Monday, September 24, 2018

Fedora 30 Self-Contained Change proposal: PHP 7.3

https://fedoraproject.org/wiki/Changes/php73

= PHP 7.3 =

== Summary ==
Update the PHP stack in Fedora to latest version 7.3.x

== Owner ==
* Name: [[User:Remi| Remi Collet]] and [[SIGs/PHP|PHP SIG]]
* Email: remi at fedoraproject dot org

== Detailed Description ==
Update the PHP stack in Fedora to latest version 7.3.x.

* [http://php.net/archive/2018.php#id2018-09-13-2 First RC] was
released on Sept 13th
* PHP 7.3.0 is [https://wiki.php.net/todo/php73 planed] for end of
year, which seems compatible with Fedora roadmap.

Compatibility for PHP code is very good.


== Benefit to Fedora ==
Provides the latest PHP version to developers and system administrators.

== Scope ==
* Proposal owners: Check Koschei status. Test with latest version to
ensure compatibility. Work with upstream on bug fixing. Needed mass
rebuild (C extensions) done by change owner.
* Other developers: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)

* Trademark approval: N/A (not needed for this Change)

== How To Test ==
* The PHP stack (extensions and libraries) are monitored by Koschei,
see the https://apps.fedoraproject.org/koschei/groups/php?order_by=state%2C-started
* install and play with your web applications

== User Experience ==
Developers and system administrators will have the great benefit or
running the latest PHP version.


== Dependencies ==
All php-* packages (and some *-php)

== Contingency Plan ==
* Contingency mechanism: Drop not compatible packages.

== Documentation ==
* [https://raw.githubusercontent.com/php/php-src/PHP-7.3/UPGRADING
* [https://raw.githubusercontent.com/php/php-src/PHP-7.3/UPGRADING.INTERNALS
--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

Thursday, September 20, 2018

The Fedora 29 Beta RC5 compose [1] is GO and is going to be shipped
live on Tuesday, September 25, 2018.

For more information please check the Go/No-Go meeting minutes [2] or logs [3].

Thank you to everyone who has and still is working on this release!

[1] http://dl.fedoraproject.org/pub/alt/stage
[2] https://meetbot.fedoraproject.org/fedora-meeting-1/2018-09-20/f29-beta-go_no_go-meeting.2018-09-20-17.00.html
[3] https://meetbot.fedoraproject.org/fedora-meeting-1/2018-09-20/f29-beta-go_no_go-meeting.2018-09-20-17.00.log.html

--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

OpenBSD Errata: September 21st, 2018 (ldtr)

Errata patches for the kernel have been released for OpenBSD 6.3 and 6.2.

On AMD CPUs, LDTR must be managed crossing between VMs.

Binary updates for the amd64 platform are available via the syspatch utility.
Source code patches can be found on the respective errata pages:

https://www.openbsd.org/errata62.html
https://www.openbsd.org/errata63.html

As these affect the kernel, a reboot will be needed after patching.

[USN-3770-2] Little CMS vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3770-2
September 20, 2018

lcms, lcms2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in Little CMS.

Software Description:
- lcms: Little CMS color management library utilities
- lcms2: Little CMS color management library

Details:

USN-3770-1 fixed a vulnerability in Little CMS. This update provides
the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 Pedro Ribeiro discoreved that Little CMS incorrectly handled certain
 files. An attacker could possibly use this issue to cause a denial of
 service. (CVE-2013-4276)

 Ibrahim El-Sayed discovered that Little CMS incorrectly handled
 certain files. An attacker could possibly use this issue to cause a
 denial of service. (CVE-2016-10165)

 Quang Nguyen discovered that Little CMS incorrectly handled certain
 files. An attacker could possibly use this issue to execute arbitrary
 code. (CVE-2018-16435)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  liblcms-utils                   1.19.dfsg-1ubuntu3.1
  liblcms1                        1.19.dfsg-1ubuntu3.1
  liblcms2-2                      2.2+git20110628-2ubuntu3.3
  liblcms2-utils                  2.2+git20110628-2ubuntu3.3

After a standard system update you need to restart applications using
Little CMS to make all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3770-2
  https://usn.ubuntu.com/usn/usn-3770-1
  CVE-2013-4276, CVE-2016-10165, CVE-2018-16435

[USN-3770-1] Little CMS vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3770-1
September 20, 2018

lcms2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Little CMS.

