Vd6hFSgv9LxSP4x758Q7uiuLHa8pH13FAacfa2ofwJs
r7FXHIHhasa3kY3gWoZmzRIuNFGQC26X1OzKxwtfShqBKDcjnfXR7xm8A+Oa7zVr
M9kozNa2mJmpbBSzJgYZnqa42Cm9TM/2manyM13N0T4YUzW93dYt6yV+IGL4mgUj
DiahxJhsnUhvBiG2yUV1HFOGZ7Vb2Uh+mqN9WBEKU5pU8pZgDmXMC8qJk1ePKk3u
q/3MVSkJtBBcIgtIRcvsHeQBD0P97fCeyL5deDJaFFkml4Byk99SObxCAqQ2TMEQ
+jueNSBVNMJcoRW+CL5P20b9IJKYHCxQH66uFSt5p+idiTclKeTfamtoZnxTK/M5
KQcVaFwt+VW1KHhO7AXyjoZUq24dLUiJVJEiQpESLQvXJszhBBn9pRWw1BUtPQfh
3FNXnNSzCJpd79ZI+n2tw4tYb9QaD15uTLAJR5y0KECQXgDALyY55l+vuibZ8Edf
J9eO1lsewwBXXrUy73SL
=pHvL
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2028-1
November 12, 2013
libxml-security-java vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Apache XML Security for Java could be tricked into validating spoofed
signatures.
Software Description:
- libxml-security-java: implementation of security standards for XML
Details:
James Forshaw discovered that Apache XML Security for Java incorrectly
validated CanonicalizationMethod parameters. An attacker could use this
flaw to spoof XML signatures.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
libxml-security-java 1.4.3-2ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2028-1
CVE-2013-2172
Package Information:
https://launchpad.net/ubuntu/+source/libxml-security-java/1.4.3-2ubuntu0.1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgm83AAoJEGVp2FWnRL6TYlIP/2dmRLLFFEG56M1b7UG0s1i0
IAAs+iDEbdLBi9dLIY3KnoTVKnYlYGPVofON9m+Gs76G2TZFNrFuXfm/K8P2MVzi
YkbssrZAWC0HoFHFxS03BrNTFFVBA9tcdNCyesvnP/WXQjrqmYOl3yjeMfFoJqWN
ghpWkYq3YEWY7d1wsCja4Vd6hFSgv9LxSP4x758Q7uiuLHa8pH13FAacfa2ofwJs
r7FXHIHhasa3kY3gWoZmzRIuNFGQC26X1OzKxwtfShqBKDcjnfXR7xm8A+Oa7zVr
M9kozNa2mJmpbBSzJgYZnqa42Cm9TM/2manyM13N0T4YUzW93dYt6yV+IGL4mgUj
DiahxJhsnUhvBiG2yUV1HFOGZ7Vb2Uh+mqN9WBEKU5pU8pZgDmXMC8qJk1ePKk3u
q/3MVSkJtBBcIgtIRcvsHeQBD0P97fCeyL5deDJaFFkml4Byk99SObxCAqQ2TMEQ
+jueNSBVNMJcoRW+CL5P20b9IJKYHCxQH66uFSt5p+idiTclKeTfamtoZnxTK/M5
KQcVaFwt+VW1KHhO7AXyjoZUq24dLUiJVJEiQpESLQvXJszhBBn9pRWw1BUtPQfh
3FNXnNSzCJpd79ZI+n2tw4tYb9QaD15uTLAJR5y0KECQXgDALyY55l+vuibZ8Edf
J9eO1lsewwBXXrUy73SL
=pHvL
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2028-1
November 12, 2013
libxml-security-java vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 10.04 LTS
Summary:
Apache XML Security for Java could be tricked into validating spoofed
signatures.
Software Description:
- libxml-security-java: implementation of security standards for XML
Details:
James Forshaw discovered that Apache XML Security for Java incorrectly
validated CanonicalizationMethod parameters. An attacker could use this
flaw to spoof XML signatures.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 10.04 LTS:
libxml-security-java 1.4.3-2ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2028-1
CVE-2013-2172
Package Information:
https://launchpad.net/ubuntu/+source/libxml-security-java/1.4.3-2ubuntu0.1
Announcing the release of Fedora 20 Beta!
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
The Fedora 20 "Heisenbug" beta release has arrived with a preview of
the latest fantastic, free, and open source technology currently under
development. Take a peek inside:
*** What is the Beta Release? ***
The beta release is the last important milestone before the release of Fedora
20. A Beta release is code-complete and bears a very strong resemblance to the
third and final release. Only critical bug fixes will be pushed as updates up
to the general release of Fedora 20. The final release of Fedora 20 is expected
in early December. Meanwhile, download the beta of Fedora 20 and help us make
it even better:
http://fedoraproject.org/get-prerelease
We need your help to make Fedora 20 the best release yet, so please take some
time to download and try out the beta and make sure the things that are
important to you are working. If you find a bug, please report it – every bug
you uncover is a chance to improve the experience for millions of Fedora users
worldwide. Together, we can make Fedora 20 a rock-solid distribution. We have a
culture of coordinating new features and pushing fixes upstream as much as
feasible and your feedback will help improve not only Fedora but Linux and free
software on the whole. (See the end of this announcement for more information
on how to help.)
Since it's a beta release, some problems may still be lurking. A list of
problems that we already know about can be found at the Common F20 bugs page,
found at http://fedoraproject.org/wiki/Common_F20_bugs.
== 10 Years of Fedora ==
The Fedora 20 release coincides nicely with the 10th anniversary of Fedora. The
first Fedora release (then called Fedora Core 1) came out on November 6, 2003.
Since then, the Fedora Project has become an active and vibrant community that
produces nearly a dozen "spins" that are tailor made for desktop users,
hardware design, gaming, musicians, artists, and early classroom environments.
== ARM as a Primary Architecture ==
While Fedora has supported a number of hardware architectures over the years,
x86/x86_64 has been the default for the majority of Fedora users and for the
Linux community in general.
