
Hello and welcome to Linux Security Weekly for October 21, 2012. Linux Security Weekly is the audio podcast which covers current and important security vulnerabilities in Linux and open source software for the past week.
Show Notes:
News
Oracle quarterly patch
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html
14 MySQL CVEs that we will never see
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html#AppendixMSQL
mod_security 2.7.0
https://twitter.com/ModSecurity/status/258374512851173378
http://mod-security.svn.sourceforge.net/viewvc/mod-security/m2/branches/2.7.x/CHANGES
Django
https://www.djangoproject.com/weblog/2012/oct/17/security/
Virtualbox 4.2.2
https://www.virtualbox.org/wiki/Changelog
PHP
http://www.php.net/archive/2012.php#id2012-10-18-1
Ubuntu 12.10
http://fridge.ubuntu.com/2012/10/18/ubuntu-12-10-quantal-quetzal-released/
OS X disables Java browser plugin OS X 10.6.8, 10.7 and 10.8
http://www.h-online.com/security/news/item/Apple-updates-Java-for-older-Mac-OS-X-kills-browser-plugin-1732089.html
Distro Updates
Red Hat
jboss-ec2-eap
http://rhn.redhat.com/errata/RHSA-2012-1376.html
Red Hat 6 – kernel
http://rhn.redhat.com/errata/RHSA-2012-1366.html
OpenStack Essex
http://rhn.redhat.com/errata/RHSA-2012-1378.html
http://rhn.redhat.com/errata/RHSA-2012-1379.html
java-1.7.0-openjdk
http://rhn.redhat.com/errata/RHSA-2012-1386.html
java-1.6.0-openjdk
http://rhn.redhat.com/errata/RHSA-2012-1385.html
http://rhn.redhat.com/errata/RHSA-2012-1384.html
java-1.6.0-sun
http://rhn.redhat.com/errata/RHSA-2012-1392.html
java-1.7.0-oracle
http://rhn.redhat.com/errata/RHSA-2012-1391.html
rhev-hypervisor6
http://rhn.redhat.com/errata/RHSA-2012-1375.html
Ubuntu
libgssglue
http://www.ubuntu.com/usn/usn-1612-1/
python2.5 and 2.4
http://www.ubuntu.com/usn/usn-1613-1/
http://www.ubuntu.com/usn/usn-1613-2/
Debian
libexif
http://www.debian.org/security/2012/dsa-2559
DNS vuln: CVE-2012-5166
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=690118
http://security-tracker.debian.org/tracker/CVE-2012-5166
