Language Selection

English French German Italian Portuguese Spanish

LWN

Syndicate content
LWN.net is a comprehensive source of news and opinions from and about the Linux community. This is the main LWN.net feed, listing all articles which are posted to the site front page.
Updated: 43 min 32 sec ago

Kernel prepatch 3.19-rc3

Tuesday 6th of January 2015 02:12:26 AM
The 3.19-rc3 prepatch is out for testing. "It's a day delayed - not because of any particular development issues, but simply because I was tiling a bathroom yesterday. But rc3 is out there now, and things have stayed reasonably calm. I really hope that implies that 3.19 is looking good, but it's equally likely that it's just that people are still recovering from the holiday season."

Cuthbertson: NixOS and Stateless Deployment

Monday 5th of January 2015 09:03:17 PM
Here is a lengthy post from Tim Cuthbertson on the virtues of building servers with NixOS. "It should hopefully be obvious at this point why NixOS is better than puppet: Both are declarative, but puppet is impure and non-exhaustive - when you apply a config, puppet compares everything specified against the current state of the system. Everything not specified is left alone, which means you’re only specifying a very tiny subset of your system. With NixOS, if something is not specified, it is not present."

Security advisories for Monday

Monday 5th of January 2015 05:47:46 PM

Debian has updated strongswan (denial of service).

Debian-LTS has updated polarssl (denial of service), pyyaml (denial of service), and sox (code execution).

Fedora has updated claws-mail (F19: man-in-the-middle attack), claws-mail-plugins (F19: man-in-the-middle attack), curl (F19: information leak), denyhosts (F20; F19: denial of service), ettercap (F21; F20; F19: multiple vulnerabilities), freetype (F20: buffer overflow), kernel (F19: multiple vulnerabilities), libetpan (F19: man-in-the-middle attack), libssh (F21; F20; F19: denial of service), mailx (F21; F20; F19: command execution), mingw-pcre (F21; F20; F19: information leak), openjpeg (F19: multiple vulnerabilities), python-django-horizon (F21: denial of service), pyxdg (F20: symlink attacks), subversion (F21; F20: denial of service), and unrtf (F21: code execution).

Mandriva has updated c-icap (denial of service), ntp (multiple code execution vulnerabilities), pcre (information leak), php (code execution), and subversion (denial of service).

Ubuntu has updated strongswan (14.10, 14.04: denial of service).

[$] OpenMediaVault: a distribution for NAS boxes

Friday 2nd of January 2015 10:44:03 PM
The Linux community has no shortage of general-purpose distributions that can be made to serve almost any need. But many Linux deployments are not on general-purpose machines; often the owner has a more specific objective in mind. One such objective is to put together a network-attached storage (NAS) box. A general-purpose distribution can easily be used in such a setting, but there are also several specialized distributions that make the task easier. This article, the first in a series, will look at OpenMediaVault, a Debian-based NAS-oriented distribution.

Friday's security updates

Friday 2nd of January 2015 03:09:33 PM

Fedora has updated glpi (F19; F20, F21: SQL injection), mingw-binutils (F20; F21: multiple vulnerabilities), mingw-curl (F20; F21: multiple vulnerabilities), mingw-dbus (F20; F21: multiple vulnerabilities), mingw-freetype (F20; F21: code execution), mingw-libjpeg-turbo (F20; F21: denial of service), mingw-libxml2 (F20; F21: denial of service), mingw-openssl (F20; F21: multiple vulnerabilities), and ntp (F19; multiple vulnerabilities).

openSUSE has updated libvirt (13.1: denial of service; 13.2: multiple vulnerabilities), ruby2.1 (13.2: multiple vulnerabilities), and ruby20 (13.1: multiple vulnerabilities).

Purism Librem 15 (Linux Journal)

Wednesday 31st of December 2014 08:37:32 PM
Linux Journal looks at the Purism Project and the Purism Librem 15 laptop. "The Librem 15 uses the Trisquel distribution which wasn't a distribution I had heard of before now. Basically it's a Debian-based distribution that not only removes the non-free repository by default, but it has no repositories at all that provide non-free software. It was picked for the Librem 15 because it is on the list of official FSF-approved GNU/Linux distributions and since that laptop is aiming to get the FSF stamp of approval, that decision makes sense. Since it's a Debian-based distribution, the desktop environment and most of the available software shouldn't seem too different for anyone who has used a Debian-based distribution before. Of course, if you do want to use any proprietary software (like certain multimedia codecs or official Flash plugins) you will have to hunt for those on your own. Then again, the whole point of this laptop is to avoid any software like that."

Ringing in 2015 with 40 Linux-friendly hacker SBCs (LinuxGizmos)

Wednesday 31st of December 2014 06:41:39 PM
For anybody looking for a single-board computer to experiment with: LinuxGizmos has a survey of 40 of them. "Over the last year we’ve seen some new quad- and octa-core boards with more memory, built-in WiFi, and other extras. Yet, most of the growth has been in the under $50 segment where the Raspberry Pi and BeagleBone reign. Based on specs alone, standouts in price/performance that have broken the $40 barrier include the new Odroid-C1 and pcDuino3 Nano, but other good deals abound here as well."

Security advisories for Wednesday

Wednesday 31st of December 2014 05:41:48 PM

Debian has updated php5 (code execution).

Gentoo has updated mit-krb5 (multiple vulnerabilities).

Mageia has updated castor (XML injection), couchdb (cross-site scripting), cxf (two vulnerabilities), plasma-nm (man-in-the-middle attack), sox (code execution), unzip (code execution), and xml-security (denial of service).

openSUSE has updated kernel (11.4: three vulnerabilities), php5 (11.4: three vulnerabilities), and python (11.4: multiple vulnerabilities).

Oracle has updated docker (OL7; OL6: multiple vulnerabilities).

The Darkmail Internet Mail Environment

Wednesday 31st of December 2014 03:37:23 PM
From Phillip Zimmermann and Ladar Levison (among others) comes the Darkmail Internet Mail Environment, an attempt to replace SMTP with a more secure protocol. It has a 108-page specification [PDF] for those wanting details, and code is available on GitHub. "In addition to the usual protection of content, a design goal for secure email must be to limit what meta-information is disclosed so that a handling agent only has access to the information it needs to see. The Dark Internet Mail Environment (DIME) achieves this with a core model having multiple layers of key management and multiple layers of message encryption."

Tuesday's security updates

Tuesday 30th of December 2014 05:09:11 PM

Debian has updated polarssl (denial of service) and pyyaml (denial of service).

Debian-LTS has updated ettercap (denial of service).

Security advisories for Monday

Monday 29th of December 2014 06:41:51 PM

Debian has updated mime-support (code execution) and unzip (code execution).

Debian-LTS has updated mime-support (code execution) and unzip (code execution).

Fedora has updated eclipse-egit (F21: code execution), eclipse-jgit (F21: code execution), gpgme (F20: code execution), links (F20: integer overflow), mediawiki (F21; F20; F19: multiple vulnerabilities), mingw-jasper (F21; F20; F19: two code execution vulnerabilities), php (F21; F20; F19: code execution), rpm (F20: code execution), and seamonkey (F21; F20; F19: multiple vulnerabilities).

Gentoo has updated asterisk (multiple vulnerabilities), facter (privilege escalation), file (denial of service), fish (multiple vulnerabilities), flac (code execution), getmail (multiple vulnerabilities), icecast (multiple vulnerabilities), lcms (denial of service), mupdf (denial of service), openssl (multiple vulnerabilities), openvpn (denial of service), policycoreutils (privilege escalation), torque (multiple vulnerabilities, some from 2011), wireshark (multiple vulnerabilities), and xen (multiple vulnerabilities).

Mageia has updated apache-poi (two XML-handling flaws), axis (SSL hostname verification bypass), erlang (command injection), mediawiki (multiple vulnerabilities), not-yet-commons-ssl (hostname verification botch), resteasy (XML eXternal Entity (XXE) attacks), smack (two vulnerabilities), wss4j (authentication spoofing), and xlockmore (X error).

openSUSE has updated apache2 (13.2, 13.1, 12.3: two vulnerabilities), docker (13.2: multiple vulnerabilities), file (13.2; 13.1: denial of service), libreoffice (13.2, 13.1: denial of service), mailx (13.2, 13.1, 12.3: command execution), python3-rpm, rpm, rpm-python (13.2, 13.1, 12.3: code execution), subversion (13.2, 13.1, 12.3: denial of service), and xorg-x11-server (13.2, 13.1, 12.3:multiple vulnerabilities).

More in Tux Machines

Leftovers: Software

  • Ekiga 5 – Progress Report
    Ekiga 5 has progressed a lot lately. OpenHUB is reportin a High Activity for the project. The main reason behind this is that I am again dedicating much of my spare time to the project. Unfortunately, we are again facing a lack of contributions. Most probably (among others) because the project has been silent during several years.
  • Calibre Gets a New Tool to Better Edit eBooks
    The Calibre eBook reader, editor, and library management software has been upgraded to version 2.17 and is now available for download. The developer has only implemented a couple of new features, but it's really worth the update if you are using this application to edit eBooks.
  • More Windows Apps and Games Now Work with Wine 1.7.35, EA's Origin Included
    Wine 1.7.35 has been released and the developers have made a number of improvements for some of the core components and they've added support for more apps and games.

today's howtos

Leftovers: Gaming

  • Dying Light Action Survival Game Coming to Steam January 27
    Dying Light, a modern first-person survival horror game set in a world hit by plague, is now available for pre-purchase on Steam and will be available for download on January 27.
  • Dying Light FPS Has Been Confirmed for Linux, Zombies Galore
    Techland is preparing to launch Dying Light, a new FPS with amazing graphics and hordes of zombies. The developer has revealed that it will also have a Linux version, right from the start.
  • Dying Light Is Now Confirmed For Linux, Bring It On Techland
    Dying Light is now confirmed for Linux thanks to the announcement from the developers on the Steam store itself. The Linux icons show up on the store pages, and the game even has a steam coming soon banner on the home-page. Time to get seriously excited.
  • Star Traders: 4X Empires Strategy Game Now On Linux
  • 5 reasons Valve's Steam Machine dream is still very alive
    Steam Machines? More like has-been machines, am I right? Actually, no: while many people are giving Valve's PC-console-hybrids the cold shoulder, this gamer reckons they'll be worth the wait. I realise that I'm part of a shrinking group still backing Valve's SteamOS-powered Linux boxes, and it's not difficult to see why the hype around them has all but evaporated. Several controller-related delays, U-turns by seemingly committed hardware partners and a lack of news from the top has made many think that Valve is blowing hot air.

Android Leftovers