The Wayback Machine - https://web.archive.org/all/20061205230606/http://news.berlios.de:80/

BerliOS News

December 05, 2006

NewsForge

Heise Newsticker

Prolinux

Studentenprojekte sollen KDE verbessern

Die Universität von Toulouse lässt eine Gruppe von Studenten im Rahmen ihres Studiums Verbesserungen am KPlato und Umbrello vornehmen.

December 05, 2006 07:15 PM

Gaia mit NASA-Daten

Das Projekt Gaia, mit dem ein freier Ersatz für Google Earth erstellt werden soll, hat eine neue Version veröffentlicht und setzt ab sofort auf NASA-Bilder.

December 05, 2006 07:15 PM

NewsForge

Heise Newsticker

Prolinux

Neue Grafiktreiber von nVidia

Der Grafikkartenhersteller nVidia hat überarbeitete Fassungen seiner proprietären Grafikkartentreiber für FreeBSD, Linux und Solaris veröffentlicht.

December 05, 2006 05:15 PM

Linux Community

Windows soll auf 100-Dollar-Laptop

Erfolg macht sexy - und an dem Erfolg des 100-Dollar-Laptop von Nicholas Negroponte will Microsoft wohl teilhaben. Im November wurde der Prototyp des 100-Dollar-Laptop vorgestellt, mehrere Millionen Interessenten sind gemeldet , Mitte nächsten Jahres soll ausgeliefert werden. Bill Gates hatte sich über das Projekt bislang eher lustig gemacht: "Himmel, nehmt lieber einen vernünftigen Computer!" .

December 05, 2006 05:11 PM

Heise Newsticker

NewsForge

silicon.de aktuell

Sparkassen Informatik schließt vier Standorte

Aus für Köln, Duisburg, Mainz und Karlsruhe

December 05, 2006 03:45 PM

BerliOS SourceWell

openMosix 2.4.26

openMosix is a a set of extensions to the standard Linux kernel allowing you to build a cluster of out of off-the-shelf PC hardware. openMosix scales perfectly up to thousands of nodes. You do not need to modify your applications to benefit from your cluster (unlike PVM, MPI, Linda, etc.). Processes in openMosix migrate transparently between nodes and the cluster will always auto-balance.

December 05, 2006 03:37 PM

silicon.de aktuell

Netapp verpasst unstrukturierten Daten ILM-Zwang

Kontrolle schwer kontrollierbarer Informationenen

December 05, 2006 03:35 PM

BerliOS SourceWell

Pixlie 1.6

Pixlie ist eine kostenlose und werbefreie Bildergalerie für Ihre Internetseite.

December 05, 2006 03:32 PM

silicon.de aktuell

Heise Newsticker

BerliOS SourceWell

OpenOffice 2.1 RC2

OpenOffice is the open source project through which Sun Microsystems is releasing the technology for the popular StarOffice(tm) productivity suite. The StarOffice office suite is free, full-featured, Microsoft Office interoperable, and open standards-based. If includes the following components: Desktop, Writer (word processor), Calc (spreadsheet), Impress (presentation), Draw (drawing and diagramming), Base (database engine and frontend), Mail and Discussion, Schedule, and Tools (web broswer, bitmap editor, etc).

December 05, 2006 03:05 PM

xine 1.1.3

xine is a free, gpl-licensed video player for unix-like systems. xine plays videos synchronizing the playback of image and audio.

December 05, 2006 02:58 PM

silicon.de aktuell

LinuxWeeklyNews

PostgreSQL 8.2 released

PostgreSQL 8.2 has been released. There's a fair amount of new stuff in this release, including significantly improved performance, SQL aggregates, advisory locks, and more. Click below for details and download information.

by corbet at December 05, 2006 02:18 PM

Heise Newsticker

silicon.de aktuell

CA aktualisiert Unicenter ASM

Release 11.1 erweitert das Plattform-Management

December 05, 2006 01:59 PM

Cisco macht tunnelloses VPN

Neue Wide Area Network Funktionen auch an Bord

December 05, 2006 01:38 PM

Kampagne soll Internetkompetenz der Eltern fördern

"Kinder mit der virtuellen Welt nicht alleine lassen"

