Népszerű fórum témák
FreeBSD Project News
Linux Weekly News
LWN.net is a comprehensive source of news and opinions from and about the Linux community. This is the main LWN.net feed, listing all articles which are posted to the site front page.
Frissült: 26 perc 19 másodperc
Fedora has updated bash (F20; F19: code injection), moodle (F20: multiple vulnerabilities), not-yet-commons-ssl (F20; F19: hostname verification botch), phpMyAdmin (F20; F19: privilege escalation), procmail (F19: code execution), wireshark (F20: yet another pile of dissector flaws), and xerces-j2 (F20; F19: denial of service from 2013).
Scientific Linux has updated bash (code injection).
Ubuntu has updated bash (14.04, 12.04, 10.04: code injection), firefox (14.04, 12.04: signature forgery), nss (14.04, 12.04, 10.04: signature forgery), and thunderbird (14.04, 12.04: signature forgery).
The LWN.net Weekly Edition for September 25, 2014 is available.
The bash shell has a vulnerability in its environment variable processing that could be remotely exploited in some situations — with CGI scripts being at the top of the list. "The fact that an environment variable with an arbitrary name can be used as a carrier for a malicious function definition containing trailing commands makes this vulnerability particularly severe; it enables network-based exploitation." The problem was disclosed (a little) prematurely, so updates are still coming in from the distributors.
Adobe made a surprise announcement at the annual ATypI conference in Barcelona, Spain, releasing one of the company's proprietary font-production tools under an open-source license. In addition, the team convinced another popular font-development project to release its core library as open source, too. Adobe framed the release as a move designed to help improve the quality of fonts produced with any application, but there may be other benefits as well—such as increasing the spread of Adobe's own open fonts. Up until now, those fonts have not been redistributable by many other free-software projects, precisely because the production tools needed to build them remained closed.
The GNOME project has released GNOME 3.14. "This is another exciting release for GNOME, and brings many new features and improvements, including multitouch, captive portal support, greatly improved sharing settings. This release also includes improved and redesigned applications for weather, maps, PDF viewing, running VMs, and more. The Wayland support has matured to the point where it is ready for day-to-day use." See the release notes for details.
Oracle has updated haproxy (OL7: denial of service).
Ubuntu has updated apt (code execution), EC2 kernel (10.04: privilege escalation), kernel (14.04; 12.04; 10.04: multiple vulnerabilities), linux-lts-trusty (12.04: multiple vulnerabilities), and linux-ti-omap4 (12.04: multiple vulnerabilities).
Bruce Schneier is a cryptographer and security specialist who is well-known in computer circles even though he has often branched into more general security areas in recent years. His blog is a great source of security news (and, of "quotes of the week" for the Security page, as readers know). Beyond all that, he travels to many security conferences to give talks, which is just what he did at AppSec USA in Denver on September 18. The keynote topic was "incident response" (IR), which is an area that is finally getting more attention in the security-product space, he said.
ACM's Queue has a lengthy article on the security failures in the HTTPS layer and the prospects for improvement. "This article outlines the systemic vulnerabilities of HTTPS, maps the thriving market for certificates, and analyzes the suggested regulatory and technological solutions on both sides of the Atlantic. The findings show existing yet surprising market patterns and perverse incentives: not unlike the financial sector, the HTTPS market is full of information asymmetries and negative externalities, as a handful of CAs dominate the market and have become 'too big to fail.' Unfortunately, the proposed E.U. legislation will reinforce systemic vulnerabilities, and the proposed technological solutions are far from being adopted at scale. The systemic vulnerabilities in this crucial technology are likely to persist for years to come"
Here's a post from Peter Hutterer on why the X.Org input stack is a mess and the new "libinput" stack is needed. "It looks like a big happy family at first, but then you see that synaptics won't talk to evdev because of the tapping incident a couple of years back, mouse and keyboard have no idea what forks and knives are for, wacom is the hippy GPL cousin that doesn't even live in the same state and no-one quite knows why elographics keeps getting invited. The X server tries to keep the peace by just generally getting in the way of everyone so no-one can argue for too long. You step back, shrug apologetically and say 'well, that's just how these things are, right?'"
Ars Technica takes a look at Kali Linux NetHunter, a penetration testing platform for Nexus devices. "NetHunter is still in its early stages, but it already includes the ability to have the Nexus device emulate a USB human interface device (HID) and launch keyboard attacks on PCs that can be used to automatically elevate privileges on a Windows PC and install a reverse-HTTP tunnel to a remote workstation. It also includes an implementation of the BadUSB man-in-the-middle attack, which can force a Windows PC to recognize the USB-connected phone as a network adapter and re-route all the PC’s traffic through it for monitoring purposes."
