Message Box

05 March 2009

[CentOS-announce] CESA-2009:0325 Critical CentOS 3 x86_64 seamonkey - security update

CentOS Errata and Security Advisory CESA-2009:0325

seamonkey security update for CentOS 3 x86_64:
https://rhn.redhat.com/errata/RHSA-2009-0325.html

The following updated file has been uploaded and is currently syncing to
the mirrors:

x86_64:
updates/x86_64/RPMS/seamonkey-1.0.9-0.34.el3.centos3.i386.rpm
updates/x86_64/RPMS/seamonkey-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-chat-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-devel-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-dom-inspector-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-js-debugger-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-mail-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-nspr-1.0.9-0.34.el3.centos3.i386.rpm
updates/x86_64/RPMS/seamonkey-nspr-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-nspr-devel-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-nss-1.0.9-0.34.el3.centos3.i386.rpm
updates/x86_64/RPMS/seamonkey-nss-1.0.9-0.34.el3.centos3.x86_64.rpm
updates/x86_64/RPMS/seamonkey-nss-devel-1.0.9-0.34.el3.centos3.x86_64.rpm

source:
updates/SRPMS/seamonkey-1.0.9-0.34.el3.centos3.src.rpm

You may update your CentOS-3 x86_64 installations by running the command:

yum update seamonkey

Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B

[CentOS-announce] CESA-2009:0325 Critical CentOS 3 i386 seamonkey - security update

CentOS Errata and Security Advisory CESA-2009:0325

seamonkey security update for CentOS 3 i386:
https://rhn.redhat.com/errata/RHSA-2009-0325.html

The following updated file has been uploaded and is currently syncing to
the mirrors:

i386:
updates/i386/RPMS/seamonkey-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-chat-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-devel-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-dom-inspector-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-js-debugger-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-mail-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-nspr-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-nspr-devel-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-nss-1.0.9-0.34.el3.centos3.i386.rpm
updates/i386/RPMS/seamonkey-nss-devel-1.0.9-0.34.el3.centos3.i386.rpm

source:
updates/SRPMS/seamonkey-1.0.9-0.34.el3.centos3.src.rpm

You may update your CentOS-3 i386 installations by running the command:

yum update seamonkey

Tru
--
Tru Huynh (mirrors, CentOS-3 i386/x86_64 Package Maintenance)
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xBEFA581B

Minutes from the Technical Board meeting, 2009-02-24

Apologies for the late sending of this, I had it all ready to send last
Wednesday (with Maria's help) but it got stuck in my Outbox!

= Attendees =

* Matt Zimmerman (chair)
* Mark Shuttleworth
* Colin Watson
* Scott James Remnant

= Minutes =

== Should technical-board@lists.ubuntu.com be public? ==

* Technical-board@ serves two purposes:
1. a contact address to reach the TB (and only the TB)
2. a mailing list to discuss TB matters
for 1., a private list is appropriate, but for 2., it is not.

* Currently, the Technical Board is responsible for the following
documents and processes:
1. The Ubuntu Package Policy,
2. Ubuntu Release Feature Goals,
3. Ubuntu Package Selection,
none of that stuff should be private, however there needs to be a
quick, easy and memorable way to talk privately to or among the TB.

* No objections to subscribing select people to the TB list who are
also participating but not actually on the TB. It was also
reaffirmed that where possible, we should shift discussion of public
matters from t-b@ onto ubuntu-devel@

The TB will stay private so long as we only use it for discussions
which ought to be private, and nothing else e.g. if someone emails
technical-board@ and raises a technical concern, we must redirect
that to ubuntu-devel@.

== MOTU Council list of nominees for MOTU Council Election ==

* Appointments to the board are made by Mark Shuttleworth subject to
confirmation by a vote amongst the maintainers

* The CC (and TB) will determine a shortlist of candidates and set up
Launchpad polls accordingly so team members can vote.

* The polls might take the form of confirmation votes or of a race
between more candidates than the available seats on the Team Council.
MC has been well organised, growing it gives an opportunity to
develop more leadership talent so 2 other seats will be added.

* The three nominees are: Daniel Holbach, Nathan Handler, and Jonathan
Davies

ACTION: sabdfl to set up Launchpad polls including per-package uploaders
for MC nominee confirmations

== SRU guidelines for Landscape ==

* https://wiki.ubuntu.com/LandscapeUpdates

* Sometimes, the Landscape client code must be updated to take
advantage of improvements/updates to the Landscape server...and this
is their reasoning for the need to be part of an SRU.

