LWN.net http://lwn.net LWN.net is a comprehensive source of news and opinions from and about the Linux community. This is the main LWN.net feed, listing all articles which are posted to the site front page. hourly 2 Ubuntu 14.04.3 LTS released http://lwn.net/Articles/653901/rss 2015-08-07T23:04:57+00:00 ris The third update to the 14.04 Long Term Support release is available for Desktop, Server, Cloud, and Core products, as well as other flavors of Ubuntu with long-term support. "<span>We have expanded our hardware enablement offering since 12.04, and with 14.04.3, this point release contains an updated kernel and X stack for new installations to support new hardware across all our supported architectures, not just x86.</span>" Firefox 39.0.3 is out http://lwn.net/Articles/653896/rss 2015-08-07T21:29:38+00:00 ris Firefox 39.0.3 has been released. According to the <a href="https://www.mozilla.org/en-US/firefox/39.0.3/releasenotes/">release notes</a> there are various security fixes. This does include a fix for the <a href="http://lwn.net/Articles/653823/">recently report</a> active exploit. CentOS Linux 6.7 released http://lwn.net/Articles/653889/rss 2015-08-07T19:03:26+00:00 ris CentOS Linux 6.7 has been released for x86 and x86_64. "<span>There are many fundamental changes in this release, compared with the past CentOS Linux 6 releases, and we highly recommend everyone study the upstream Release Notes as well as the upstream Technical Notes about the changes and how they might impact your installation. (See the 'Further Reading' section of the <a href="http://wiki.centos.org/Manuals/ReleaseNotes/CentOS6.7">CentOS release notes</a>.</span>" Security updates for Friday http://lwn.net/Articles/653866/rss 2015-08-07T16:54:41+00:00 ris <p><b>Arch Linux</b> has updated <a href="http://lwn.net/Articles/653842/">firefox</a> (information leak) and <a href="http://lwn.net/Articles/653843/">wordpress</a> (multiple vulnerabilities). <p><b>Debian</b> has updated <a href="http://lwn.net/Articles/653844/">kernel</a> (multiple vulnerabilities). <p><b>Debian-LTS</b> has updated <a href="http://lwn.net/Articles/653845/">openssh</a> (two vulnerabilities) and <a href="http://lwn.net/Articles/653846/">remind</a> (buffer overflow). <p><b>Fedora</b> has updated <b>drupal6-cck</b> (<a href="http://lwn.net/Articles/653848/">F22</a>; <a href="http://lwn.net/Articles/653847/">F21</a>: unspecified vulnerability), <b>lighttpd</b> (<a href="http://lwn.net/Articles/653850/">F22</a>; <a href="http://lwn.net/Articles/653849/">F21</a>: log injection), <b>mantis</b> (<a href="http://lwn.net/Articles/653852/">F22</a>; <a href="http://lwn.net/Articles/653851/">F21</a>: information disclosure), <b>opensaml-java</b> (<a href="http://lwn.net/Articles/653854/">F22</a>; <a href="http://lwn.net/Articles/653853/">F21</a>: missing host name verification), <b>opensaml-java-openws</b> (<a href="http://lwn.net/Articles/653856/">F22</a>; <a href="http://lwn.net/Articles/653855/">F21</a>: missing host name verification), and <a href="http://lwn.net/Articles/653857/">openstack-swift</a> (F22: arbitrary object deletion). <p><b>Oracle</b> has updated <b>kernel&nbsp;3.8.13</b> (<a href="http://lwn.net/Articles/653859/">OL7</a>; <a href="http://lwn.net/Articles/653858/">OL6</a>: information leak), <b>kernel&nbsp;2.6.39</b> (<a href="http://lwn.net/Articles/653861/">OL6</a>; <a href="http://lwn.net/Articles/653860/">OL5</a>: two vulnerabilities), and <b>kernel&nbsp;2.6.32</b> (<a href="http://lwn.net/Articles/653863/">OL6</a>; <a href="http://lwn.net/Articles/653862/">OL5</a>: two vulnerabilities). <p><b>Ubuntu</b> has updated <a href="http://lwn.net/Articles/653864/">firefox</a> (15.04, 14.04, 12.04: information leak) and <a href="http://lwn.net/Articles/653865/">openjdk-6</a> (12.04: multiple vulnerabilities). Privacy Badger 1.0 http://lwn.net/Articles/653826/rss 2015-08-07T11:54:01+00:00 corbet The Electronic Frontier Foundation has <a href="https://www.eff.org/deeplinks/2015/08/privacy-badger-10-here-stop-online-tracking">announced</a> the 1.0 release of the Privacy Badger browser extension. "<span>As you browse the Web, Privacy Badger looks at any third party domains that are loaded on a given site and determines whether or not they appear to be tracking you (e.g. by setting cookies that could be used for tracking, or fingerprinting your browser). If the same third party domain appears to be tracking you on three or more different websites, Privacy Badger will conclude that the third party domain is a tracker and block future connections to it.</span>" The extension is distributed under GPLv3; see <a href="https://www.eff.org/privacybadger">this page</a> for more information. An active Firefox exploit http://lwn.net/Articles/653823/rss 2015-08-07T11:13:49+00:00 corbet Mozilla has posted <a href="https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/">a warning</a> about a Firefox vulnerability that is currently being actively exploited on the net. "<span>The vulnerability comes from the interaction of the mechanism that enforces JavaScript context separation (the 'same origin policy') and Firefox’s PDF Viewer. Mozilla products that don’t contain the PDF Viewer, such as Firefox for Android, are not vulnerable. The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. This allowed it to search for and upload potentially sensitive local files.</span>" There is <a href="https://support.mozilla.org/en-US/kb/update-firefox-latest-version">a security update</a> for the problem. Grasch: A Frank Look at Simon: Where To Go From Here http://lwn.net/Articles/653781/rss 2015-08-06T20:25:49+00:00 jake On his blog, Peter Grasch <a href="http://grasch.net/node/192">considers</a> the future for the <a href="https://simon.kde.org/">Simon</a> speech-recognition system for KDE. He is <a href="http://grasch.net/node/174">passing the torch</a> and will no longer be actively participating in the project, but he spent some time passing on his knowledge and some thoughts on where things might go from here. In addition, he built a working prototype of a speech-based command and control system for the Plasma desktop called <a href="http://quickgit.kde.org/?p=scratch%2Fgrasch%2Flera.git">Lera</a>. "<span>If anything, Lera is a starting point. The next steps would be to move Simon’s “eventsimulation” library into a separate framework, to be shared between Lera and Simon. Lera could then use this to type out the recognition results (see Simon’s Dictation plugin). Then, I would suggest porting a simplified notion of “Scenarios” to Lera, which should only really contain a set of commands, and maybe context information (vocabulary and “grammar” can be synthesized automatically from the command triggers). The implementation of training (acoustic model adaption) would then complete a very sensible, very usable version 1.0.</span>" Federated Cloud Sharing in ownCloud 8.1 (ownCloud blog) http://lwn.net/Articles/653768/rss 2015-08-06T18:13:59+00:00 jake The ownCloud blog has a <a href="https://owncloud.org/blog/federated-cloud-sharing-in-owncloud-8-1/">post</a> about federated file sharing between ownCloud instances in ownCloud&nbsp;8.1, but it also looks at the wider view of federation between various kinds of cloud servers. ownCloud founder Frank Karlitschek has a series of posts (<a href="https://owncloud.com/it-is-time-to-federate-our-clouds/">It is Time to Federate Our Clouds</a>, <a href="https://owncloud.com/the-next-generation-file-sync-and-share-technology/">The Next Generation File Sync and Share Technology</a>, and <a href="https://owncloud.com/the-federated-architecture-of-next-generation-file-sync-and-share/">The Federated Architecture of Next Generation File Sync and Share</a>) on federation technology and has also proposed a cross-cloud-platform federation API: "<span>In addition, today Frank <a href="http://karlitschek.de/2015/08/announcing-the-draft-federated-cloud-sharing-api/">proposed a draft of a Federated Cloud Sharing API</a> to the <a href="https://owncloud.com/lp/opencloudmesh/">Open Cloud Mesh</a> working group with the goal of jump-starting a discussion about what is needed to enable federation between different file sharing implementations. Sharing among ownClouds is great, but the true power of a federated file cloud is available when you can share among different implementations seamlessly, because you all speak the same common language. This is the goal of the Open Cloud Mesh working group (of which ownCloud is a member as well), and outside of that, drafts have been shared with a number of well known standards organizations around web technologies and fellow open source file share and sync projects to get the work started.