December 05, 2006 01:18 PM

Heise Newsticker

LinuxWeeklyNews

Child's play: Sneaking a peek at the OLPC OS (Linux.com)

Linux.com takes a look at the OLPC laptops. "The first One Laptop Per Child hardware devices are still months from deployment, but you can sneak a peek at their Sugar desktop environment and bundled applications by running an OS image under an emulator. It's a great way to finally get some hands-on time with this long-anticipated project, even though it's not perfect."

by ris at December 05, 2006 12:54 PM

The Ruby Way (Linux Journal)

Nicholas Petreley reviews The Ruby Way on Linux Journal. "I've wanted to tackle Ruby for quite some time. Luckily, Addison-Wesley just sent me a copy of The Ruby Way, Second Edition by Hal Fulton. This is one of those books that makes me think publishers feel the need to sell books by the pound. The sad part about that is that, in many cases, books printed by the pound contain tons of fluff and useless information. Not so with The Ruby Way. Every page contains gems valuable for anyone who wants to program with Ruby."

by ris at December 05, 2006 12:48 PM

Tuesday's security updates

Ubuntu has updated xine-lib (buffer overflow), libgsf (heap buffer overflow).

by ris at December 05, 2006 12:47 PM

silicon.de aktuell

Baidu.com sucht bald auch außerhalb Chinas

Japan als erster Schritt der Expansionspläne

December 05, 2006 12:39 PM

Heise Newsticker

LinuxWeeklyNews

The Linux way to Flickr (Linux.com)

Linux.com looks at the Flickr Web portal. "The Flickr Web portal allows people to publish and share online, grouped and tagged by subject, whole galleries of digital pictures. You can use Flickr with several GNU/Linux-based applications. Developers can also use the API published on the Web site to obtain an API_KEY and build new interfaces to download, upload, or process pictures in Flickr. What might be less known is that Flickr already is another place where GNU/Linux users can meet, as well as a potentially very useful advocacy tool."

by ris at December 05, 2006 12:15 PM

Prolinux

Reiser4 doch nicht im Kernel 2.6.20?

Wie Andrew Morton in einer Email an die Linux Kernel Mailingsliste (LKML) bekannt gab, planen die Entwickler entgegen früheren Aussagen die aktuelle Version von Reiser4 noch nicht in den Kernel aufzunehmen.

December 05, 2006 12:15 PM

Zweiter Release-Kandidat von OpenOffice.org 2.1

Auf dem Weg zur neuen Version 2.1 von OpenOffice.org ist der zweite Release-Kandidat verfügbar.

December 05, 2006 12:15 PM

Heise Newsticker

Linux Enterprise

Terracotta macht Cluster-VM-Technologie Open Source

Terracotta meldet, dass es seine Cluster-VM-Technologie Terracotta DSO Open Source unter der Terracotta Public License, die auf der …

by () at December 05, 2006 11:00 AM

silicon.de aktuell

LSI Logic übernimmt Agere Systems

Speicherchips für Mobility, Networking, Telekom...

December 05, 2006 10:33 AM

Heise Newsticker

silicon.de aktuell

Vista kann sich gegen jeden dritten Schädling nicht wehren

Gegen Social Engineering ist offenbar kein Kraut gewachsen

December 05, 2006 10:12 AM

Heise Newsticker

NewsForge

Heise Newsticker

Prolinux

OSDL stehen vor Umstrukturierung

Die Open Source Development Labs werden ihren Geschäftsführer wechseln und zugleich weitere neun Angestellte entlassen.

December 05, 2006 08:15 AM

Linux Enterprise

Iona veröffentlicht Open-Source ESB

Iona veröffentlicht mit Celtix Enterprixe einen Open-Source ESB (Source Enterprise Service Bus). Celtix bietet ein leichtgewichtiges …

by () at December 05, 2006 07:00 AM

PHP-Bildergalerie Pixlie in Version 1.6 erhältlich

Die PHP-Bildergalerie Pixlie, die nun in Version 1.6 erhältlich ist, ermöglicht das Hochladen von zahlreichen Bildern per FTP. Pixlie …

by (Magdalena Rendulic) at December 05, 2006 07:00 AM

FreeBSD News

BerliOS SourceWell

GNU Parted 1.8.1

GNU Parted is a program for creating, destroying, resizing, checking and copying partitions, and the file systems on them. This is useful for creating space for new operating systems, reorganising disk usage, copying data between hard disks and disk imaging.

December 05, 2006 03:43 AM

CakePHP 1.1.11.4064

Cake is a rapid development framework for PHP which uses commonly known design patterns like ActiveRecord, Association Data Mapping, Front Controller and MVC. Our primary goal is to provide a structured framework that enables PHP users at all levels to rapidly develop robust web applications, without any loss to flexibility.

December 05, 2006 03:43 AM

GNU Smalltalk 2.2e

GNU Smalltalk is a free implementation of the Smalltalk-80 language

December 05, 2006 03:43 AM

Scribus 1.3.3.6

Scribus is a desktop publishing (DTP) program similar to QuarkXPress(TM), Adobe PageMaker(TM) or Adobe InDesign(TM). Unlike other programs, Scribus uses only Type1 fonts, ensuring that the displayed and printed works look the same.

December 05, 2006 03:43 AM

mirmon 1.37

Many software projects are mirrored worldwide. The mirror sites are required to update the mirror archive regularly (daily, weekly) from a root server. Mirmon helps administrators in keeping an eye on the mirror sites. In a concise graphic format, mirmon shows each site's status history of the last two weeks. It is easy to spot stale or dead mirrors.

December 05, 2006 03:43 AM

Heise Newsticker

O'Reilly Conferences

Tools of Change for Publishing Conference Call for Participation is Open

There's a brand new generation of technology engulfing the publishing industry, and we're launching an event designed to highlight the opportunities: TOC, the Tools of Change for Publishing Conference. TOC is happening in San Jose, California June 18-20, 2007, and we've just opened the call for participation.

If you're a publisher, editor, author, marketing or production manager, consultant, technology provider, or other interested commentator with bold ideas for the future of publishing and would like to share them with 500 other publishing innovators and decision-makers, we want to hear from you. The deadline to submit proposals to speak at TOC is January 22, 2007.

by Suzanne Axtell, PR Gal at December 05, 2006 01:43 AM

December 04, 2006

Heise Newsticker

Linux Enterprise

Novells OpenOffice mit Unterstützung für Open XML

Im Rahmen seines Interoperabilitäts-Programms mit Microsoft hat Novell jetzt angekündigt, das Office Open XML-Format, wie es zum Beispiel …

by () at December 04, 2006 11:00 PM

openMosix 2.6 mit neuem Projektleiter

Neuer Projektleiter für die Entwicklung der Linux-Kernelerweiterung openMosix 2.6 ist Florian Delizy. Die Erweiterung erlaubt es, ein …

by () at December 04, 2006 11:00 PM

NewsForge

Fedora News

Fedora QA Meeting - 1700 UTC Thursday, Dec. 7

From: Will Woods
To: fedora-test-list
Date: Mon, 04 Dec 2006 16:24:17 -0500
Subject: Fedora QA Meeting - 1700 UTC Thursday, Dec. 7
It's time for another fun Fedora QA (aka Fedora Testing) meeting!

(Yes, I'm calling it "Fedora QA" now. I want it to be obvious to the
world that Fedora really does have an official QA group.)

It'll be this Thursday, Dec. 7, at 1700UTC in the usual place

December 04, 2006 09:40 PM

NewsForge

BerliOS SourceWell

Stable Linux 2.6 Kernel 2.6.18.5

Stable Linux 2.6 Kernel. Linux is a clone of the operating system Unix, written from scratch by Linus Torvalds with assistance from a loosely-knit team of hackers across the Net. It aims towards POSIX and Single UNIX Specification compliance. It has all the features you would expect in a modern fully-fledged Unix, including true multitasking, virtual memory, shared libraries, demand loading, shared copy-on- write executables, proper memory management, and TCP/IP networking.