* The reasons why Landscape is suitable, given the negotiations to
date, are:
- it has an extensive test suite (yes, like other packages in the
archive)
- its developers have committed to doing specific QA on a variety of
upgrade and fresh-install combinations
- it has very limited interactions with the rest of Ubuntu, that are
straightforward to enumerate so that we can have a clear idea of
regression potential
- those interactions have been specifically called out in the
mandatory QA process that each upgrade must go through
- its developers have agreed to work within the Ubuntu update
process

* Landscape developers originally raised:
https://bugs.edge.launchpad.net/ubuntu/+source/landscape-client/+bug/306360

* We want assurance that the potential impact is limited, and that the
testing conducted is sufficient to provide the level of assurance we
expect for stable updates.

* We've entrusted the SRU team to assess the QA aspect and will review
that ourselves as well based on the document that outlines the
criteria we used to make the decision and includes the sentence ("the
TB will consider additional applications in due course following
similar criteria")

ACTION: cjwatson to write up a formal decision which the TB can then
vote on

== Upload permission for Romain Francoise for 'emacs-snapshot' ==

* https://edge.launchpad.net/ubuntu/+source/emacs-snapshot

* Jono has been in touch with Romain. To be followed up

== Other ==

* Codecs in ffmpeg, jono is working on

* Archive reorg governance ACTION: cjwatson to rework archive reorg
proposal to unblock governance work

* mdke's application was dealt with by email and privileges granted.


Scott
--
Scott James Remnant
scott@canonical.com

The H news 05/03/2009


The H news 05/03/2009
www.h-online.com
[please load images]
Overview of the news from the past 24 hours
The H Security news
Poll: Oracle admins have a poor update install record

A study by the Independent Oracle User Group shows that eleven per cent of administrators have not installed any Critical Patch Updates

 Read article   [please load images]   [please load images]



German police close down cracker forum

According to a report, special internet investigators of Baden-Württemberg's Criminal Investigation Department have closed down a forum for sharing malicious software

 Read article   [please load images]   [please load images]



Use of PGP by UK MPs is "not recommended"

UK MPs are told not to use PGP on their computers as the authorities declare it incompatible with the Parliamentary VPN

 Read article   [please load images]   [please load images]



Vulnerability in sound processing library libsndfile

A vulnerability in the open source sound processing library libsndfile can allow an attacker to inject and execute arbitrary code

 Read article   [please load images]   [please load images]



Security update for cURL

cURL and libcurl are vulnerable to a redirection attack which could expose local files or even allow them to be overwritten

 Read article   [please load images]   [please load images]



Five per cent of all company PCs infected with bots

A study says antivirus software takes 54 days on average to detect a bot. Faced with a growing botnet problem, Australia has launched National Zombie Awareness Week

 Read article   [please load images]   [please load images]



The H Open Source news
Red Hat hit by a patent suit

Red Hat is being accused of patent infringement, but it's not Linux in the dock, it's the company's JBoss middleware

 Read article   [please load images]   [please load images]



Vulnerability in sound processing library libsndfile

A vulnerability in the open source sound processing library libsndfile can allow an attacker to inject and execute arbitrary code

 Read article   [please load images]   [please load images]



Security update for cURL

cURL and libcurl are vulnerable to a redirection attack which could expose local files or even allow them to be overwritten

 Read article   [please load images]   [please load images]



Car Makers collaborate on Linux for cars

Genivi is a new industry alliance aiming to bring a Linux based open source platform for car makers to use for "In-Vehicle Infotainment"

 Read article   [please load images]   [please load images]



End-to-End testing with JSFUnit 1.0

The Red Hat JBoss unit has released JSFUnit 1.0 which now includes HtmlUnit

 Read article   [please load images]   [please load images]



Linux Foundation takes over Linux.com

The Linux Foundation has taken over Linux.com to create a new community site and is now offering training courses

 Read article   [please load images]   [please load images]



[please load images] [please load images]

This newsletter is sent to in a multipart format. If you want to read it as plain text, you will have to change the display mode of your e-mail program.


You are receiving The H news because you subscribed at our website.
If you no longer wish to receive the newsletter, you can cancel your subscription at http://www.h-online.com/newsletter/manage/news.


For more news from the world of technology, subscribe to our other newsletters:

Newsletter The H Open Source:
All the latest about Free and Open Source software from The H, including news, features, analysis and case studies. www.h-online.com/newsletter/manage/open

Newsletter The H Security:
IT security news and alerts to keep your systems secure, with features giving an in-depth look at the world of IT security. www.h-online.com/newsletter/manage/security


Legal notice

Publishers: Christian Heise, Ansgar Heise, Christian Persson

Editor-in-chief: Dj Walker-Morgan

All rights reserved. Any copies or dissemination on any medium, either in part of whole, requires the written consent of the publisher.

Copyright (c) 2009 Heise Media UK Ltd.