5 év 9 hónap óta
Security updates have been issued by CentOS (firefox and nss-softokn), Fedora (samba), Oracle (nss, nss-softokn, nss-util, nss-softokn, and thunderbird), Scientific Linux (thunderbird), SUSE (firefox), and Ubuntu (librabbitmq and samba).
jake
5 év 9 hónap óta
An effort to protect package downloads from the
Python
Package Index (PyPI) has resulted in a Python Enhancement Proposal
(PEP) and, perhaps belatedly, some discussion in the wider community. The
basic idea is to use
The
Update Framework (TUF) to protect PyPI users from
some malicious
actors who are aiming to interfere with the installation and update of
Python modules. But the name of the PEP and its wording, coupled with some
recent typosquatting problems on PyPI, caused
some confusion along the way. There are some competing interests and
different cultures coming together over this PEP; the process has not run as
smoothly as anyone might want, though that seems to be resolving itself at
this point.
jake
5 év 9 hónap óta
Security updates have been issued by Arch Linux (crypto++ and thunderbird), Debian (cacti, freeimage, git, and jackson-databind), Fedora (nss), openSUSE (clamav, dnsmasq, munge, opencv, permissions, and shadowsocks-libev), Red Hat (nss, nss-softokn, nss-util, rh-maven35-jackson-databind, and thunderbird), Scientific Linux (nss, nss-softokn, nss-util, nss-softokn, and thunderbird), SUSE (caasp-openstack-heat-templates, crowbar-core, crowbar-openstack, crowbar-ui, etcd, flannel, galera-3, mariadb, mariadb-connector-c, openstack-dashboard-theme-SUSE, openstack-heat-templates, openstack-neutron, openstack-nova, openstack-quickstart, patterns-cloud, python-oslo.messaging, python-oslo.utils, python-pysaml2, libssh, and strongswan), and Ubuntu (git, libpcap, libssh, and thunderbird).
ris
5 év 9 hónap óta
The Electronic Frontier Foundation has posted
a detailed
study on third-party corporate surveillance on the Internet (and
beyond). "Both Google and Apple encourage developers to use ad IDs
for behavioral profiling in lieu of other identifiers like IMEI or phone
number. Ostensibly, this gives users more control over how they are
tracked, since users can reset their identifiers by hand if they
choose. However, in practice, even if a user goes to the trouble to reset
their ad ID, it’s very easy for trackers to identify them across resets by
using other identifiers, like IP address or in-app storage. Android’s
developer policy instructs trackers not to engage in such behavior, but the
platform has no technical safeguards to stop it. In February 2019, a study
found that over 18,000 apps on the Play store were violating Google’s
policy."
corbet
5 év 9 hónap óta
The Git project has released Git v2.24.1, v2.23.1, v2.22.2, v2.21.1,
v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and
v2.14.6. "These releases fix various security flaws, which allowed an
attacker to overwrite arbitrary paths, remotely execute code, and/or
overwrite files in the .git/ directory etc." The release notes
contained in this announcement have the details.
ris