LWN.net Logo

Gentoo Weekly Newsletter - Volume 3, Issue 14

From:  Yuji Kosugi <carlos-AT-gentoo.org>
To:  gentoo-gwn-AT-lists.gentoo.org
Subject:  [gentoo-gwn] Gentoo Weekly Newsletter - Volume 3, Issue 14
Date:  Mon, 5 Apr 2004 18:05:03 -0400

---------------------------------------------------------------------------
Gentoo Weekly Newsletter
http://www.gentoo.org/news/en/gwn/current.xml
This is the Gentoo Weekly Newsletter for the week of March 29th, 2004.
---------------------------------------------------------------------------
 
==============
1. Gentoo News
==============
  
Gentoo Linux Project seeking additional kernel developers
---------------------------------------------------------
  
Gentoo Linux is currently seeking some additional kernel developers, 
primarily for the x86, amd64, ppc, and ppc64 architectures. Applicants 
should have a fair amount of experience with the kernel, specifically with 
one or more of the above architectures. Send an email to John 
Mylchreest[1] if you're interested. 

 1. johnm@gentoo.org
    
Gentoo Weekly Newsletter seeking additional contributors
--------------------------------------------------------
  
The Gentoo Weekly Newsletter is seeking additional contributors to help 
with community coverage - this involves monitoring mailing lists, web 
forums, or the international community and summarizing the interesting 
traffic each week. We'd also like to take on some volunteers to help with 
some of the other sections, bringing new ideas to the team and lightening 
the load on the current contributors. The only real requirement of 
applicants is a solid knowledge of written English. Experience with 
journalism or Linux, as well as a variety of other skills might be 
helpful, but are not necessary, although motivation and willingness to 
work about a couple of hours each week is. Still interested? Drop us a 
line here[2] with some background info and any ideas you have for the 
newsletter. 

 2. gwn-feedback@gentoo.org
    
==================
2. Gentoo Security
==================
  
Fetchmail 6.2.5 fixes a remote DoS
----------------------------------
  
Fetchmail versions 6.2.4 and earlier can be crashed by sending a 
specially-crafted email to a fetchmail user. 
 
For more information, please see the GLSA Announcement[3] 

 3. http://www.gentoo.org/security/en/glsa/glsa-200403-10.xml
    
Squid ACL [url_regex] bypass vulnerability
------------------------------------------
  
Squid versions 2.0 through to 2.5.STABLE4 could allow a remote attacker to 
bypass Access Control Lists by sending a specially-crafted URL request 
containing '%00': in such circumstances; the url_regex ACL may not 
properly detect the malicious URL, allowing the attacker to effectively 
bypass the ACL. 
 
For more information, please see the GLSA Announcement[4] 

 4. http://www.gentoo.org/security/en/glsa/glsa-200403-11.xml
    
OpenLDAP DoS Vulnerability
--------------------------
  
A failed password operation can cause the OpenLDAP slapd server, if it is 
using the back-ldbm backend, to free memory that was never allocated. 
 
For more information, please see the GLSA Announcement[5] 

 5. http://www.gentoo.org/security/en/glsa/glsa-200403-12.xml
    
Remote buffer overflow in MPlayer
---------------------------------
  
MPlayer contains a remotely exploitable buffer overflow in the HTTP parser 
that may allow attackers to run arbitrary code on a user's computer. 
 
For more information, please see the GLSA Announcement[6] 

 6. http://www.gentoo.org/security/en/glsa/glsa-200403-13.xml
    
Multiple Security Vulnerabilities in Monit
------------------------------------------
  
A denial of service and a buffer overflow vulnerability have been found in 
Monit. 
 
For more information, please see the GLSA Announcement[7] 

 7. http://www.gentoo.org/security/en/glsa/glsa-200403-14.xml
    
=========================
3. Heard in the Community
=========================
  
Web Forums
----------
  
GLSA Integration in Portage 
 
Gentoo developer Genone has set up a sticky thread a while ago that deals 
with the upcoming integration of security announcements in Portage. Check 
here for updates to the script that is now in gentoolkit, before its final 
implementation as part of emerge:
 
 * portage GLSA integration (aka `emerge security`)[8] 
 * Portage GLSA integration project page[9]
 8. http://forums.gentoo.org/viewtopic.php?t=148463
 9. http://www.gentoo.org/proj/en/portage/glsa-integration.xml

 
The Colour: Purple... 
 
The "Lila Theme" is a new concerted effort at designing a Gentoo wallpaper 
and desktop icons collection, in purple (German: "lila") and pink, the 
predominant Gentoo colours. Sounds awful, looks stunningly beautiful, and 
it's entirely SVG-based, so you can generate your own PNGs with a Python 
script via Sodipodi or Inkscape! The Firefox theme has even made it onto 
the list of the "official" upstream themes. Here's where the artists 
coordinate their work:
 
 * Lila Theme Official Thread[10] 
 * dgt84's Gentoo Linux Artwork pages[11] 
 * KDE version by telex4[12] 
 * Firefox purple theme[13]
 10. http://forums.gentoo.org/viewtopic.php?t=145661
 11. http://programmer-art.org/index.php?page=gentoo
 12. http://www.kde-look.org/content/show.php?content=11492
 13. http://texturizer.net/firefox/themes/#Lila

=======================
4. Gentoo International
=======================
  
Germany: Yet Another GUM in Oberhausen
--------------------------------------
  
The next Gentoo User Meeting in Oberhausen (Ruhr region of central 
Germany) will take place this Wednesday, 7 April. The meeting point will 
again be the Gasthof Harlos[14], and the GUM starts at 19:00. Newcomers 
and regulars alike are most welcome. The coordination thread in the Forums 
is at its usual location[15].

 14. http://www.gasthof-harlos.de
 15. http://forums.gentoo.org/viewtopic.php?t=94915
    
===========
5. Bugzilla
===========
  
Summary
-------
  
 * Statistics 
 * Closed Bug Ranking 
 * New Bug Rankings 
    
Statistics
----------
  
The Gentoo community uses Bugzilla (bugs.gentoo.org[16]) to record and 
track bugs, notifications, suggestions and other interactions with the 
development team. Between 27 March 2004 and 02 April 2004, activity on the 
site has resulted in: 

 16. http://bugs.gentoo.org
 
 * 697 new bugs during this period 
 * 438 bugs closed or resolved during this period 
 * 20 previously closed bugs were reopened this period 
 
Of the 5510 currently open bugs: 130 are labeled 'blocker', 203 are 
labeled 'critical', and 460 are labeled 'major'. 
    
Closed Bug Rankings
-------------------
  
The developers and teams who have closed the most bugs during this period 
are: 
 
 * AMD64 Porting Team[17], with 76 closed bugs[18]  
 * Gentoo Security[19], with 17 closed bugs[20]  
 * Jeremy Huddleston[21], with 17 closed bugs[22]  
 * Gnome Desktop Team[23], with 15 closed bugs[24]  
 * Gentoo Games[25], with 15 closed bugs[26]  
 17. amd64@gentoo.org
 18. 
http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&
chfield=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&
resolution=FIXED&assigned_to=amd64@gentoo.org
19. security@gentoo.org 20. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&
chfield=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&
resolution=FIXED&assigned_to=security@gentoo.org
21. eradicator@gentoo.org 22. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&
chfield=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&
resolution=FIXED&assigned_to=eradicator@gentoo.org
23. gnome@gentoo.org 24. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&
chfield=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&
resolution=FIXED&assigned_to=gnome@gentoo.org
25. games@gentoo.org 26. http://bugs.gentoo.org/buglist.cgi?bug_status=RESOLVED&bug_status=CLOSED&
chfield=bug_status&chfieldfrom=2004-03-27&chfieldto=2004-04-02&
resolution=FIXED&assigned_to=games@gentoo.org
New Bug Rankings ---------------- The developers and teams who have been assigned the most new bugs during this period are: * Apache Herd[27], with 33 new bugs[28] * Core System Packages Team[29], with 20 new bugs[30] * Gentoo KDE team[31], with 19 new bugs[32] * Java team[33], with 17 new bugs[34] * AMD64 Porting Team[35], with 16 new bugs[36] 27. apache-bugs@gentoo.org 28. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&
bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&
chfieldto=2004-04-02&assigned_to=apache-bugs@gentoo.org
29. base-system@gentoo.org 30. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&
bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&
chfieldto=2004-04-02&assigned_to=base-system@gentoo.org
31. kde@gentoo.org 32. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&
bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&
chfieldto=2004-04-02&assigned_to=kde@gentoo.org
33. java@gentoo.org 34. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&
bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&
chfieldto=2004-04-02&assigned_to=java@gentoo.org
35. amd64@gentoo.org 36. http://bugs.gentoo.org/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&
bug_status=REOPENED&chfield=assigned_to&chfieldfrom=2004-03-27&
chfieldto=2004-04-02&assigned_to=amd64@gentoo.org
================== 6. Tips and Tricks ================== Multiple X-Sessions XFree86 allows you to have multiple X sessions open at once. This can be useful if you want or need two different desktop environments open at once. --------------------------------------------------------------------------- | Code Listing 6.1: | |-------------------------------------------------------------------------| | | | By default X uses the display :0 | |% startx | | To open a second display, use another number | |% startx -- :1 | --------------------------------------------------------------------------- The desktops will be on terminals F7-F12 =========================== 7. Moves, Adds, and Changes =========================== Moves ----- The following developers recently left the Gentoo team: * none this week Adds ---- The following developers recently joined the Gentoo Linux team: * none this week Changes ------- The following developers recently changed roles within the Gentoo Linux project: * none this week ==================== 8. Contribute to GWN ==================== Interested in contributing to the Gentoo Weekly Newsletter? Send us an email[37]. 37. gwn-feedback@gentoo.org =============== 9. GWN Feedback =============== Please send us your feedback[38] and help make the GWN better. 38. gwn-feedback@gentoo.org ================================ 10. GWN Subscription Information ================================ To subscribe to the Gentoo Weekly Newsletter, send a blank email to gentoo-gwn-subscribe@gentoo.org. To unsubscribe to the Gentoo Weekly Newsletter, send a blank email to gentoo-gwn-unsubscribe@gentoo.org from the email address you are subscribed under. =================== 11. Other Languages =================== The Gentoo Weekly Newsletter is also available in the following languages: * Dutch[39] * English[40] * German[41] * French[42] * Japanese[43] * Italian[44] * Polish[45] * Portuguese (Brazil)[46] * Portuguese (Portugal)[47] * Russian[48] * Spanish[49] * Turkish[50] 39. http://www.gentoo.org/news/be/gwn/gwn.xml 40. http://www.gentoo.org/news/en/gwn/gwn.xml 41. http://www.gentoo.org/news/de/gwn/gwn.xml 42. http://www.gentoo.org/news/fr/gwn/gwn.xml 43. http://www.gentoo.org/news/ja/gwn/gwn.xml 44. http://www.gentoo.org/news/it/gwn/gwn.xml 45. http://www.gentoo.org/news/pl/gwn/gwn.xml 46. http://www.gentoo.org/news/br/gwn/gwn.xml 47. http://www.gentoo.org/news/pt/gwn/gwn.xml 48. http://www.gentoo.org/news/ru/gwn/gwn.xml 49. http://www.gentoo.org/news/es/gwn/gwn.xml 50. http://www.gentoo.org/news/tr/gwn/gwn.xml Yuji Carlos Kosugi <carlos@gentoo.org> - Editor AJ Armstrong <aja@clanarmstrong.com> - Contributor Brian Downey <bdowney@briandowney.net> - Contributor Luke Giuliani <cold_flame@email.com> - Contributor Grant Goodyear <g2boojum@gentoo.org> - Contributor Aron Griffis <agriffis@gentoo.org> - Contributor Stuart Herbert <stuart@gentoo.org> - Contributor Kurt Lieber <klieber@gentoo.org> - Contributor Rafael Cordones Marcos <rcm@sasaska.net> - Contributor David Narayan <david@phrixus.net> - Contributor David Nielsen <Lovechild@foolclan.com> - Contributor Ulrich Plate <plate@gentoo.org> - Contributor Simon Holm Thagersen <simon@lysbro.net> - Danish Translation Jesper Brodersen <broeman@gentoo.org> - Danish Translation Arne Mejlholm <aaby@gentoo.org> - Danish Translation Hendrik Eeckhaut <Hendrik.Eeckhaut@UGent.be> - Dutch Translation Jorn Eilander <sephiroth@quicknet.nl> - Dutch Translation Bernard Kerckenaere <bernieke@bernieke.com> - Dutch Translation Peter ter Borg <peter@daborg.nl> - Dutch Translation Jochen Maes <linux@sejo.be> - Dutch Translation Roderick Goessen <rgoessen@home.nl> - Dutch Translation Gerard van den Berg <gerard@steelo.net> - Dutch Translation Matthieu Montaudouin <mat@frheaven.com> - French Translation Xavier Neys <neysx@gentoo.org> - French Translation Martin Prieto <riverdale@linuxmail.org> - French Translation Antoine Raillon <cabec2@pegase.net> - French Translation Sebastien Cevey <seb@cine7.net> - French Translation Jean-Christophe Choisy <mabouya@petitefleure.org> - French Translation Thomas Raschbacher <lordvan@gentoo.org> - German Translation Steffen Lassahn <madeagle@gentoo.org> - German Translation Matthias F. Brandstetter <haim@gentoo.org> - German Translation Lukas Domagala <Cyrik@gentoo.org> - German Translation Tobias Scherbaum <dertobi123@gentoo.org> - German Translation Daniel Gerholdt <Sputnik1969@gentoo.org> - German Translation Marc Herren <dj-submerge@gentoo.org> - German Translation Tobias Matzat <SirSeoman@gentoo.org> - German Translation Marco Mascherpa <mush@monrif.net> - Italian Translation Claudio Merloni <paper@tiscali.it> - Italian Translation Christian Apolloni <bsolar@bluewin.ch> - Italian Translation Stefano Lucidi <stefano.lucidi@gentoo-italia.org> - Italian Translation Katuyuki Konno <katuyuki@siva.ddo.jp> - Japanese Translation Hiroyuki Takeda <hiro@extreme.jspeed.jp> - Japanese Translation Masato Hatakeyama <hatake@mx2.ttcn.ne.jp> - Japanese Translation Masayoshi Nakamura <masayang@masasushi.com> - Japanese Translation Yasunori Fukudome <yasunori@mail.portland.co.uk> - Japanese Translation Tomoyuki Sakurai <web-gentoo-doc-jp@trombik.mine.nu> - Japanese Translation Lukasz Strzygowski <lucass@gentoo.pl> - Polish Translation Karol Goralski <gooroo@gentoo.pl> - Polish Translation Atila "Jedi" Bohlke Vasconcelos <bohlke@inf.ufrgs.br> - Portuguese (Brazil) Translation Eduardo Belloti <dudu@datavibe.net> - Portuguese (Brazil) Translation Jo??o Rafael Moraes Nicola <joaoraf@rudah.com.br> - Portuguese (Brazil) Translation Marcelo Gon??alves de Azambuja <mgazambuja@terra.com.br> - Portuguese (Brazil) Translation Otavio Rodolfo Piske <angusy@gentoobr.org> - Portuguese (Brazil) Translation Pablo N. Hess -- NatuNobilis <natunobilis@gentoobr.org> - Portuguese (Brazil) Translation Pedro de Medeiros <pzilla@yawl.com.br> - Portuguese (Brazil) Translation Ventura Barbeiro <venturasbarbeiro@ig.com.br> - Portuguese (Brazil) Translation Bruno Ferreira <blueroom@digitalmente.net> - Portuguese (Portugal) Translation Gustavo Felisberto <humpback@felisberto.net> - Portuguese (Portugal) Translation Jos?? Costa <jose_costa@netcabo.pt> - Portuguese (Portugal) Translation Luis Medina <metalgodin@linuxmail.org> - Portuguese (Portugal) Translation Ricardo Loureiro <rjlouro@rjlouro.org> - Portuguese (Portugal) Translation Aleksandr Martyncev <amncorp@bk.ru> - Russian Translator Sergey Galkin <gals_home@list.ru> - Russian Translator Sergey Kuleshov <svyatogor@gentoo.org> - Russian Translator Alex Spirin <asp13@mail.ru> - Russian Translator Denis Zaletov <dzaletov@rambler.ru> - Russian Translator Lanark <lanark@lanark.com.ar> - Spanish Translation Fernando J. Pereda <ferdy@ferdyx.org> - Spanish Translation Lluis Peinado Cifuentes <lpeinado@uoc.edu> - Spanish Translation Zephryn Xirdal T <ZEPHRYNXIRDAL@telefonica.net> - Spanish Translation Guillermo Juarez <katossi@usuarios.retecal.es> - Spanish Translation Jes??s Garc??a Crespo <correo@sevein.com> - Spanish Translation Carlos Castillo <carlos@castillobueno.com> - Spanish Translation Julio Castillo <julio@castillobueno.com> - Spanish Translation Sergio G??mez <s3r@fibertel.com.ar> - Spanish Translation Aycan Irican <aycan@core.gen.tr> - Turkish Translation Bugra Cakir <bugra@myrealbox.com> - Turkish Translation Cagil Seker <cagils@biznet.com.tr> - Turkish Translation Emre Kazdagli <emre@core.gen.tr> - Turkish Translation Evrim Ulu <evrim@core.gen.tr> - Turkish Translation Gursel Kaynak <gurcell@core.gen.tr> - Turkish Translation

(Log in to post comments)

Copyright © 2004, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds