Népszerű fórum témák
FreeBSD Project News
Linux Weekly News
LWN.net is a comprehensive source of news and opinions from and about the Linux community. This is the main LWN.net feed, listing all articles which are posted to the site front page.
Frissült: 21 perc 43 másodperc
Debian has updated apt (regression in previous security update).
Fedora has updated apache-poi (F20: two XML handling flaws), asterisk (F20; F19: denial of service), haproxy (F20: unspecified vulnerabilities), kernel (F20: three vulnerabilities), pdns-recursor (F20; F19: denial of service), polkit-qt (F20; F19: authorization bypass), and ReviewBoard (F19: two vulnerabilities).
A new organization to "make security easy and fun" has announced itself in a blog post entitled "Why Hello, World!". Simply Secure is targeting the usability of security solutions: "If privacy and security aren’t easy and intuitive, they don’t work. Usability is key." The organization was started by Google and Dropbox; it also has the Open Technology Fund as one of its partners. "To build trust and ensure quality outcomes, one core component of our work will be public audits of interfaces and code. This will help validate the security and usability claims of the efforts we support. More generally, we aim to take a page from the open-source community and make as much of our work transparent and widely-accessible as possible. This means that as we get into the nitty-gritty of learning how to build collaborations around usably secure software, we will share our developing methodologies and expertise publicly. Over time, this will build a body of community resources that will allow all projects in this space to become more usable and more secure."
openSUSE has updated curl (13.1, 12.3: two cookie-handling vulnerabilities).
Oracle has updated automake (OL5: code execution from 2012), bind97 (OL5: three vulnerabilities, two from 2013), conga (OL5: multiple vulnerabilities some going back to 2012), krb5 (OL5: code execution), krb5 (OL5: multiple vulnerabilities, two from 2013), and nss, nspr (multiple vulnerabilities, one from 2013).
SUSE has updated squid3 (SLE11SP3: denial of service).
The LWN.net Weekly Edition for September 18, 2014 is available.
Greg Kroah-Hartman has made some progress on the stable patch backlog with the release of 3.16.3, 3.14.19, and 3.10.55.
In a talk entitled "SteamOS Magic", longtime X developer Keith Packard looked at the new Linux "distribution" and the effort to turn the Linux desktop into a gaming console. It turns out that, with a fairly small amount of code, Steam and SteamOS creator, Valve, was able to take the existing X-based desktop and turn it into a "living-room experience".
Click below (subscribers only) for the full report from LinuxCon North
Red Hat has updated krb5 (RHEL5: code execution).
Matthew Garrett writes about the challenges faced by the developers working on ACPI-based ARM systems. "Somebody is going to need to take responsibility for tracking ACPI behaviour and incrementing the exported interface whenever it changes, and we need to know who that's going to be before any of these systems start shipping. The alternative is a sea of ARM devices that only run specific kernel versions, which is exactly the scenario that ACPI was supposed to be fixing."
The openSUSE project has posted a statement on how things will change after Attachmate's merger with Micro Focus. In short, they don't think anything will change. "Business as Usual: There are no changes planned for the SUSE business structure and leadership. There is no need for any action by the openSUSE Project as a result of this announcement."
The OpenSSL project is widely known due to its broad adoption as the SSL/TLS library of choice for open-source software—though, in April, it also became widely known because of a particularly vicious security vulnerability. To a large degree, the project weathered the storm, but the project has also undertaken some changes in the wake of the incident. The most recent is the adoption of a public security policy describing how issues of various kinds will be dealt with.
SUSE's parent entity, the Attachmate Group has entered into an agreement to merge with Micro Focus, prompting some to wonder about how that might affect openSUSE. SUSE's President and General Manager, Nils Brauckmann has contacted the openSUSE Board with a reassuring message. "Business as Usual: There are no changes planned for the SUSE business structure and leadership."
The Register reports that SUSE Linux owner Attachmate Group is being purchased by Micro Focus International. "Micro Focus is taking Attachmate Group in exchange for 86.60 million shares, in a deal described as a merger. The combined companies will create a “leading global infrastructure software company” with revenue of $1.4bn, Micro Focus said. The deal is expected to close in November."
Andrew Tanenbaum has announced the release of MINIX 3.3.0, a major new release of the OS. "It is based on a tiny (13 KLoC) microkernel with the operating system running as a set of protected user-mode processes. Each device driver is also a separate process. If a driver fails, it is automatically and transparently restarted without rebooting and without applications even noticing, making the system self-healing. In addition to the x86, the ARM Cortex A8 is now supported, with ports to the BeagleBoard and BeagleBone available. Finally, the entire userland has been redone to make it NetBSD compatible, with thousands of NetBSDpackages available out of the box."
openSUSE has updated php5 (13.1, 12.3: multiple vulnerabilities), ppp (13.1, 12.3: privilege escalation), python-django (13.1, 12.3: multiple vulnerabilities), and flash-player (11.4: multiple vulnerabilities).
Red Hat has updated automake (RHEL5: code execution), bind97 (RHEL5: denial of service), conga (RHEL5: multiple vulnerabilities), krb5 (RHEL5: multiple vulnerabilities), and nss, nspr (RHEL5: multiple vulnerabilities).
Scientific Linux has updated axis (SL5&6: SSL hostname verification bypass).
Ubuntu has updated python-django (multiple vulnerabilities).
The Rust Programming Language Blog has an article describing recent changes to the language and what remains to be done for the eventual 1.0 release. "The key to all these changes has been a focus on the core concepts of ownership and borrowing. Initially, we introduced ownership as a means of transferring data safely and efficiently between tasks, but over time we have realized that the same mechanism allows us to move all sorts of things out of the language and into libraries. The resulting design is not only simpler to learn, but it is also much 'closer to the metal' than we ever thought possible before. All Rust language constructs have a very direct mapping to machine operations, and Rust has no required runtime or external dependencies."
Version 4.12.0 of the RPM package manager is out. New features include weak dependencies ("suggests," "recommends," "supplements," and "enhances" tags), a new rpm2archive utility to turn a package into a tar archive, lots of internal improvements, the removal of the "collections" feature, and, for those who think it is wise, the ability to put files larger than 4GB into a package.
Linux.com takes a look at Intel's Edison computing module. "Linux-based platforms for wearables include Android Wear, Samsung's Tizen SDK for Wearables, and now Intel's Yocto Linux and Intel Atom-based Edison computing module. The Edison was released last week in conjunction with the Intel Developer Forum. Prior to the formal launch, some 70 Intel Edison beta units have been seeded, forming the basis for about 40 Edison-based projects, says Intel."
The freenode infrastructure team found a server issue that indicated that an IRC server may have been compromised. "We immediately started an investigation to map the extent of the problem and located similar issues with several other machines and have taken those offline. For now, since network traffic may have been sniffed, we recommend that everyone change their NickServ password as a precaution." (Thanks to Paul Wise)
Mageia has updated dump (denial of service/possible code execution), glibc (two vulnerabilities), libgadu (missing ssl certificate validation), mariadb (code execution), and moodle (two vulnerabilities).
openSUSE has updated LibreOffice (13.1, 12.3: two vulnerabilities).
Ubuntu has updated curl (two cookie-handling vulnerabilities).
Version 1.4.0 of the LedgerSMB accounting system is out. It features a new contact management subsystem, a reworked report generation subsystem, better integration with other business applications, and more. The announcement left out download information; those who are interested can find the software at ledgersmb.org.
HUP napi hírlevél
Legfrissebb Linux játékvideók
Legfrissebb HUP képek
Legfrissebb HUP dokumentumok
IQ-m az online Mensa teszt alapján:
125-nél _NEM_ kevesebb
Csak az eredmény érdekel.
Összes szavazat: 315