Fri Oct 23 19:47:58 2020
EVENTS
 FREE
SOFTWARE
INSTITUTE

POLITICS
JOBS
MEMBERS'
CORNER

MAILING
LIST

NYLXS Mailing Lists and Archives
NYLXS Members have a lot to say and share but we don't keep many secrets. Join the Hangout Mailing List and say your peice.

DATE 2017-11-01

HANGOUT

2020-10-23 | 2020-09-23 | 2020-08-23 | 2020-07-23 | 2020-06-23 | 2020-05-23 | 2020-04-23 | 2020-03-23 | 2020-02-23 | 2020-01-23 | 2019-12-23 | 2019-11-23 | 2019-10-23 | 2019-09-23 | 2019-08-23 | 2019-07-23 | 2019-06-23 | 2019-05-23 | 2019-04-23 | 2019-03-23 | 2019-02-23 | 2019-01-23 | 2018-12-23 | 2018-11-23 | 2018-10-23 | 2018-09-23 | 2018-08-23 | 2018-07-23 | 2018-06-23 | 2018-05-23 | 2018-04-23 | 2018-03-23 | 2018-02-23 | 2018-01-23 | 2017-12-23 | 2017-11-23 | 2017-10-23 | 2017-09-23 | 2017-08-23 | 2017-07-23 | 2017-06-23 | 2017-05-23 | 2017-04-23 | 2017-03-23 | 2017-02-23 | 2017-01-23 | 2016-12-23 | 2016-11-23 | 2016-10-23 | 2016-09-23 | 2016-08-23 | 2016-07-23 | 2016-06-23 | 2016-05-23 | 2016-04-23 | 2016-03-23 | 2016-02-23 | 2016-01-23 | 2015-12-23 | 2015-11-23 | 2015-10-23 | 2015-09-23 | 2015-08-23 | 2015-07-23 | 2015-06-23 | 2015-05-23 | 2015-04-23 | 2015-03-23 | 2015-02-23 | 2015-01-23 | 2014-12-23 | 2014-11-23 | 2014-10-23 | 2014-09-23 | 2014-08-23 | 2014-07-23 | 2014-06-23 | 2014-05-23 | 2014-04-23 | 2014-03-23 | 2014-02-23 | 2014-01-23 | 2013-12-23 | 2013-11-23 | 2013-10-23 | 2013-09-23 | 2013-08-23 | 2013-07-23 | 2013-06-23 | 2013-05-23 | 2013-04-23 | 2013-03-23 | 2013-02-23 | 2013-01-23 | 2012-12-23 | 2012-11-23 | 2012-10-23 | 2012-09-23 | 2012-08-23 | 2012-07-23 | 2012-06-23 | 2012-05-23 | 2012-04-23 | 2012-03-23 | 2012-02-23 | 2012-01-23 | 2011-12-23 | 2011-11-23 | 2011-10-23 | 2011-09-23 | 2011-08-23 | 2011-07-23 | 2011-06-23 | 2011-05-23 | 2011-04-23 | 2011-03-23 | 2011-02-23 | 2011-01-23 | 2010-12-23 | 2010-11-23 | 2010-10-23 | 2010-09-23 | 2010-08-23 | 2010-07-23 | 2010-06-23 | 2010-05-23 | 2010-04-23 | 2010-03-23 | 2010-02-23 | 2010-01-23 | 2009-12-23 | 2009-11-23 | 2009-10-23 | 2009-09-23 | 2009-08-23 | 2009-07-23 | 2009-06-23 | 2009-05-23 | 2009-04-23 | 2009-03-23 | 2009-02-23 | 2009-01-23 | 2008-12-23 | 2008-11-23 | 2008-10-23 | 2008-09-23 | 2008-08-23 | 2008-07-23 | 2008-06-23 | 2008-05-23 | 2008-04-23 | 2008-03-23 | 2008-02-23 | 2008-01-23 | 2007-12-23 | 2007-11-23 | 2007-10-23 | 2007-09-23 | 2007-08-23 | 2007-07-23 | 2007-06-23 | 2007-05-23 | 2007-04-23 | 2007-03-23 | 2007-02-23 | 2007-01-23 | 2006-12-23 | 2006-11-23 | 2006-10-23 | 2006-09-23 | 2006-08-23 | 2006-07-23 | 2006-06-23 | 2006-05-23 | 2006-04-23 | 2006-03-23 | 2006-02-23 | 2006-01-23 | 2005-12-23 | 2005-11-23 | 2005-10-23 | 2005-09-23 | 2005-08-23 | 2005-07-23 | 2005-06-23 | 2005-05-23 | 2005-04-23 | 2005-03-23 | 2005-02-23 | 2005-01-23 | 2004-12-23 | 2004-11-23 | 2004-10-23 | 2004-09-23 | 2004-08-23 | 2004-07-23 | 2004-06-23 | 2004-05-23 | 2004-04-23 | 2004-03-23 | 2004-02-23 | 2004-01-23 | 2003-12-23 | 2003-11-23 | 2003-10-23 | 2003-09-23 | 2003-08-23 | 2003-07-23 | 2003-06-23 | 2003-05-23 | 2003-04-23 | 2003-03-23 | 2003-02-23 | 2003-01-23 | 2002-12-23 | 2002-11-23 | 2002-10-23 | 2002-09-23 | 2002-08-23 | 2002-07-23 | 2002-06-23 | 2002-05-23 | 2002-04-23 | 2002-03-23 | 2002-02-23 | 2002-01-23 | 2001-12-23 | 2001-11-23 | 2001-10-23 | 2001-09-23 | 2001-08-23 | 2001-07-23 | 2001-06-23 | 2001-05-23 | 2001-04-23 | 2001-03-23 | 2001-02-23 | 2001-01-23 | 2000-12-23 | 2000-11-23 | 2000-10-23 | 2000-09-23 | 2000-08-23 | 2000-07-23 | 2000-06-23 | 2000-05-23 | 2000-04-23 | 2000-03-23 | 2000-02-23 | 2000-01-23 | 1999-12-23

Key: Value:

Key: Value:

MESSAGE
DATE 2017-11-16
FROM opensuse-security@opensuse.org
SUBJECT Subject: [Hangout - NYLXS] [security-announce] SUSE-SU-2017:2327-2:
From hangout-bounces-at-nylxs.com Thu Nov 16 13:57:04 2017
Return-Path:
X-Original-To: archive-at-nylxs.com
Delivered-To: archive-at-nylxs.com
Received: from www.mrbrklyn.com (www.mrbrklyn.com [96.57.23.82])
by mrbrklyn.com (Postfix) with ESMTP id DB4EE163F5A;
Thu, 16 Nov 2017 13:57:03 -0500 (EST)
X-Original-To: hangout-at-www.mrbrklyn.com
Delivered-To: hangout-at-www.mrbrklyn.com
Received: by mrbrklyn.com (Postfix, from userid 1000)
id E28B9163F59; Thu, 16 Nov 2017 13:57:01 -0500 (EST)
Resent-From: Ruben Safir
Resent-Date: Thu, 16 Nov 2017 13:57:01 -0500
Resent-Message-ID: <20171116185701.GB13575-at-www.mrbrklyn.com>
Resent-To: hangout-at-mrbrklyn.com
X-Original-To: ruben-at-mrbrklyn.com
Delivered-To: ruben-at-mrbrklyn.com
Received: from hydra.opensuse.org (proxy-nue1.opensuse.org [195.135.221.145])
by mrbrklyn.com (Postfix) with ESMTP id 97794160876
for ; Thu, 16 Nov 2017 09:08:06 -0500 (EST)
Received: from lists5.opensuse.org (baloo.infra.opensuse.org [192.168.47.38])
by hydra.opensuse.org (Postfix) with ESMTP id E8FAD235F5
for ; Thu, 16 Nov 2017 14:06:58 +0000 (UTC)
Received: from baloo.infra.opensuse.org (localhost [127.0.0.1])
by lists5.opensuse.org (Postfix) with ESMTP id 123C711033;
Thu, 16 Nov 2017 14:06:55 +0000 (UTC)
X-Original-To: opensuse-security-announce-at-lists5-opensuse.suse.de
Delivered-To: opensuse-security-announce-at-lists5-opensuse.suse.de
Received: from relay2.suse.de (unknown [149.44.160.134])
by lists5.opensuse.org (Postfix) with ESMTP id 938DA11012
for ;
Thu, 16 Nov 2017 14:06:52 +0000 (UTC)
Received: from maintenance.suse.de (maintenance.nue.suse.com [149.44.176.14])
by relay2.suse.de (Postfix) with ESMTP id 7D30C2C1C6
for ;
Thu, 16 Nov 2017 14:06:52 +0000 (UTC)
Received: by maintenance.suse.de (Postfix, from userid 32005)
id 7A6FAFD05; Thu, 16 Nov 2017 15:06:52 +0100 (CET)
From: opensuse-security-at-opensuse.org
To: opensuse-security-announce-at-opensuse.org
Message-Id: <20171116140652.7A6FAFD05-at-maintenance.suse.de>
Date: Thu, 16 Nov 2017 15:06:52 +0100 (CET)
Precedence: bulk
Mailing-List: contact opensuse-security-announce+help-at-opensuse.org;
run by mlmmj
X-Mailinglist: opensuse-security-announce
List-Owner:
List-Archive:
X-MIME-Notice: attachments may have been removed from this message
Subject: [Hangout - NYLXS] [security-announce] SUSE-SU-2017:2327-2:
important: Security update for xen
X-BeenThere: hangout-at-nylxs.com
X-Mailman-Version: 2.1.17
List-Id: NYLXS Tech Talk and Politics
List-Unsubscribe: ,

List-Post:
List-Help:
List-Subscribe: ,

MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: hangout-bounces-at-nylxs.com
Sender: "Hangout"

SUSE Security Update: Security update for xen
______________________________________________________________________________

Announcement ID: SUSE-SU-2017:2327-2
Rating: important
References: #1002573 #1026236 #1027519 #1035231 #1046637
#1049578 #1051787 #1051788 #1051789 #1052686
#1055695
Cross-References: CVE-2017-10664 CVE-2017-11434 CVE-2017-12135
CVE-2017-12136 CVE-2017-12137 CVE-2017-12855

Affected Products:
SUSE Linux Enterprise Server 12-SP3
______________________________________________________________________________

An update that solves 6 vulnerabilities and has 5 fixes is
now available.

Description:

This update for xen fixes several issues.

These security issues were fixed:

- CVE-2017-12135: Unbounded recursion in grant table code allowed a
malicious guest to crash the host or potentially escalate
privileges/leak information (XSA-226, bsc#1051787).
- CVE-2017-12137: Incorrectly-aligned updates to pagetables allowed for
privilege escalation (XSA-227, bsc#1051788).
- CVE-2017-12136: Race conditions with maptrack free list handling allows
a malicious guest administrator to crash the host or escalate their
privilege to that of the host (XSA-228, bsc#1051789).
- CVE-2017-11434: The dhcp_decode function in slirp/bootp.c allowed local
guest OS users to cause a denial of service (out-of-bounds read) via a
crafted DHCP
options string (bsc#1049578).
- CVE-2017-10664: qemu-nbd did not ignore SIGPIPE, which allowed remote
attackers to cause a denial of service (daemon crash) by disconnecting
during a server-to-client reply attempt (bsc#1046637).
- CVE-2017-12855: Premature clearing of GTF_writing / GTF_reading lead to
potentially leaking sensitive information (XSA-230 bsc#1052686.

These non-security issues were fixed:

- bsc#1055695: XEN: 11SP4 and 12SP3 HVM guests can not be restored after
the save using xl stack
- bsc#1035231: Migration of HVM domU did not use superpages on destination
dom0
- bsc#1002573: Optimized LVM functions in block-dmmd block-dmmd


Patch Instructions:

To install this SUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- SUSE Linux Enterprise Server 12-SP3:

zypper in -t patch SUSE-SLE-SERVER-12-SP3-2017-1437=1

To bring your system up-to-date, use "zypper patch".


Package List:

- SUSE Linux Enterprise Server 12-SP3 (x86_64):

xen-4.9.0_11-3.9.1
xen-debugsource-4.9.0_11-3.9.1
xen-doc-html-4.9.0_11-3.9.1
xen-libs-32bit-4.9.0_11-3.9.1
xen-libs-4.9.0_11-3.9.1
xen-libs-debuginfo-32bit-4.9.0_11-3.9.1
xen-libs-debuginfo-4.9.0_11-3.9.1
xen-tools-4.9.0_11-3.9.1
xen-tools-debuginfo-4.9.0_11-3.9.1
xen-tools-domU-4.9.0_11-3.9.1
xen-tools-domU-debuginfo-4.9.0_11-3.9.1


References:

https://www.suse.com/security/cve/CVE-2017-10664.html
https://www.suse.com/security/cve/CVE-2017-11434.html
https://www.suse.com/security/cve/CVE-2017-12135.html
https://www.suse.com/security/cve/CVE-2017-12136.html
https://www.suse.com/security/cve/CVE-2017-12137.html
https://www.suse.com/security/cve/CVE-2017-12855.html
https://bugzilla.suse.com/1002573
https://bugzilla.suse.com/1026236
https://bugzilla.suse.com/1027519
https://bugzilla.suse.com/1035231
https://bugzilla.suse.com/1046637
https://bugzilla.suse.com/1049578
https://bugzilla.suse.com/1051787
https://bugzilla.suse.com/1051788
https://bugzilla.suse.com/1051789
https://bugzilla.suse.com/1052686
https://bugzilla.suse.com/1055695

--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe-at-opensuse.org
For additional commands, e-mail: opensuse-security-announce+help-at-opensuse.org
_______________________________________________
Hangout mailing list
Hangout-at-nylxs.com
http://lists.mrbrklyn.com/mailman/listinfo/hangout

  1. 2017-11-01 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Movies of the Week
  2. 2017-11-01 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Jobs with Amazon and Linux
  3. 2017-11-01 Ruben Safir <mrbrklyn-at-panix.com> Subject: [Hangout - NYLXS] Fwd: Linux System Admin _ Contract ?W2
  4. 2017-11-02 NCPA eCommunications <ncpa.ecommunications-at-ncpanet.org> Subject: [Hangout - NYLXS] NCPA's qAM: Drug Shortages Loom Across U.S. as
  5. 2017-11-02 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [soledad.esteban-at-icp.cat: [dinosaur] Course
  6. 2017-11-02 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] I can't breath wit this hay fever
  7. 2017-11-03 From: "S." <sman356-at-yahoo.com> Re: [Hangout - NYLXS] I can't breath wit this hay fever
  8. 2017-11-01 From: "Free Software Foundation" <info-at-fsf.org> Subject: [Hangout - NYLXS] Free Software Supporter Issue 115, November 2017
  9. 2017-11-01 From: "David H. Adler" <dha-at-panix.com> Subject: [Hangout - NYLXS] [MEETING] November Social Meeting
  10. 2017-11-01 From: "American Museum of Natural History" <email-at-amnh.org> Subject: [Hangout - NYLXS] Deck the Halls with Dinosaurs
  11. 2017-11-01 From: "Brooklyn College" <grads-at-brooklyn.cuny.edu> Subject: [Hangout - NYLXS] Join Us for the Brooklyn College Graduate Open
  12. 2017-11-05 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Internet of things now worries
  13. 2017-11-06 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] jobs
  14. 2017-11-06 From: "Louise Adler - American Museum of Natural History" <members-at-amnh.org> Subject: [Hangout - NYLXS] SEE IT FIRST: Our most interactive exhibition yet
  15. 2017-11-05 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #328 - The London Perl Workshop
  16. 2017-11-04 Chris Knadle <Chris.Knadle-at-coredump.us> Subject: [Hangout - NYLXS] [luny-talk] Signal is now available as a Desktop
  17. 2017-11-02 From: "American Museum of Natural History" <mat-at-amnh.org> Subject: [Hangout - NYLXS] Change lives. Teach science.
  18. 2017-11-07 Ruben Safir <ruben.safir-at-my.liu.edu> Subject: [Hangout - NYLXS] Weird Election results
  19. 2017-11-08 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Fwd: Your EMB Weekly Newsletter is HERE!
  20. 2017-11-08 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Fwd: Free Software Supporter Issue 115,
  21. 2017-11-09 From: "American Museum of Natural History" <publicprograms-at-amnh.org> Subject: [Hangout - NYLXS] Stir Your Senses with Events and Courses
  22. 2017-11-10 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Android Replacements and SDK
  23. 2017-11-10 aicra-at-faqlinux.com Subject: [Hangout - NYLXS] [linux-elitists] December 31 - Deadline for DMCA
  24. 2017-11-11 Ruben Safir <mrbrklyn-at-panix.com> Subject: [Hangout - NYLXS] why we need free software
  25. 2017-11-13 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] NY Times: The world s ingrave Danger
  26. 2017-11-13 From: "Donald Robertson, III, FSF" <info-at-fsf.org> Subject: [Hangout - NYLXS] You can now register as a DMCA agent without
  27. 2017-11-14 Ruben Safir <mrbrklyn-at-panix.com> Re: [Hangout - NYLXS] You can now register as a DMCA agent without
  28. 2017-11-14 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Logging using tcp transport
  29. 2017-11-16 From: "IEEE Spectrum Tech Alert" <reply-at-media.ieee.org> Subject: [Hangout - NYLXS] Two Top Supercomputer Rankings Lists,
  30. 2017-11-16 opensuse-security-at-opensuse.org Subject: [Hangout - NYLXS] [security-announce] SUSE-SU-2017:2871-2:
  31. 2017-11-16 opensuse-security-at-opensuse.org Subject: [Hangout - NYLXS] [security-announce] SUSE-SU-2017:2327-2:
  32. 2017-11-17 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] I need a volunteer
  33. 2017-11-18 Chris Knadle <Chris.Knadle-at-coredump.us> Re: [Hangout - NYLXS] You can now register as a DMCA agent without
  34. 2017-11-18 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Linux with NYC
  35. 2017-11-18 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Hackers Meeting
  36. 2017-11-19 Ruben Safir <ruben-at-mrbrklyn.com> Re: [Hangout - NYLXS] You can now register as a DMCA agent without
  37. 2017-11-19 Ruben Safir <ruben.safir-at-my.liu.edu> Re: [Hangout - NYLXS] You can now register as a DMCA agent without
  38. 2017-11-20 From: "Mancini, Sabin (DFS)" <Sabin.Mancini-at-dfs.ny.gov> Re: [Hangout - NYLXS] Hackers Meeting | | * Ok Ruben, so,
  39. 2017-11-20 Ruben Safir <mrbrklyn-at-panix.com> Re: [Hangout - NYLXS] Hackers Meeting | | * Ok Ruben, so,
  40. 2017-11-20 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #330 - Tube? Metro? Underground?
  41. 2017-11-20 Gabor Szabo <gabor-at-szabgab.com> Subject: [Hangout - NYLXS] [Perlweekly] #330 - Tube? Metro? Underground?
  42. 2017-11-22 Christos Nouskas <nous-at-artixlinux.org> Re: [Hangout - NYLXS] [artix-general] elongind and X
  43. 2017-11-22 artoo <artoo-at-cromnix.org> Re: [Hangout - NYLXS] [artix-general] icu - run both versions
  44. 2017-11-22 Chris Cromer <chris-at-cromer.cl> Re: [Hangout - NYLXS] [artix-general] icu - run both versions
  45. 2017-11-22 artoo <artoo-at-cromnix.org> Re: [Hangout - NYLXS] [artix-general] icu - run both versions
  46. 2017-11-22 Chris Cromer <chris-at-cromer.cl> Re: [Hangout - NYLXS] [artix-general] icu - run both versions
  47. 2017-11-22 Christos Nouskas <nous-at-artixlinux.org> Re: [Hangout - NYLXS] [artix-general] elongind and X
  48. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Re: [Hangout - NYLXS] Fwd: Re: [artix-general] icu - run both
  49. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Re: [Hangout - NYLXS] [artix-general] elongind and X
  50. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Fwd: Re: [artix-general] icu - run both versions
  51. 2017-11-22 artoo <artoo-at-cromnix.org> Re: [Hangout - NYLXS] [artix-general] elongind and X
  52. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Re: [Hangout - NYLXS] [artix-general] elongind and X
  53. 2017-11-22 artoo <artoo-at-cromnix.org> Re: [Hangout - NYLXS] [artix-general] elongind and X
  54. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] [artix-general] elongind and X
  55. 2017-11-21 Ruben Safir <ruben-at-mrbrklyn.com> Re: [Hangout - NYLXS] [artix-general] icu - run both versions
  56. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Movie of the week
  57. 2017-11-22 RestorationART <restorationart-at-restorationplaza.org> Subject: [Hangout - NYLXS] The Billie Holiday Theatre's production of AUTUMN
  58. 2017-11-23 The Hebron Fund <info-at-hebronfund.org> Subject: [Hangout - NYLXS] Anti-Hebron Activist Caught, Visitors,
  59. 2017-11-23 From: "Molly de Blanc" <info-at-fsf.org> Subject: [Hangout - NYLXS] Give the gift of freedom with the Ethical
  60. 2017-11-22 Ruben Safir <ruben-at-mrbrklyn.com> Subject: [Hangout - NYLXS] Fwd: Re: [artix-general] icu - run both versions

NYLXS are Do'ers and the first step of Doing is Joining! Join NYLXS and make a difference in your community today!