CentOS Errata and Security Advisory 2014:1655 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1655.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
fc837a4e2b3b952bb6e0ec91eec3720b02fe7415a4baaddf0bcd5ff15bf6067e libxml2-2.9.1-5.el7_0.1.i686.rpm
157e1167f06c646e4a07e442523af74c8fc99252ffa1e2eadf58278be9ae89ea libxml2-2.9.1-5.el7_0.1.x86_64.rpm
b436dee56e93dd9997ee55b3c4f6fe136ac69c4c515cdb68fa9db6ee51abded9 libxml2-devel-2.9.1-5.el7_0.1.i686.rpm
78aead85ea11bb764824d4a48bdc74c32792424584fec634c6c669079fa43713 libxml2-devel-2.9.1-5.el7_0.1.x86_64.rpm
26f5e7225af4df0c5be969f3946b01db741a8ae130e10cc6684609bf656faa7e libxml2-python-2.9.1-5.el7_0.1.x86_64.rpm
6ba3f9e569d8e88f3f62c9f01de9a0c03df3dcb421f5115c99b6cbde49f4c810 libxml2-static-2.9.1-5.el7_0.1.i686.rpm
9c6d6f67c5fc34a28a60fabf6813ff9355b7f8453a82399e178e06bd85cd580b libxml2-static-2.9.1-5.el7_0.1.x86_64.rpm
Source:
d0c32e4869401f37357010f431e2c651bdc5189095999d7d1c5d3a57d3ad4a03 libxml2-2.9.1-5.el7_0.1.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1652
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
-----------------------------
i386
-----------------------------
5898ac3179dfdd904c352badd79b6f5ec702315f4bc7b8989de8f114304fbd78 openssl-1.0.1e-30.el6_5.2.i686.rpm
dcc5d47340d69f53af592a92282df89ef3bd4705ce34f4a57a93d211e93cfd7d openssl-devel-1.0.1e-30.el6_5.2.i686.rpm
dc42eb136b3cfef78d590d4ab29d36e5e5951bc9433d20d5ca633033d960a00d openssl-perl-1.0.1e-30.el6_5.2.i686.rpm
95e67f00f7d58348e5f0df6ac74d7baecb9d5fc214d58ad257a14bec353219a3 openssl-static-1.0.1e-30.el6_5.2.i686.rpm
-----------------------------
X86_64
-----------------------------
5898ac3179dfdd904c352badd79b6f5ec702315f4bc7b8989de8f114304fbd78 openssl-1.0.1e-30.el6_5.2.i686.rpm
17bfdb52afcb2ebaa16875819b9d8d2f3dc84eb061ee3e194da14e286bc76029 openssl-1.0.1e-30.el6_5.2.x86_64.rpm
dcc5d47340d69f53af592a92282df89ef3bd4705ce34f4a57a93d211e93cfd7d openssl-devel-1.0.1e-30.el6_5.2.i686.rpm
7c390aab888c07887fc783686f42216711665738e58c2b23029748292dd0f96d openssl-devel-1.0.1e-30.el6_5.2.x86_64.rpm
dfdcf88163743d5f4fda06a69cba00b822b73ba66aa5841faf8c0e9841b91bcb openssl-perl-1.0.1e-30.el6_5.2.x86_64.rpm
0f8cc0615d96d4d7e74b5ffc109143873510406dbb6be679d4ab94bd4f731cdb openssl-static-1.0.1e-30.el6_5.2.x86_64.rpm
-----------------------------
Source:
-----------------------------
1a1c3ed0d8eb5775d89b726e7f19ff2d8b52b7ef27f6e36260e83ffc40328460 openssl-1.0.1e-30.el6_5.2.src.rpm
=====================================================
The following upstream security issues are addressed in this update:
https://rhn.redhat.com/errata/RHSA-2014-1652.html
=====================================================
NOTE: This update is released into the CentOS-6.5 tree and has a .el6_5 dist
tag, *NOT* the .el6_6 dist tag that Red Hat used for RHEL in the link above.
This update was built against 'CentOS-6.5 + updates' and that is where it is
intended to be used.