</span>" Security updates for Thursday http://lwn.net/Articles/653742/rss 2015-08-06T14:31:55+00:00 jake <p><b>CentOS</b> has updated <a href="http://lwn.net/Articles/653733/">kernel</a> (C7: multiple vulnerabilities, one from 2014). <p><b>Fedora</b> has updated <a href="http://lwn.net/Articles/653734/">kernel</a> (F22: three vulnerabilities). <p><b>openSUSE</b> has updated <a href="http://lwn.net/Articles/653735/">ghostscript</a> (13.2, 13.1: code execution) and <a href="http://lwn.net/Articles/653736/">php5</a> (13.2, 13.1: two vulnerabilities). <p><b>Red Hat</b> has updated <a href="http://lwn.net/Articles/653730/">kernel</a> (RHEL7: multiple vulnerabilities, one from 2014) and <b>kernel-rt</b> (<a href="http://lwn.net/Articles/653731/">RHEL7</a>; <a href="http://lwn.net/Articles/653732/">RHEL6</a>: multiple vulnerabilities, one from 2014). <p><b>Scientific Linux</b> has updated <a href="http://lwn.net/Articles/653737/">kernel</a> (SL7: multiple vulnerabilities, one from 2014). <p><b>SUSE</b> has updated <a href="http://lwn.net/Articles/653738/">oracle-update</a> (Manager 2.1: multiple vulnerabilities). <p><b>Ubuntu</b> has updated <a href="http://lwn.net/Articles/653739/">cinder</a> (15.04: arbitrary file reads), <a href="http://lwn.net/Articles/653740/">python-keystoneclient, python-keystonemiddleware</a> (15.04, 14.04: two vulnerabilities, one from 2014), and <a href="http://lwn.net/Articles/653741/">swift</a> (15.04, 14.04, 12,04: two vulnerabilities, one from 2014). [$] LWN.net Weekly Edition for August 6, 2015 http://lwn.net/Articles/653180/rss 2015-08-06T01:24:32+00:00 corbet The LWN.net Weekly Edition for August 6, 2015 is available. [$] "Big data" features coming in PostgreSQL 9.5 http://lwn.net/Articles/653411/rss 2015-08-05T18:16:58+00:00 jake PostgreSQL 9.5 Alpha 2 is due to be released on August&nbsp;6. Not only does the new version support UPSERT, more JSON functionality, and other new features we <a href="http://lwn.net/Articles/650341/">looked at</a> back in July, it also has some major enhancements for "big data" workloads. Among these are faster sorts, <tt>TABLESAMPLE</tt>, <tt>GROUPING SETS</tt> and <tt>CUBE</tt>, BRIN indexes, and Foreign Data Wrapper improvements. Taken together, these features strengthen arguments for using PostgreSQL for data warehouses, and enable users to continue using it with bigger databases. Security updates for Wednesday http://lwn.net/Articles/653603/rss 2015-08-05T15:55:50+00:00 ris <p><b>Debian</b> has updated <a href="http://lwn.net/Articles/653599/">wordpress</a> (regression in previous update). <p><b>Debian-LTS</b> has updated <a href="http://lwn.net/Articles/653600/">ia32-libs</a> (multiple vulnerabilities). <p><b>Red Hat</b> has updated <a href="http://lwn.net/Articles/653596/">java-1.5.0-ibm</a> (RHEL5,6: multiple vulnerabilities) and <b>node.js</b> (<a href="http://lwn.net/Articles/653597/">RHOSE2.1</a>; <a href="http://lwn.net/Articles/653598/">RHOSE2.0</a>: man-in-the-middle attack). <p><b>SUSE</b> has updated <a href="http://lwn.net/Articles/653601/">java-1_6_0-ibm</a> (SLEM12: multiple vulnerabilities). <p><b>Ubuntu</b> has updated <a href="http://lwn.net/Articles/653602/">oxide-qt</a> (15.04, 14.04: multiple vulnerabilities). [$] Fuzzing perf_events http://lwn.net/Articles/653382/rss 2015-08-05T12:36:11+00:00 jake You might be surprised to learn that starting with Linux 2.6.31 (in 2009) it has been rather easy to crash the Linux kernel. This date marks the introduction of the <a href="http://lwn.net/Articles/339361/">perf_event subsystem</a>. It is likely that perf_event is not any more prone to errors than any other large kernel subsystem, but it has the distinction of being subjected to intense testing from the <a href="http://web.eece.maine.edu/~vweaver/projects/perf_events/fuzzer/"> perf_fuzzer</a> tool, which methodically probes the interface for bugs. <p> Click below (subscribers only) for the full article from perf_fuzzer author Vince Weaver. LibreOffice 5.0 released http://lwn.net/Articles/653574/rss 2015-08-05T11:53:37+00:00 corbet The LibreOffice 5.0 release is out. "<span>LibreOffice 5.0 sports a significantly improved user interface, with a better management of the screen space and a cleaner look. In addition, it offers better interoperability with office suites such as Microsoft Office and Apple iWork, thanks to new and improved filters to handle non standard formats.</span>" See <a href="https://people.gnome.org/~michael/blog/2015-08-05-under-the-hood-5-0.html">this post from Michael Meeks</a> for a detailed description of the work that went into this release. Coalition Announces New ‘Do Not Track’ Standard for Web Browsing http://lwn.net/Articles/653514/rss 2015-08-04T19:50:42+00:00 ris The Electronic Frontier Foundation (EFF), privacy company Disconnect and a coalition of Internet companies have <a href="https://www.eff.org/press/releases/coalition-announces-new-do-not-track-standard-web-browsing">announced</a> a stronger “Do Not Track” (DNT) setting for Web browsing—"<span>a new policy standard that, coupled with privacy software, will better protect users from sites that try to secretly follow and record their Internet activity, and incentivize advertisers and data collection companies to respect a user’s choice not to be tracked online.</span>"