The Fedora project has released Fedora 21 Alpha. This is the first release of Fedora.next, which introduces three products rather than the traditional single deliverable. The Fedora 21 Base includes only the base set of packages (such as kernel, RPM, yum, systemd, and Anaconda) used by all the products. Fedora 21 Cloud includes images for use in private cloud environments like OpenStack, as well as AMIs for use on Amazon, and a new image streamlined for running Docker containers. The server product is aimed at making it easier to install discrete infrastructure services. The Fedora Server will introduce three new technologies in Fedora to handle this task, rolekit, Cockpit and OpenLMI. The third product is Fedora 21 Workstation, which is aimed at providing a platform for development of server side and client applications that is attractive to developers of all stripes. The final release of Fedora 21 is expected in December.
This opensource.com article holds out Ansible as an example of a project worth emulating and delves into the reasons for its success. "The idea that a user can try something out over a lunch break, and understand it—and then learn what is left to learn—is a key success driver for open source software. Too many projects fail needlessly because they don’t invest in this critical idea."
CentOS has updated kernel (C7: denial of service).
Oracle has updated kernel (OL7: multiple vulnerabilities).
Red Hat has updated kernel (RHEL7: denial of service).
PyPy is an optimized implementation of the Python (2.x) programming language; the 2.4 release is now available. As is often the case, performance improvements top the list of changes in this release. "Benchmarks improved after internal enhancements in string and bytearray handling, and a major rewrite of the GIL handling. This means that external calls are now a lot faster, especially the CFFI ones. It also means better performance in a lot of corner cases with handling strings or bytearrays." Various bug fixes and an update to the Python 2.7.8 standard library are included as well.
Mandriva has updated gnupg (side-channel attack).
Red Hat has updated qemu-kvm-rhev (RHEL OSP5.0: multiple vulnerabilities).
SUSE has updated dbus-1 (SLE11 SP3: denial of service).
Ubuntu has updated nss (CA certificate update).
Linus has released the 3.17-rc6 kernel prepatch, saying: "It's been quiet - enough so that coupled with my upcoming travel, this might just be the last -rc, and final 3.17 might be next weekend."
The version 1.6.0 releases of the Wayland display manager and Weston compositor are available. Wayland improvements include better error handling and an improved self-testing infrastructure. On the Weston side, they have made a number of xdg-shell protocol changes ("Yes, we broke it again since 1.5.0"), some keyboard repeat improvements, a switch to libinput by default, and more.
Debian has updated apt (regression in previous security update).
Fedora has updated apache-poi (F20: two XML handling flaws), asterisk (F20; F19: denial of service), haproxy (F20: unspecified vulnerabilities), kernel (F20: three vulnerabilities), pdns-recursor (F20; F19: denial of service), polkit-qt (F20; F19: authorization bypass), and ReviewBoard (F19: two vulnerabilities).
A new organization to "make security easy and fun" has announced itself in a blog post entitled "Why Hello, World!". Simply Secure is targeting the usability of security solutions: "If privacy and security aren’t easy and intuitive, they don’t work. Usability is key." The organization was started by Google and Dropbox; it also has the Open Technology Fund as one of its partners. "To build trust and ensure quality outcomes, one core component of our work will be public audits of interfaces and code. This will help validate the security and usability claims of the efforts we support. More generally, we aim to take a page from the open-source community and make as much of our work transparent and widely-accessible as possible. This means that as we get into the nitty-gritty of learning how to build collaborations around usably secure software, we will share our developing methodologies and expertise publicly. Over time, this will build a body of community resources that will allow all projects in this space to become more usable and more secure."
openSUSE has updated curl (13.1, 12.3: two cookie-handling vulnerabilities).
Oracle has updated automake (OL5: code execution from 2012), bind97 (OL5: three vulnerabilities, two from 2013), conga (OL5: multiple vulnerabilities some going back to 2012), krb5 (OL5: code execution), krb5 (OL5: multiple vulnerabilities, two from 2013), and nss, nspr (multiple vulnerabilities, one from 2013).
SUSE has updated squid3 (SLE11SP3: denial of service).
HUP napi hírlevél
Legfrissebb Linux játékvideók
Legfrissebb HUP képek
Legfrissebb HUP dokumentumok
IQ-m az online Mensa teszt alapján:
125-nél _NEM_ kevesebb
Csak az eredmény érdekel.
Összes szavazat: 304