LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Saturday, June 18th, 2016

    Time Event
    12:14a
    Friday's security updates

    CentOS has updated firefox (C6; C5; C7: multiple vulnerabilities) and imagemagick (C6; C7: multiple vulnerabilities).

    Debian has updated drupal7 (privilege escalation).

    Debian-LTS has updated imagemagick (buffer overflow) and kernel (multiple vulnerabilities).

    Gentoo has updated nginx (multiple vulnerabilities) and spice (multiple vulnerabilities).

    Mageia has updated expat (M5: multiple vulnerabilities), flash-player-plugin (M5: multiple vulnerabilities), and virtualbox (M5: unspecified vulnerability).

    openSUSE has updated wireshark (13.2, Leap 42.1: multiple vulnerabilities).

    Oracle has updated ImageMagick (O7; O6: multiple vulnerabilities).

    Red Hat has updated flash-plugin (RHEL 5,6: multiple vulnerabilities) and imagemagick (RHEL 6,7: multiple vulnerabilities).

    Scientific Linux has updated firefox (SL 5,6,7: multiple vulnerabilities), kernel (SL6: multiple vulnerabilities), ntp (SL 6,7: multiple vulnerabilities), spice-server (SL6: multiple vulnerabilities), squid (SL6: multiple vulnerabilities), and squid34 (SL6: multiple vulnerabilities).

    SUSE has updated ImageMagick (SLE11: command execution), libxml2 (SLE11: multiple vulnerabilities), and ntp (SLE11: multiple vulnerabilities).

    12:40a
    Klumpp: A few words about the future of the Limba project

    Those concerned about the proliferation of application-packaging formats will soon have one fewer to worry about. At his blog, Matthias Klumpp announces that he intends to scale back his work on Limba, the cross-distribution application-packaging format he has developed as an extension of the ideas in the earlier Listaller. The decision comes on the heels of discussions with Flatpak developer Alexander Larsson, since the two projects overlap in many respects: "Alex and I had very productive discussions, and except for the modularity issue, we were pretty much on the same page in every other aspect regarding the sandboxing and app-distribution matters."

    Given that he has several other active projects in development, Klumpp has decided to throttle back on Limba, although he will continue to hack on it "as a research project" and sees several opportunities where it might still fit into vendor-independent software distribution down the road. "This is good news for all the people out there using the Tanglu Linux distribution, AppStream-metadata-consuming services, PackageKit on Debian, etc. – those will receive more attention," Klumpp concludes.

    << Previous Day 2016/06/18
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org