LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Monday, January 25th, 2016

    Time Event
    5:23p
    A change of maintainership for Mercurial
    Matt Mackall, the creator of the Mercurial source-code management system,
    has announced that
    he is ready to move on to a new project. "So over the course of this
    year, I'm going to gradually remove myself from daily involvement in the
    project. As lots of people and companies have a lot invested in Mercurial,
    I'm doing this over a long period of time to make sure it goes
    smoothly.
    "
    6:51p
    Security updates for Monday

    Arch Linux has updated ecryptfs-utils (privilege escalation), linux-lts (privilege escalation), privoxy (two denial of service flaws), python-rsa (signature forgery), and python2-rsa (signature forgery).

    CentOS has updated ntp (C7; C6: missing check for zero originate timestamp).

    Debian has updated claws-mail (code execution).

    Debian-LTS has updated foomatic-filters (buffer overflows), imlib2 (denial of service), pound (multiple vulnerabilities, one from 2009), and privoxy (two denial of service flaws).

    Fedora has updated bind (F23: two denial of service flaws), bind99 (F23: denial of service), chrony (F23: packet modification), dhcp (F22: denial of service), java-1.8.0-openjdk (F23: unspecified), mod_nss (F22: enables insecure ciphersuites), owncloud (F23; F22: multiple vulnerabilities), python-rsa (F22: signature forgery), and qemu (F23: multiple vulnerabilities).

    Mageia has updated virtualbox (unspecified vulnerabilities).

    openSUSE has updated bind (13.1: denial of service), cgit (13.1: three vulnerabilities), giflib (13.1: heap-based buffer overflow), jasper (13.2; 13.1: denial of service), libvirt (Leap42.1, 13.2; 13.1: path traversal), openldap2 (13.2: two vulnerabilities), roundcubemail (Leap42.1; 13.2; 13.1: code execution), and tiff (13.2; 13.1: denial of service).

    Oracle has updated ntp (OL7: missing check for zero originate timestamp).

    Red Hat has updated ntp (RHEL6,7: missing check for zero originate timestamp).

    Scientific Linux has updated ntp (SL6,7: missing check for zero originate timestamp).

    SUSE has updated bind (SLES10-SP4: four denial of service vulnerabilities), openldap2 (SLE12-SP1: two vulnerabilities), and kernel (SLE12: privilege escalation).

    8:07p
    [$] 4.5 merge window part 3
    As expected, Linus released the 4.5-rc1
    development kernel and
    closed the merge window for this cycle on January 24. Less than 2,000
    changes were pulled since last week's
    summary
    , but there were some significant changes to be found among
    them. Click below (subscribers only) for the final part of LWN's 4.5 merge
    window coverage.

    << Previous Day 2016/01/25
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org