Monday, October 26, 2020
Orphaned packages looking for new maintainers
are orphaned for six weeks, unless someone adopts them. If you know for sure
that the package should be retired, please do so now with a proper reason:
https://fedoraproject.org/wiki/How_to_remove_a_package_at_end_of_life
Note: If you received this mail directly you (co)maintain one of the affected
packages or a package that depends on one. Please adopt the affected package or
retire your depending package to avoid broken dependencies, otherwise your
package will be retired when the affected package gets retired.
Request package ownership via the *Take* button in he left column on
https://src.fedoraproject.org/rpms/<pkgname>
This report is available at:
https://churchyard.fedorapeople.org/orphans-2020-10-26.txt
grep it for your FAS username and follow the dependency chain.
For human readable dependency chains, see https://packager.fedorainfracloud.org/
For all orphaned packages, see https://packager.fedorainfracloud.org/orphan
Package (co)maintainers Status Change
===============================================================================
apache-commons-configuration fnasser, mizdebsk, orphan, spike 2 weeks ago
arpwatch orphan 0 weeks ago
celt071 orphan 0 weeks ago
dnscap orphan 0 weeks ago
electrum orphan 0 weeks ago
hub orphan, ralph, sgallagh 3 weeks ago
jboss-interceptors-1.2-api orphan 6 weeks ago
jboss-jsf-2.1-api orphan 2 weeks ago
libbind orphan 0 weeks ago
log4j12 mizdebsk, orphan 6 weeks ago
metadata-extractor2 cquad, orphan 2 weeks ago
mingw-gtkglext epienbro, maci, orphan 0 weeks ago
pipsi orphan, python-sig 4 weeks ago
pyqtrailer orphan 2 weeks ago
python-XStatic-jQuery openstack-sig, orphan, rdopiera 3 weeks ago
python-beanbag orphan 2 weeks ago
python-libsass orphan 2 weeks ago
pytrailer orphan 2 weeks ago
rofi orphan, sway-sig 0 weeks ago
vdr-skinsoppalusikka orphan 5 weeks ago
vrpn orphan 0 weeks ago
vtun orphan 5 weeks ago
The following packages require above mentioned packages:
Depending on: celt071 (1), status change: 2020-10-20 (0 weeks ago)
mumble (maintained by: carlwgeorge, ngompa)
mumble-1.3.2-2.fc34.src requires celt071-devel = 0.7.1-20.fc33
mumble-1.3.2-2.fc34.x86_64 requires celt071(x86-64) = 0.7.1-20.fc33
Depending on: jboss-interceptors-1.2-api (1), status change: 2020-09-13 (6 weeks
ago)
geronimo-jcdi-1.1-api (maintained by: jjelen)
geronimo-jcdi-1.1-api-1.0-10.fc33.src requires
mvn(org.jboss.spec.javax.interceptor:jboss-interceptors-api_1.2_spec) = 1.0.1.Final
Depending on: jboss-jsf-2.1-api (1), status change: 2020-10-06 (2 weeks ago)
apache-commons-chain (maintained by: jjelen)
apache-commons-chain-1.2-24.fc33.noarch requires
mvn(org.jboss.spec.javax.faces:jboss-jsf-api_2.1_spec) = 2.0.2.Final
apache-commons-chain-1.2-24.fc33.src requires
mvn(org.jboss.spec.javax.faces:jboss-jsf-api_2.1_spec) = 2.0.2.Final
Depending on: libbind (1), status change: 2020-10-20 (0 weeks ago)
dnscap (maintained by: orphan)
dnscap-141-19.fc33.src requires libbind-devel = 6.0-22.fc33
dnscap-141-19.fc33.x86_64 requires libbind.so.4()(64bit)
Depending on: log4j12 (3), status change: 2020-09-13 (6 weeks ago)
apache-commons-configuration (maintained by: fnasser, mizdebsk, orphan, spike)
apache-commons-configuration-1.10-15.fc32.src requires mvn(log4j:log4j:1.2.17)
