LWN.net's Journal
 
[Most Recent Entries] [Calendar View]

Tuesday, July 2nd, 2019

    Time Event
    2:38p
    Security updates for Tuesday
    Security updates have been issued by Arch Linux (firefox, firefox-developer-edition, libarchive, and vlc), CentOS (firefox, thunderbird, and vim), Debian (firefox-esr, openssl, and python-django), Fedora (glpi and xen), Mageia (thunderbird), openSUSE (ImageMagick, irssi, libheimdal, and phpMyAdmin), Red Hat (libssh2 and qemu-kvm), Scientific Linux (firefox, thunderbird, and vim), SUSE (389-ds, cf-cli, curl, dbus-1, dnsmasq, evolution, glib2, gnutls, graphviz, java-1_8_0-openjdk, and libxslt), and Ubuntu (python-django).
    7:42p
    [$] OpenPGP certificate flooding
    A problem with the way that OpenPGP
    public-key certificates are handled by key servers and applications is
    wreaking some havoc, but not just for those who own the certificates (and
    keys)—anyone who has those keys on their keyring and does regular updates
    will be affected. It is effectively a denial of service attack, but one
    that propagates differently than most others. The mechanism of this
    "certificate flooding" is one that is
    normally used to add attestations to the key owner's identity (also known as
    "signing
    the key"), but because
    of the way most key servers work, it can be used to fill a certificate with
    "spam"—with far-reaching effects.

    << Previous Day 2019/07/02
    [Calendar]
    Next Day >>

LWN.net   About LJ.Rossia.org