Software Description:
- lcms2: Little CMS color management library

Details:

Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain
files. An attacker could possibly use this issue to cause a denial of
service. (CVE-2016-10165)

Quang Nguyen discovered that Little CMS incorrectly handled certain
files. An attacker could possibly use this issue to execute arbitrary
code. (CVE-2018-16435)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  liblcms2-2                      2.9-1ubuntu0.1
  liblcms2-utils                  2.9-1ubuntu0.1

Ubuntu 16.04 LTS:
  liblcms2-2                      2.6-3ubuntu2.1
  liblcms2-utils                  2.6-3ubuntu2.1

Ubuntu 14.04 LTS:
  liblcms2-2                      2.5-0ubuntu4.2
  liblcms2-utils                  2.5-0ubuntu4.2

After a standard system update you need to restart applications using
Little CMS to make all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3770-1
  CVE-2016-10165, CVE-2018-16435

Package Information:
  https://launchpad.net/ubuntu/+source/lcms2/2.9-1ubuntu0.1
  https://launchpad.net/ubuntu/+source/lcms2/2.6-3ubuntu2.1
  https://launchpad.net/ubuntu/+source/lcms2/2.5-0ubuntu4.2

[USN-3769-1] Bind vulnerability

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAlujYygACgkQZWnYVadE
vpNi6Q//VN5pZp1TdQaYSTsMK7v4YThnf6OqnnUVE/TP9oKJ8kG1EyizsigFbpRz
X37QPDb3MBleXJVQBR0TYWo97EZdJCC0UZi6a6TQkAqFcMPE+rbj0ISf7hqQoJ/r
Ts0CdV4xGESJv5Lll5386RDKqQkDYoQ5RBAAMQa5ZP8gaFOOjUGawYn2oh347yKl
gInV7J7Sl8ySfznDCmAuGXoa7Z6NiDnOD1HcbujmRHI97gs5vr8PcGeZgF0DE08s
bn/ccvIgP74ip0uMmWoZmzmm+bdnDJgYIp6+cUOwZSjli1kSucA9t1iqJXN8cyLP
tmBK+BwiyRR1jCTOtUvPcr3E1UCx4Gr/gQ1rdvt+Q68dMs+63MYDOZEenWoraNH9
Cn07AY8Q5z1IYbWRbYoKp9uBiD3cWxon8t2Rau0SCkZsNDZQ4S54ToSmKezR+068
igtZfzhb5QFQSMiS7Uo1cSn0nh/IpcOy+GBP11KcoO3SYJm5zgpFH52iJnCrMjjc
Azi+RPq4SdaMOJNzv/1+i59r23cVs59gwvkwlFOA+bbJH1ORDUlJcqvq1XoF0LyY
3jsgaU1eRj0i5FDXrzvsSdI5O4Qe8/FIVftGY/gDPLN5I+aGpW/usexPewqiZK4d
0DFzuDrjjoeRQt/iYWOWmUAOI0bmwxEkoKv0OO+mbtAzapi+E/0=
=WtDE
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3769-1
September 20, 2018

bind9 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Bind could be made to crash if it received specially crafted network
traffic.

Software Description:
- bind9: Internet Domain Name Server

Details:

It was discovered that Bind incorrectly handled the deny-answer-aliases
feature. If this feature is enabled, a remote attacker could use this issue
to cause Bind to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
bind9 1:9.11.3+dfsg-1ubuntu1.2

Ubuntu 16.04 LTS:
bind9 1:9.10.3.dfsg.P4-8ubuntu1.11

Ubuntu 14.04 LTS:
bind9 1:9.9.5.dfsg-3ubuntu0.18

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3769-1
CVE-2018-5740

Package Information:
https://launchpad.net/ubuntu/+source/bind9/1:9.11.3+dfsg-1ubuntu1.2
https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.11
https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.18

Wednesday, September 19, 2018

Re: Fedora 29 Beta Go/No-Go meeting

Dear all,

The Go/No-Go meeting for the Fedora 29 Beta release will be held on
Thursday, 2018-09-20 at 17:00 UTC in #fedora-meeting-1. For more
information, see: https://fedoraproject.org/wiki/Go_No_Go_Meeting

View the meeting on Fedocal at
https://apps.fedoraproject.org/calendar/Fedora%20release/2018/9/10/#m9338

We will NOT be holding another Release Readiness meeting afterward.
For the results of the Release Readiness meeting, see
https://meetbot.fedoraproject.org/fedora-meeting-1/2018-09-13/f29-beta-readiness-meeting.2018-09-13-19.02.html

--
Ben Cotton
Fedora Program Manager
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org

[USN-3766-2] PHP vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3766-2
September 19, 2018

php5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in PHP.