ARM, however, has been making massive strides. It already dominates the mobile
market, and is becoming a go-to platform for hobbyists and makers, and is
showing enormous promise for the server market as well.
In keeping with Fedora's commitment to innovation, the Fedora community has
been pushing to make ARM a primary architecture to satisfy the needs of users
and developers targeting the ARM platform.
*** Maturity and Advanced Features ***
Sometimes it's not the big new features that make a users' experience better,
it's the little enhancements or long-awaited tricky features that really help
make a new release the bee's knees.
=== NetworkManager Improvements ===
NetworkManager is getting several improvements in Fedora 20 that will be
welcome additions for power users and system administrators.
Users will now be able to add, edit, delete, activate, and de-activate network
connections via the nmcli command line tool, which will make life much easier
for non-desktop uses of Fedora.
NetworkManager is also getting support for bonding interfaces and bridging
interfaces. Bonding and bridging are used in many enterprise setups and are
necessary for virtualization and fail-over scenarios.
=== No Default Sendmail, Syslog ===
Fedora 20 removes some services that many users find unnecessary, though (of
course) they will remain available as installable packages for users who might
need them.
The systemd journal now takes the place as the default logging solution, having
been tested and able to manage persistent logging in place of syslog.
Also, Sendmail will no longer be installed by default, as most Fedora installs
have no need of a Mail Transfer Agent (MTA).
=== Cloud and Virtualization Improvements ===
The Fedora 20 release continues the Fedora tradition of adopting and
integrating leading edge technologies used in cloud computing. This release
includes a number of features that will make working with virtualization and
cloud computing much easier.
=== First-Class Cloud Images ===
The Fedora Cloud SIG has been working hard on providing images that are
well-suited to running as guests in public and private clouds like Amazon Web
Services (AWS) and OpenStack. If you're using public or private cloud, you
should definitely test-drive the beta images today!
=== OS Installer Support for LVM Thin Provisioning ===
LVM has introduced thin provisioning technology, which provides greatly
improved snapshot functionality in addition to thin provisioning capability.
This change will make it possible to configure thin provisioning during OS
installation.
=== VM Snapshot UI with virt-manager ===
This change will make taking VM snapshots much easier. qemu and libvirt have
all the major pieces in place for performing safe VM snapshots/checkpoints,
however there isn't any simple discoverable UI. This feature will track adding
that UI to virt-manager, and any other virt stack bits that need to be fixed/
improved. This includes adding functionality to libvirt to support deleting and
rebasing to external snapshots.
=== Role based access control with libvirt ===
Libvirt role based access control will allow fine grained access control like
'user FOO can only start/stop/pause vm BAR', but for all libvirt APIs and
objects.
=== ARM on x86 with libvirt/virt-manager ===
This change will fix running ARM VMs on x86 hosts using standard libvirt tools
libvirt virsh, virt-manager and virt-install.
*** Developer Goodness ***
As always, Fedora 20 will include several new features and updated packages
that will be of interest to all manner of developers.
=== ACPICA Tools Update ===
Fedora 20 includes an update to the ACPICA tools from the Component
Architecture (ACPICA) project. This provides developers with a significant
number of additional tools that have never been included in Fedora before --
for example, tools that allow one to create an ACPI table and execute the
methods contained in the table in user space, instead of having to modify
existing tables. The update brings Fedora up-to-date for ACPI development and
exploration, and reflects the reference implementation as closely as possible.
=== Ruby on Rails 4.0 ===
This update will keep Fedora up-to-date and will ensure that the current Ruby
on Rails developers stay with us as they will get support for system-packaged
Ruby on Rails of the latest version. Apart from that, Rails 4.0 also bring
improved functionality, speed, security and better modularization.
=== GNU C Library 2.18 ===
Fedora 20 includes the GNU C Library version 2.18, which brings the project up
to sync with the upstream release from the GNU project, released in August.
This resolves a number of bugs from upstream as well as security issues. This
upgrade should be backwards compatible.
*** Even More Changes ***
Fedora prides itself on bringing cutting-edge technologies to users of open
source software around the world, and this release continues that tradition. No
matter what you do, Fedora 20 has the tools you need to help you get things
done.
A complete list with details of each new change is available here:
https://fedoraproject.org/wiki/Releases/20/ChangeSet
*** Desktop Environments and Spins ***
The Fedora project strives to provide the best desktop experiences possible for
users, from desktop environment to application selection.
== GNOME 3.10 ==
Fedora 20 Beta will have a preview of GNOME 3.10. GNOME 3.10 will have a number
of new applications and new features that will please GNOME-lovers in the
Fedora 20 release. This release includes a new music application (gnome-music),
a new maps application (gnome-maps), a revamp for the system status menu, and
Zimbra support in Evolution.
== KDE Plasma Workspaces 4.11 ==
The Fedora KDE SIG has rebased to KDE 4.11 for Fedora 20. This release includes
faster Nepomuk indexing, improvements to Kontact, KScreen integration in KWin,
Metalink/HTTP support for KGet, and much more.
== X2Go ==
The current nx package in Fedora is based on the last open source release from
NoMachine. NoMachine is no longer developing nx as an open source project. The
X2Go project has taken the nx code and is maintaining it as well as developing
new client and server code around it.
*** Spins ***
Spins are alternate versions of Fedora. In addition to various desktop
environments for Fedora, spins are also available as tailored environments for
various types of users via hand-picked application sets or customizations.
To see all of the Official Fedora 20 Release Spins, see the Fedora 20 Release
Spins link.
Nightly composes of alternate Spins are available here:
http://dl.fedoraproject.org/pub/alt/nightly-composes
*** Note on performance ***
Fedora development releases use a kernel with extra debug information to help
us understand and resolve issues faster; however, this can have a significant
impact on performance. Refer to the kernel debug strategy for more details. You
can boot with slub_debug=- or use the kernel from nodebug repository to disable
the extra debug info.
*** Issues and Details ***
Heisenbug Alpha is a testing release. To report issues encountered during
testing, contact the Fedora QA team via the mailing list or in #fedora-qa on
freenode.