December 04, 2006 08:10 PM

Linux Community

KDE-Konferenz: Videos online

Die Vortrags-Videos der KDE-Konferenz Akademy 2006 , stehen nun zum Download bereit . Das dazugehörige Programm mit Zusammenfassung gibt es auf der Konferenzseite . Zu den Vorträgen, die sich vor allem an Entwickler und technisch Interessierte richten, zählen Referate zum neuen Build-System C-Make , dem KDE-PIM-Backend Akonadi oder der Qualitätssicherungsseite English Breakfast Network .

December 04, 2006 07:40 PM

BerliOS SourceWell

FlightGear 0.9.10

The FlightGear flight simulator project is an open-source, multi-platform, cooperative flight simulator development project. Source code for the entire project is available and licensed under the GNU General Public License.

The goal of the FlightGear project is to create a sophisticated flight simulator framework for use in research or academic environments, for the development and pursuit of other interesting flight simulation ideas, and as an end-user application. We are developing a sophisticated, open simulation framework that can be expanded and improved upon by anyone interested in contributing.

December 04, 2006 07:39 PM

Heise Newsticker

Prolinux

OpenOffice.org soll OpenXML unterstützen

Wie Novell bekannt gab, arbeitet das Unternehmen an freien OpenXML-Filtern für die Bürosuite OpenOffice.org.

December 04, 2006 07:15 PM

Heise Newsticker

Prolinux

Asterisk-Buch im Betatest

Da das neue Buch »Asterisk« von Stefan Wintermeyer unter der GNU FDL veröffentlicht werden soll, stellt der Autor ab sofort Betaversionen des Textes bereit.

December 04, 2006 06:15 PM

Heise Newsticker

LinuxWeeklyNews

Ulteo Newsletter #1

The first Ulteo Newsletter takes a look at what's been happening behind the scenes of the Ulteo Project. The first alpha release of Ulteo should be available soon. "For this first alpha release, be prepared to dive a bit inside the system to understand the potential of Ulteo. On the desktop you will find only a few differences with what you can use or see when compared to a graphical environment on other distro's. Maybe then you will understand what makes Ulteo different, and you will start to think about the next steps of development." (For those just tuning in, Ulteo is what Gaël Duval has been working on since leaving Mandriva).

by ris at December 04, 2006 05:09 PM

BerliOS SourceWell

BOSS (BSI OSS Security Suite) 2.0

Die Open Source Software BOSS (BSI OSS Security Suite) baut im wesentlichen auf dem bewährten Sicherheits-Scanner Nessus auf. Hinzugekommen ist neben der BOSS-Oberfläche der Security Local Auditing Daemon (SLAD), der die Steuerung der angebundenen lokalen Sicherheitssoftware übernimmt.

December 04, 2006 04:28 PM

silicon.de aktuell

HP-UX Version 3 soll Unix neu vitalisieren

Hewlett-Packard mit neuer Server-Grundlage

December 04, 2006 04:26 PM

LinuxWeeklyNews

Bastille: rated security with education (Linux.com)

Linux.com takes a look at Bastille. "Bastille is a program for improving system security on Debian, Fedora, Gentoo, Mandriva, Red Hat Enterprise Linux, and SUSE. Unlike packet sniffers, anti-virus programs, and the majority of security programs available today, Bastille does not wait to react to possible security breaches, but prevents them by removing system vulnerabilities. With many distributions softening security in their default installations in the name of convenience, this approach is enough by itself to make Bastille an essential program."

by ris at December 04, 2006 04:21 PM

Heise Newsticker

NewsForge

silicon.de aktuell

Wenige teilen sich deutschen Mail-Markt

Tausende Kleinanbieter, das Geschäft machen aber wenige Große

December 04, 2006 03:52 PM

ITU warnt vor Passwort-Dschungel

IT-Sicherheit ist keine nationale oder private Frage, so die UNO

December 04, 2006 03:28 PM

BerliOS SourceWell

ParallelKnoppix 2.0

ParallelKnoppix is a fast and easy way to create a HPC cluster for parallel computing. It takes less than 10 minutes to go from a cold start to having a running cluster. Using virtualization tools, you can create a real PK cluster from any distribution of Linux, or from other popular operating systems. You don't even need to burn a CD.

