LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Thursday, November 15th, 2012

    Time Event
    1:49a
    [$] LWN.net Weekly Edition for November 15, 2012
    The LWN.net Weekly Edition for November 15, 2012 is available.
    5:23p
    Security advisories for Thursday

    CentOS has updated mysql (C6: multiple unspecified vulnerabilities) and libproxy (C6: code execution).

    Oracle has updated kernel (OL5; OL5: denial of service), libproxy (OL6: code execution), and mysql (OL6: multiple unspecified vulnerabilities).

    Red Hat has updated libproxy (RHEL6: code execution) and mysql (RHEL6: multiple unspecified vulnerabilities).

    Scientific Linux has updated mysql (SL6: multiple unspecified vulnerabilities) and libproxy (SL6: code execution).

    Ubuntu has updated libtiff (two code execution flaws).

    9:12p
    Garrett: More in the series of bizarre UEFI bugs
    As we start to see more UEFI firmware become available, one would guess we'll find more exciting weirdness like what Matthew Garrett found. For whatever reason, the firmware in a Lenovo Thinkcentre M92p only wants to boot Windows or Red Hat Enterprise Linux (and, no, it is not secure boot related): "Every UEFI boot entry has a descriptive string. This is used by the firmware when it's presenting a menu to users - instead of "Hard drive 0" and "USB drive 3", the firmware can list "Windows Boot Manager" and "Fedora Linux". There's no reason at all for the firmware to be parsing these strings. But the evidence seemed pretty strong - given two identical boot entries, one saying "Windows Boot Manager" and one not, only the first would work."

    << Previous Day 2012/11/15
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org