= 1.2.17
apache-log4j-extras (maintained by: coolsvap, gil, moceap)
apache-log4j-extras-1.2.17.1-18.fc33.noarch requires mvn(log4j:log4j:1.2.17) =
1.2.17
apache-log4j-extras-1.2.17.1-18.fc33.src requires mvn(log4j:log4j:1.2.17) = 1.2.17
azureus (maintained by: djuran)
azureus-5.7.6.0-13.fc34.noarch requires log4j12 = 1.2.17-30.fc34
azureus-5.7.6.0-13.fc34.src requires log4j12 = 1.2.17-30.fc34
Depending on: python-XStatic-jQuery (1), status change: 2020-09-28 (3 weeks ago)
python-XStatic-jquery-ui (maintained by: mrunge, openstack-sig, rdopiera)
python3-XStatic-jquery-ui-1.12.0.1-12.fc33.noarch requires
python3-XStatic-jQuery = 3.4.1.0-3.fc33, python3.9dist(xstatic-jquery) = 3.4.1
Depending on: python-beanbag (2), status change: 2020-10-09 (2 weeks ago)
pdc-client (maintained by: bliu, chcao, cheng, chuzhang, kevin, lholecek,
lsedlar, nphilipp)
pdc-client-1.8.0-20.fc33.src requires python3-beanbag = 1.9.2-17.fc33
python3-pdc-client-1.8.0-20.fc33.noarch requires python3-beanbag =
1.9.2-17.fc33, python3.9dist(beanbag) = 1.9.2
python-lightblue (maintained by: araszka)
python-lightblue-0.1.4-11.fc33.src requires python3-beanbag = 1.9.2-17.fc33
python3-lightblue-0.1.4-11.fc33.noarch requires python3-beanbag =
1.9.2-17.fc33, python3.9dist(beanbag) = 1.9.2
Depending on: python-libsass (1), status change: 2020-10-09 (2 weeks ago)
python-qtsass (maintained by: nonamedotc)
python3-qtsass-0.1.1-3.fc33.noarch requires python3.9dist(libsass) = 0.20,
python3dist(libsass) = 0.20
Depending on: pytrailer (1), status change: 2020-10-09 (2 weeks ago)
pyqtrailer (maintained by: orphan)
pyqtrailer-0.6.2-25.fc33.src requires python3-pytrailer = 0.6.1-17.fc33
python3-pyqtrailer-0.6.2-25.fc33.noarch requires python3-pytrailer = 0.6.1-17.fc33
See dependency chains of your packages at https://packager.fedorainfracloud.org/
See all orphaned packages at https://packager.fedorainfracloud.org/orphan
Affected (co)maintainers (either directly or via packages' dependencies):
araszka: python-beanbag
bliu: python-beanbag
carlwgeorge: celt071
chcao: python-beanbag
cheng: python-beanbag
chuzhang: python-beanbag
coolsvap: log4j12
cquad: metadata-extractor2
djuran: log4j12
epienbro: mingw-gtkglext
fnasser: log4j12, apache-commons-configuration
gil: log4j12
jjelen: jboss-jsf-2.1-api, jboss-interceptors-1.2-api
kevin: python-beanbag
lholecek: python-beanbag
lsedlar: python-beanbag
maci: mingw-gtkglext
mizdebsk: log4j12, apache-commons-configuration
moceap: log4j12
mrunge: python-XStatic-jQuery
ngompa: celt071
nonamedotc: python-libsass
nphilipp: python-beanbag
openstack-sig: python-XStatic-jQuery
python-sig: pipsi
ralph: hub
rdopiera: python-XStatic-jQuery
sgallagh: hub
spike: log4j12, apache-commons-configuration
sway-sig: rofi
--
The script creating this output is run and developed by Fedora
Release Engineering. Please report issues at its pagure instance:
https://pagure.io/releng/
The sources of this script can be found at:
https://pagure.io/releng/blob/master/f/scripts/find_unblocked_orphans.py
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
F34 Change proposal: AArch64 KDE Plasma Desktop image (Self-Contained Change)
== Summary ==
Add an AArch64 KDE Plasma Desktop spin disk image to deliverables in Fedora 34.
