LWN.net
http://lwn.net
LWN.net is a comprehensive source of news and opinions from
and about the Linux community. This is the main LWN.net feed,
listing all articles which are posted to the site front page.
hourly2Ubuntu 14.04.3 LTS released
http://lwn.net/Articles/653901/rss
2015-08-07T23:04:57+00:00ris
The third update to the 14.04 Long Term Support release is available for
Desktop, Server, Cloud, and Core products, as well as other flavors of
Ubuntu with long-term support. "<span>We have expanded our hardware
enablement offering since 12.04, and with
14.04.3, this point release contains an updated kernel and X stack for
new installations to support new hardware across all our supported
architectures, not just x86.</span>"
Firefox 39.0.3 is out
http://lwn.net/Articles/653896/rss
2015-08-07T21:29:38+00:00ris
Firefox 39.0.3 has been released. According to the <a
href="https://www.mozilla.org/en-US/firefox/39.0.3/releasenotes/">release
notes</a> there are various security fixes. This does include a fix for
the <a href="http://lwn.net/Articles/653823/">recently report</a> active exploit.
CentOS Linux 6.7 released
http://lwn.net/Articles/653889/rss
2015-08-07T19:03:26+00:00ris
CentOS Linux 6.7 has been released for x86 and x86_64. "<span>There are
many fundamental changes in this release, compared with the past CentOS
Linux 6 releases, and we highly recommend everyone study the upstream
Release Notes as well as the upstream Technical Notes about the changes and
how they might impact your installation. (See the 'Further Reading' section
of the <a href="http://wiki.centos.org/Manuals/ReleaseNotes/CentOS6.7">CentOS release notes</a>.</span>"
Security updates for Friday
http://lwn.net/Articles/653866/rss
2015-08-07T16:54:41+00:00ris
<p><b>Arch Linux</b> has updated <a href="http://lwn.net/Articles/653842/">firefox</a> (information leak) and <a href="http://lwn.net/Articles/653843/">wordpress</a> (multiple vulnerabilities).
<p><b>Debian</b> has updated <a href="http://lwn.net/Articles/653844/">kernel</a> (multiple vulnerabilities).
<p><b>Debian-LTS</b> has updated <a href="http://lwn.net/Articles/653845/">openssh</a>
(two vulnerabilities) and <a href="http://lwn.net/Articles/653846/">remind</a> (buffer overflow).
<p><b>Fedora</b> has updated <b>drupal6-cck</b> (<a
href="http://lwn.net/Articles/653848/">F22</a>; <a href="http://lwn.net/Articles/653847/">F21</a>:
unspecified vulnerability), <b>lighttpd</b> (<a
href="http://lwn.net/Articles/653850/">F22</a>; <a href="http://lwn.net/Articles/653849/">F21</a>: log
injection), <b>mantis</b> (<a href="http://lwn.net/Articles/653852/">F22</a>; <a
href="http://lwn.net/Articles/653851/">F21</a>: information disclosure),
<b>opensaml-java</b> (<a href="http://lwn.net/Articles/653854/">F22</a>; <a
href="http://lwn.net/Articles/653853/">F21</a>: missing host name verification),
<b>opensaml-java-openws</b> (<a href="http://lwn.net/Articles/653856/">F22</a>; <a
href="http://lwn.net/Articles/653855/">F21</a>: missing host name verification), and <a
href="http://lwn.net/Articles/653857/">openstack-swift</a> (F22: arbitrary object deletion).
<p><b>Oracle</b> has updated <b>kernel 3.8.13</b> (<a
href="http://lwn.net/Articles/653859/">OL7</a>; <a href="http://lwn.net/Articles/653858/">OL6</a>:
information leak), <b>kernel 2.6.39</b> (<a
href="http://lwn.net/Articles/653861/">OL6</a>; <a href="http://lwn.net/Articles/653860/">OL5</a>: two
vulnerabilities), and <b>kernel 2.6.32</b> (<a
href="http://lwn.net/Articles/653863/">OL6</a>; <a href="http://lwn.net/Articles/653862/">OL5</a>: two vulnerabilities).
<p><b>Ubuntu</b> has updated <a href="http://lwn.net/Articles/653864/">firefox</a>
(15.04, 14.04, 12.04: information leak) and <a
href="http://lwn.net/Articles/653865/">openjdk-6</a> (12.04: multiple vulnerabilities).
Privacy Badger 1.0
http://lwn.net/Articles/653826/rss
2015-08-07T11:54:01+00:00corbet
The Electronic Frontier Foundation has <a
href="https://www.eff.org/deeplinks/2015/08/privacy-badger-10-here-stop-online-tracking">announced</a>
the 1.0 release of the Privacy Badger browser extension. "<span>As you
browse the Web, Privacy Badger looks at any third party domains that are
loaded on a given site and determines whether or not they appear to be
tracking you (e.g. by setting cookies that could be used for tracking, or
fingerprinting your browser). If the same third party domain appears to be
tracking you on three or more different websites, Privacy Badger will
conclude that the third party domain is a tracker and block future
connections to it.</span>" The extension is distributed under GPLv3; see
<a href="https://www.eff.org/privacybadger">this page</a> for more
information.
