LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Monday, December 22nd, 2014

    Time Event
    2:41p
    Severe NTP vulnerabilities
    Here is a
    CERT advisory
    warning of a number of code-execution vulnerabilities in
    the network time protocol (NTP) implementation. "These
    vulnerabilities could be exploited remotely. Exploits that target these
    vulnerabilities are publicly available.
    " Most distributors already
    have updates available; applying them seems like a good idea.
    6:49p
    Security advisories for Monday

    CentOS has updated ntp (C7; C6; C5: multiple code execution vulnerabilities).

    Debian has updated firebird2.5 (denial of service), jasper (two code execution vulnerabilities), ntp (multiple code execution vulnerabilities), subversion (denial of service), and subversion (regression in previous update).

    Debian-LTS has updated linux-2.6 (multiple vulnerabilities), ntp (multiple code execution vulnerabilities), qt4-x11 (code execution), subversion (denial of service), and xorg-server (multiple vulnerabilities).

    Fedora has updated ctdb (F20: insecure temporary files), dbus (F19: multiple vulnerabilities), firebird (F21; F20: denial of service), flac (F19: multiple vulnerabilities), gpgme (F21: code execution), kernel (F21; F20: multiple vulnerabilities), mantis (F21; F20; F19: multiple vulnerabilities), ntp (F20: multiple code execution vulnerabilities), pcre (F20; F19: information leak), python-tornado (F19: denial of service), pyxdg (F21: symlink attacks), sagemath (F21; F20: cross-site scripting), and unbound (F21; F20: denial of service).

    Gentoo has updated sendmail (information disclosure).

    Mageia has updated c-icap (denial of service), claws-mail (denial of service), docuwiki (cross-site scripting), file (denial of service), jasper (two code execution vulnerabilities), krb5 (NULL dereference), nail (command execution), ntp (multiple code execution vulnerabilities), pcre (denial of service), php (code execution), pwgen (two vulnerabilities), x11-server (multiple vulnerabilities), and znc (denial of service).

    openSUSE has updated clamav (11.4: two vulnerabilities), libksba (13.2, 13.1, 12.3: denial of service), kernel (13.2: multiple vulnerabilities), ntp (13.2, 13.1, 12.3; 11.4: two code execution vulnerabilities), pdns-recursor (13.1, 12.3: denial of service), and kernel (13.1; 12.3: multiple vulnerabilities).

    Oracle has updated ntp (OL7; OL6; OL5: multiple code execution vulnerabilities).

    Red Hat has updated ntp (RHEL6,7; RHEL5: multiple code execution vulnerabilities).

    Scientific Linux has updated glibc (SL7: code execution) and ntp (SL6,7; SL5: multiple code execution vulnerabilities).

    Ubuntu has updated ntp (multiple code execution vulnerabilities).

    11:00p
    Best of open hardware in 2014 (Opensource.com)
    Opensource.com wraps
    up
    its open hardware coverage for 2014. You'll find pointers to resources and
    articles previously published on Opensource.com throughout the year. "Open hardware is the physical foundation of the open movement. It is through understanding, designing, manufacturing, commercializing, and adopting open hardware, that we built the basis for a healthy and self-reliant community of open. And the year of 2014 had plenty of activities in the open hardware front."

    << Previous Day 2014/12/22
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org