== Owner ==
* Name: [[User:ngompa | Neal Gompa]]
* Email: ngompa13@gmail.com
* Product: KDE Plasma
* Responsible WG: KDE SIG
== Detailed Description ==
We currently offer Workstation, Xfce, Minimal and Server images for use with AArch64 computers. We would like to add a variant offering the KDE Plasma Desktop.
== Benefit to Fedora ==
Better user experience and an additional desktop choice for AArch64 computers.
== Scope ==
* Proposal owners: The KDE SIG will make the kickstart changes needed to support adding the desktop image to the compose.
* Other developers: N/A
* Release engineering: Enable building of the AArch64 KDE desktop image. Small tweaks may be required to the pungi configs or fedora kickstarts but those will be completed by the SIG and sent as pull requests. Issue[https://pagure.io/releng/issue/9815 #9815]
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: N/A (not needed for this Change)
== Upgrade/compatibility impact ==
No upgrade compatibility required, this is a new image variant.
== How To Test ==
Testing can be completed on any supported AArch64 computer using the existing arm-image-installer. Any additional instructions will be added to the ARM installation documentation.
== User Experience ==
Users will have increased choice in desktop offerings for AArch64 computers. Those who wish to use the KDE Plasma Desktop on AArch64 computers will have an easy option to use.
== Dependencies ==
N/A (not a System Wide Change)
== Contingency Plan ==
* Contingency mechanism: N/A
* Contingency deadline: N/A
* Blocks release? No
* Blocks product? No
== Documentation ==
All documentation will be added or updated via the ARM Landing Page.
== Release Notes ==
--
He / Him / His
Senior Program Manager, Fedora & CentOS Stream
Red Hat
TZ=America/Indiana/Indianapolis
F34 Change proposal: MariaDB 10.5 (Self-Contained Change)
Update of MariaDB ('mariadb' package) in Fedora from 10.4 to 10.5 version.
[[Category:Package MariaDB]]
== Owner ==
* Name: [[User:mschorm| Michal Schorm]]
* Email: mschorm@redhat.com
== Detailed Description ==
Update of MariaDB package in Fedora from 10.4 version to 10.5 version.
== Benefit to Fedora ==
I'm cooperating with the upstream to bring the latest stable software to Fedora users.
10.5 series introduces number of enhancements, which cannot be found in previous series.
Overview of the new features can be found here: https://mariadb.com/kb/en/changes-improvements-in-mariadb-105/
== Scope ==
* Proposal owners:
**Prepare MariaDB 10.4 as a module for Rawhide and atleast one stable Fedora release (done)<br />so users which want to stay on the current release have the possibility.<br />This also serve as a failover mechanism in case of issues with the 10.5.
**Prepare MariaDB 10.5 as a module for Rawhide and atleast one stable Fedora release (done in Rawhide; the rest in BODHI)<br />so users can test the 10.5 in advance. (installing 10.5 module on already stable release)<br />This also serve as a upgrade path - users can install 10.5 module on Fedora release which have 10.4 in base; and then upgrade to 10.5 module on a Fedora release which will have 10.5 in base.
**Release MariaDB 10.5 to Rawhide (blocked; 10.5 modules needs testing first)
**Check software that requires or depends on 'mariadb' or 'galera' package for incompatibilities<br />This shouldn't be an issue in general, as vast majority of the software requires client library, provided by "mariadb-connector-c" package, which won't change.
**Gather user input on the changes between MariaDB 10.4 and 10.5
* Other developers: N/A (not a System Wide Change)
* Policies and guidelines: N/A (not a System Wide Change)
* Trademark approval: N/A (not needed for this Change)
== Upgrade/compatibility impact ==
The MariaDB client library is compatible, so the shouldn't be any issues and / or need for rebuild of dependent packages.
==='''UPDATE (10/2020)'''===
MariaDB 10.5 modules are now available for Fedora Rawhide and in BODHI for the stable releases
== How To Test ==
Usual testing as when upgrading between major MariaDB versions.
Test that all other software runs well with MariaDB 10.5.
Report any issues, so I can reach the different upstreams and check if they plan update their software to support MariaDB 10.5 and when.
== User Experience ==
The users will have to upgrade their databases the same way as between major MariaDB versions.
If the users want to stick with MariaDB 10.4 for a little longer, the MariaDB 10.4 module is available for them in all stable Fedora releases as well as in Rawhide.
If the users want to test the 10.5 series beforehand, the MariaDB 10.5 module is available.
== Dependencies ==
Since the client library ('mariadb-connector-c') is not changing, dependent software should work fine.
Only a rare cases builds against the server part of MariaDB. (e.g. building a server plugin)
== Contingency Plan ==
Modules will provide the functional version of MariaDB 10.4, available to all users.
* Contingency mechanism: Fedora Modules for 10.4 available
* Contingency deadline: already in place
* Blocks release? N/A (not a System Wide Change)
* Blocks product? N/A (not a System Wide Change)
== Documentation ==
Upgrade startegy: https://mariadb.com/kb/en/library/upgrading-from-mariadb-104-to-mariadb-105/
Upgrading and incompatibilities: https://mariadb.com/kb/en/library/upgrading-from-mariadb-104-to-mariadb-105/#incompatible-changes-between-104-and-105
== Release Notes ==
Release notes for each release: https://mariadb.com/kb/en/library/release-notes-mariadb-105-series/
Overall overview of the changes and improvements: https://mariadb.com/kb/en/library/changes-improvements-in-mariadb-105/
He / Him / His
Senior Program Manager, Fedora & CentOS Stream
Red Hat
TZ=America/Indiana/Indianapolis
[USN-4602-1] Perl vulnerabilities
iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAl+WtgEACgkQZWnYVadE
vpOfrg/+LBhJSw3wFB7o4CzFDyiKcVKPybRqWTs1DXlU12jGFILKAUQxss0FAtlR
dHGPgGiku/+an0YHaZCbiS0rkT/EcwI4recZtSeS/v3377sFKvIPd410zlN49s09
mlIN7fRhnKYj/z7+NwlAoFxqAMkszZrl624YHvaAYt0Vb3zzbUEv1xIVZC7tk5i0
k9Spny71CjiIkA8553R8LRGmd2e2KRbOI4/fpEAlegQfLZv+HXH8D2cfRgH8/koC
bny/X8ljBfBi2s6ETzT0l3eJtlzRlUst3q1EzLV/VewRhI+SxDhhwywROmmpR6nR
g2Av6+Lq24Iij6OVbEmsU+mxtXEIp77zHUpQG0/NtILrccLs1/4mfoSQRYTgpcV7
hs6MxIkadTI2+GbL0yT3bZhLGYQiWUGU4VhxUhZJap8cueUUJDEf+cqfM9gQJUNA
Vf+kSOPZH2b4uNvKpYRZxdi/LE1c1VixnFVrANWQcwQKr7N+fs/xO/NJk3yvQCly
xQwHSxENbp+8CZzuwJ/umFSTpiTRwmMwSdCnHVYp0qbtzauwVE28et96cl4XKDa/
ZIEwyz1GxYqsifxHtKUGNmRWKHYi7j1uBVIxafnUdJ6O3ayRJjLnAMr/HXwo48/M
yLYPE/ysC9eYjggDv4LNFcQI1UMuk3msj5I5wgJnVWGSBSxTMzA=
=2If+
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4602-1
October 26, 2020
perl vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Perl.
Software Description:
- perl: Practical Extraction and Report Language
Details:
ManhND discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-10543)
Hugo van der Sanden and Slaven Rezic discovered that Perl incorrectly
handled certain regular expressions. In environments where untrusted
regular expressions are evaluated, a remote attacker could possibly use
this issue to cause Perl to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2020-10878)
Sergey Aleynikov discovered that Perl incorrectly handled certain regular
expressions. In environments where untrusted regular expressions are
evaluated, a remote attacker could possibly use this issue to cause Perl to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2020-12723)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
perl 5.30.0-9ubuntu0.2
Ubuntu 18.04 LTS:
perl 5.26.1-6ubuntu0.5
Ubuntu 16.04 LTS:
perl 5.22.1-9ubuntu0.9
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4602-1
CVE-2020-10543, CVE-2020-10878, CVE-2020-12723
Package Information:
https://launchpad.net/ubuntu/+source/perl/5.30.0-9ubuntu0.2
https://launchpad.net/ubuntu/+source/perl/5.26.1-6ubuntu0.5
https://launchpad.net/ubuntu/+source/perl/5.22.1-9ubuntu0.9
Sunday, October 25, 2020
GitLab AMA Topic Discussion: Permissions & Access
Thanks again for your involvement in the GitLab AMA session on IRC in
September. As promised, this is the first of a 5-part series breaking
down main topics that came up during the session. I will send a topic
every week for discussion to both Fedora and CentOS devel lists. I
have pulled the relevant questions and answers from the original
hackmd doc into one email. If you would like to discuss this topic
specifically, here might be a good place to do so. I dont consider
myself technical enough to weigh in on details, but I am happy to
facilitate as best I can via email. And more importantly (for me),
learn from the discussion too.
Here are some links to resources as well:
* Questions and Answers hackmd link https://hackmd.io/RW8HahOeR7OJPON1dwuo3w
* Chat log from session
https://meetbot.fedoraproject.org/fedora-meeting-1/2020-09-10/ama_session_with_gitlab.2020-09-10-13.31.log.html
* AMA Blog post
https://communityblog.fedoraproject.org/gitlab-ama-follow-up/#more-9346
* Here is this email in hackmd if you wish to view it there:
https://hackmd.io/1pjX1cVnTjekOLVowj5UiQ?view
## Topic: Permission and Access
- Question: Fedora has a group-based access system. People in the
`packager` group have (commit) access to only the packages they
maintain. People in the `provenpackager` group have (commit) access to
all the active packages, but a few (for legal reason). People in the
`releng` group have commit access to all the packages. Is this an
access model that GitLab can support? If not, how would this work in a
GitLab world? How would notifications work (Esp consider people in the
`provenpackager` or `releng` group do not want to be notified for all
the projects they have access to)?
- Answer: What I explored was something along the lines of :
- Packager → Using GitLab's Maintainer or Developer role for
the project they maintain (Maintainer have the ability to access
project settings and change pretty much everything there, so that
might be blocking here, Developer only have commit access, so we need
another way to change some settings for Packagers)
- Co-Maintainer → Using GitLab's Developer role (commit access)
- Proven-Packager → GitLab's Developer role on all repo (expect 2)
- Release Engineer/Admin/etc .. → GitLab's Owner role on all repos
- This is not an exact matching with what we currently have
but should give us a way to experiment with this and look at what is
acceptable or not.
- There is also a GitLab ticket
(https://gitlab.com/gitlab-org/gitlab/-/issues/7626) to implement
policies for the project that could give more granular control of
permissions.
- Gitlab's notifications are quite granular and can be managed
at the different levels (Merge Requests, Projects, Group, Global)
https://docs.gitlab.com/ee/user/profile/notifications.html#global-notification-settings
- Question: Fedora supports the concept of a retired `project` (ie:
archived) that no-one can commit to. Does GitLab have an equivalent
concept? (The retired status is not something project admins can
change)
- Answer: There is an option to have a "retired" group which is
configured to have nobody with commit access. Then retiring a project
would simply mean to move the project from the "rpm" group to
"retired" group for example.
There is also possibility to simply archive projects
https://docs.gitlab.com/ee/user/project/settings/#archiving-a-project
- Question: could gitlab (inc) maintain a Community Edition GitLab
instance that Fedora uses?
- Answer: There is no plan to create custom versions of GitLab for
customers. Instead, GitLab encourages paid customers and free users
alike to contribute upstream to make sure that GitLab continues to
work well for the most amount of users possible. As an open core
company, GitLab has a public roadmap and works with its community
members to build a great product.
GitLab regularly engages with its community and takes into account its
feedback. As a result, features are often ported down into lower tiers
in order to make the Community Edition and Free tiers continuously
more useful (see example of 18 features moved to open source). GitLab
hosting is available to users of GitLab.com SaaS, but GitLab does not
offer hosting and management for GitLab CE or EE instances.
- Question: Can project creation be restricted to a specific group of
people in GitLab?
- Answer: Yes this can be configured at the instance level
(https://gitlab.com/help/user/admin_area/settings/visibility_and_access_controls.md#default-project-creation-protection)
or at the group level
(https://gitlab.com/help/user/group/index.md#default-project-creation-level)
- Question: Can project (main project, not fork) deletion be
restricted to a specific group of people in GitLab? (ie: project
owner/maintainer must not be allowed to delete a main project, they
can delete their own fork of course)
- Answer: There is an issue
https://gitlab.com/gitlab-org/gitlab/-/issues/233379 that could help
with this by requiring an additional person approve the deletion &
there's a related issue
https://gitlab.com/gitlab-org/gitlab/-/issues/227468 to create a list
of authorized approvers for these types of changes (not MRs) that
sounds aligned with this ask
- Question: How would group membership be sync to GitLab?
- Answer: We are still not 100% clear on that, since GitLab
supports OpenIDC & we will need to investigate if we could make use of
the group scope returned by AAA. Otherwise we will need a solution to
sync the groups to GitLab most likely using API calls.
- Question:Will there be better support for Podman in CI workflows in GitLab?
- Answer: Short term solution might be using a custom executor,
long term solution would be getting the Runner executor podman (#4185)
feature request issue scheduled and closed. Ultimately product team
schedules work, while everyone can contribute MRs or fixes ahead of
schedule. In the past, I've seen a lot of enthusiasm from GitLab team
members in helping solve problems from Open Source Program members
whenever possible.
These are all the questions that had answers I could spot from the
larger hackmd document, however my apologies if I missed any.
next week I will pull in all the questions and answers on 'Message
Bus' in a new email and send for discussion.
I know there are still some questions unanswered so I will try to
chase down answers to these, but it could take some time. If I can get
them answered over the next few weeks, I will send a 'misc' topic
email at the end of these few weeks worth of emails.
I hope you find this helpful and it is going to take some time to work
through everything so thank you for your patience and involvement in
this, it is very much appreciated.
Kindest regards,
Aoife
--
Aoife Moloney
Product Owner
Community Platform Engineering Team
Red Hat EMEA
Communications House
Cork Road
Waterford
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Friday, October 23, 2020
[arch-announce] libtraceevent>=5.9-1 update requires manual intervention
of these errors
libtraceevent: /usr/lib/libtraceevent.so.1 exists in filesystem
when updating, use
pacman -Syu --overwrite usr/lib/libtraceevent.so.1
to perform the upgrade.
URL: https://www.archlinux.org/news/libtraceevent59-1-update-requires-manual-intervention/
_______________________________________________
arch-announce mailing list
arch-announce@archlinux.org
https://lists.archlinux.org/listinfo/arch-announce
[USN-4593-2] FreeType vulnerability
Ubuntu Security Notice USN-4593-2
October 22, 2020
freetype vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 14.04 ESM
Summary:
FreeType could be made to crash or run programs as your login if it
opened a specially crafted file.
Software Description:
- freetype: FreeType 2 is a font engine library
Details:
USN-4593-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Sergei Glazunov discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 ESM:
libfreetype6 2.5.2-1ubuntu2.8+esm2
After a standard system update you need to restart your session to make
all the necessary changes.
References:
https://usn.ubuntu.com/4593-2
https://usn.ubuntu.com/4593-1
CVE-2020-15999
[LSN-0073-1] Linux kernel vulnerability
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
- Ubuntu 20.04 LTS
Summary
Several security issues were fixed in the kernel.
Software Description
- linux - Linux kernel
- linux-aws - Linux kernel for Amazon Web Services (AWS) systems
- linux-azure - Linux kernel for Microsoft Azure Cloud systems
- linux-gcp - Linux kernel for Google Cloud Platform (GCP) systems
- linux-oem - Linux kernel for OEM systems
Details
Andy Nguyen discovered that the Bluetooth L2CAP implementation in the
Linux kernel contained a type-confusion error. A physically proximate
remote attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2020-12351)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the
Linux kernel did not properly initialize memory in some situations. A
physically proximate remote attacker could use this to expose sensitive
information (kernel memory). (CVE-2020-12352)
Andy Nguyen discovered that the Bluetooth HCI event packet parser in the
Linux kernel did not properly handle event advertisements of certain
sizes, leading to a heap-based buffer overflow. A physically proximate
remote attacker could use this to cause a denial of service (system
crash) or possibly execute arbitrary code. (CVE-2020-24490)
Update instructions
The problem can be corrected by updating your kernel livepatch to the
following versions:
Ubuntu 18.04 LTS
aws - 73.1
generic - 73.1
lowlatency - 73.1
oem - 73.1
Ubuntu 20.04 LTS
aws - 73.1
azure - 73.1
gcp - 73.1
generic - 73.1
lowlatency - 73.1
Support Information
Kernels older than the levels listed below do not receive livepatch
updates. If you are running a kernel version earlier than the one listed
below, please upgrade your kernel as soon as possible.
Ubuntu 18.04 LTS
linux-aws - 4.15.0-1054
linux-azure - 5.0.0-1025
linux-gcp - 5.0.0-1025
linux-oem - 4.15.0-1063
linux - 4.15.0-69
Ubuntu 20.04 LTS
linux-aws - 5.4.0-1009
linux-azure - 5.4.0-1010
linux-gcp - 5.4.0-1009
linux-oem - 5.4.0-26
linux - 5.4.0-26
Ubuntu 16.04 LTS
linux-aws - 4.4.0-1098
linux-azure - 4.15.0-1063
linux-hwe - 4.15.0-69
linux - 4.4.0-168
Ubuntu 14.04 ESM
linux-lts-xenial - 4.4.0-168
References
- CVE-2020-12351
- CVE-2020-12352
- CVE-2020-24490
--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
[USN-4599-1] Firefox vulnerabilities
iQEzBAEBCgAdFiEERN//5MGgCOgyKeIFYR+97NWUbg8FAl+SvpEACgkQYR+97NWU
bg8RNgf/aQZtLnCSssxLbk1BtpAng6EPtqHp7KNF/QLBHhTEHisS3RlU69wOIaX0
eawudGOIhvpL49yjBA1PUpNWZ8jyQzAp98mGc/hB+HdQ9GJIkC128QmZFgpyDsN2
MSmB3C/sxu8DGO/e2JWzSnXRFammZyur9suIq5XhDfhKnZyMNWDB+dqslT20cnE3
hYG1/Iy1MBLZ6CAXutBxqnfLD+1m3sx+a3Vnk46EO2T3W5UueSw2g1dhhKD4X5v6
SAVn1sKLA6bpskgEj4OpHviuIObZyOiekP0cNlqgrbiSzCd1lQeB5pPAxTzljMg5
9F1FACNgN8UNc1jz6S2WjdXCQiU6Hw==
=mcvA
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4599-1
October 23, 2020
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
Summary:
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the prompt
for opening an external application, obtain sensitive information, or
execute
arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.10:
firefox 82.0+build2-0ubuntu0.20.10.1
Ubuntu 20.04 LTS:
firefox 82.0+build2-0ubuntu0.20.04.1
Ubuntu 18.04 LTS:
firefox 82.0+build2-0ubuntu0.18.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
https://usn.ubuntu.com/4599-1
CVE-2020-15254, CVE-2020-15680, CVE-2020-15681, CVE-2020-15682,
CVE-2020-15683, CVE-2020-15684, CVE-2020-15969
Package Information:
https://launchpad.net/ubuntu/+source/firefox/82.0+build2-0ubuntu0.20.10.1
https://launchpad.net/ubuntu/+source/firefox/82.0+build2-0ubuntu0.20.04.1
https://launchpad.net/ubuntu/+source/firefox/82.0+build2-0ubuntu0.18.04.1
Thursday, October 22, 2020
[USN-4601-1] pip vulnerability
iQIzBAEBCgAdFiEE7MowLJorxPNkyBZZW+PTAFZKyRgFAl+SC3cACgkQW+PTAFZK
yRgrZg/+OU0aPoQlFKJOUblaIwyxslB6UCfK2dRebLsGNOP1hY7yEtkOcN2XJHJn
GPiXKkdNB00TTDrvYzm/XwiMeJiNN3Evaa7HzdeJk0Rdi4s/zyiuHwOXmC7Ae3EV
LXZcp2xY0Gm7omBZjrbwctz092+oHRhI+tYZ3FfmeM2kQmoskUU/2UT0z4rMfPYX
aXHGTW7M3criSqFCmkp+qMSX2tbAkvEKF/Zc4hlpNbNtfMCVfoocjAZQlWrHXSdL
EaijKL1wrudYahJsvqexk51HZKIpfrGdP4CxcBXXGpReacfMv3Vq+RI90rkSLlcw
2FxMu6LzX8VnUKxHG1GwRiglvqhpnkKILWLqAI10tsXHZNtvHgJ3g7lV5Jc5rLw1
aMG53qutIIsgqxo4AiKOFugTuTADb12gpZnyu3TJiFQGUzHcYNl69oB84+4OPB4e
E9KhXFUUu4MJj5WnVArOFolU43+Pt+4vatYvyLtf/SoiHcwMYbPUMmuf1iSphKHc
L/3sCdDJYAVGTDUnIT6114cap1fFf+fXQTsqn6ibGPoFdD4UXxGEtd3u0cnq8pnn
+WwHXArR5GJBep1oKh83jF1wJzOPm0xfNINkn/sBERRCxwTNNXpTI763z2RtBXrS
jLA/o70xrKvx6MfB5foLG5lmIMptg1GffoBcgdEdIWHcQ4zK9s8=
=TREf
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-4601-1
October 22, 2020
python-pip vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 18.04 LTS
Summary:
pip could be made to overwrite files as the administrator.
Software Description:
- python-pip: Python package installer
Details:
It was discovered that pip did not properly sanitize the filename during
pip install. A remote attacker could possible use this issue to read and
write arbitrary files on the host filesystem as root, resulting in a
directory traversal attack. (CVE-2019-20916)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.04 LTS:
python-pip 9.0.1-2.3~ubuntu1.18.04.4
python3-pip 9.0.1-2.3~ubuntu1.18.04.4
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4601-1
CVE-2019-20916
Package Information:
https://launchpad.net/ubuntu/+source/python-pip/9.0.1-2.3~ubuntu1.18.04.4
[USN-4600-1] Netty vulnerabilities
Ubuntu Security Notice USN-4600-1
October 22, 2020
netty-3.9 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 16.04 LTS
Summary:
Netty could be made to expose sensitive information over the
network.
Software Description:
- netty-3.9: Asynchronous event-driven network application framework
Details:
It was discovered that Netty had HTTP request smuggling vulnerabilities. A
remote attacker could used it to extract sensitive information. (CVE-2019-16869,
CVE-2019-20444, CVE-2019-20445, CVE-2020-7238)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 16.04 LTS:
libnetty-3.9-java 3.9.0.Final-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4600-1
CVE-2019-16869, CVE-2019-20444, CVE-2019-20445, CVE-2020-7238
Package Information:
https://launchpad.net/ubuntu/+source/netty-3.9/3.9.0.Final-1ubuntu0.1
Fedora 33 Final is GO
on Tuesday, 27 October 2020.
For more information please check the Go/No-Go meeting minutes [2] or logs [3].
Thank you to everyone who has worked on this release and getting it out on time.
[1] https://dl.fedoraproject.org/pub/alt/stage/33_RC-1.2/
[2] https://meetbot.fedoraproject.org/fedora-meeting-1/2020-10-22/f33-final-go_no_go-meeting.2020-10-22-17.00.html
[3] https://meetbot.fedoraproject.org/fedora-meeting-1/2020-10-22/f33-final-go_no_go-meeting.2020-10-22-17.00.log.html
--
Ben Cotton
He / Him / His
Senior Program Manager, Fedora & CentOS Stream
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org