An active Firefox exploit
http://lwn.net/Articles/653823/rss
2015-08-07T11:13:49+00:00corbet
Mozilla has posted <a
href="https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/">a
warning</a> about a Firefox vulnerability that is currently being actively
exploited on the net. "<span>The vulnerability comes from the interaction
of the mechanism that enforces JavaScript context separation (the 'same
origin policy') and Firefox’s PDF Viewer. Mozilla products that don’t
contain the PDF Viewer, such as Firefox for Android, are not
vulnerable. The vulnerability does not enable the execution of arbitrary
code but the exploit was able to inject a JavaScript payload into the local
file context. This allowed it to search for and upload potentially
sensitive local files.</span>" There is <a
href="https://support.mozilla.org/en-US/kb/update-firefox-latest-version">a
security update</a> for the problem.
Grasch: A Frank Look at Simon: Where To Go From Here
http://lwn.net/Articles/653781/rss
2015-08-06T20:25:49+00:00jake
On his blog, Peter Grasch <a href="http://grasch.net/node/192">considers</a> the future for the <a href="https://simon.kde.org/">Simon</a> speech-recognition system for KDE. He is <a href="http://grasch.net/node/174">passing the torch</a> and will no longer be actively participating in the project, but he spent some time passing on his knowledge and some thoughts on where things might go from here. In addition, he built a working prototype of a speech-based command and control system for the Plasma desktop called <a href="http://quickgit.kde.org/?p=scratch%2Fgrasch%2Flera.git">Lera</a>. "<span>If anything, Lera is a starting point. The next steps would be to move Simon’s “eventsimulation” library into a separate framework, to be shared between Lera and Simon. Lera could then use this to type out the recognition results (see Simon’s Dictation plugin). Then, I would suggest porting a simplified notion of “Scenarios” to Lera, which should only really contain a set of commands, and maybe context information (vocabulary and “grammar” can be synthesized automatically from the command triggers). The implementation of training (acoustic model adaption) would then complete a very sensible, very usable version 1.0.</span>"
Federated Cloud Sharing in ownCloud 8.1 (ownCloud blog)
http://lwn.net/Articles/653768/rss
2015-08-06T18:13:59+00:00jake
The ownCloud blog has a <a href="https://owncloud.org/blog/federated-cloud-sharing-in-owncloud-8-1/">post</a> about federated file sharing between ownCloud instances in ownCloud 8.1, but it also looks at the wider view of federation between various kinds of cloud servers. ownCloud founder Frank Karlitschek has a series of posts (<a href="https://owncloud.com/it-is-time-to-federate-our-clouds/">It is Time to Federate Our Clouds</a>, <a href="https://owncloud.com/the-next-generation-file-sync-and-share-technology/">The Next Generation File Sync and Share Technology</a>, and <a href="https://owncloud.com/the-federated-architecture-of-next-generation-file-sync-and-share/">The Federated Architecture of Next Generation File Sync and Share</a>) on federation technology and has also proposed a cross-cloud-platform federation API:
"<span>In addition, today Frank <a href="http://karlitschek.de/2015/08/announcing-the-draft-federated-cloud-sharing-api/">proposed a draft of a Federated Cloud Sharing API</a> to the <a href="https://owncloud.com/lp/opencloudmesh/">Open Cloud Mesh</a> working group with the goal of jump-starting a discussion about what is needed to enable federation between different file sharing implementations. Sharing among ownClouds is great, but the true power of a federated file cloud is available when you can share among different implementations seamlessly, because you all speak the same common language. This is the goal of the Open Cloud Mesh working group (of which ownCloud is a member as well), and outside of that, drafts have been shared with a number of well known standards organizations around web technologies and fellow open source file share and sync projects to get the work started.</span>"
Security updates for Thursday
http://lwn.net/Articles/653742/rss
2015-08-06T14:31:55+00:00jake
<p><b>CentOS</b> has updated <a href="http://lwn.net/Articles/653733/">kernel</a> (C7: multiple vulnerabilities, one from 2014).
<p><b>Fedora</b> has updated <a href="http://lwn.net/Articles/653734/">kernel</a> (F22:
three vulnerabilities).
<p><b>openSUSE</b> has updated <a href="http://lwn.net/Articles/653735/">ghostscript</a>
(13.2, 13.1: code execution) and <a href="http://lwn.net/Articles/653736/">php5</a>
(13.2, 13.1: two vulnerabilities).
<p><b>Red Hat</b> has updated <a href="http://lwn.net/Articles/653730/">kernel</a>
(RHEL7: multiple vulnerabilities, one from 2014) and <b>kernel-rt</b> (<a href="http://lwn.net/Articles/653731/">RHEL7</a>; <a href="http://lwn.net/Articles/653732/">RHEL6</a>: multiple vulnerabilities, one from 2014).