Software Description:
- php5: HTML-embedded scripting language interpreter

Details:

USN-3766-1 fixed a vulnerability in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that PHP incorrectly handled certain exif tags in
 JPEG images. A remote attacker could possibly use this issue to cause
 PHP to crash, resulting in a denial of service. 
 (CVE-2018-14851, CVE-2018-14883)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libapache2-mod-php5             5.3.10-1ubuntu3.32
  php5-cgi                        5.3.10-1ubuntu3.32
  php5-cli                        5.3.10-1ubuntu3.32
  php5-fpm                        5.3.10-1ubuntu3.32

In general, a standard system update will make all the necessary
changes.

References:
  https://usn.ubuntu.com/usn/usn-3766-2
  https://usn.ubuntu.com/usn/usn-3766-1
  CVE-2018-14851, CVE-2018-14883

[USN-3767-2] GLib vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3767-2
September 19, 2018

glib2.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

Several security issues were fixed in GLib.

Software Description:
- glib2.0: GLib Input, Output and Streaming Library (fam module)

Details:

USN-3767-1 fixed a vulnerability in GLib. This update provides
the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that GLib incorrectly handled certain files.
 An attacker could possibly use this issue to cause a denial of service
 or execute arbitrary code. (CVE-2018-16428)

 It was discovered that GLib incorrectly handled certain files.
 An attacker could possibly use this issue to access sensitive
 information. (CVE-2018-16429)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libglib2.0-0                    2.32.4-0ubuntu1.1
  libglib2.0-bin                  2.32.4-0ubuntu1.1
  libglib2.0-dev                  2.32.4-0ubuntu1.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3767-2
  https://usn.ubuntu.com/usn/usn-3767-1
  CVE-2018-16428, CVE-2018-16429

[USN-3768-1] Ghostscript vulnerabilities

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAluiBWEACgkQZWnYVadE
vpM/RQ/8DWgSB6sSA/1HkYmNA0GEw9tnjMOqgRo0DCdMhNw4mz9PzdBMg25dPV2r
g8BH6Ji7YGcakalkzENV9UT3dv1J4A3RnvX7xTKGlqe7lszeCw3HMcGEN/gfjpCb
j13Cwk0NOf+5OapaYzKPCZQiCWjNm9zMqX/dR71YDVVnnNyAevMyTtztc0Fyjr/0
gSrnnNcJt+offhRaktH7AnuJzJP3W1Vs2XXJINyaFQq0RqlFuTA1U5V+cS+W+Esh
NOdvBuZJ/thRgjGYIsqn9d9lxccA3l1LQ5c2zgHvFQ+vm8jwYk66pzmqfeQ/KFac
IvmxSxocgUHhooDznH3PVl+S2TcTxJL0IJ8ouDSK9jhTXFQZPRpVtbBoR2KMurSO
W5Ga0iau64JBKhP2aEwQrDpuqAAN37+lD7YAlAGiIfuQI4IRSd73Cw/KhA/Rk4oN
PT9vPGn9wpYPqV9zksbZZNRP6JZyRQFH/idWaKMpGbhYq85T/YFEhygcj/Su3cZr
STSZw+OruNerH2VegagLE4M8XHcIQg5YALkjGSAV78RuCSgAtojSVzRj9gj2ufY8
ckXjCJXIWR3xj5ZTbsNa81F4I4/tZLdA5/g4GVD7OX4avg9viyAGHPACTvHzsmcO
oi4bDaLfibIlOTAAwzNN1otMxrHTf1c+uYfeMtKghqhxzi2JzNE=
=ojuO
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-3768-1
September 19, 2018

ghostscript vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Ghostscript.

Software Description:
- ghostscript: PostScript and PDF interpreter

Details:

Tavis Ormandy discovered multiple security issues in Ghostscript. If a user
or automated system were tricked into processing a specially crafted file,
a remote attacker could possibly use these issues to access arbitrary
files, execute arbitrary code, or cause a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
ghostscript 9.22~dfsg+1-0ubuntu1.2
libgs9 9.22~dfsg+1-0ubuntu1.2

Ubuntu 16.04 LTS:
ghostscript 9.18~dfsg~0-0ubuntu2.9
libgs9 9.18~dfsg~0-0ubuntu2.9

Ubuntu 14.04 LTS:
ghostscript 9.10~dfsg-0ubuntu10.13
libgs9 9.10~dfsg-0ubuntu10.13

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3768-1
CVE-2018-11645, CVE-2018-15908, CVE-2018-15909, CVE-2018-15910,
CVE-2018-15911, CVE-2018-16509, CVE-2018-16510, CVE-2018-16511,
CVE-2018-16513, CVE-2018-16539, CVE-2018-16540, CVE-2018-16541,
CVE-2018-16542, CVE-2018-16543, CVE-2018-16585, CVE-2018-16802

Package Information:
https://launchpad.net/ubuntu/+source/ghostscript/9.22~dfsg+1-0ubuntu1.2
https://launchpad.net/ubuntu/+source/ghostscript/9.18~dfsg~0-0ubuntu2.9
https://launchpad.net/ubuntu/+source/ghostscript/9.10~dfsg-0ubuntu10.13

[USN-3767-1] GLib vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3767-1
September 19, 2018

glib2.0 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in GLib.

Software Description:
- glib2.0: GLib Input, Output and Streaming Library (fam module)

Details:

It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2018-16428)

It was discovered that GLib incorrectly handled certain files.
An attacker could possibly use this issue to access sensitive
information. (CVE-2018-16429)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  libglib2.0-0                    2.56.2-0ubuntu0.18.04.2
  libglib2.0-bin                  2.56.2-0ubuntu0.18.04.2
  libglib2.0-dev                  2.56.2-0ubuntu0.18.04.2

Ubuntu 16.04 LTS:
  libglib2.0-0                    2.48.2-0ubuntu4.1
  libglib2.0-bin                  2.48.2-0ubuntu4.1
  libglib2.0-dev                  2.48.2-0ubuntu4.1

Ubuntu 14.04 LTS:
  libglib2.0-0                    2.40.2-0ubuntu1.1
  libglib2.0-bin                  2.40.2-0ubuntu1.1
  libglib2.0-dev                  2.40.2-0ubuntu1.1

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3767-1
  CVE-2018-16428, CVE-2018-16429

Package Information:
  https://launchpad.net/ubuntu/+source/glib2.0/2.56.2-0ubuntu0.18.04.2
  https://launchpad.net/ubuntu/+source/glib2.0/2.48.2-0ubuntu4.1
  https://launchpad.net/ubuntu/+source/glib2.0/2.40.2-0ubuntu1.1

Tuesday, September 18, 2018

[USN-3722-6] ClamAV vulnerabilities

==========================================================================
Ubuntu Security Notice USN-3722-6
September 18, 2018

clamav vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

USN-3722-1 introduced a regression in ClamAV.

Software Description:
- clamav: Anti-virus utility for Unix

Details:

USN-3722-1 fixed vulnerabilities in ClamAV. The new package introduced
an issue which caused dpkg-reconfigure to enter an infinite loop. This
update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that ClamAV incorrectly handled parsing certain HWP
 files. A remote attacker could use this issue to cause ClamAV to hang,
 resulting in a denial of service. (CVE-2018-0360)

 It was discovered that ClamAV incorrectly handled parsing certain PDF
 files. A remote attacker could use this issue to cause ClamAV to hang,
 resulting in a denial of service. (CVE-2018-0361)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  clamav                          0.100.1+dfsg-1ubuntu0.12.04.4

In general, a standard system update will make all the necessary
changes.

References:
  https://usn.ubuntu.com/usn/usn-3722-6
  https://usn.ubuntu.com/usn/usn-3722-1
  https://launchpad.net/bugs/1792051