As testing progresses, common issues are tracked at
https://fedoraproject.org/wiki/Common_F20_bugs
For tips on reporting a bug effectively, read
http://fedoraproject.org/wiki/How_to_file_a_bug_report .
*** Contributing ***
There are many ways to contribute beyond bug reporting. You can help translate
software and content, test and give feedback on software updates, write and
edit documentation, design and do artwork, help with all sorts of promotional
activities, and package free software for use by millions of Fedora users
worldwide. To get started, visit http://join.fedoraproject.org today!
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iQIcBAEBAgAGBQJSgkG/AAoJEH7ltONmPFDRzScQALEcS5RkbI4y8/xeuEVQ2yPc
NyDDVWWnEq2GuqlFP0eDudk+9TqFRBVaniundhg6VutRjcj+h9fwg//Iosf0X3P1
xK46siwmXOHFWXkw65+2E2kYQP9K83Z5KPwz/lW2UPmHUjqTrx5ejK2/Zpe0018S
viASROl/mU1NrYodx1fYzwFJKEqQ+wisMyd8MZCRx0mmMdOuhiRGLeDL15lS62N9
HAODCS3RvnjmMbWTut0fNGbiebG3N7VGjQEknTJxJMzsa3eJLBt+rddWw2H7Rtyq
rc04cadfliEprmVCHSxrxhGv78I93F36JPMwEXKGFcCrRSHSmsGdAvHSZrwF9mIa
DtVBXB+POO0gdRySE5gukOL1O4JP/YqUx4bfZUDNKChOXAw6VJHJJWnWCl5G8cp5
XdNGRWz9SGHegtWTqCPXfrFmTGof36wSIak0GSO+Z1+whDV6jFGGcjY9m0EcspbP
wtB80pzcjjOfgL6BnqBTbAzr/pkvf6K2INcRGHg6WCGMf9EIz7y1rf3p79otkG4C
C3PFkoLKbOX0XmLpOgXgiAfKV5bMPelRFaPEhAxRxjFi2VaSAgtHBVs/N+m2w3/D
fmRh3J4o9C9/WmgEJXPlUprpHpKAKXDvDXR4GGfdx6mTla/WFahfQLg9E/SbJSAY
5iN+BnC08LxB0f34+p34
=KGU+
-----END PGP SIGNATURE-----
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
Hash: SHA1
The Fedora 20 "Heisenbug" beta release has arrived with a preview of
the latest fantastic, free, and open source technology currently under
development. Take a peek inside:
*** What is the Beta Release? ***
The beta release is the last important milestone before the release of Fedora
20. A Beta release is code-complete and bears a very strong resemblance to the
third and final release. Only critical bug fixes will be pushed as updates up
to the general release of Fedora 20. The final release of Fedora 20 is expected
in early December. Meanwhile, download the beta of Fedora 20 and help us make
it even better:
http://fedoraproject.org/get-prerelease
We need your help to make Fedora 20 the best release yet, so please take some
time to download and try out the beta and make sure the things that are
important to you are working. If you find a bug, please report it – every bug
you uncover is a chance to improve the experience for millions of Fedora users
worldwide. Together, we can make Fedora 20 a rock-solid distribution. We have a
culture of coordinating new features and pushing fixes upstream as much as
feasible and your feedback will help improve not only Fedora but Linux and free
software on the whole. (See the end of this announcement for more information
on how to help.)
Since it's a beta release, some problems may still be lurking. A list of
problems that we already know about can be found at the Common F20 bugs page,
found at http://fedoraproject.org/wiki/Common_F20_bugs.
== 10 Years of Fedora ==
The Fedora 20 release coincides nicely with the 10th anniversary of Fedora. The
first Fedora release (then called Fedora Core 1) came out on November 6, 2003.
Since then, the Fedora Project has become an active and vibrant community that
produces nearly a dozen "spins" that are tailor made for desktop users,
hardware design, gaming, musicians, artists, and early classroom environments.
== ARM as a Primary Architecture ==
While Fedora has supported a number of hardware architectures over the years,
x86/x86_64 has been the default for the majority of Fedora users and for the
Linux community in general.
ARM, however, has been making massive strides. It already dominates the mobile
market, and is becoming a go-to platform for hobbyists and makers, and is
showing enormous promise for the server market as well.
In keeping with Fedora's commitment to innovation, the Fedora community has
been pushing to make ARM a primary architecture to satisfy the needs of users
and developers targeting the ARM platform.
*** Maturity and Advanced Features ***
Sometimes it's not the big new features that make a users' experience better,
it's the little enhancements or long-awaited tricky features that really help
make a new release the bee's knees.
=== NetworkManager Improvements ===
NetworkManager is getting several improvements in Fedora 20 that will be
welcome additions for power users and system administrators.
Users will now be able to add, edit, delete, activate, and de-activate network
connections via the nmcli command line tool, which will make life much easier
for non-desktop uses of Fedora.
NetworkManager is also getting support for bonding interfaces and bridging
interfaces. Bonding and bridging are used in many enterprise setups and are
necessary for virtualization and fail-over scenarios.
=== No Default Sendmail, Syslog ===
Fedora 20 removes some services that many users find unnecessary, though (of
course) they will remain available as installable packages for users who might
need them.
The systemd journal now takes the place as the default logging solution, having
been tested and able to manage persistent logging in place of syslog.
Also, Sendmail will no longer be installed by default, as most Fedora installs
have no need of a Mail Transfer Agent (MTA).
=== Cloud and Virtualization Improvements ===
The Fedora 20 release continues the Fedora tradition of adopting and
integrating leading edge technologies used in cloud computing. This release
includes a number of features that will make working with virtualization and
cloud computing much easier.
=== First-Class Cloud Images ===
The Fedora Cloud SIG has been working hard on providing images that are
well-suited to running as guests in public and private clouds like Amazon Web
Services (AWS) and OpenStack. If you're using public or private cloud, you
should definitely test-drive the beta images today!
