All posts by jake

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/958676/

Security updates have been issued by CentOS (ImageMagick), Debian (chromium), Fedora (golang-x-crypto, golang-x-mod, golang-x-net, golang-x-text, gtkwave, redis, and zbar), Mageia (tinyxml), Oracle (.NET 7.0, .NET 8.0, java-1.8.0-openjdk, java-11-openjdk, python3, and sqlite), Red Hat (gstreamer-plugins-bad-free, java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, and java-21-openjdk), SUSE (kernel, libqt5-qtbase, libssh, pam, rear23a, and rear27a), and Ubuntu (pam and zookeeper).

[$] Growing pains for typing in Python

Post Syndicated from jake original https://lwn.net/Articles/958326/

Python’s static-typing feature has come a long way since it was introduced in 2014. Adding type
information to functions has always been—and will remain—optional, but typing
still remains somewhat contentious. There are multiple kinds of
consumers of the information, each with their own needs and
wishes, as well as users of the feature with expectations of their own. That has
led to the formation of a Python typing council
to govern the type system for the language, though, as might be guessed,
there are still grumblings from various quarters.

[$] Julia v1.10: Performance, a new parser, and more

Post Syndicated from jake original https://lwn.net/Articles/958337/

The new year arrived bearing a new version of Julia, a general-purpose, open-source
programming language
with a focus on high-performance
scientific computing
.
Some of Julia’s unusual features are Lisp-inspired
metaprogramming, the ability to examine compiled representations of code in
the REPL or in a “reactive
notebook
“, an advanced type and dispatch system, and a sophisticated,
built-in package manager.
Version 1.10 brings big increases in
speed and developer convenience,
especially improvements in code precompilation and loading times. It also
features a new parser written in Julia.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/958315/

Security updates have been issued by CentOS (bind, cups, curl, firefox, ipa, iperf3, java-1.8.0-openjdk, java-11-openjdk, kernel, libssh2, linux-firmware, open-vm-tools, openssh, postgresql, python, python3, squid, thunderbird, tigervnc, and xorg-x11-server), Fedora (chromium, python-flask-security-too, and tkimg), Gentoo (libgit2, Opera, QPDF, and zlib), Mageia (chromium-browser-stable, gnutls, openssh, packages, and vlc), Oracle (.NET 6.0, fence-agents, frr, ipa, kernel, nss, pixman, and tomcat), and SUSE (gstreamer-plugins-bad).

Linux Mint 21.3 “Virginia” released

Post Syndicated from jake original https://lwn.net/Articles/958162/

The Linux Mint distribution has announced the release of Linux Mint 21.3, which is codenamed “Virginia”. It has the Cinnamon 6.0 desktop, “comes with full support for SecureBoot and compatibility with a wider variety of BIOS and EFI implementation“, has added new features to the Hypnotix TV-viewer application, and more. See the release notes for even more information about it.

Linux Mint 21.3 “Virginia” released

Post Syndicated from jake original https://lwn.net/Articles/958162/

The Linux Mint distribution has announced the release of Linux Mint 21.3, which is codenamed “Virginia”. It has the Cinnamon 6.0 desktop, “comes with full support for SecureBoot and compatibility with a wider variety of BIOS and EFI implementation“, has added new features to the Hypnotix TV-viewer application, and more. See the release notes for even more information about it.

Security updates for Friday

Post Syndicated from jake original https://lwn.net/Articles/958124/

Security updates have been issued by Debian (kernel, linux-5.10, php-phpseclib, php-phpseclib3, and phpseclib), Fedora (openssh and tinyxml), Gentoo (FreeRDP and Prometheus SNMP Exporter), Mageia (packages), Red Hat (openssl), SUSE (gstreamer-plugins-rs and python-django-grappelli), and Ubuntu (dotnet6, dotnet7, dotnet8, openssh, and xerces-c).

Security updates for Thursday

Post Syndicated from jake original https://lwn.net/Articles/958029/

Security updates have been issued by Debian (chromium), Fedora (chromium, python-paramiko, tigervnc, and xorg-x11-server), Oracle (ipa, libxml2, python-urllib3, python3, and squid), Red Hat (.NET 6.0, .NET 7.0, .NET 8.0, container-tools:4.0, fence-agents, frr, gnutls, idm:DL1, ipa, kernel, kernel-rt, libarchive, libxml2, nss, openssl, pixman, python-urllib3, python3, tigervnc, tomcat, and virt:rhel and virt-devel:rhel modules), SUSE (gstreamer-plugins-bad), and Ubuntu (firefox, Go, linux-aws, linux-gcp-5.15, linux-intel-iotg-5.15, linux-iot, linux-oem-6.1, and twisted).

