Friday, October 23, 2015

[CentOS-announce] Release for Software Collections SIG content

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The Software Collections SIG group is pleased to announce a way of
Software Collections packages availability for CentOS Linux users. The
Software Collections packages have been build in CentOS Build System
[1] and will be available soon on CentOS mirrors. Collections will be
released in stacks, as we test and validate them.

With Software Collections provided by SCLo SIG, users of CentOS Linux
as well as other SIG groups in the CentOS ecosystem will be able to
use the latest versions of popular application stacks, databases or
other content mainly focused on developers. And they are able to do
this without any impact to the system versions already installed on
their machine.

The SCLo SIG is not only meant to include packages rebuilt from
Software Collections that have been made available in Red Hat Software
Collections (RHSCL), but it is also meant to include updated content
or collections that are not part of the RHSCL portfolio at all.

So far, the collections rebuilt by SCLo SIG from RHSCL are
devassist09, devtoolset-3, git19, httpd24, mariadb55, maven30,
mongodb24, mysql55, nginx14, nginx16, nodejs010, perl516, php54,
php55, postgresql92, python27, python33, rh-java-common,
rh-mariadb100, rh-mongodb26, rh-mysql56, rh-passenger40, rh-perl520,
rh-php56, rh-postgresql94, rh-python34, rh-ror41, rh-ruby22, ror40,
ruby193, ruby200, thermostat1 and v8314.

With Software Collections that are not part of RHSCL (so far
sclo-vagrant1 collection), both CentOS Linux and RHEL users will be
provided by content that is not available on those platforms otherwise.

Getting started with Software collections:
On an updated CentOS Linux 7/x86_64 machine run:
yum install centos-release-scl

This will enable the right repositories, and bring any metadata needed
to validate the content.

Learn more about Software Collections concepts at:
http://softwarecollections.org/ You can find information on the SIG at
https://wiki.centos.org/SpecialInterestGroup/SCLo this includes howto
get involved and help with the effort.

[1]: http://cbs.centos.org

- --
Karanbir Singh, Project Lead, The CentOS Project
+44-207-0999389 | http://www.centos.org/ | twitter.com/CentOS
GnuPG Key : http://www.karan.org/publickey.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQEcBAEBAgAGBQJWKllPAAoJEI3Oi2Mx7xbtRL8H/2Xt2FVKc+z+GIv8FOZmujRv
ou9OqR6UxusgWBPVBaIZ3HTTaVYRkbzt7VpbGcsbxeA6q98LyAonCOn1hoZv+d1x
SaItfkDIbz7e4lln7YUvrgfuKlNAZ7kzTXGY301VndZQRV/jU3sf4JuUR9upO9qx
J8jkKS+/1g0QP0LRATCafHlDd9PbIirASOmHcc47GyPQRD+683ulwiE7ADFw1gbP
CTVlGnXzxnFoJGGO9ZKhV9L374nWMVBqOqIF7oGddrrQ2rmSzI8P7InVjv8cMXVa
78f54x/E7/0jBJe4S0T4Wgy6uHo7y2Al8hto3DOktXnUofaOxZ6v9kGA32Svlpc=
=ace6
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] Release for qemu-kvm-ev from Virtualization SIG

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I am pleased to announce the immediate availability of qemu-kvm-ev
stack for CentOS Linux 7/x86_64. This release is delivered by the work
done in the CentOS Virtualization Special Interest Group.

In order to use this qemu-kvm version, on an updated CentOS Linux
7/x86_64 machine, you should run:
yum install centos-release-qemu-ev
yum install qemu-kvm-ev

This will bring in all the dependencies needed, including the updated
qemu-img tools.

This stack is curated as a part of the CentOS Virtualization SIG. You
can find more details about this group, including the technologies
they are bring to CentOS at their page
https://wiki.centos.org/SpecialInterestGroup/Virtualization . This
group meetings every alternate Tuesday in #centos-devel on
irc.freenode.net, details for the meetings can be found on their SIG pag
e.

We welcome participation in this group from anyone interested in
virtualization and technologies associated with it. Feel free to drop
into our list at https://lists.centos.org/mailman/listinfo/centos-virt
and say hi.

Thanks to Sandro Bonazzola from the oVirt team for building and
maintaining this qemu-kvm-ev stack.


