LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Monday, September 26th, 2016

    Time Event
    8:27a
    Prodromou: Adopt a pump.io server

    Evan Prodromou, creator of identi.ca and pump.io, has put a call out for interested parties to adopt the administration of public pump.io microblogging servers, which he is currently funding out of his own pocket. "Almost all of them are on $5/month Digital Ocean droplets, which makes them relatively cheap for a single person to support. If you decide you want to adopt a server, E14N will sell you the domain and all the software and data for $1. But you'll be obligated to keep the server running pump.io for at least a year, and if you decide you don't want to run it, you have to sell it back to me." There are currently around 25 servers in the federated network initially started by Prodromou, which does not count other pump.io instances. He notes that one important exception is the identi.ca site, which is significantly larger than the rest, and which he would like to find a trusted non-profit organization to maintain.

    1:04p
    Kernel prepatch 4.8-rc8
    The 4.8-rc8 kernel prepatch is out.
    "Things actually did start to calm down this week, but I
    didn't get the feeling that there was no point in doing one final rc,
    so here we are. I expect the final 4.8 release next weekend, unless
    something really unexpected comes up.
    "
    1:12p
    OpenSSL security advisory for September 26
    This OpenSSL
    security advisory
    is notable in that it's the second one in four days;
    sites that updated after the first one may need to do so again.
    "This security update addresses issues that were caused by patches
    included in our previous security update, released on 22nd September
    2016. Given the Critical severity of one of these flaws we have
    chosen to release this advisory immediately to prevent upgrades to the
    affected version, rather than delaying in order to provide our usual
    public pre-notification.
    "
    4:23p
    Security advisories for Monday

    Debian has updated imagemagick (code execution), libarchive (three vulnerabilities), openssl (regression in previous update), and unadf (two vulnerabilities).

    Debian-LTS has updated dropbear (two vulnerabilities), dwarfutils (two vulnerabilities), mactelnet (code execution), openssl (multiple vulnerabilities), and policycoreutils (sandbox escape).

    Fedora has updated bash (F24; F23: code execution) and firefox (F24; F23: multiple vulnerabilities).

    Gentoo has updated bundler (installs malicious gem files) and qemu (multiple vulnerabilities).

    Mageia has updated gdk-pixbuf2.0 (denial of service), golang (denial of service), libarchive (file overwrite), libtorrent-rasterbar (denial of service), php (multiple vulnerabilities), and wireshark (multiple vulnerabilities).

    openSUSE has updated curl (Leap42.1: multiple vulnerabilities), flash-player (13.1: multiple vulnerabilities), gd (Leap42.1: multiple vulnerabilities), gtk2 (Leap42.1; 13.2: code execution), firefox, nss (Leap42.1, 13.2: multiple vulnerabilities), samba (Leap42.1: crypto downgrade), thunderbird (13.1: multiple vulnerabilities), tiff (13.1: multiple vulnerabilities), and wpa_supplicant (Leap42.1: multiple vulnerabilities).

    Slackware has updated php (multiple vulnerabilities).

    Ubuntu has updated openssl (regression in previous update).

    9:21p
    Announcing the KDE Advisory Board
    KDE e.V. introduces
    the KDE Advisory Board. "One of the core goals of the Advisory Board is to provide KDE with insights into the needs of the various organizations that surround us. We are very aware that we need the ability to combine our efforts for greater impact and the only way we can do that is by adopting a more diverse view from outside of our organization on topics that are relevant to us. This will allow all of us to benefit from one another's experience."

    << Previous Day 2016/09/26
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org