[$] Notes on Emacs Org mode

Post Syndicated from jake original https://lwn.net/Articles/957316/

As part of my quest to master Emacs, which
is sort of a sub-quest on the way toward learning more about Lisp, I have
spent a fair amount of time discovering various corners of the Emacs
world. One of those is the famous “Org
mode
” that is used for a wide variety of organizational tasks within
the editor—and not just Emacs, but for Vim and others too.
Org mode can be
used for to-do lists, notes with interconnections between them, literate
programming, web sites, and more. Now my quests are growing quests of
their own and digging into Org mode is one of those.

[$] The odd saga of CVE-2012-5639

Post Syndicated from jake original https://lwn.net/Articles/957219/

A new release
for any project with a fix for a 12-year old CVE is going to stand
out pretty
obviously; a recent release has a fix of that nature, but the trail of CVE-2012-5639 is
rather elusive. The Apache
OpenOffice
project made its 4.1.15
release
with fixes for four CVEs, including one for
CVE-2012-5639 (“Loading internal / external resources without
warning”)
, on December 22. But nearly everything about that CVE
seems rather murky, and it is difficult to get a clear picture of what,
exactly, was done in OpenOffice to address the problem.

Security updates for Monday

Post Syndicated from jake original https://lwn.net/Articles/957146/

Security updates have been issued by Debian (exim4), Fedora (chromium, perl-Spreadsheet-ParseExcel, python-aiohttp, python-pysqueezebox, and tinyxml), Gentoo (Apache Batik, Eclipse Mosquitto, firefox, R, Synapse, and util-linux), Mageia (libssh2 and putty), Red Hat (squid), SUSE (libxkbcommon), and Ubuntu (gnutls28).

Security updates for Friday

Post Syndicated from jake original https://lwn.net/Articles/957005/

Security updates have been issued by Debian (asterisk, chromium, exim4, netatalk, and tomcat9), Fedora (chromium), Gentoo (BlueZ, c-ares, CUPS filters, RDoc, and WebKitGTK+), Oracle (firefox, squid:4, thunderbird, and tigervnc), SUSE (python-aiohttp and python-paramiko), and Ubuntu (linux-intel-iotg).

[$] The return of None-aware operators for Python

Post Syndicated from jake original https://lwn.net/Articles/956862/

The saga of the None-aware (or null-coalescing) operators for Python
continues. We last looked in on the topic
a little over a year ago and noted that either adoption or a clear
rejection of the idea might help tamp down its regular recurrence. That
has not happened, so, predictably, it was raised again—and does not look
any closer to resolution this time around.

[$] Smuggling email inside of email

Post Syndicated from jake original https://lwn.net/Articles/956533/

Normally, when a new vulnerability is discovered and releases are
coordinated with those affected, the announcement is done at
a convenient time—not generally right before the end-of-year holidays, for
example. The SMTP
Smuggling vulnerability
has taken a different path, however, with its
announcement landing on December 18. That may well have been
unpleasant for some administrators that had not yet updated, but it was
particularly problematic for
some projects that had not been made aware of the vulnerability at
all—though it was known to affect several open-source mailers.

Lenôtre: Maestro – Introduction

Post Syndicated from jake original https://lwn.net/Articles/956699/

On his blog,
Luc Lenôtre introduces
Maestro
, “a Unix-like kernel and operating system written from
scratch in Rust
“. Maestro is intended to be
“lightweight and compatible-enough with Linux to be usable in everyday
life
“. The project began, in C, back in 2018, but switched over to
Rust after a year-and-a-half. The current status:

Maestro is a monolithic kernel, supporting only the x86 (in 32 bits)
architecture for now.

At the time of writing, 135 out of 437 Linux system calls
(roughly 31%) are
more or less implemented. The project has 48 800 lines of code
across 615
files (all repositories combined, counted using the cloc command).

There is a Hacker
News discussion
of the project as well.