1 |
--------------------------------------------------------------------------- |
2 |
Gentoo Weekly Newsletter |
3 |
http://www.gentoo.org/news/en/gwn/current.xml |
4 |
This is the Gentoo Weekly Newsletter for the week of March 29th, 2004. |
5 |
--------------------------------------------------------------------------- |
6 |
|
7 |
============== |
8 |
1. Gentoo News |
9 |
============== |
10 |
|
11 |
Gentoo Linux Project seeking additional kernel developers |
12 |
--------------------------------------------------------- |
13 |
|
14 |
Gentoo Linux is currently seeking some additional kernel developers, |
15 |
primarily for the x86, amd64, ppc, and ppc64 architectures. Applicants |
16 |
should have a fair amount of experience with the kernel, specifically with |
17 |
one or more of the above architectures. Send an email to John |
18 |
Mylchreest[1] if you're interested. |
19 |
|
20 |
1. johnm@g.o |
21 |
|
22 |
Gentoo Weekly Newsletter seeking additional contributors |
23 |
-------------------------------------------------------- |
24 |
|
25 |
The Gentoo Weekly Newsletter is seeking additional contributors to help |
26 |
with community coverage - this involves monitoring mailing lists, web |
27 |
forums, or the international community and summarizing the interesting |
28 |
traffic each week. We'd also like to take on some volunteers to help with |
29 |
some of the other sections, bringing new ideas to the team and lightening |
30 |
the load on the current contributors. The only real requirement of |
31 |
applicants is a solid knowledge of written English. Experience with |
32 |
journalism or Linux, as well as a variety of other skills might be |
33 |
helpful, but are not necessary, although motivation and willingness to |
34 |
work about a couple of hours each week is. Still interested? Drop us a |
35 |
line here[2] with some background info and any ideas you have for the |
36 |
newsletter. |
37 |
|
38 |
2. gwn-feedback@g.o |
39 |
|
40 |
================== |
41 |
2. Gentoo Security |
42 |
================== |
43 |
|
44 |
Fetchmail 6.2.5 fixes a remote DoS |
45 |
---------------------------------- |
46 |
|
47 |
Fetchmail versions 6.2.4 and earlier can be crashed by sending a |
48 |
specially-crafted email to a fetchmail user. |
49 |
|
50 |
For more information, please see the GLSA Announcement[3] |
51 |
|
52 |
3. http://www.gentoo.org/security/en/glsa/glsa-200403-10.xml |
53 |
|
54 |
Squid ACL [url_regex] bypass vulnerability |
55 |
------------------------------------------ |
56 |
|
57 |
Squid versions 2.0 through to 2.5.STABLE4 could allow a remote attacker to |
58 |
bypass Access Control Lists by sending a specially-crafted URL request |
59 |
containing '%00': in such circumstances; the url_regex ACL may not |
60 |
properly detect the malicious URL, allowing the attacker to effectively |
61 |
bypass the ACL. |
62 |
|
63 |
For more information, please see the GLSA Announcement[4] |
64 |
|
65 |
4. http://www.gentoo.org/security/en/glsa/glsa-200403-11.xml |
66 |
|
67 |
OpenLDAP DoS Vulnerability |
68 |
-------------------------- |
69 |
|
70 |
A failed password operation can cause the OpenLDAP slapd server, if it is |
71 |
using the back-ldbm backend, to free memory that was never allocated. |
72 |
|
73 |
For more information, please see the GLSA Announcement[5] |
74 |
|
75 |
5. http://www.gentoo.org/security/en/glsa/glsa-200403-12.xml |
76 |
|
77 |
Remote buffer overflow in MPlayer |
78 |
--------------------------------- |
79 |
|
80 |
MPlayer contains a remotely exploitable buffer overflow in the HTTP parser |
81 |
that may allow attackers to run arbitrary code on a user's computer. |
82 |
|
83 |
For more information, please see the GLSA Announcement[6] |
84 |
|
85 |
6. http://www.gentoo.org/security/en/glsa/glsa-200403-13.xml |
86 |
|
87 |
Multiple Security Vulnerabilities in Monit |
88 |
------------------------------------------ |
89 |
|
90 |
A denial of service and a buffer overflow vulnerability have been found in |
91 |
Monit. |
92 |
|
93 |
For more information, please see the GLSA Announcement[7] |
94 |
|
95 |
7. http://www.gentoo.org/security/en/glsa/glsa-200403-14.xml |
96 |
|
97 |
========================= |
98 |
3. Heard in the Community |
99 |
========================= |
100 |
|
101 |
Web Forums |
102 |
---------- |
103 |
|
104 |
GLSA Integration in Portage |
105 |
|
106 |
Gentoo developer Genone has set up a sticky thread a while ago that deals |
107 |
with the upcoming integration of security announcements in Portage. Check |
108 |
here for updates to the script that is now in gentoolkit, before its final |
109 |
implementation as part of emerge: |
110 |
|
111 |
* portage GLSA integration (aka `emerge security`)[8] |
112 |
* Portage GLSA integration project page[9] |
113 |
8. http://forums.gentoo.org/viewtopic.php?t=148463 |
114 |
9. http://www.gentoo.org/proj/en/portage/glsa-integration.xml |
115 |
|
116 |
|
117 |
The Colour: Purple... |
118 |
|
119 |
The "Lila Theme" is a new concerted effort at designing a Gentoo wallpaper |
120 |
and desktop icons collection, in purple (German: "lila") and pink, the |
121 |
predominant Gentoo colours. Sounds awful, looks stunningly beautiful, and |
122 |
it's entirely SVG-based, so you can generate your own PNGs with a Python |
123 |
script via Sodipodi or Inkscape! The Firefox theme has even made it onto |
124 |
the list of the "official" upstream themes. Here's where the artists |
125 |
coordinate their work: |
126 |
|
127 |
* Lila Theme Official Thread[10] |
128 |
* dgt84's Gentoo Linux Artwork pages[11] |
129 |
* KDE version by telex4[12] |
130 |
* Firefox purple theme[13] |
131 |
10. http://forums.gentoo.org/viewtopic.php?t=145661 |
132 |
11. http://programmer-art.org/index.php?page=gentoo |
133 |
12. http://www.kde-look.org/content/show.php?content=11492 |
134 |
13. http://texturizer.net/firefox/themes/#Lila |
135 |
|
136 |
======================= |
137 |
4. Gentoo International |
138 |
======================= |
139 |
|
140 |
Germany: Yet Another GUM in Oberhausen |
141 |
-------------------------------------- |
142 |
|
143 |
The next Gentoo User Meeting in Oberhausen (Ruhr region of central |
144 |
Germany) will take place this Wednesday, 7 April. The meeting point will |
145 |
again be the Gasthof Harlos[14], and the GUM starts at 19:00. Newcomers |
146 |
and regulars alike are most welcome. The coordination thread in the Forums |
147 |
is at its usual location[15]. |
148 |
|
149 |
14. http://www.gasthof-harlos.de |
150 |
15. http://forums.gentoo.org/viewtopic.php?t=94915 |
151 |
|
152 |
=========== |
153 |
5. Bugzilla |
154 |
=========== |
155 |
|
156 |
Summary |
157 |
------- |
158 |
|
159 |
* Statistics |
160 |
* Closed Bug Ranking |
161 |
* New Bug Rankings |
162 |
|
163 |
Statistics |
164 |
---------- |
165 |
|
166 |
The Gentoo community uses Bugzilla (bugs.gentoo.org[16]) to record and |
167 |
track bugs, notifications, suggestions and other interactions with the |
168 |
development team. Between 27 March 2004 and 02 April 2004, activity on the |
169 |
site has resulted in: |
170 |
|
171 |
16. http://bugs.gentoo.org |
172 |
|
173 |
* 697 new bugs during this period |
174 |
* 438 bugs closed or resolved during this period |
175 |
* 20 previously closed bugs were reopened this period |
176 |
|
177 |
Of the 5510 currently open bugs: 130 are labeled 'blocker', 203 are |
178 |
labeled 'critical', and 460 are labeled 'major'. |
179 |
|
180 |
Closed Bug Rankings |
181 |
------------------- |
182 |
|
183 |
The developers and teams who have closed the most bugs during this period |
184 |
are: |
185 |
|
186 |
* AMD64 Porting Team[17], with 76 closed bugs[18] |
187 |
* Gentoo Security[19], with 17 closed bugs[20] |
188 |
* Jeremy Huddleston[21], with 17 closed bugs[22] |
189 |
* Gnome Desktop Team[23], with 15 closed bugs[24] |
190 |
* Gentoo Games[25], with 15 closed bugs[26] |
191 |
17. amd64@g.o |
192 |
18. |
193 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch |
194 |
field=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&resolution=FIX |
195 |
ED&assigned_to=amd64@g.o |
196 |
19. security@g.o |
197 |
20. |
198 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch |
199 |
field=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&resolution=FIX |
200 |
ED&assigned_to=security@g.o |
201 |
21. eradicator@g.o |
202 |
22. |
203 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch |
204 |
field=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&resolution=FIX |
205 |
ED&assigned_to=eradicator@g.o |
206 |
23. gnome@g.o |
207 |
24. |
208 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch |
209 |
field=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&resolution=FIX |
210 |
ED&assigned_to=gnome@g.o |
211 |
25. games@g.o |
212 |
26. |
213 |
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&ch |
214 |
field=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&resolution=FIX |
215 |
ED&assigned_to=games@g.o |
216 |
|
217 |
New Bug Rankings |
218 |
---------------- |
219 |
|
220 |
The developers and teams who have been assigned the most new bugs during |
221 |
this period are: |
222 |
|
223 |
* Apache Herd[27], with 33 new bugs[28] |
224 |
* Core System Packages Team[29], with 20 new bugs[30] |
225 |
* Gentoo KDE team[31], with 19 new bugs[32] |
226 |
* Java team[33], with 17 new bugs[34] |
227 |
* AMD64 Porting Team[35], with 16 new bugs[36] |
228 |
27. apache-bugs@g.o |
229 |
28. |
230 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s |
231 |
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&chfieldto=2004-04 |
232 |
-02&assigned_to=apache-bugs@g.o |
233 |
29. base-system@g.o |
234 |
30. |
235 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s |
236 |
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&chfieldto=2004-04 |
237 |
-02&assigned_to=base-system@g.o |
238 |
31. kde@g.o |
239 |
32. |
240 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s |
241 |
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&chfieldto=2004-04 |
242 |
-02&assigned_to=kde@g.o |
243 |
33. java@g.o |
244 |
34. |
245 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s |
246 |
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&chfieldto=2004-04 |
247 |
-02&assigned_to=java@g.o |
248 |
35. amd64@g.o |
249 |
36. |
250 |
http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&bug_s |
251 |
tatus=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&chfieldto=2004-04 |
252 |
-02&assigned_to=amd64@g.o |
253 |
|
254 |
|
255 |
================== |
256 |
6. Tips and Tricks |
257 |
================== |
258 |
|
259 |
Multiple X-Sessions |
260 |
|
261 |
XFree86 allows you to have multiple X sessions open at once. This can be |
262 |
useful if you want or need two different desktop environments open at once. |
263 |
|
264 |
--------------------------------------------------------------------------- |
265 |
| Code Listing 6.1: | |
266 |
|-------------------------------------------------------------------------| |
267 |
| | |
268 |
| By default X uses the display :0 | |
269 |
|% startx | |
270 |
| To open a second display, use another number | |
271 |
|% startx -- :1 | |
272 |
--------------------------------------------------------------------------- |
273 |
|
274 |
The desktops will be on terminals F7-F12 |
275 |
|
276 |
=========================== |
277 |
7. Moves, Adds, and Changes |
278 |
=========================== |
279 |
|
280 |
Moves |
281 |
----- |
282 |
|
283 |
The following developers recently left the Gentoo team: |
284 |
* none this week |
285 |
|
286 |
Adds |
287 |
---- |
288 |
|
289 |
The following developers recently joined the Gentoo Linux team: |
290 |
|
291 |
* none this week |
292 |
|
293 |
Changes |
294 |
------- |
295 |
|
296 |
The following developers recently changed roles within the Gentoo Linux |
297 |
project: |
298 |
|
299 |
* none this week |
300 |
|
301 |
==================== |
302 |
8. Contribute to GWN |
303 |
==================== |
304 |
|
305 |
Interested in contributing to the Gentoo Weekly Newsletter? Send us an |
306 |
email[37]. |
307 |
|
308 |
37. gwn-feedback@g.o |
309 |
|
310 |
=============== |
311 |
9. GWN Feedback |
312 |
=============== |
313 |
|
314 |
Please send us your feedback[38] and help make the GWN better. |
315 |
|
316 |
38. gwn-feedback@g.o |
317 |
|
318 |
================================ |
319 |
10. GWN Subscription Information |
320 |
================================ |
321 |
|
322 |
To subscribe to the Gentoo Weekly Newsletter, send a blank email to |
323 |
gentoo-gwn-subscribe@g.o. |
324 |
|
325 |
To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to |
326 |
gentoo-gwn-unsubscribe@g.o from the email address you are |
327 |
subscribed under. |
328 |
|
329 |
=================== |
330 |
11. Other Languages |
331 |
=================== |
332 |
|
333 |
The Gentoo Weekly Newsletter is also available in the following languages: |
334 |
|
335 |
* Dutch[39] |
336 |
* English[40] |
337 |
* German[41] |
338 |
* French[42] |
339 |
* Japanese[43] |
340 |
* Italian[44] |
341 |
* Polish[45] |
342 |
* Portuguese (Brazil)[46] |
343 |
* Portuguese (Portugal)[47] |
344 |
* Russian[48] |
345 |
* Spanish[49] |
346 |
* Turkish[50] |
347 |
39. http://www.gentoo.org/news/be/gwn/gwn.xml |
348 |
40. http://www.gentoo.org/news/en/gwn/gwn.xml |
349 |
41. http://www.gentoo.org/news/de/gwn/gwn.xml |
350 |
42. http://www.gentoo.org/news/fr/gwn/gwn.xml |
351 |
43. http://www.gentoo.org/news/ja/gwn/gwn.xml |
352 |
44. http://www.gentoo.org/news/it/gwn/gwn.xml |
353 |
45. http://www.gentoo.org/news/pl/gwn/gwn.xml |
354 |
46. http://www.gentoo.org/news/br/gwn/gwn.xml |
355 |
47. http://www.gentoo.org/news/pt/gwn/gwn.xml |
356 |
48. http://www.gentoo.org/news/ru/gwn/gwn.xml |
357 |
49. http://www.gentoo.org/news/es/gwn/gwn.xml |
358 |
50. http://www.gentoo.org/news/tr/gwn/gwn.xml |
359 |
|
360 |
Yuji Carlos Kosugi <carlos@g.o> - Editor |
361 |
AJ Armstrong <aja@×××××××××××××.com> - Contributor |
362 |
Brian Downey <bdowney@×××××××××××.net> - Contributor |
363 |
Luke Giuliani <cold_flame@×××××.com> - Contributor |
364 |
Grant Goodyear <g2boojum@g.o> - Contributor |
365 |
Aron Griffis <agriffis@g.o> - Contributor |
366 |
Stuart Herbert <stuart@g.o> - Contributor |
367 |
Kurt Lieber <klieber@g.o> - Contributor |
368 |
Rafael Cordones Marcos <rcm@×××××××.net> - Contributor |
369 |
David Narayan <david@×××××××.net> - Contributor |
370 |
David Nielsen <Lovechild@××××××××.com> - Contributor |
371 |
Ulrich Plate <plate@g.o> - Contributor |
372 |
Simon Holm Thagersen <simon@××××××.net> - Danish Translation |
373 |
Jesper Brodersen <broeman@g.o> - Danish Translation |
374 |
Arne Mejlholm <aaby@g.o> - Danish Translation |
375 |
Hendrik Eeckhaut <Hendrik.Eeckhaut@×××××.be> - Dutch Translation |
376 |
Jorn Eilander <sephiroth@××××××××.nl> - Dutch Translation |
377 |
Bernard Kerckenaere <bernieke@××××××××.com> - Dutch Translation |
378 |
Peter ter Borg <peter@××××××.nl> - Dutch Translation |
379 |
Jochen Maes <linux@××××.be> - Dutch Translation |
380 |
Roderick Goessen <rgoessen@××××.nl> - Dutch Translation |
381 |
Gerard van den Berg <gerard@××××××.net> - Dutch Translation |
382 |
Matthieu Montaudouin <mat@××××××××.com> - French Translation |
383 |
Xavier Neys <neysx@g.o> - French Translation |
384 |
Martin Prieto <riverdale@×××××××××.org> - French Translation |
385 |
Antoine Raillon <cabec2@××××××.net> - French Translation |
386 |
Sebastien Cevey <seb@×××××.net> - French Translation |
387 |
Jean-Christophe Choisy <mabouya@××××××××××××.org> - French Translation |
388 |
Thomas Raschbacher <lordvan@g.o> - German Translation |
389 |
Steffen Lassahn <madeagle@g.o> - German Translation |
390 |
Matthias F. Brandstetter <haim@g.o> - German Translation |
391 |
Lukas Domagala <Cyrik@g.o> - German Translation |
392 |
Tobias Scherbaum <dertobi123@g.o> - German Translation |
393 |
Daniel Gerholdt <Sputnik1969@g.o> - German Translation |
394 |
Marc Herren <dj-submerge@g.o> - German Translation |
395 |
Tobias Matzat <SirSeoman@g.o> - German Translation |
396 |
Marco Mascherpa <mush@××××××.net> - Italian Translation |
397 |
Claudio Merloni <paper@×××××××.it> - Italian Translation |
398 |
Christian Apolloni <bsolar@×××××××.ch> - Italian Translation |
399 |
Stefano Lucidi <stefano.lucidi@×××××××××××××.org> - Italian Translation |
400 |
Katuyuki Konno <katuyuki@××××××××.jp> - Japanese Translation |
401 |
Hiroyuki Takeda <hiro@××××××××××××××.jp> - Japanese Translation |
402 |
Masato Hatakeyama <hatake@×××××××××××.jp> - Japanese Translation |
403 |
Masayoshi Nakamura <masayang@×××××××××.com> - Japanese Translation |
404 |
Yasunori Fukudome <yasunori@××××××××××××××××.uk> - Japanese Translation |
405 |
Tomoyuki Sakurai <web-gentoo-doc-jp@××××××××××××.nu> - Japanese Translation |
406 |
Lukasz Strzygowski <lucass@××××××.pl> - Polish Translation |
407 |
Karol Goralski <gooroo@××××××.pl> - Polish Translation |
408 |
Atila "Jedi" Bohlke Vasconcelos <bohlke@×××××××××.br> - Portuguese |
409 |
(Brazil) Translation |
410 |
Eduardo Belloti <dudu@××××××××.net> - Portuguese (Brazil) Translation |
411 |
Jo??o Rafael Moraes Nicola <joaoraf@×××××××××.br> - Portuguese (Brazil) |
412 |
Translation |
413 |
Marcelo Gon??alves de Azambuja <mgazambuja@×××××××××.br> - Portuguese |
414 |
(Brazil) Translation |
415 |
Otavio Rodolfo Piske <angusy@××××××××.org> - Portuguese (Brazil) |
416 |
Translation |
417 |
Pablo N. Hess -- NatuNobilis <natunobilis@××××××××.org> - Portuguese |
418 |
(Brazil) Translation |
419 |
Pedro de Medeiros <pzilla@××××××××.br> - Portuguese (Brazil) Translation |
420 |
Ventura Barbeiro <venturasbarbeiro@××××××.br> - Portuguese (Brazil) |
421 |
Translation |
422 |
Bruno Ferreira <blueroom@××××××××××××.net> - Portuguese (Portugal) |
423 |
Translation |
424 |
Gustavo Felisberto <humpback@××××××××××.net> - Portuguese (Portugal) |
425 |
Translation |
426 |
Jos?? Costa <jose_costa@×××××××.pt> - Portuguese (Portugal) Translation |
427 |
Luis Medina <metalgodin@×××××××××.org> - Portuguese (Portugal) Translation |
428 |
Ricardo Loureiro <rjlouro@×××××××.org> - Portuguese (Portugal) Translation |
429 |
Aleksandr Martyncev <amncorp@××.ru> - Russian Translator |
430 |
Sergey Galkin <gals_home@××××.ru> - Russian Translator |
431 |
Sergey Kuleshov <svyatogor@g.o> - Russian Translator |
432 |
Alex Spirin <asp13@××××.ru> - Russian Translator |
433 |
Denis Zaletov <dzaletov@×××××××.ru> - Russian Translator |
434 |
Lanark <lanark@××××××××××.ar> - Spanish Translation |
435 |
Fernando J. Pereda <ferdy@××××××.org> - Spanish Translation |
436 |
Lluis Peinado Cifuentes <lpeinado@×××.edu> - Spanish Translation |
437 |
Zephryn Xirdal T <ZEPHRYNXIRDAL@××××××××××.net> - Spanish Translation |
438 |
Guillermo Juarez <katossi@××××××××××××××××.es> - Spanish Translation |
439 |
Jes??s Garc??a Crespo <correo@××××××.com> - Spanish Translation |
440 |
Carlos Castillo <carlos@×××××××××××××.com> - Spanish Translation |
441 |
Julio Castillo <julio@×××××××××××××.com> - Spanish Translation |
442 |
Sergio G??mez <s3r@××××××××××××.ar> - Spanish Translation |
443 |
Aycan Irican <aycan@××××××××.tr> - Turkish Translation |
444 |
Bugra Cakir <bugra@×××××××××.com> - Turkish Translation |
445 |
Cagil Seker <cagils@××××××××××.tr> - Turkish Translation |
446 |
Emre Kazdagli <emre@××××××××.tr> - Turkish Translation |
447 |
Evrim Ulu <evrim@××××××××.tr> - Turkish Translation |
448 |
Gursel Kaynak <gurcell@××××××××.tr> - Turkish Translation |