The CentOS team will build and release a openssl-1.0.1e-30.el6_6.2.src.rpm as
a zero day update to CentOS-6.6 when that is released as we are currently
building CentOS-6.6 from the released Red Hat Enterprise Linux sources.
Please also note that even after installing this update, further action is
required to mitigate the POODLE issue on CentOS-6. Please see this link for
steps to take and ways to test for both the POODLE and TLS_FALLBACK_SCSV issues.
http://wiki.centos.org/Security/POODLE
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos at irc.freenode.net
CentOS Errata and Security Advisory 2014:1652 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1652.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
982ba4376041d2d99d4b84dc05fbeac6b925777aa34d631aceeedb598bb98413 openssl-1.0.1e-34.el7_0.6.x86_64.rpm
426ba8dc7ac74f8b71f7965ec2e6e6b398ab466dc892394e8d1d5bd80ca4a4e6 openssl-devel-1.0.1e-34.el7_0.6.i686.rpm
7fdf24148ed86f0abb2618d92741d5c8f0769de6136b4ed9df2a60b8c795abe3 openssl-devel-1.0.1e-34.el7_0.6.x86_64.rpm
ebc0fc79108a67efd64da36669c90865b4a75a38b4c07a5316078edd98b65da9 openssl-libs-1.0.1e-34.el7_0.6.i686.rpm
5d0607c487922602ae315f62d9d3c0eb8ca76a65c288e6c8fc61f688dad59593 openssl-libs-1.0.1e-34.el7_0.6.x86_64.rpm
4b092081206a1140a5d2901c2f5513c8155ec2b57a05cafdd6c9011ccdde78f5 openssl-perl-1.0.1e-34.el7_0.6.x86_64.rpm
d664f61543bb84773467300c726d870700584f5af616df7a9f29922822773dd8 openssl-static-1.0.1e-34.el7_0.6.i686.rpm
c57075f8c198ec81db1936eb2dea8ff210de317f76047ffa601eefd8230d3bae openssl-static-1.0.1e-34.el7_0.6.x86_64.rpm
Source:
6638e94c18b6961748e7986823b7115d852b25883ccff03ec89a16234cbca517 openssl-1.0.1e-34.el7_0.6.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Enhancement Advisory 2014:1649
Upstream details at : https://rhn.redhat.com/errata/RHEA-2014-1649.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
51d8cfeb1a49efd3d778fcbf00537076b2d68f6ebcd0098fa174cd885c29dc6a kpatch-0.1.10-3.el7_0.noarch.rpm
Source:
4d7cb8146fc0433167cd8e18f439d3b3cf7748649ce21b509b501fd46cc45c58 kpatch-0.1.10-3.el7_0.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1653 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1653.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
0c3787137a7d1a0402612833b173693910eb27f79e0c4f8cedf6185b4f7141f9 openssl-0.9.8e-31.el5_11.i386.rpm
5ef64e16dd1349a254a96e91cfdfdd6215fb9daa846360d2efff515bbb6a56b8 openssl-devel-0.9.8e-31.el5_11.i386.rpm
b98e5df6d59eddee85d544ca35bf0b7ca469a4c7032138465189c4c7bc27e5e6 openssl-perl-0.9.8e-31.el5_11.i386.rpm
x86_64:
85ee93123052e86fd4204694e3ac52fad6797b3f7009d8bce8e1f908bfed5352 openssl-0.9.8e-31.el5_11.x86_64.rpm
5ef64e16dd1349a254a96e91cfdfdd6215fb9daa846360d2efff515bbb6a56b8 openssl-devel-0.9.8e-31.el5_11.i386.rpm
11362d4d6755f5e33609a8adf6fbd0002f1343e72cd5e06ddbf2c8e99cf0d514 openssl-devel-0.9.8e-31.el5_11.x86_64.rpm
4aa6b35c036489a83a193ceb26fea4d1b5da93e7fddc08245fe59ffde0d7f509 openssl-perl-0.9.8e-31.el5_11.x86_64.rpm
Source:
1741388be54beb7176f7b5d90a3ddd1be99e1fcd5296725f4999c446a30c35c5 openssl-0.9.8e-31.el5_11.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1647 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1647.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
bc59af1c3aa2950614736db2e2e1e1596eb77228a98ac4a83fec2735e6a58257 thunderbird-31.2.0-2.el5.centos.i386.rpm
x86_64:
b3065ffa9bbe359d2b810a2c7ac3eb702966e4c37cb638b69229019965584992 thunderbird-31.2.0-2.el5.centos.x86_64.rpm
Source:
0c0305b9aedc7ced272157b8582dfa756f4db974dc4d5bdb394b02a0fe489cb0 thunderbird-31.2.0-2.el5.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1620 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1620.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
002dee0a0bdf11e376d99fb4ad2971f31dfe1204b1154419344244fce83238d8 java-1.7.0-openjdk-1.7.0.71-2.5.3.1.el7_0.x86_64.rpm
19420477ed938598934e8bb3edb856e12b52a1078987ea3ae5851257e548ec0e java-1.7.0-openjdk-accessibility-1.7.0.71-2.5.3.1.el7_0.x86_64.rpm
ec749fb28d1434a785046cb4ac367523ed1be0472384b2e1b8b90125188dac7a java-1.7.0-openjdk-demo-1.7.0.71-2.5.3.1.el7_0.x86_64.rpm
528cf0637d50f83eb14f14852e350dac8bc13981817d630e8ffc0c27f27f6f28 java-1.7.0-openjdk-devel-1.7.0.71-2.5.3.1.el7_0.x86_64.rpm
fd1b2a97c9b87dc283db7503bfbb2ed3f312133f864f1af4a86f1c5928c4b83e java-1.7.0-openjdk-headless-1.7.0.71-2.5.3.1.el7_0.x86_64.rpm
8de25453d7898c7ce00cefb1fc4b4ade295507b1c157848c4d826a66968fbaf2 java-1.7.0-openjdk-javadoc-1.7.0.71-2.5.3.1.el7_0.noarch.rpm
b9d91f7b9e069cf942bf96d8e30e538a9ac03a8537d9182868d778e3a05aed1c java-1.7.0-openjdk-src-1.7.0.71-2.5.3.1.el7_0.x86_64.rpm
Source:
a2e80b7c19c2ccad896649a93ea1d97a3a722a245c34973acc0941deb1e16a83 java-1.7.0-openjdk-1.7.0.71-2.5.3.1.el7_0.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1634 Important
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1634.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
235d58e6756e5bd6c033aa98373311e4706a7bc2ce5e717e08fd09b5f1bc2e4f java-1.6.0-openjdk-1.6.0.33-1.13.5.0.el7_0.x86_64.rpm
f747489a1afff1f19a0abc503ce4bd271dba6d7a501b0a9af068a34296d6ce42 java-1.6.0-openjdk-demo-1.6.0.33-1.13.5.0.el7_0.x86_64.rpm
290565d69afedfa4f198bb61702f3b09b8b1e4c976c07c060266eaf316992d79 java-1.6.0-openjdk-devel-1.6.0.33-1.13.5.0.el7_0.x86_64.rpm
2567dd401a1752ad2ec3740d87abff5a98e20ddf8c3a55eacc32b6ba08c47c12 java-1.6.0-openjdk-javadoc-1.6.0.33-1.13.5.0.el7_0.x86_64.rpm
ca6278bb38d570c2cedeab68beced1a75b0818a59787e9110fd84da407d9f464 java-1.6.0-openjdk-src-1.6.0.33-1.13.5.0.el7_0.x86_64.rpm
Source:
4fea1ba7337b0ba553c05103d411b1062082412e012acff2fddbb4c91d360ec9 java-1.6.0-openjdk-1.6.0.33-1.13.5.0.el7_0.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1635 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1635.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
x86_64:
b5bf77e58f0df4d4838bf72de18af77fc1299c64b944717b9be8023af642b2c7 firefox-31.2.0-3.el7.centos.i686.rpm
f067bcd3d034b5878519cdc52befe29d493a8bbe19d64cc3ebf774f179a0b6e6 firefox-31.2.0-3.el7.centos.x86_64.rpm
5c28de4b7be9d9762646c2b99d80d2a4d42dd5b2787169cf48e919d93920d629 xulrunner-31.2.0-1.el7.centos.i686.rpm
f7333789ff7a8c662e0f8e9a1f54c6ed508ee9fdd2fa98762492b076af18dd50 xulrunner-31.2.0-1.el7.centos.x86_64.rpm
db657d67fc48d4a27bf50596a26cd35df82b06ec2d1f10004c94964c00ce3002 xulrunner-devel-31.2.0-1.el7.centos.i686.rpm
9045ff98c6fff3dab5a7fa9a73a3bcd05608a3723f83070e72e78fe6124c2202 xulrunner-devel-31.2.0-1.el7.centos.x86_64.rpm
Source:
cd172114374d6f81aae6c1dd22d1bb00cbd2a2244b0a7e726a09ed20459de604 firefox-31.2.0-3.el7.centos.src.rpm
c24e3e31ba4b610cb3e291e28905b4f11f59bc10f2e55ad0a9dd9324d013b43f xulrunner-31.2.0-1.el7.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2014:1642
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1642.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
1cbecc8922d43a0adcccd726e5803e76175f2fcca868baa94977f23a0882d983 rsync-3.0.6-6.el5_11.i386.rpm
x86_64:
aa673131601130f8ac144a0047914df78daf1296a424fd7ba9b0dbe61a4276df rsync-3.0.6-6.el5_11.x86_64.rpm
Source:
12ce50da9141459819c943b7ac95dff36fb8cc9f42b50842ece6bbe0cb574b73 rsync-3.0.6-6.el5_11.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Security Advisory 2014:1635 Critical
Upstream details at : https://rhn.redhat.com/errata/RHSA-2014-1635.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
9df05ee668d515f3ece37ee2e4cf518ffef8d1c52de35a0c59743ef9cf574cd7 firefox-31.2.0-3.el5.centos.i386.rpm
x86_64:
9df05ee668d515f3ece37ee2e4cf518ffef8d1c52de35a0c59743ef9cf574cd7 firefox-31.2.0-3.el5.centos.i386.rpm
fbd203f1998e1dee8e25010a1d4fa29b4b5321d20db4125b985b03a8592346ff firefox-31.2.0-3.el5.centos.x86_64.rpm
Source:
f5201abc4f86e806a1fcb6f85333b750203339111f506ffb2641beb02c3693f4 firefox-31.2.0-3.el5.centos.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
As most of you already know, there is an important SSLv3 vulnerability
(CVE-2014-3566 - see https://access.redhat.com/articles/1232123) ,
known as Poodle.
While it's easy to disable SSLv3 in the allowed Protocols at the
server level (for example SSLProtocol All -SSLv2 -SSLv3 for apache),
some clients are still defaulting to SSLv3, and Koji does that.
We currently have disabled SSLv3 on our cbs.centos.org koji instance,
so if you're a cbs/koji user, please adapt your local koji package
(local fix !)
At the moment, there is no available upstream package, but the
following patch has been tested by Fedora people too (and credits go
to
https://lists.fedoraproject.org/pipermail/infrastructure/2014-October/01497…)
=====================================================
- --- SSLCommon.py.orig 2014-10-15 11:42:54.747082029 +0200
+++ SSLCommon.py 2014-10-15 11:44:08.215257590 +0200
@@ -37,7 +37,8 @@
if f and not os.access(f, os.R_OK):
raise StandardError, "%s does not exist or is not
readable" % f
- - ctx = SSL.Context(SSL.SSLv3_METHOD) # SSLv3 only
+ #ctx = SSL.Context(SSL.SSLv3_METHOD) # SSLv3 only
+ ctx = SSL.Context(SSL.TLSv1_METHOD) # TLSv1 only
ctx.use_certificate_file(key_and_cert)
ctx.use_privatekey_file(key_and_cert)
ctx.load_client_ca(ca_cert)
@@ -45,7 +46,8 @@
verify = SSL.VERIFY_PEER | SSL.VERIFY_FAIL_IF_NO_PEER_CERT
ctx.set_verify(verify, our_verify)
ctx.set_verify_depth(10)
- - ctx.set_options(SSL.OP_NO_SSLv2 | SSL.OP_NO_TLSv1)
+ #ctx.set_options(SSL.OP_NO_SSLv2 | SSL.OP_NO_TLSv1)
+ ctx.set_options(SSL.OP_NO_SSLv2 | SSL.OP_NO_TLSv1 | SSL.OP_NO_SSLv3)
return ctx
=====================================================
We'll keep you informed about possible upstream koji packages that
would default to at least TLSv1
If you encounter a problem, feel free to drop into #centos-devel
channel on irc.freenode.net and have a chat with us
on behalf of the Infra team,
- --
Fabian Arrotin
The CentOS Project | http://www.centos.org
gpg key: 56BEC54E | twitter: @arrfab
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iEYEARECAAYFAlQ+TUUACgkQnVkHo1a+xU4JyQCfefp2h7yRdmljBqRc+M76jPTf
z7wAn3dOkaNPNfEnV0pxWDFX7BDDqKuY
=lxsg
-----END PGP SIGNATURE-----
CentOS Errata and Enhancement Advisory 2014:1393
Upstream details at : https://rhn.redhat.com/errata/RHEA-2014-1393.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
d0d7eaa262746e1760fd3d533b9fa82684ef87bb344b38422946f6b1b81c69c1 kmod-be2iscsi-10.2.273.0r-1.el6_5.i686.rpm
x86_64:
c066e98a14fc3db9b8237d19d3ffef9a62bcb8e063d6f996b166040f2a047bd2 kmod-be2iscsi-10.2.273.0r-1.el6_5.x86_64.rpm
Source:
6d708190df4651c157dd173748290b83bb624071c37e0602540e04a72696d085 be2iscsi-10.2.273.0r-1.el6_5.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
CentOS Errata and Bugfix Advisory 2014:1395
Upstream details at : https://rhn.redhat.com/errata/RHBA-2014-1395.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
1387ed663fe471b6b1b4c7ace450886b76d8513ca399fa407f91125cf5b6c765 ksh-20120801-10.el6_5.12.i686.rpm
x86_64:
1376e7817bab4dd5b14a4bd2ec56e973d05fbc6367350ceb110a5e39163a7be9 ksh-20120801-10.el6_5.12.x86_64.rpm
Source:
7c1fe6ed97a97af63f4810947c747fd9ec6017ba9dcd7104b6d0c9fe007833fc ksh-20120801-10.el6_5.12.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos(a)irc.freenode.net
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
We have to do some hardware/software maintenance on the machine
actually hosting the Wiki service (http://wiki.centos.org). Instead of
just taking the wiki instance down during that maintenance, we've
decided to relocate it to a temporary host, proceed to maintenance,
and then migrate it back to the previous node.
Migration is scheduled for Friday October 10th, 11:00 am UTC time.
You can convert to local time with $(date -d '2014-10-10 11:00 UTC')
Migration will happen in several steps:
1 - we "freeze" the wiki on the actual node, transfer data, update the
A record, restore the service on the temporary node (disruption ~ 30min)
2 - we proceed to the needed maintenance on first node (no disruption
in service, but no estimated time)
3 - depending on time needed for step [2], and assuming we have no
hardware issue, we proceed like step [1], but in reverse (so
disruption ~30 minutes again)
Thanks for your comprehending and patience.
on behalf of the Infra team,
- --
Fabian Arrotin
The CentOS Project | http://www.centos.org
gpg key: 56BEC54E | twitter: @arrfab
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
iEYEARECAAYFAlQ2g0kACgkQnVkHo1a+xU4flACfc1IjPeHelBntwt4eNTd6SBvM
wXAAnAqtOg4Ko4nqd0QVUfX7ZcQevD5K
=v15z
-----END PGP SIGNATURE-----