<p><b>Scientific Linux</b> has updated <a href="http://lwn.net/Articles/653737/">kernel</a> (SL7: multiple vulnerabilities, one from 2014).
<p><b>SUSE</b> has updated <a href="http://lwn.net/Articles/653738/">oracle-update</a>
(Manager 2.1: multiple vulnerabilities).
<p><b>Ubuntu</b> has updated <a href="http://lwn.net/Articles/653739/">cinder</a> (15.04:
arbitrary file reads), <a href="http://lwn.net/Articles/653740/">python-keystoneclient,
python-keystonemiddleware</a> (15.04, 14.04: two vulnerabilities, one from
2014), and <a href="http://lwn.net/Articles/653741/">swift</a> (15.04, 14.04, 12,04: two
vulnerabilities, one from 2014).
[$] LWN.net Weekly Edition for August 6, 2015
http://lwn.net/Articles/653180/rss
2015-08-06T01:24:32+00:00corbet
The LWN.net Weekly Edition for August 6, 2015 is available.
[$] "Big data" features coming in PostgreSQL 9.5
http://lwn.net/Articles/653411/rss
2015-08-05T18:16:58+00:00jake
PostgreSQL 9.5 Alpha 2 is due to be released on August 6. Not only
does the new version support UPSERT, more JSON functionality, and other new
features we <a href="http://lwn.net/Articles/650341/">looked at</a> back in July, it also
has some major enhancements for "big data" workloads. Among these are
faster sorts, <tt>TABLESAMPLE</tt>, <tt>GROUPING SETS</tt> and
<tt>CUBE</tt>, BRIN indexes, and Foreign Data Wrapper improvements. Taken
together, these features strengthen arguments for using PostgreSQL for data
warehouses, and enable users to continue using it with bigger databases.
Security updates for Wednesday
http://lwn.net/Articles/653603/rss
2015-08-05T15:55:50+00:00ris
<p><b>Debian</b> has updated <a href="http://lwn.net/Articles/653599/">wordpress</a>
(regression in previous update).
<p><b>Debian-LTS</b> has updated <a href="http://lwn.net/Articles/653600/">ia32-libs</a> (multiple vulnerabilities).
<p><b>Red Hat</b> has updated <a
href="http://lwn.net/Articles/653596/">java-1.5.0-ibm</a> (RHEL5,6: multiple
vulnerabilities) and <b>node.js</b> (<a
href="http://lwn.net/Articles/653597/">RHOSE2.1</a>; <a
href="http://lwn.net/Articles/653598/">RHOSE2.0</a>: man-in-the-middle attack).
<p><b>SUSE</b> has updated <a href="http://lwn.net/Articles/653601/">java-1_6_0-ibm</a>
(SLEM12: multiple vulnerabilities).
<p><b>Ubuntu</b> has updated <a href="http://lwn.net/Articles/653602/">oxide-qt</a>
(15.04, 14.04: multiple vulnerabilities).
[$] Fuzzing perf_events
http://lwn.net/Articles/653382/rss
2015-08-05T12:36:11+00:00jake
You might be surprised to learn that starting with Linux 2.6.31 (in 2009)
it has been rather easy to crash the Linux kernel.
This date marks the introduction of the
<a href="http://lwn.net/Articles/339361/">perf_event subsystem</a>.
It is likely that perf_event is not any more prone to errors than
any other large kernel subsystem, but it has the distinction of
being subjected to intense testing from the
<a href="http://web.eece.maine.edu/~vweaver/projects/perf_events/fuzzer/">
perf_fuzzer</a> tool, which methodically probes the interface for bugs.
<p>
Click below (subscribers only) for the full article from perf_fuzzer author
Vince Weaver.
LibreOffice 5.0 released
http://lwn.net/Articles/653574/rss
2015-08-05T11:53:37+00:00corbet
The LibreOffice 5.0 release is out. "<span>LibreOffice 5.0 sports a significantly improved user interface, with a
better management of the screen space and a cleaner look. In addition,
it offers better interoperability with office suites such as Microsoft
Office and Apple iWork, thanks to new and improved filters to handle non
standard formats.</span>" See <a
href="https://people.gnome.org/~michael/blog/2015-08-05-under-the-hood-5-0.html">this
post from Michael Meeks</a> for a detailed description of the work that went
into this release.
Coalition Announces New ‘Do Not Track’ Standard for Web Browsing
http://lwn.net/Articles/653514/rss
2015-08-04T19:50:42+00:00ris
The Electronic Frontier Foundation (EFF), privacy company Disconnect and a
coalition of Internet companies have <a
href="https://www.eff.org/press/releases/coalition-announces-new-do-not-track-standard-web-browsing">announced</a> a stronger “Do Not Track” (DNT) setting for Web browsing—"<span>a new policy standard that, coupled with privacy software, will better protect users from sites that try to secretly follow and record their Internet activity, and incentivize advertisers and data collection companies to respect a user’s choice not to be tracked online.</span>"