=== OS Installer Support for LVM Thin Provisioning ===
LVM has introduced thin provisioning technology, which provides greatly
improved snapshot functionality in addition to thin provisioning capability.
This change will make it possible to configure thin provisioning during OS
installation.
=== VM Snapshot UI with virt-manager ===
This change will make taking VM snapshots much easier. qemu and libvirt have
all the major pieces in place for performing safe VM snapshots/checkpoints,
however there isn't any simple discoverable UI. This feature will track adding
that UI to virt-manager, and any other virt stack bits that need to be fixed/
improved. This includes adding functionality to libvirt to support deleting and
rebasing to external snapshots.
=== Role based access control with libvirt ===
Libvirt role based access control will allow fine grained access control like
'user FOO can only start/stop/pause vm BAR', but for all libvirt APIs and
objects.
=== ARM on x86 with libvirt/virt-manager ===
This change will fix running ARM VMs on x86 hosts using standard libvirt tools
libvirt virsh, virt-manager and virt-install.
*** Developer Goodness ***
As always, Fedora 20 will include several new features and updated packages
that will be of interest to all manner of developers.
=== ACPICA Tools Update ===
Fedora 20 includes an update to the ACPICA tools from the Component
Architecture (ACPICA) project. This provides developers with a significant
number of additional tools that have never been included in Fedora before --
for example, tools that allow one to create an ACPI table and execute the
methods contained in the table in user space, instead of having to modify
existing tables. The update brings Fedora up-to-date for ACPI development and
exploration, and reflects the reference implementation as closely as possible.
=== Ruby on Rails 4.0 ===
This update will keep Fedora up-to-date and will ensure that the current Ruby
on Rails developers stay with us as they will get support for system-packaged
Ruby on Rails of the latest version. Apart from that, Rails 4.0 also bring
improved functionality, speed, security and better modularization.
=== GNU C Library 2.18 ===
Fedora 20 includes the GNU C Library version 2.18, which brings the project up
to sync with the upstream release from the GNU project, released in August.
This resolves a number of bugs from upstream as well as security issues. This
upgrade should be backwards compatible.
*** Even More Changes ***
Fedora prides itself on bringing cutting-edge technologies to users of open
source software around the world, and this release continues that tradition. No
matter what you do, Fedora 20 has the tools you need to help you get things
done.
A complete list with details of each new change is available here:
https://fedoraproject.org/wiki/Releases/20/ChangeSet
*** Desktop Environments and Spins ***
The Fedora project strives to provide the best desktop experiences possible for
users, from desktop environment to application selection.
== GNOME 3.10 ==
Fedora 20 Beta will have a preview of GNOME 3.10. GNOME 3.10 will have a number
of new applications and new features that will please GNOME-lovers in the
Fedora 20 release. This release includes a new music application (gnome-music),
a new maps application (gnome-maps), a revamp for the system status menu, and
Zimbra support in Evolution.
== KDE Plasma Workspaces 4.11 ==
The Fedora KDE SIG has rebased to KDE 4.11 for Fedora 20. This release includes
faster Nepomuk indexing, improvements to Kontact, KScreen integration in KWin,
Metalink/HTTP support for KGet, and much more.
== X2Go ==
The current nx package in Fedora is based on the last open source release from
NoMachine. NoMachine is no longer developing nx as an open source project. The
X2Go project has taken the nx code and is maintaining it as well as developing
new client and server code around it.
*** Spins ***
Spins are alternate versions of Fedora. In addition to various desktop
environments for Fedora, spins are also available as tailored environments for
various types of users via hand-picked application sets or customizations.
To see all of the Official Fedora 20 Release Spins, see the Fedora 20 Release
Spins link.
Nightly composes of alternate Spins are available here:
http://dl.fedoraproject.org/pub/alt/nightly-composes
*** Note on performance ***
Fedora development releases use a kernel with extra debug information to help
us understand and resolve issues faster; however, this can have a significant
impact on performance. Refer to the kernel debug strategy for more details. You
can boot with slub_debug=- or use the kernel from nodebug repository to disable
the extra debug info.
*** Issues and Details ***
Heisenbug Alpha is a testing release. To report issues encountered during
testing, contact the Fedora QA team via the mailing list or in #fedora-qa on
freenode.
As testing progresses, common issues are tracked at
https://fedoraproject.org/wiki/Common_F20_bugs
For tips on reporting a bug effectively, read
http://fedoraproject.org/wiki/How_to_file_a_bug_report .
*** Contributing ***
There are many ways to contribute beyond bug reporting. You can help translate
software and content, test and give feedback on software updates, write and
edit documentation, design and do artwork, help with all sorts of promotional
activities, and package free software for use by millions of Fedora users
worldwide. To get started, visit http://join.fedoraproject.org today!
