<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="ARTICLE @ XOOPS powered by FeedCreator" -->
<rss version="0.91">
    <channel>
        <title>Ubuntu 正體中文站 :: 首頁</title>
        <description><![CDATA[首頁 XML]]></description>
        <link>http://www.ubuntu-tw.org/modules/planet/index.php</link>
        <lastBuildDate>Fri, 03 Sep 2010 05:04:04 +1600</lastBuildDate>
        <generator>ARTICLE @ XOOPS powered by FeedCreator</generator>
        <image>
            <url>http://www.ubuntu-tw.org/modules/planet/images/planet.png</url>
            <title>Ubuntu 正體中文站 :: 首頁</title>
            <link>http://www.ubuntu-tw.org/modules/planet/</link>
            <width>80</width>
            <height>15</height>
            <description>首頁 XML</description>
        </image>
        <language>zh-tw</language>
        <managingEditor>bluet at ubuntu-tw dot org</managingEditor>
        <webMaster>bluet at ubuntu-tw dot org</webMaster>
        <category>星球</category>
        <item>
            <title>USN-981-1: libwww-perl vulnerability</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2370</link>
            <description><![CDATA[<div class="field field-type-text field-field-referenced-cves"><br />      <div class="field-label">Referenced CVEs:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    CVE-2010-2253        </div><br />        </div><br /></div><br /><div class="field field-type-text field-field-description"><br />      <div class="field-label">Description:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    <div class="usn"><br />===========================================================<br />Ubuntu Security Notice USN-981-1            August 31, 2010<br />libwww-perl vulnerability<br />CVE-2010-2253<br />===========================================================<br /><br />A security issue affects the following Ubuntu releases:<br /><br />Ubuntu 6.06 LTS<br />Ubuntu 8.04 LTS<br />Ubuntu 9.04<br />Ubuntu 9.10<br />Ubuntu 10.04 LTS<br /><br />This advisory also applies to the corresponding versions of<br />Kubuntu, Edubuntu, and Xubuntu.<br /><br />The problem can be corrected by upgrading your system to the<br />following package versions:<br /><br />Ubuntu 6.06 LTS:<br />  libwww-perl                     5.803-4ubuntu0.1<br /><br />Ubuntu 8.04 LTS:<br />  libwww-perl                     5.808-1ubuntu0.1<br /><br />Ubuntu 9.04:<br />  libwww-perl                     5.820-1ubuntu0.1<br /><br />Ubuntu 9.10:<br />  libwww-perl                     5.831-1ubuntu0.1<br /><br />Ubuntu 10.04 LTS:<br />  libwww-perl                     5.834-1ubuntu0.1<br /><br />In general, a standard system update will make all the necessary changes.<br /><br />Details follow:<br /><br />It was discovered that libwww-perl incorrectly filtered filenames suggested<br />by Content-Disposition headers. If a user were tricked into downloading a<br />file from a malicious site, a remote attacker could overwrite hidden files<br />in the user's directory.<br /></div>        </div><br />        </div><br /></div><br />出處: http://www.ubuntu.com/usn/usn-981-1 SecurityTeam]]></description>
            <author>SecurityTeam</author>
            <pubDate>Tue, 31 Aug 2010 22:05:39 +1600</pubDate>
        </item>
        <item>
            <title>USN-980-1: bogofilter vulnerability</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2368</link>
            <description><![CDATA[<div class="field field-type-text field-field-referenced-cves"><br />      <div class="field-label">Referenced CVEs:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    CVE-2010-2494        </div><br />        </div><br /></div><br /><div class="field field-type-text field-field-description"><br />      <div class="field-label">Description:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    <div class="usn"><br />===========================================================<br />Ubuntu Security Notice USN-980-1            August 31, 2010<br />bogofilter vulnerability<br />CVE-2010-2494<br />===========================================================<br /><br />A security issue affects the following Ubuntu releases:<br /><br />Ubuntu 8.04 LTS<br />Ubuntu 9.04<br />Ubuntu 9.10<br />Ubuntu 10.04 LTS<br /><br />This advisory also applies to the corresponding versions of<br />Kubuntu, Edubuntu, and Xubuntu.