- --
Karanbir Singh, Project Lead, The CentOS Project
+44-207-0999389 | http://www.centos.org/ | twitter.com/CentOS
GnuPG Key : http://www.karan.org/publickey.asc
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQEcBAEBAgAGBQJWKldBAAoJEI3Oi2Mx7xbtb3gIAIIF7If9daApI0cZtRPCLNC+
fz6FPpWd/OyBOkyXHFtREp32voR16eq0EMowW8P+mLAB5YJ6iauMfv7vDTHJWAnw
n3/x2MSHMsSiRCUUDnLAJHBqqJ4X1YUsNkbHE/f+Vb7AF9w2fuQE7BBUJsjGY5tQ
9V1SIkVSdzaYy2tps7Y6b9iHBk5zpMiWnFdMKfW/QTSoLp9wpi+0jlwx7aebHRAK
y1tEIljDEgwSF85IkGkNtah1LGjhiB1J4aseewjKw2azsQ1z41fh4MFnujvPXSbj
40aJoRDcLvtXtaHB5dMMXOeMFkaki4iJxH5GV3H32sGfrLm+7ZuH3n397rfuAvk=
=aU1U
-----END PGP SIGNATURE-----
_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[announce] NYC*BUG Upcoming

We are excited for the November meeting, are working on a good line-up
for 2016. Some sort of city-wide technical holiday party is in the
works, which we will publicize once we know the details.

Note that we are NOT meeting the first Wednesday of November!

We now this will be a packed meeting, so we recommend coming early.

****

November 19th - Special Meeting, Stephen R. Bourne
18:45, Stone Creek Bar & Lounge: 140 E 27th St
Notice: special meeting, not regular date

Abstract

my history and background
how and why we had to re write the shell
why I wrote my own memory management
key language design decisions
where those ideas came from
what was hard to get right
system changes we made to accommodate sh
what the rules were in UNIX group
what would I do differently today

Speaker Bio

Steve Bourne is computer scientist who is internationally known for his
work on the UNIX operating system. While at Bell Laboratories, Steve
designed the UNIX Command Language known as the "Bourne Shell". It is
the standard command line interface to UNIX and is widely used today in
scripting in the UNIX programming environment.

Steve has a Bachelor's degree in mathematics from King's College London,
England. He has a Diploma (or Master's degree) in Computer Science and a
Ph.D. in mathematics from Trinity College, Cambridge. While at the
University of Cambridge Computer Laboratory he worked on an ALGOL 68
compiler and CAMAL an early algebra system.

After Cambridge, Steve spent nine years at Bell Labs with the Seventh
Edition Unix team. As well as the Bourne shell, he wrote the adb
debugger and published /The UNIX System/, the second book on the UNIX
system, intended for a general readership. This book is recognized as a
text for the effective use of UNIX.

After Bell Labs, he spent 20 years in senior engineering management
positions. At Cisco Systems, he was director of engineering for
enterprise network management; at Sun Microsystems, he managed the
Solaris 2.0 program; at Digital Equipment Corporation, he developed
DEC's first RISC-based workstation; and at Silicon Graphics, he was
Director of Software Engineering responsible for the introduction of the
IRIS, the company's first graphics workstation.

From 2000 to 2002 he was President of the Association for Computing
Machinery. For his work on computing he was made a Fellow of the ACM in
2005. He is also a Fellow of the Royal Astronomical Society.

At present Steve is chief technology officer at Rally Venture Partners,
a Menlo Park-based venture capital group in California. He is also the
chair of the Editorial Advisory Board for /ACM Queue/, a magazine he
started when he was President of the ACM.

_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

libicu upgrade to 56.1 with soname bump in rawhide

Hi,

I'll upgrade libicu to 56.1 in rawhide, which as usual comes with
a soname bump. I requested a side tag for the builds, David Tardon will
help with rebuilding the dependent packages.

Eike

--
LibreOffice Calc developer. Number formatter stricken i18n transpositionizer.
GPG key "ID" 0x65632D3A - 2265 D7F3 A7B0 95CC 3918 630B 6A6C D5B7 6563 2D3A
Better use 64-bit 0x6A6CD5B765632D3A here is why: https://evil32.com/
Care about Free Software, support the FSFE https://fsfe.org/support/?erack

Update of Fedora 23 schedule

Hi,

due to a slip of the Fedora 23 GA date, I have modified the schedule and re-planned all the remaining tasks.
Please let me know in case you will find any discrepancy or anything missing.

Regards,
Jan

--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic

Fedora 23 Go/No-Go Meeting - 2nd round, on Thursday, October 29th, 4PM (UTC)

Join us on irc.freenode.net in #fedora-meeting-2 for the second round of the Go/No-Go meeting, wherein we shall determine the readiness of the Fedora 23. The meeting is scheduled at 4PM (UTC). Please follow the [FedoCal] link to find the time of the meeting in your time-zone.

[FedoCal] https://apps.fedoraproject.org/calendar/meeting/3146/


"Before each public release Development, QA and Release Engineering meet to determine if the release criteria are met for a particular release. This meeting is called the Go/No-Go Meeting."

"Verifying that the Release criteria are met is the responsibility of the QA Team."


For more details about this meeting see: https://fedoraproject.org/wiki/Go_No_Go_Meeting


In the meantime, keep an eye on the Fedora 23 Final Blocker list: https://qa.fedoraproject.org/blockerbugs/milestone/23/final/buglist


Thanks for attending, Jan

--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic

[USN-2780-2] MiniUPnP vulnerability

==========================================================================
Ubuntu Security Notice USN-2780-2
October 23, 2015

miniupnpc vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

An application using the MiniUPnP library could be made to crash or run
programs as your login if it received specially crafted network traffic.

Software Description:
- miniupnpc: UPnP IGD client lightweight library

Details:

USN-2780-1 fixed a vulnerability in the MiniUPnP library in Ubuntu
12.04 LTS, Ubuntu 14.04 LTS, and Ubuntu 15.04. This update provides
the corresponding update for Ubuntu 15.10.

Original advisory details:

Aleksandar Nikolic discovered a buffer overflow vulnerability in the
XML parser functionality of the MiniUPnP library. A remote attacker
could use this to cause a denial of service (application crash) or
possibly execute arbitrary code with privileges of the user running
an application that uses the MiniUPnP library.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
libminiupnpc10 1.9.20140610-2ubuntu2

After a standard system update you need to restart applications using
the MiniUPnP library to make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2780-2
http://www.ubuntu.com/usn/usn-2780-1
CVE-2015-6031

Package Information:
https://launchpad.net/ubuntu/+source/miniupnpc/1.9.20140610-2ubuntu2

Thursday, October 22, 2015

[CentOS-announce] CESA-2015:1925 Important CentOS 5 kvm Security Update

CentOS Errata and Security Advisory 2015:1925 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1925.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )


x86_64:
b0a8d2af276b509ddfb3ef7fa12b7cbd3afba9fb5fa1ae9ae38cfbb422ae0ac7 kmod-kvm-83-274.el5.centos.x86_64.rpm
8d31e38f3292cb236f64936500a7348f72150fce7bb8f06c87d7c14741d47306 kmod-kvm-debug-83-274.el5.centos.x86_64.rpm
ed8834e21ed763ebf75ac6ba8b82a17ddc282b6aa15393e2f46812460f504f50 kvm-83-274.el5.centos.x86_64.rpm
a24df4e5846371f312fd22b26a76b93ab89d9349ee9b82c35273595beef80acd kvm-qemu-img-83-274.el5.centos.x86_64.rpm
2378ff35f2480ca16be825bb66df4d5ae50773f5e0028a1d4e96410555cc3e1c kvm-tools-83-274.el5.centos.x86_64.rpm

Source:
c97f9162acf233ce5954dbba68437dfcfc7eb7709abacddf1c25b010d9485757 kvm-83-274.el5.centos.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2015:1924 Important CentOS 6 qemu-kvm Security Update

CentOS Errata and Security Advisory 2015:1924 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2015-1924.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
d32c5c64f2a0f4022a010d9404e31ef0ac6363eb3cde9b14b7e117d6672c14ec qemu-guest-agent-0.12.1.2-2.479.el6_7.2.i686.rpm

x86_64:
c535cec05139f127a6d26e2df47c3833524ac81678e61cc8b8958f0d7090c1a5 qemu-guest-agent-0.12.1.2-2.479.el6_7.2.x86_64.rpm
cbfe2c45541f1f5b97780cbd09eb23d4543156e9730c8d09873da706d7388ffe qemu-img-0.12.1.2-2.479.el6_7.2.x86_64.rpm
4cd10f6b78f67f61f46c43f9bc0cdec759a9eae1abdd3e510627dfef04bacee6 qemu-kvm-0.12.1.2-2.479.el6_7.2.x86_64.rpm
3214261a38e162a356e7f96d45a920243f0b160925bbaf6309b5292601b90f74 qemu-kvm-tools-0.12.1.2-2.479.el6_7.2.x86_64.rpm

Source:
0b2dc5f1be528fe9711582f4bae0092dfe9de8958d39f5d6bff756f838d1767f qemu-kvm-0.12.1.2-2.479.el6_7.2.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

Fedora 23 Final status is NO-GO

At the Fedora 23 Final Go/No-Go Meeting that just ends, was agreed *not to release* the Fedora 23 Final.

Due to present blockers in the RC2 build, the decision is No-Go. The release slips for one week. Second Go/No-Go meeting to be planned for the next Thursday.