December 04, 2006 03:22 PM

silicon.de aktuell

IBM stellt neue Carrier-Blades vor

10 Mal mehr Bandbreite für die Telekommunikation

December 04, 2006 03:10 PM

Heise Newsticker

silicon.de aktuell

Siemens blickt in die Mobilfunk-Zukunft

Long Term Evolution und Konvergenz aus UMTS und GSM

December 04, 2006 02:40 PM

LinuxWeeklyNews

Lightweight Linux for High-Performance Computing (LinuxWorld.com)

LinuxWorld.com takes a look at lightweight Linux for HPC. "Linux has long provided an outstanding operating system for a wide range of users in a variety of settings. However, high-performance computing users, who must run applications on thousands of nodes, historically have faced challenges that Linux could not effectively address."

by ris at December 04, 2006 02:24 PM

silicon.de aktuell

SCO sackt ab

Schicksalsschläge vor Gericht und an der Börse

December 04, 2006 02:09 PM

Heise Newsticker

BerliOS DocsWell

Debian Security DSA-1227-1 mozilla-thunderbird -- several vulnerabilities (English)

Date Reported: 04 Dec 2006
Affected Packages: mozilla-thunderbird
Vulnerable: Yes

Security database references:

More information:

Several security related problems have been discovered in Mozilla and derived products such as Mozilla Thunderbird. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

  • CVE-2006-4310

    Tomas Kempinsky discovered that malformed FTP server responses could lead to denial of service.

  • CVE-2006-5462

    Ulrich Kühn discovered that the correction for a cryptographic flaw in the handling of PKCS-1 certificates was incomplete, which allows the forgery of certificates.

  • CVE-2006-5463

    "shutdown" discovered that modification of JavaScript objects during execution could lead to the execution of arbitrary JavaScript bytecode.

  • CVE-2006-5464

    Jesse Ruderman and Martijn Wargers discovered several crashes in the layout engine, which might also allow execution of arbitrary code.

  • CVE-2006-5748

    Igor Bukanov and Jesse Ruderman discovered several crashes in the JavaScript engine, which might allow execution of arbitrary code.

This update also adresses several crashes, which could be triggered by malicious websites and fixes a regression introduced in the previous Mozilla update.

For the stable distribution (sarge) these problems have been fixed in version 1.0.4-2sarge13.

For the unstable distribution (sid) these problems have been fixed in the current icedove package 1.5.0.8.

We recommend that you upgrade your mozilla-thunderbird package.

December 04, 2006 02:02 PM

silicon.de aktuell

IPTV ist nichts für kopflose Investitionen

Chancen und Risiken der Ausgaben für neue Glasfaserstruktur

December 04, 2006 01:55 PM

Briten geben bei Online-Werbung den Takt vor

USA kleben am Fernseher und verlieren den Anschluss

December 04, 2006 01:47 PM

LinuxWeeklyNews

Linux lab cuts staff, focuses on legal issues (ZDNet)

ZDNet reports on layoffs at Open Source Development Labs. "CEO Stuart Cohen resigned to pursue opportunities with higher-level open-source software, and nine employees in technical and administrative roles lost their jobs, said Mike Temple, OSDL's chief operating officer and its new leader. That leaves a staff of 19, including Tom Hanrahan in charge of engineering, Diane Peters in charge of legal work, and top Linux programmers Linus Torvalds and Andrew Morton."

by ris at December 04, 2006 01:23 PM

BerliOS DocsWell

Debian Security DSA-1225-1 mozilla-firefox -- several vulnerabilities (English)

Date Reported: 03 Dec 2006
Affected Packages: mozilla-firefox
Vulnerable: Yes

Security database references:

More information:

Several security related problems have been discovered in Mozilla and derived products such as Mozilla Firefox. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

  • CVE-2006-4310

    Tomas Kempinsky discovered that malformed FTP server responses could lead to denial of service.

  • CVE-2006-5462

    Ulrich Kühn discovered that the correction for a cryptographic flaw in the handling of PKCS-1 certificates was incomplete, which allows the forgery of certificates.

