/srv/irclogs.ubuntu.com/2013/01/14/#ubuntu-meeting.txt

=== JoseAntonioR is now known as JoseeAntonioR
=== popey_ is now known as popey
=== doko_ is now known as doko
=== Tonio_ is now known as Tonio_aw
=== soren_ is now known as soren
=== Ursinha is now known as Ursinha-afk
=== Ursinha-afk is now known as Ursinha
=== chiluk_away is now known as chiluk
=== Ursinha is now known as Ursinha-afk
=== Ursinha-afk is now known as Ursinha
=== Tonio_aw is now known as Tonio_
=== yofel_ is now known as yofel
=== Tonio_ is now known as Tonio_aw
=== Tonio_aw is now known as Tonio_
=== Tonio_ is now known as Tonio_aw
=== Tonio_aw is now known as Tonio_
=== Tonio_ is now known as Tonio_aw
=== Tonio_aw is now known as Tonio_
=== Tonio_ is now known as Tonio_aw
=== tyhicks` is now known as tyhicks
=== chiluk is now known as chiluk_away
=== chiluk_away is now known as chiluk
jdstrandhi18:25
jdstrandsorry we are a bit late18:25
tyhickshello18:25
mdeslaur\o18:25
sarnoldhello18:25
* sbeattie waves18:25
jdstrand#startmeeting18:25
meetingologyMeeting started Mon Jan 14 18:25:46 2013 UTC.  The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology.18:25
meetingologyAvailable commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired18:25
jdstrandThe meeting agenda can be found at:18:26
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting18:26
jdstrand[TOPIC] Announcements18:26
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
jdstrandThanks to the following individuals who provided security for Ubuntu:18:26
jdstrandStefan Bader (smb) provided debdiffs for oneiric-quantal for xen18:27
jdstrandChad Miller (chad) for getting chromium-browser up to 23.0.1271.97 for lucid-quantal18:27
jdstrandBenjamin Drung (bdrung) provided an update for precise and quantal for vlc (LP: #1084054)18:27
ubottuLaunchpad bug 1084054 in vlc (Ubuntu Oneiric) "Denial of service via crafted PNG file" [Undecided,Confirmed] https://launchpad.net/bugs/108405418:27
jdstrandChristian Kuersteiner (ckuerste) provided a debdiff for precise for xymon (LP: #1092412)18:27
ubottuLaunchpad bug 1092412 in xymon (Ubuntu Oneiric) "Xymon Multiple XSS" [Undecided,New] https://launchpad.net/bugs/109241218:27
jdstrandYour work is very much appreciated and will keep Ubuntu users secure. Great job! :)18:27
jdstrand[TOPIC] Weekly stand-up report18:27
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
jdstrandI'll go first18:27
jdstrandI'm on triage today18:27
jdstrandrather, this week18:28
jdstrandI planned to get nss out last week, but was unable. I need to do new upstream releases for nss and nspr for this update, and I spent last week preparing those18:29
jdstrandthat should go out today or tomorrow18:29
jdstrandchromium-browser (as mentioned) is now at 23.0.1271.97 for the stable releases, but upstream releases 24 last week, so I'll be sponsoring/testing that as well18:29
mdeslaur±o/18:30
mdeslaurargh18:30
mdeslaur\o/18:30
jdstrandI'm going to look at the recent java issue some more18:30
jdstrandand I need to patch pilot18:31
jdstrandmdeslaur: you're up18:31
mdeslaurI'm on community this week18:31
mdeslaurI've just released a couple of security updates, and will pick some more off the list18:31
mdeslaurand that's pretty much it. sbeattie, you're up18:32
sbeattieI'm again an apparmor monkey this week18:32
sbeattieMy primary focus is on getting the display manager prototype going18:33
sbeattieI'm not sure where jjohansen is on getting the alpha out the door, but may pitch in to help on that after getting 2.8.1 out last week.18:33
sbeattieI'll also poke at the random things that have popped up on the list.18:34
sbeattiethat's it for me. tyhicks?18:34
tyhicksSimilar to last week. Embargoed item and apparmor policy kernel interface.18:34
tyhicksThat's it for me. Back to you, jdstrand18:34
jdstrandactually, we skipped sarnold18:35
jdstrandsarnold: you're up18:35
mdeslaurwho's sarnold?18:35
tyhickssorry, sarnold :)18:35
mdeslaur:)18:35
sarnoldI'm in happy place this week, hoping to make forward progress on dnsmasq update, now using mdeslaur's suggestion for VM with two NICs, will combine with jdstrand's suggestion to use two VMs rather than do the testing via my host...18:35
sarnold.. but if I have more trouble reproducing the reporter's situation, I'll be leaning towards just regression testing.18:36
mdeslaursarnold: sounds reasonable18:37
sarnold(I'm thinking end-of-the-day today as the decision point...)18:37
sarnoldjdstrand: back to you18:37
mdeslaursarnold: you can get one of us to review your changes too, as a sanity check/second opinion since it affects an important package18:38
sarnoldmdeslaur: thanks :)18:38
jdstrand[TOPIC] Highlighted packages18:38
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
jdstrandThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.18:38
jdstrandSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.18:38
jdstrandNormally we provide a list of 5 packages. However, this week I'd like to ask for help on updating the recent raills vulnerabilities:18:39
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0156.html18:39
ubottuactive_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity referen... (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0156)18:39
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-0155.html18:39
ubottuRuby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated b... (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0155)18:39
jdstrand[TOPIC] Miscellaneous and Questions18:40
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
jdstrandDoes anyone have any other questions or items to discuss?18:40
jdstrandmdeslaur, sbeattie, tyhicks, sarnold: thanks!18:43
jdstrand#endmeeting18:43
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Jan 14 18:43:36 2013 UTC.18:43
meetingologyMinutes (wiki):        http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-01-14-18.25.moin.txt18:43
meetingologyMinutes (html):        http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-01-14-18.25.html18:43
sarnoldthanks jdstrand :)18:43
mdeslaurthanks jdstrand!18:43
tyhicksthanks!18:43
sbeattiethanks jdstrand18:43
=== Tonio_aw is now known as Tonio_
=== Ursinha is now known as Ursinha-afk
=== Ursinha-afk is now known as Ursinha
=== Tonio_ is now known as Tonio_aw
=== Tonio_aw is now known as Tonio_
=== Tonio_ is now known as Tonio_aw
=== Tonio_aw is now known as Tonio_
=== Tonio_ is now known as Tonio_aw
=== Tonio_aw is now known as Tonio_

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!