Gentoo Weekly Newsletter: April 5th, 2004
1.
Gentoo News
Gentoo Linux Project seeking additional kernel developers
Gentoo Linux is currently seeking some additional kernel developers, primarily for the x86, amd64, ppc, and ppc64 architectures. Applicants should have a fair amount of experience with the kernel, specifically with one or more of the above architectures. Send an email to John Mylchreest if you're interested.
Gentoo Weekly Newsletter seeking additional contributors
The Gentoo Weekly Newsletter is seeking additional contributors to help with community coverage - this involves monitoring mailing lists, web forums, or the international community and summarizing the interesting traffic each week. We'd also like to take on some volunteers to help with some of the other sections, bringing new ideas to the team and lightening the load on the current contributors. The only real requirement of applicants is a solid knowledge of written English. Experience with journalism or Linux, as well as a variety of other skills might be helpful, but are not necessary, although motivation and willingness to work about a couple of hours each week is. Still interested? Drop us a line here with some background info and any ideas you have for the newsletter.
2.
Gentoo Security
Fetchmail 6.2.5 fixes a remote DoS
Fetchmail versions 6.2.4 and earlier can be crashed by sending a
specially-crafted email to a fetchmail user.
For more information, please see the GLSA Announcement
Squid ACL [url_regex] bypass vulnerability
Squid versions 2.0 through to 2.5.STABLE4 could allow a remote attacker to
bypass Access Control Lists by sending a specially-crafted URL request
containing '%00': in such circumstances; the url_regex ACL may not properly
detect the malicious URL, allowing the attacker to effectively bypass the
ACL.
For more information, please see the GLSA Announcement
OpenLDAP DoS Vulnerability
A failed password operation can cause the OpenLDAP slapd server, if it is
using the back-ldbm backend, to free memory that was never allocated.
For more information, please see the GLSA Announcement
Remote buffer overflow in MPlayer
MPlayer contains a remotely exploitable buffer overflow in the HTTP parser
that may allow attackers to run arbitrary code on a user's computer.
For more information, please see the GLSA Announcement
Multiple Security Vulnerabilities in Monit
A denial of service and a buffer overflow vulnerability have been found in
Monit.
For more information, please see the GLSA Announcement
3.
Heard in the Community
Web Forums
GLSA Integration in Portage
Gentoo developer Genone has set up a sticky thread a while ago that deals with the upcoming integration of security announcements in Portage. Check here for updates to the script that is now in gentoolkit, before its final implementation as part of emerge:
The Colour: Purple...
The "Lila Theme" is a new concerted effort at designing a Gentoo wallpaper and desktop icons collection, in purple (German: "lila") and pink, the predominant Gentoo colours. Sounds awful, looks stunningly beautiful, and it's entirely SVG-based, so you can generate your own PNGs with a Python script via Sodipodi or Inkscape! The Firefox theme has even made it onto the list of the "official" upstream themes. Here's where the artists coordinate their work:
4.
Gentoo International
Germany: Yet Another GUM in Oberhausen
The next Gentoo User Meeting in Oberhausen (Ruhr region of central Germany) will take place this Wednesday, 7 April. The meeting point will again be the Gasthof Harlos, and the GUM starts at 19:00. Newcomers and regulars alike are most welcome. The coordination thread in the Forums is at its usual location.
5.
Bugzilla
Summary
Statistics
The Gentoo community uses Bugzilla (bugs.gentoo.org) to record and track
bugs, notifications, suggestions and other interactions with the development team. Between 27 March 2004 and 02 April 2004, activity
on the site has resulted in:
- 697 new bugs during this period
- 438 bugs closed or resolved during this period
- 20 previously closed bugs were reopened this period
Of the 5510 currently open bugs: 130 are labeled 'blocker', 203 are labeled 'critical', and 460 are labeled 'major'.
Closed Bug Rankings
The developers and teams who have closed the most bugs during this period are:
New Bug Rankings
The developers and teams who have been assigned the most new bugs during this period are:
6.
Tips and Tricks
Multiple X-Sessions
XFree86 allows you to have multiple X sessions open at once. This
can be useful if you want or need two different desktop
environments open at once.
Code Listing 6.1 |
% startx
% startx -- :1 |
The desktops will be on terminals F7-F12
7.
Moves, Adds, and Changes
Moves
The following developers recently left the Gentoo team:
Adds
The following developers recently joined the Gentoo Linux team:
Changes
The following developers recently changed roles within the Gentoo Linux project:
8.
Contribute to GWN
Interested in contributing to the Gentoo Weekly Newsletter? Send us an email.
9.
GWN Feedback
Please send us your feedback and help make the GWN better.
10.
GWN Subscription Information
To subscribe to the Gentoo Weekly Newsletter, send a blank email to gentoo-gwn-subscribe@gentoo.org.
To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to gentoo-gwn-unsubscribe@gentoo.org from the email address you are subscribed under.
11.
Other Languages
The Gentoo Weekly Newsletter is also available in the following languages:
|