Meeting details can be seen here:
Minutes: http://meetbot.fedoraproject.org/fedora-meeting-2/2015-10-22/f23-final-go_no_go-meeting.2015-10-22-16.00.html
Log: http://meetbot.fedoraproject.org/fedora-meeting-2/2015-10-22/f23-final-go_no_go-meeting.2015-10-22-16.00.log.html

Thanks everyone!

--
Jan Kuřík
Platform & Fedora Program Manager
Red Hat Czech s.r.o., Purkynova 99/71, 612 45 Brno, Czech Republic

[USN-2770-2] Oxide vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWKR2OAAoJEGEfvezVlG4P/boH/icwDYLHaybdx9cx1iGAOBi+
e9EzBakKTABiQE93WLNKmoSKEdMBHrwW4abdRhtAa1NfOp0GS0z1mP99y2SeGO2X
aw1TsWZMm75pS9+cv5bT4GnGVR/pVzXe27GwCUhssrM4Q55WMBgUu085EjH9tq9n
/3tmUK35kO+BXlslwM5megSdLs2ByyHyhJzkOIghb5tgmnZZYf5Eadm0rFo2uW0a
gtxWJ+zhuul35/vS4dlVkmMGGmZJsmVIXP58nJa4//5znmZFSuK1RWDXzTqGMcNv
4a2B1czHXgA/MJP12SUqM9pkLenS0jiBOIpJKqM5yn1s76m7LXZGoiFTAOSFkeg=
=ttfe
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2770-2
October 22, 2015

oxide-qt vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10

Summary:

Several security issues were fixed in Oxide.

Software Description:
- oxide-qt: Web browser engine library for Qt (QML plugin)

Details:

USN-2770-1 fixed vulnerabilities in Oxide in Ubuntu 14.04 LTS and Ubuntu
15.04. This update provides the corresponding updates for Ubuntu 15.10.

Original advisory details:

It was discovered that ContainerNode::parserInsertBefore in Blink would
incorrectly proceed with a DOM tree insertion in some circumstances. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to bypass same origin restrictions.
(CVE-2015-6755)

A use-after-free was discovered in the service worker implementation in
Chromium. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2015-6757)

It was discovered that Blink did not ensure that the origin of
LocalStorage resources are considered unique. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to obtain sensitive information. (CVE-2015-6759)

A race condition and memory corruption was discovered in FFmpeg. If a user
were tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via renderer crash,
or execute arbitrary code with the privileges of the sandboxed render
process. (CVE-2015-6761)

It was discovered that CSSFontFaceSrcValue::fetch in Blink did not use
CORS in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
bypass same origin restrictions. (CVE-2015-6762)

Multiple security issues were discovered in Chromium. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to read uninitialized memory, cause a denial
of service via application crash or execute arbitrary code with the
privileges of the user invoking the program. (CVE-2015-6763)

Multiple security issues were discovered in V8. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit these to read uninitialized memory, cause a denial of service via
renderer crash or execute arbitrary code with the privileges of the
sandboxed render process. (CVE-2015-7834)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
liboxideqtcore0 1.10.3-0ubuntu0.15.10.1

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2770-2
http://www.ubuntu.com/usn/usn-2770-1
CVE-2015-6755, CVE-2015-6757, CVE-2015-6759, CVE-2015-6761,
CVE-2015-6762, CVE-2015-6763, CVE-2015-7834

Package Information:
https://launchpad.net/ubuntu/+source/oxide-qt/1.10.3-0ubuntu0.15.10.1

[CentOS-announce] CEBA-2015:1922 CentOS 5 device-mapper-multipath BugFix Update

CentOS Errata and Bugfix Advisory 2015:1922

Upstream details at : https://rhn.redhat.com/errata/RHBA-2015-1922.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
3c96d4c6c99b5f3bc8f1c7f25f027f36fba0874a13df57b5b970f957d5e86e5e device-mapper-multipath-0.4.7-64.el5_11.i386.rpm
4933607a62a3cf3dc2f85f60c542c40a1c11af9190f7d755d3297a2dd74fa5f3 kpartx-0.4.7-64.el5_11.i386.rpm

x86_64:
32ae417fbba831a010a7cbca765e6e0627434fb64fd6094e0f13162537bfcdc9 device-mapper-multipath-0.4.7-64.el5_11.x86_64.rpm
cf028d56581bf3f069d69b304978acbf19e663ef5a8d3ed113307908a576df49 kpartx-0.4.7-64.el5_11.x86_64.rpm

Source:
e26389d0fabbbaebd6aa6ce297d9828f58c055d18798123bbda1387ecfd9b3d6 device-mapper-multipath-0.4.7-64.el5_11.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce