Bug

Submission + - Linux Xorg Critical Security Flaw Silently Patched (softpedia.com)

eldavojohn writes: On June 17th, the X.org team was notified by Invisible Things Lab of a critical security flaw (PDF) that affected both x86_32 and x86_64 platforms. The flaw deals with escalated privileges of a user process that has access to the X server. The founder of ITL said of the flaw, 'The attack allows a (unpriviliged) user process that has access to the X server (so, any GUI application) to unconditionally escalate to root (but again, it doesn't take advantage of any bug in the X server!). In other words: any GUI application (think e.g. sandboxed PDF viewer), if compromised (e.g. via malicious PDF document) can bypass all the Linux fancy security mechanisms, and escalate to root, and compromise the whole system.' This has apparently been a security flaw since kernel 2.6 was released. From the article, 'On 13 August, Linus Torvalds committed an initial fix, but several patches were added afterward for various reasons. The problem has been addressed in versions 2.6.27.52, 2.6.32.19, 2.6.34.4 and 2.6.35.2 of the kernel.'
Linux

Submission + - Linux wall warts small on size, big on possibiliti (itwire.com)

davidmwilliams writes: Every geek and technology lover will undoubtedly have stumbled across online adverts for tiny headless Linux-powered devices that are barely larger than the power point they plug into. What can you actually do with them? Plenty, it seems!
Ubuntu

Gestures With Multitouch In Ubuntu 10.10 185

jitendraharlalka writes "Mark Shuttleworth recently announced on his blog that the first cut of Canonical's UTouch framework is ready and will be available in Ubuntu Maverick. He goes on to talk about the development of 'touch language' by the design team. The 'touch language' will allow the chaining of basic gestures to create complex gestures. The approach is quite different from the single magic gestures implemented elsewhere. In Maverick, a few Gtk applications will support gesture-based scrolling."
Debian

Happy 17th Birthday, Debian! 225

An anonymous reader writes "Debian turns 17 today. Yes it has really come a long way from being Murdock's pet project back in 1993 to being the distribution on which the most popular Linux distribution, Ubuntu, is now based."
Windows

Submission + - New Jaguar XJ suffers Blue Screen of Death (cnet.co.uk)

An anonymous reader writes: CNET UK is reporting that it crashed a £90,000 Jaguar XJ Super Sport — one of the most technologically advanced cars on the planet today. It's not the sort of crash you'd imagine, however — An unforseen glitch somewhere within the car's dozens of separate onboard computers, 100s of millions of lines of code or its internal vehicular network led to the dramatic BSOD, which had to be resolved with the use of a web-connected laptop.
KDE

KDE 4.5 Released 302

An anonymous reader writes "KDE 4.5.0 has been released to the world. See the release announcement for details. Highlights include a Webkit browser rendering option for Konqueror, a new caching mechanism for a faster experience and a re-worked notification system. Another new feature is Perl bindings, in addition to Python, Ruby and JavaScript support. The Phonon multimedia library now integrates with PulseAudio. See this interview with KDE developer and spokesperson Sebastian Kugler on how KDE can continue to be innovative in the KDE4 age. Packages should be available for most Linux distributions in the coming days. More than 16000 bug fixes were committed since 4.4."
Ubuntu

Canonical Begins Tracking Ubuntu Installations 548

suraj.sun passes along this excerpt from Phoronix: "Just uploaded to the Ubuntu Lucid repository for Ubuntu 10.04 LTS (and we imagine it will appear shortly in Maverick too for Ubuntu 10.10) is a new package called canonical-census, which marks its initial release. Curious about what this package provides, we did some digging and found it's for tracking Ubuntu installations by sending an 'I am alive' ping to Canonical on a daily basis. When the canonical-census package is installed, the program is to be added to the daily Cron jobs to be executed so that each day it will report to Canonical over HTTP the number of times this system previously sent to Canonical (this counter is stored locally and with it running on a daily basis it's thereby indicating how many days the Ubuntu installation has been active), the Ubuntu distributor channel, the product name as acquired by the system's DMI information, and which Ubuntu release is being used. That's all that canonical-census does, at least for now. Previously there haven't been such Ubuntu tracking measures attempted by Canonical."
Ubuntu

Submission + - Canonical Begins Tracking Ubuntu Installations (phoronix.com)

suraj.sun writes: Canonical Begins Tracking Ubuntu Installations, On a Daily Basis

Just uploaded to the Ubuntu Lucid repository for Ubuntu 10.04 LTS (and we imagine it will appear shortly in Maverick too for Ubuntu 10.10) is a new package called canonical-census, which marks its initial release. Curious about what this package provides, we did some digging and found it's for tracking Ubuntu installations by sending an "I am alive" ping to Canonical on a daily basis.

When the canonical-census package is installed, the program is to be added to the daily Cron jobs to be executed so that each day it will report to Canonical over HTTP the number of times this system previously sent to Canonical (this counter is stored locally and with it running on a daily basis it's thereby indicating how many days the Ubuntu installation has been active), the Ubuntu distributor channel, the product name as acquired by the system's DMI information, and which Ubuntu release is being used. That's all that canonical-census does, at least for now. Previously there haven't been such Ubuntu tracking measures attempted by Canonical.

Phoronix: http://www.phoronix.com/scan.php?page=news_item&px=ODQ5MA

Debian

Debian 6.0 "Squeeze" Frozen 202

edesio writes with a snippet from debian-news.net, trumpeting an announcement from the ongoing DebConf10 in NYC: "Debian's release managers have announced a major step in the development cycle of the upcoming stable release Debian 6.0 'Squeeze': Debian 'Squeeze' has now been frozen. In consequence this means that no more new features will be added and all work will now be concentrated on polishing Debian 'Squeeze' to achieve the quality Debian stable releases are known for. The upcoming release will use Linux 2.6.32 as its default kernel in the installer and on all Linux architectures.""
Debian

Submission + - Debian 6.0 “Squeeze” frozen (debian-news.net)

edesio writes: From debian-news.net:

"In this very moment, during the ongoing annual Debian Developer
Conference “Debconf10 in New York, Debian’s release managers have
announced a major step in the development cycle of the upcoming stable release Debian 6.0 “Squeeze”: Debian “Squeeze” has now been frozen.

In consequence this means that no more new features will be added and
all work will now be concentrated on polishing Debian “Squeeze” to
achieve the quality Debian stable releases are known for.

The upcoming release will use Linux 2.6.32 as its default kernel
in the installer and on all Linux architectures."

Announcements

Linux Kernel 2.6.35 Released 159

eldavojohn writes "Linus has announced the release of 2.6.35 for people to download and test after he found not a lot of changes between this week and last. The big features to look out for include: 'Transparent spreading of incoming network traffic load across CPUs, Btrfs improvements, KDB kernel debugger frontend, Memory compaction and Support for multiple multicast route tables' as well as various performance and graphics improvements. Linus also praised the community saying that 'regression changes only' after rc1 improved this time around and gave numbers to back it up saying 'in the 2.6.34 release, there were 3800 commits after -rc1, but in the current 35 release cycle we had less than 2000.' Good to see the process is becoming more refined and controlled after the first release candidate — hopefully there's no impending burnout."
Announcements

Submission + - Linux Kernel 2.6.35 Released (lwn.net) 2

eldavojohn writes: Linus has announced the release of 3.6.35 for people to download and test after he found not a lot of changes between this week and last. The big features to look out for include: "Transparent spreading of incoming network traffic load across CPUs, Btrfs improvements, KDB kernel debugger frontend, Memory compaction and Support for multiple multicast route tables" as well as various performance and graphics improvements. Linus also praised the community saying that 'regression changes only' after rc1 improved this time around and gave numbers to back it up saying "in the 2.6.34 release, there were 3800 commits after -rc1, but in the current 35 release cycle we had less than 2000." Good to see the process is becoming more refined and controlled after the first release candidate — hopefully there's no impending burnout.
GNOME

First GNOME Census Results 175

supersloshy writes "The GNOME Census, a project to see who contributes to GNOME and how, has released its first set of results. The results group people by their reasons to contribute code, what they contributed code to, and what percentage of the total contributions they have. For example, 23.45% of code contributions were volunteer, 16.3% of code contributions came from Red Hat, 1% of contributions came from Canonical (which has caused a lot of controversy), and 0.24% came from Mozilla Corporation. The census results are also represented in diagrams (release activity, why contributions were made, and what was contributed to and by who). The report is also available here and is licensed under a Creative Commons Attribution Share-Alike license."

Slashdot Top Deals