  • CVE-2006-5463

    "shutdown" discovered that modification of JavaScript objects during execution could lead to the execution of arbitrary JavaScript bytecode.

  • CVE-2006-5464

    Jesse Ruderman and Martijn Wargers discovered several crashes in the layout engine, which might also allow execution of arbitrary code.

  • CVE-2006-5748

    Igor Bukanov and Jesse Ruderman discovered several crashes in the JavaScript engine, which might allow execution of arbitrary code.

This update also adresses several crashes, which could be triggered by malicious websites and fixes a regression introduced in the previous Mozilla update.

For the stable distribution (sarge) these problems have been fixed in version 1.0.4-2sarge13.

For the unstable distribution (sid) these problems have been fixed in the current iceweasel package 2.0+dfsg-1.

We recommend that you upgrade your mozilla firefox package.

December 04, 2006 01:22 PM

Heise Newsticker

Prolinux

BOSS 2.0 freigegeben

Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hat eine neue Version der Prüfsoftware für Netzwerksicherheit BOSS (BSI OSS Security Suite) vorgestellt.

December 04, 2006 01:15 PM

openSUSE 10.2 kommt noch diese Woche

Wie Andreas Jaeger auf der Mailingliste des Projektes bekannt gab, wird die kommende Version der openSUSE-Distribution Ende der Woche freigegeben werden.

December 04, 2006 01:15 PM

BerliOS DocsWell

Debian Security DSA-1224-1 mozilla -- several vulnerabilities (English)

Date Reported: 03 Dec 2006
Affected Packages: mozilla
Vulnerable: Yes

Security database references:

More information:

Several security related problems have been discovered in Mozilla and derived products. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities:

  • CVE-2006-4310

    Tomas Kempinsky discovered that malformed FTP server responses could lead to denial of service.

  • CVE-2006-5462

    Ulrich Kühn discovered that the correction for a cryptographic flaw in the handling of PKCS-1 certificates was incomplete, which allows the forgery of certificates.

  • CVE-2006-5463

    "shutdown" discovered that modification of JavaScript objects during execution could lead to the execution of arbitrary JavaScript bytecode.

  • CVE-2006-5464

    Jesse Ruderman and Martijn Wargers discovered several crashes in the layout engine, which might also allow execution of arbitrary code.

  • CVE-2006-5748

    Igor Bukanov and Jesse Ruderman discovered several crashes in the JavaScript engine, which might allow execution of arbitrary code.

This update also adresses several crashes, which could be triggered by malicious websites and fixes a regression introduced in the previous Mozilla update.

For the stable distribution (sarge) these problems have been fixed in version 1.7.8-1sarge8.

We recommend that you upgrade your mozilla package.

December 04, 2006 01:11 PM

Debian Security DSA-1223-1 tar -- input validation error (English)

Date Reported: 01 Dec 2006
Affected Packages: tar
Vulnerable: Yes

Security database references:

More information:

Teemu Salmela discovered a vulnerability in GNU tar that could allow a malicious user to overwrite arbitrary files by inducing the victim to attempt to extract a specially crafted tar file containing a GNUTYPE_NAMES record with a symbolic link.

For the stable distribution (sarge), this problem has been fixed in version 1.14-2.3

For the unstable distribution (sid) and the forthcoming stable release (etch), this problem will be fixed in version 1.16-2.

We recommend that you upgrade your tar package.

December 04, 2006 01:07 PM

Debian Security DSA-1222-2 proftpd -- several vulnerabilities (English)

Date Reported: 30 Nov 2006
Affected Packages: proftpd
Vulnerable: Yes

Security database references:

More information:

Due to technical problems yesterday's proftpd update lacked a build for the amd64 architecture, which is now available. For reference please find below the original advisory text:

Several remote vulnerabilities have been discovered in the proftpd FTP daemon, which may lead to the execution of arbitrary code or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems:

  • CVE-2006-5815

    It was discovered that a buffer overflow in the sreplace() function may lead to denial of service and possibly the execution of arbitrary code.

  • CVE-2006-6170

    It was discovered that a buffer overflow in the mod_tls addon module may lead to the execution of arbitrary code.

  • CVE-2006-6171

    It was discovered that insufficient validation of FTP command buffer size limits may lead to denial of service. Due to unclear information this issue was already fixed in DSA-1218 as CVE-2006-5815.

For the stable distribution (sarge) these problems have been fixed in version 1.2.10-15sarge3.

For the unstable distribution (sid) these problems have been fixed in version 1.3.0-16 of the proftpd-dfsg package.

We recommend that you upgrade your proftpd package.

December 04, 2006 01:04 PM

Debian Security DSA-1221-1 libgsf -- buffer overflow (English)

Date Reported: 30 Nov 2006
Affected Packages: libgsf
Vulnerable: Yes

Security database references:

  • No other external database security references currently available.

More information:

"infamous41md" discovered a heap buffer overflow vulnerability in libgsf, a GNOME library for reading and writing structured file formats, which could lead to the execution of arbitrary code.

For the stable distribution (sarge) this problem has been fixed in version 1.11.1-1sarge1

For the unstable distribution (sid) this problem has been fixed in version 1.14.2-1

We recommend that you upgrade your libgsf packages.

December 04, 2006 01:02 PM

Debian Security DSA-1220-1 pstotext -- insecure file name quoting (English)

Date Reported: 26 Nov 2006
Affected Packages: pstotext
Vulnerable: Yes

Security database references:

More information:

Brian May discovered that pstotext, a utility to extract plain text from Postscript and PDF files, performs insufficient quoting of file names, which allows execution of arbitrary shell commands.

For the stable distribution (sarge) this problem has been fixed in version 1.9-1sarge2. The build for the mipsel architecture is not yet available due to technical problems with the build host.

For the upcoming stable distribution (etch) this problem has been fixed in version 1.9-4.

For the unstable distribution (sid) this problem has been fixed in version 1.9-4.

We recommend that you upgrade your pstotext package.

December 04, 2006 12:59 PM

Debian Security DSA-1219-1 texinfo -- buffer overflow (English)

Date Reported: 27 Nov 2006
Affected Packages: texinfo
Vulnerable: Yes

Security database references:

More information:

Multiple vulnerabilities have been found in the GNU texinfo package, a documentation system for on-line information and printed output.

  • CVE-2005-3011

    Handling of temporary files is performed in an insecure manner, allowing an attacker to overwrite any file writable by the victim.

  • CVE-2006-4810

    A buffer overflow in util/texindex.c could allow an attacker to execute arbitrary code with the victim's access rights by inducing the victim to run texindex or tex2dvi on a specially crafted texinfo file.

For the stable distribution (sarge), these problems have been fixed in version 4.7-2.2sarge2. Note that binary packages for the mipsel architecture are not currently available due to technical problems with the build host. These packages will be made available as soon as possible.

For unstable (sid) and the upcoming stable release (etch), these problems have been fixed in version 4.8.dfsg.1-4.

We recommend that you upgrade your texinfo package.

December 04, 2006 12:55 PM

LinuxWeeklyNews

Security updates for Monday

Mandriva has updated koffice (integer overflow), imagemagick (buffer overflows), gv (stack-based buffer overflow).

Slackware has updated tar (symlink vulnerability), proftpd (several vulnerabilities), libpng (denial of service).

Debian has updated mozilla (multiple vulnerabilities), mozilla-firefox (multiple vulnerabilities), mozilla-firefox (covers MIPS architecture), links (arbitrary file access), mozilla-thunderbird (multiple vulnerabilities).

rPath has updated doxygen (libpng denial of service vulnerability).

by ris at December 04, 2006 12:54 PM

University Students to Enhance KDE (KDE.News)

KDE.News has an interview with some students working on KDE. "A group of students at the Paul Sabatier University in Toulouse will be collaborating on the KDE projects KPlato and Umbrello as part of their Institut Universitaire Professionalisé en Ingénierie des Systèmes Informatiques (Professional Institute of Computer Software Engineering) course of study."

by ris at December 04, 2006 12:53 PM

silicon.de aktuell

BerliOS DocsWell

Fedora Weekly News Issue 69 (English)

Welcome to our issue number 69 of Fedora Weekly News.

http://fedoranews.org/wiki/Fedora_Weekly_News_Issue_69

1 Fedora Project is Hiring
2 Fedora Ambassadors Day
3 Eclipse on Linux Distributions Project
4 FUDCon Boston 2007
5 SCALE 5X Registration Opens
6 Migration to Fedora Core 6
7 Fedora Weekly Reports 2006-11-27
8 Fedora Core 5 and 6 Updates

December 04, 2006 12:37 PM

Heise Newsticker

Prolinux

Betaversion einer Fedora-Live-CD

Das Fedora-Projekt ist dabei, eine offizielle Live-CD von Fedora Core 6 zu produzieren.

December 04, 2006 12:15 PM

NewsForge

silicon.de aktuell

3D-Transistoren sparen Strom

Infineon testet erfolgreich 'Multigate-Technologie'

December 04, 2006 11:24 AM

Heise Newsticker

silicon.de aktuell

Vista-Upgrade in Indien erledigen lassen

Automatisch, kostensparend und ITIL-konform – verspricht HCL

December 04, 2006 11:03 AM

Linux für den Power-Prozessor

IBM zeigt sich mit dem Programm 'Chiphopper' zufrieden

December 04, 2006 10:51 AM

Start-up macht Software-basierten Funk alltagstauglich

Energiesparender Konverter sprengt militärische Grenzen

December 04, 2006 10:41 AM

Personalchef und Analysten bringen René Obermann unter Druck

"Permanentes Restrukturieren und Reorganisieren bringt zu viel Unruhe"

December 04, 2006 10:26 AM

Heise Newsticker

BerliOS Developer News

Nagelfar 1.1.6 released

Changes include better 8.5 support including new {*} syntax.

December 04, 2006 10:15 AM

NewsForge

LinuxWeeklyNews

Stable kernel 2.6.18.5

The 2.6.18.5 stable kernel release is out. This one contains a couple dozen fixes for various severe problems.

by corbet at December 04, 2006 09:48 AM

Heise Newsticker

LinuxWeeklyNews

Novell adds OpenXML to OpenOffice.org

Novell has sent out a press release proclaiming its intent to implement OpenXML support for OpenOffice.org. "Novell will release the code to integrate the Open XML format into its product as open source and submit it for inclusion in the OpenOffice.org project. As a result, end users will be able to more easily share files between Microsoft Office and OpenOffice.org, as documents will better maintain consistent formats, formulas and style templates across the two office productivity suites."

by corbet at December 04, 2006 08:55 AM

Fedora News

Fedora Weekly News Issue 69

Welcome to our issue number 69 of Fedora Weekly News.

http://fedoranews.org/wiki/Fedora_Weekly_News_Issue_69

In this issue, we have following articles:

1 Fedora Project is Hiring
2 Fedora Ambassadors Day
3 Eclipse on Linux Distributions Project
4 FUDCon Boston 2007
5 SCALE 5X Registration Opens
6 Migration to Fedora Core 6
7 Fedora Weekly Reports 2006-11-27
8 Fedora Core 5 and 6 Updates

December 04, 2006 08:36 AM

Heise Newsticker

Prolinux

NetBSD 4.0 für März 2007 geplant

Der Release-Prozess für NetBSD 4.0 wurde neu gestartet und soll zu einer Veröffentlichung im März 2007 führen.

December 04, 2006 08:15 AM

Gewinner des OpenOffice-Wettbewerbs

Das Projekt OpenOffice.org hat die Gewinner seines Vorlagen- und Clipart-Wettbewerbs bekannt gegeben.

December 04, 2006 08:15 AM

Linux Enterprise

MonoDevelop 1.0 für März 2007 geplant

Die Entwicklungsumgebung MonoDevelop für das Open-Source-Framework Mono soll im März 2007 in der Version 1.0 verfügbar sein. Die aktuelle …

by (Markus Zeischke) at December 04, 2006 07:00 AM

Release von Commons Validator 1.3.1

Das Jakarta Commons Validator-Team hat die Version 1.3.1 von Commons Validator veröffentlicht. Commons Validator ist ein open source …

by (Steffen Hertlein) at December 04, 2006 07:00 AM