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iQIcBAEBAgAGBQJSgkG/AAoJEH7ltONmPFDRzScQALEcS5RkbI4y8/xeuEVQ2yPc
NyDDVWWnEq2GuqlFP0eDudk+9TqFRBVaniundhg6VutRjcj+h9fwg//Iosf0X3P1
xK46siwmXOHFWXkw65+2E2kYQP9K83Z5KPwz/lW2UPmHUjqTrx5ejK2/Zpe0018S
viASROl/mU1NrYodx1fYzwFJKEqQ+wisMyd8MZCRx0mmMdOuhiRGLeDL15lS62N9
HAODCS3RvnjmMbWTut0fNGbiebG3N7VGjQEknTJxJMzsa3eJLBt+rddWw2H7Rtyq
rc04cadfliEprmVCHSxrxhGv78I93F36JPMwEXKGFcCrRSHSmsGdAvHSZrwF9mIa
DtVBXB+POO0gdRySE5gukOL1O4JP/YqUx4bfZUDNKChOXAw6VJHJJWnWCl5G8cp5
XdNGRWz9SGHegtWTqCPXfrFmTGof36wSIak0GSO+Z1+whDV6jFGGcjY9m0EcspbP
wtB80pzcjjOfgL6BnqBTbAzr/pkvf6K2INcRGHg6WCGMf9EIz7y1rf3p79otkG4C
C3PFkoLKbOX0XmLpOgXgiAfKV5bMPelRFaPEhAxRxjFi2VaSAgtHBVs/N+m2w3/D
fmRh3J4o9C9/WmgEJXPlUprpHpKAKXDvDXR4GGfdx6mTla/WFahfQLg9E/SbJSAY
5iN+BnC08LxB0f34+p34
=KGU+
-----END PGP SIGNATURE-----
_______________________________________________
devel-announce mailing list
devel-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel-announce
[USN-2027-1] SPICE vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgiqUAAoJEGVp2FWnRL6TBPMP/3raRY+WNxiKcdW/CwEkiiH+
qf0LQXkgXMWZlBoIIJASZyZiB3ct63sZpQENJBFVeZCYjKquElEhiryVn8mLbrtC
w8t5IbZYrY4Is6PEn3z0LRWZvR5xHs9VYTyaPZM9uP8dXpB5jWIYAFb4liCAR/qT
X3kuC1s3ZDVzyMpsGlhVYzcZAHLz4wp8ad8yCCMCS4xFNR5rjyObvgUpavg1kxrw
ryeP12SY3gSAAnrph4B/x2tn8aXekSlvo85+DoS1cec460H4RgSbUQVzd2YQNR1W
UUBDcvxgEd+NFjbeIubl/1i/ZH0/aNejlJj1lS5DfHu9R+pgSwFcfitQvtmwsQos
A4Xwoj49+SoWt2D9sHBeFAb5jaIeODIkf7/5rqZQdFDorsg356Z5oVcxqagA7T6q
afcKygtjjwUeCutK06BxXzFM0NX+yWu12WhiEeWv2qfifFWG/PW9lGMsWLy+kwC9
EQMApHDh7DqYbI8TgC8IGxCqA0gCIk0EKSjbx+f8JlZMb2ZIdMVEuFoM3/L/tYa1
ZgrrGneXvbzTttkpecTISPSJamKgNz8K5SZqq6wPJpxLwR1i/HouxDpS4UPVoS+t
c50hQwCl9FoESj7kEjcVFrrTq3GWhj2UbToUGZsnbBaLRV1f+d5jJUEqS2FJ/Rsp
9fTtqYSPxhB/x+CJkTRK
=RSjO
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2027-1
November 12, 2013
spice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.10
- Ubuntu 13.04
Summary:
SPICE could be made to crash if it received specially crafted network
traffic.
Software Description:
- spice: SPICE protocol client and server library
Details:
Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in
SPICE tickets. An attacker could use this issue to cause the SPICE server
to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
libspice-server1 0.12.4-0nocelt1ubuntu0.1
Ubuntu 13.04:
libspice-server1 0.12.2-0nocelt2expubuntu1.2
After a standard system update you need to restart applications using the
SPICE protocol, such as QEMU, to make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2027-1
CVE-2013-4282
Package Information:
https://launchpad.net/ubuntu/+source/spice/0.12.4-0nocelt1ubuntu0.1
https://launchpad.net/ubuntu/+source/spice/0.12.2-0nocelt2expubuntu1.2
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgiqUAAoJEGVp2FWnRL6TBPMP/3raRY+WNxiKcdW/CwEkiiH+
qf0LQXkgXMWZlBoIIJASZyZiB3ct63sZpQENJBFVeZCYjKquElEhiryVn8mLbrtC
w8t5IbZYrY4Is6PEn3z0LRWZvR5xHs9VYTyaPZM9uP8dXpB5jWIYAFb4liCAR/qT
X3kuC1s3ZDVzyMpsGlhVYzcZAHLz4wp8ad8yCCMCS4xFNR5rjyObvgUpavg1kxrw
ryeP12SY3gSAAnrph4B/x2tn8aXekSlvo85+DoS1cec460H4RgSbUQVzd2YQNR1W
UUBDcvxgEd+NFjbeIubl/1i/ZH0/aNejlJj1lS5DfHu9R+pgSwFcfitQvtmwsQos
A4Xwoj49+SoWt2D9sHBeFAb5jaIeODIkf7/5rqZQdFDorsg356Z5oVcxqagA7T6q
afcKygtjjwUeCutK06BxXzFM0NX+yWu12WhiEeWv2qfifFWG/PW9lGMsWLy+kwC9
EQMApHDh7DqYbI8TgC8IGxCqA0gCIk0EKSjbx+f8JlZMb2ZIdMVEuFoM3/L/tYa1
ZgrrGneXvbzTttkpecTISPSJamKgNz8K5SZqq6wPJpxLwR1i/HouxDpS4UPVoS+t
c50hQwCl9FoESj7kEjcVFrrTq3GWhj2UbToUGZsnbBaLRV1f+d5jJUEqS2FJ/Rsp
9fTtqYSPxhB/x+CJkTRK
=RSjO
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2027-1
November 12, 2013
spice vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.10
- Ubuntu 13.04
Summary:
SPICE could be made to crash if it received specially crafted network
traffic.
Software Description:
- spice: SPICE protocol client and server library
Details:
Tomas Jamrisko discovered that SPICE incorrectly handled long passwords in
SPICE tickets. An attacker could use this issue to cause the SPICE server
to crash, resulting in a denial of service.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
libspice-server1 0.12.4-0nocelt1ubuntu0.1
Ubuntu 13.04:
libspice-server1 0.12.2-0nocelt2expubuntu1.2
After a standard system update you need to restart applications using the
SPICE protocol, such as QEMU, to make all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2027-1
CVE-2013-4282
Package Information:
https://launchpad.net/ubuntu/+source/spice/0.12.4-0nocelt1ubuntu0.1
https://launchpad.net/ubuntu/+source/spice/0.12.2-0nocelt2expubuntu1.2
Monday, November 11, 2013
Scientific Linux 5.10 is officially released for i686/x86_64
Scientific Linux "SL 5.10" for i386/x86_64 Nov 11, 2013
As a reminder, the SL5x repo always points to the most recent release.
The SL5x repo has been updated to point to SL 5.10 at this time.
Users of the Scientific Linux 5x repo should run
yum clean expire-cache
This should allow yum to notice the updated metadata within the 5x repo.
Mirror sites are encouraged to synchronize their mirrors at this time.
You can read the full release notes from SL and TUV at:
SL:
http://ftp.scientificlinux.org/linux/scientific/510/i386/SL.releasenote
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/SL.releasenote
TUV:
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/SL.documentation/RELEASE-NOTES-U10-x86_64-en.html
http://ftp.scientificlinux.org/linux/scientific/510/i386/SL.documentation/RELEASE-NOTES-U10-x86-en.html
_____________________________________________________________________________
DOWNLOAD INFO
_____________________________________________________________________________
http://ftp.scientificlinux.org/linux/scientific/510/i386/
http://ftp1.scientificlinux.org/linux/scientific/510/i386/
ftp://ftp.scientificlinux.org/linux/scientific/510/i386/
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/
http://ftp1.scientificlinux.org/linux/scientific/510/x86_64/
ftp://ftp.scientificlinux.org/linux/scientific/510/x86_64/
-----------------------------------------------------------------------------
Major Differences from SL 5.10
-----------------------------------------------------------------------------
As always we encourage you to read the official release notes:
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/SL.documentation/RELEASE-NOTES-U10-x86_64-en.html
MySQL:
Scientific Linux 5.10 provides updated versions, specifically versions
5.1 and 5.5, of the MySQL packages as software collections.
In order to migrate from MySQL 5.0 to 5.5, you must first update to
MySQL 5.1. Note that the MySQL 5.1 packages are not supported and are
provided only for the purposes of migration to MySQL 5.5. You should not
use MySQL 5.1 on any of your production systems.
For more information on the migration from MySQL 5.0 to MySQL 5.5, refer
to chapter Migrating from MySQL 5.0 to MySQL 5.5 provided by Upstream
at:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/5/html/Deployment_Guide/ch-Migrating_from_MySQL_5.0_to_MySQL_5.5.html
As a result of this update, we will not issue any more security
advisories for the MySQL 5.0 packages (mysql-5.0.* and related
packages). Security advisories will be provided only for MySQL 5.5.
-----------------------------------------------------------------------------
Mailing Lists
scientific-linux-users@fnal.gov - Users of Scientific Linux supporting
each other
scientific-linux-devel@fnal.gov - Development of Scientific Linux
scientific-linux-announce@fnal.gov - Announcements concerning Scientific
Linux
scientific-linux-errata@fnal.gov - Announcements about Security Errata
scientific-linux-mirrors@fnal.gov - Announcements about Scientific Linux
related to mirroring
--
Pat Riehecky
Scientific Linux developer
http://www.scientificlinux.org/
As a reminder, the SL5x repo always points to the most recent release.
The SL5x repo has been updated to point to SL 5.10 at this time.
Users of the Scientific Linux 5x repo should run
yum clean expire-cache
This should allow yum to notice the updated metadata within the 5x repo.
Mirror sites are encouraged to synchronize their mirrors at this time.
You can read the full release notes from SL and TUV at:
SL:
http://ftp.scientificlinux.org/linux/scientific/510/i386/SL.releasenote
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/SL.releasenote
TUV:
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/SL.documentation/RELEASE-NOTES-U10-x86_64-en.html
http://ftp.scientificlinux.org/linux/scientific/510/i386/SL.documentation/RELEASE-NOTES-U10-x86-en.html
_____________________________________________________________________________
DOWNLOAD INFO
_____________________________________________________________________________
http://ftp.scientificlinux.org/linux/scientific/510/i386/
http://ftp1.scientificlinux.org/linux/scientific/510/i386/
ftp://ftp.scientificlinux.org/linux/scientific/510/i386/
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/
http://ftp1.scientificlinux.org/linux/scientific/510/x86_64/
ftp://ftp.scientificlinux.org/linux/scientific/510/x86_64/
-----------------------------------------------------------------------------
Major Differences from SL 5.10
-----------------------------------------------------------------------------
As always we encourage you to read the official release notes:
http://ftp.scientificlinux.org/linux/scientific/510/x86_64/SL.documentation/RELEASE-NOTES-U10-x86_64-en.html
MySQL:
Scientific Linux 5.10 provides updated versions, specifically versions
5.1 and 5.5, of the MySQL packages as software collections.
In order to migrate from MySQL 5.0 to 5.5, you must first update to
MySQL 5.1. Note that the MySQL 5.1 packages are not supported and are
provided only for the purposes of migration to MySQL 5.5. You should not
use MySQL 5.1 on any of your production systems.
For more information on the migration from MySQL 5.0 to MySQL 5.5, refer
to chapter Migrating from MySQL 5.0 to MySQL 5.5 provided by Upstream
at:
https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/5/html/Deployment_Guide/ch-Migrating_from_MySQL_5.0_to_MySQL_5.5.html
As a result of this update, we will not issue any more security
advisories for the MySQL 5.0 packages (mysql-5.0.* and related
packages). Security advisories will be provided only for MySQL 5.5.
-----------------------------------------------------------------------------
Mailing Lists
scientific-linux-users@fnal.gov - Users of Scientific Linux supporting
each other
scientific-linux-devel@fnal.gov - Development of Scientific Linux
scientific-linux-announce@fnal.gov - Announcements concerning Scientific
Linux
scientific-linux-errata@fnal.gov - Announcements about Security Errata
scientific-linux-mirrors@fnal.gov - Announcements about Scientific Linux
related to mirroring
--
Pat Riehecky
Scientific Linux developer
http://www.scientificlinux.org/
[USN-2026-1] libvirt vulnerability
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgP/6AAoJEGVp2FWnRL6TcOYQAJ9xo5r2gBkuOC1ZCJbYnbJW
DP3NfKI9fZt4g/JL8TY5gYM2d7mkrBn609UuDOimhrWi45PKsac8KZYJrEl/arbn
gojRoGjGZdy3zqIEKE9WJc8baJthDKfMEsT/5MoxuKxZB+F35Hrm0p0YcBO5G3Tx
yXeruBm/i3EVDEHdcn+wGZ7xnWWPlL8n0XcynoFmzPO536Y87byEd/wjUfCo5gPH
cBMve60M05pQUUK2AdgDUVJUyVN03Rp7oWjarm+x1Nk5buNHTzsP4dbD54X9UHzk
m+pGjBx6F2WSnNcKhCgDcVL/StosWd7R1qEos4XCvoPXsnzNTo4OkwNjeyDo4i8B
gtYUtblZyA6Xq0jCJNQ89d4KmpS5dNMQZ3Bb4SjrHVroSUug+A+RXKvN1mXASQTb
XG79GCWAPzSkodA5n+atq1rRdhnf+aeSIaIJwQKn0r58s3zlWQhLBrchUiz7ua8v
Gtjfp0kAbd7u6aSaXA8uILDXtqD5fIwaXnrEqvatlwrwDWTmZQwXohy76hccjXD4
bsivRfa2xbJXGCBZVrp28vrtEochSNzuQA57fAgrb4SsB7zJmRS2T5VG56N6x8A/
FKtZraJQvD5x7SZqEOTmLmvfEiG6Qr4jy4Fz/0XidoSCo4Ctn/IYqenw0MKNG4iN
azA11nQECo/S5jeSqNkE
=aA84
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2026-1
November 11, 2013
libvirt vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.10
Summary:
libvirt would allow unintended access privileges.
Software Description:
- libvirt: Libvirt virtualization toolkit
Details:
It was discovered that libvirt incorrectly checked privileges when the
virConnectDomainXMLToNative API function was used. An attacker could
possibly use this flaw to gain write privileges, contrary to expected
behaviour.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
libvirt0 1.1.1-0ubuntu8.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2026-1
CVE-2013-4401
Package Information:
https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgP/6AAoJEGVp2FWnRL6TcOYQAJ9xo5r2gBkuOC1ZCJbYnbJW
DP3NfKI9fZt4g/JL8TY5gYM2d7mkrBn609UuDOimhrWi45PKsac8KZYJrEl/arbn
gojRoGjGZdy3zqIEKE9WJc8baJthDKfMEsT/5MoxuKxZB+F35Hrm0p0YcBO5G3Tx
yXeruBm/i3EVDEHdcn+wGZ7xnWWPlL8n0XcynoFmzPO536Y87byEd/wjUfCo5gPH
cBMve60M05pQUUK2AdgDUVJUyVN03Rp7oWjarm+x1Nk5buNHTzsP4dbD54X9UHzk
m+pGjBx6F2WSnNcKhCgDcVL/StosWd7R1qEos4XCvoPXsnzNTo4OkwNjeyDo4i8B
gtYUtblZyA6Xq0jCJNQ89d4KmpS5dNMQZ3Bb4SjrHVroSUug+A+RXKvN1mXASQTb
XG79GCWAPzSkodA5n+atq1rRdhnf+aeSIaIJwQKn0r58s3zlWQhLBrchUiz7ua8v
Gtjfp0kAbd7u6aSaXA8uILDXtqD5fIwaXnrEqvatlwrwDWTmZQwXohy76hccjXD4
bsivRfa2xbJXGCBZVrp28vrtEochSNzuQA57fAgrb4SsB7zJmRS2T5VG56N6x8A/
FKtZraJQvD5x7SZqEOTmLmvfEiG6Qr4jy4Fz/0XidoSCo4Ctn/IYqenw0MKNG4iN
azA11nQECo/S5jeSqNkE
=aA84
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2026-1
November 11, 2013
libvirt vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.10
Summary:
libvirt would allow unintended access privileges.
Software Description:
- libvirt: Libvirt virtualization toolkit
Details:
It was discovered that libvirt incorrectly checked privileges when the
virConnectDomainXMLToNative API function was used. An attacker could
possibly use this flaw to gain write privileges, contrary to expected
behaviour.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
libvirt0 1.1.1-0ubuntu8.1
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2026-1
CVE-2013-4401
Package Information:
https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.1
[USN-2025-1] Libav vulnerabilities
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgP/lAAoJEGVp2FWnRL6TFHAP/iS00tjidaXTqBvigfMieEAY
TvgpRPCQUzJQOjV4DgDDe/XtQs0rmCgZ3wBEHNW4U0RCyizO3cM1jCOXxpBmFmOy
7x5nLuuW6qANUL4avipp7mcga+QD24pOr2tJX38pNGaAhImzj/kPcKg4CWknGhBi
MI0WDwA4MuN2C22h8m3p6qwg1VMfVjmtomuHwjSCHyRhdKmk9vsCtSABgAFwmVYB
CYBZJglocw44T3ktMP6fXTeIlbZE/Dcu3oF9BCIO0R5DBuGKfpndPnN66CpWjfMn
MPuKeRAbA0Ko/dwbBGjKSUmAtJcvbcQmxyY0ipE6zpyCxBrKX4BHTBzXij2vQK45
F3o0bM0Q6AhfpL10Lmvk/0Ff6Cr/CPLCpGicARiBVheIaD2VTehMx3iSZXldlFux
vBBwLrPv3UHyWdFkSdNc/TWMUzMx6SfYN4TDcKsEBGJkptaTH10TdB2Vfx64I5j8
6cUsEHl3G6Bn/5YUK+bjhLJksqeXkJMQLvlEe2RSgKDkc9Zv+ReK7Ksf6YAfSsRX
NGTkSFyM9ljti8/4ck2lVEzVHQTEKvzikz+BoApSFSGAqXyA6XTxVwd3g55vs5VP
qNz3/xQH7CZ8ij/exztmgirIcnHvvW68cXpMAO5+GMKqFtzhWzTuySevcvRpjtHr
VsxREsHvJgs7ZaJKPrdX
=s4c8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2025-1
November 11, 2013
libav vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
Software Description:
- libav: Multimedia player, server, encoder and transcoder
Details:
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
libavcodec53 6:0.8.9-0ubuntu0.13.10.1
libavformat53 6:0.8.9-0ubuntu0.13.10.1
Ubuntu 13.04:
libavcodec53 6:0.8.9-0ubuntu0.13.04.1
libavformat53 6:0.8.9-0ubuntu0.13.04.1
Ubuntu 12.10:
libavcodec53 6:0.8.9-0ubuntu0.12.10.1
libavformat53 6:0.8.9-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
libavcodec53 4:0.8.9-0ubuntu0.12.04.1
libavformat53 4:0.8.9-0ubuntu0.12.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
http://www.ubuntu.com/usn/usn-2025-1
https://launchpad.net/bugs/1249621
Package Information:
https://launchpad.net/ubuntu/+source/libav/6:0.8.9-0ubuntu0.13.10.1
https://launchpad.net/ubuntu/+source/libav/6:0.8.9-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/libav/6:0.8.9-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/libav/4:0.8.9-0ubuntu0.12.04.1
Version: GnuPG v1.4.14 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCgAGBQJSgP/lAAoJEGVp2FWnRL6TFHAP/iS00tjidaXTqBvigfMieEAY
TvgpRPCQUzJQOjV4DgDDe/XtQs0rmCgZ3wBEHNW4U0RCyizO3cM1jCOXxpBmFmOy
7x5nLuuW6qANUL4avipp7mcga+QD24pOr2tJX38pNGaAhImzj/kPcKg4CWknGhBi
MI0WDwA4MuN2C22h8m3p6qwg1VMfVjmtomuHwjSCHyRhdKmk9vsCtSABgAFwmVYB
CYBZJglocw44T3ktMP6fXTeIlbZE/Dcu3oF9BCIO0R5DBuGKfpndPnN66CpWjfMn
MPuKeRAbA0Ko/dwbBGjKSUmAtJcvbcQmxyY0ipE6zpyCxBrKX4BHTBzXij2vQK45
F3o0bM0Q6AhfpL10Lmvk/0Ff6Cr/CPLCpGicARiBVheIaD2VTehMx3iSZXldlFux
vBBwLrPv3UHyWdFkSdNc/TWMUzMx6SfYN4TDcKsEBGJkptaTH10TdB2Vfx64I5j8
6cUsEHl3G6Bn/5YUK+bjhLJksqeXkJMQLvlEe2RSgKDkc9Zv+ReK7Ksf6YAfSsRX
NGTkSFyM9ljti8/4ck2lVEzVHQTEKvzikz+BoApSFSGAqXyA6XTxVwd3g55vs5VP
qNz3/xQH7CZ8ij/exztmgirIcnHvvW68cXpMAO5+GMKqFtzhWzTuySevcvRpjtHr
VsxREsHvJgs7ZaJKPrdX
=s4c8
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2025-1
November 11, 2013
libav vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 13.10
- Ubuntu 13.04
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
Libav could be made to crash or run programs as your login if it opened a
specially crafted file.
Software Description:
- libav: Multimedia player, server, encoder and transcoder
Details:
It was discovered that Libav incorrectly handled certain malformed media
files. If a user were tricked into opening a crafted media file, an
attacker could cause a denial of service via application crash, or possibly
execute arbitrary code with the privileges of the user invoking the
program.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 13.10:
libavcodec53 6:0.8.9-0ubuntu0.13.10.1
libavformat53 6:0.8.9-0ubuntu0.13.10.1
Ubuntu 13.04:
libavcodec53 6:0.8.9-0ubuntu0.13.04.1
libavformat53 6:0.8.9-0ubuntu0.13.04.1
Ubuntu 12.10:
libavcodec53 6:0.8.9-0ubuntu0.12.10.1
libavformat53 6:0.8.9-0ubuntu0.12.10.1
Ubuntu 12.04 LTS:
libavcodec53 4:0.8.9-0ubuntu0.12.04.1
libavformat53 4:0.8.9-0ubuntu0.12.04.1
This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
References:
http://www.ubuntu.com/usn/usn-2025-1
https://launchpad.net/bugs/1249621
Package Information:
https://launchpad.net/ubuntu/+source/libav/6:0.8.9-0ubuntu0.13.10.1
https://launchpad.net/ubuntu/+source/libav/6:0.8.9-0ubuntu0.13.04.1
https://launchpad.net/ubuntu/+source/libav/6:0.8.9-0ubuntu0.12.10.1
https://launchpad.net/ubuntu/+source/libav/4:0.8.9-0ubuntu0.12.04.1
[CentOS-announce] CEBA-2013:1511 CentOS 5 rgmanager Update
CentOS Errata and Bugfix Advisory 2013:1511
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1511.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
9ded8cda8eaac003ade6fe78617fb6adb8b0ab38a1e8195722f53a2422392b8f rgmanager-2.0.52-47.el5.centos.4.i386.rpm
x86_64:
737e69d1517b587c8a4f6bd8e67c22f49025864e305a1aa49030835d06d8d9d0 rgmanager-2.0.52-47.el5.centos.4.x86_64.rpm
Source:
ba0a1e6566686f8e71e6dd00e65bcc11d0400485a2da72cdf739c2e98b0811d5 rgmanager-2.0.52-47.el5.centos.4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Upstream details at : https://rhn.redhat.com/errata/RHBA-2013-1511.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
9ded8cda8eaac003ade6fe78617fb6adb8b0ab38a1e8195722f53a2422392b8f rgmanager-2.0.52-47.el5.centos.4.i386.rpm
x86_64:
737e69d1517b587c8a4f6bd8e67c22f49025864e305a1aa49030835d06d8d9d0 rgmanager-2.0.52-47.el5.centos.4.x86_64.rpm
Source:
ba0a1e6566686f8e71e6dd00e65bcc11d0400485a2da72cdf739c2e98b0811d5 rgmanager-2.0.52-47.el5.centos.4.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
http://lists.centos.org/mailman/listinfo/centos-announce
Subscribe to:
Posts (Atom)