<br /><br />The problem can be corrected by upgrading your system to the<br />following package versions:<br /><br />Ubuntu 8.04 LTS:<br />  bogofilter-bdb                  1.1.5-2ubuntu5.1<br />  bogofilter-sqlite               1.1.5-2ubuntu5.1<br /><br />Ubuntu 9.04:<br />  bogofilter-bdb                  1.1.7-1ubuntu1.1<br />  bogofilter-sqlite               1.1.7-1ubuntu1.1<br /><br />Ubuntu 9.10:<br />  bogofilter-bdb                  1.2.0-3ubuntu1.1<br />  bogofilter-sqlite               1.2.0-3ubuntu1.1<br /><br />Ubuntu 10.04 LTS:<br />  bogofilter-bdb                  1.2.1-0ubuntu1.1<br />  bogofilter-sqlite               1.2.1-0ubuntu1.1<br /><br />In general, a standard system update will make all the necessary changes.<br /><br />Details follow:<br /><br />Julius Plenz discovered that bogofilter incorrectly handled certain<br />malformed encodings. By sending a specially crafted email, a remote<br />attacker could exploit this and cause bogofilter to crash, resulting in a<br />denial of service.<br /></div>        </div><br />        </div><br /></div><br />出處: http://www.ubuntu.com/usn/usn-980-1 SecurityTeam]]></description>
            <author>SecurityTeam</author>
            <pubDate>Tue, 31 Aug 2010 21:46:56 +1600</pubDate>
        </item>
        <item>
            <title>USN-979-1: okular vulnerability</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2366</link>
            <description><![CDATA[<div class="field field-type-text field-field-referenced-cves"><br />      <div class="field-label">Referenced CVEs:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    CVE-2010-2575        </div><br />        </div><br /></div><br /><div class="field field-type-text field-field-description"><br />      <div class="field-label">Description:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    <div class="usn"><br />===========================================================<br />Ubuntu Security Notice USN-979-1            August 27, 2010<br />kdegraphics vulnerability<br />CVE-2010-2575<br />===========================================================<br /><br />A security issue affects the following Ubuntu releases:<br /><br />Ubuntu 9.04<br />Ubuntu 9.10<br />Ubuntu 10.04 LTS<br /><br />This advisory also applies to the corresponding versions of<br />Kubuntu, Edubuntu, and Xubuntu.<br /><br />The problem can be corrected by upgrading your system to the<br />following package versions:<br /><br />Ubuntu 9.04:<br />  okular                          4:4.2.2-0ubuntu2.1<br /><br />Ubuntu 9.10:<br />  okular                          4:4.3.2-0ubuntu1.1<br /><br />Ubuntu 10.04 LTS:<br />  okular                          4:4.4.2-0ubuntu1.1<br /><br />After a standard system update you need to restart any running instances<br />of okular to make all the necessary changes.<br /><br />Details follow:<br /><br />Stefan Cornelius of Secunia Research discovered a boundary error during<br />RLE decompression in the "TranscribePalmImageToJPEG()" function in<br />generators/plucker/inplug/image.cpp of okular when processing images<br />embedded in PDB files, which can be exploited to cause a heap-based<br />buffer overflow. (CVE-2010-2575)<br /></div>        </div><br />        </div><br /></div><br />出處: http://www.ubuntu.com/usn/usn-979-1 SecurityTeam]]></description>
            <author>SecurityTeam</author>
            <pubDate>Fri, 27 Aug 2010 10:06:17 +1600</pubDate>
        </item>
        <item>
            <title>為 mupdf 加上全螢幕切換功能</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2364</link>
            <description><![CDATA[昨天受邀去內湖某公司作簡報，因為 OpenOffice 產生的 PDF 檔案稍大，用 evince 播放時，略為停頓一下，致使跟不上預定的節奏，有些細節就不慎忽略。回辦公室後，認真思考改良 PDF 簡報放映的方式，歸納以下軟體需求： 避免太多相依性或執行時期的檔案 -- 讓任何一台裝有 GNU/Linux 的電腦都能作簡報與程式展示 快速 -- 就算播放幾十 MBytes 的 PDF 檔案也順暢 流暢鍵盤操作 -- 快速 zooming, 切換視角, 切換頁面，標注重點等等 open source -- 這還要說嗎？這年頭好多 closed source PDF viewer 根本就是 spy/ad-ware [MuPDF] 是目前最符合上述需求的軟體，輕薄短小，而且相當快速，但缺乏最重要的功能，也就是全螢幕播放，只好自己動手改。初步的 patch...<br />出處: http://blog.linux.org.tw/~jserv/archives/2010/08/_mupdf.html jserv]]></description>
            <author>jserv</author>
            <pubDate>Fri, 27 Aug 2010 16:50:00 +1600</pubDate>
        </item>
        <item>
            <title>Linux上的電子收銀機系統（POS）-LemonPOS</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2362</link>
            <description><![CDATA[最近我在幫一間我認識的小商店研究從原始的收銀方式，邁進到省錢、自由度又高的電子收銀機制（一般被稱為Point Of Sale的東西）方案。經過一番研究，我發現Ubuntu裡面內附的LemonPOS很符合需求，簡單好用，朋友並沒有開連鎖店，只是想把閒置的電腦拿來運用，不想買市面上一體式給很多分店用的那種專用高貴POS電腦，LemonpPOS剛好符合他需求，然後我覺得超讚的是，沒想到現在的USB條碼槍很棒，我跟認識書店老闆借一隻試用看看，首先先把自己建檔成一個商品XD然後把USB條碼槍插上去試刷看看。天哪，裝上去就直接可以用了！！！！好棒喔，Kernel直接就有driver耶！我只是拿現成的條碼槍用的說，沒去特別注意有沒有支援Linux，而且發現條碼槍很好玩，原來刷到的資料會盡入到當前的任何「游標焦點」，可以是console、編輯器、瀏覽器、bra..brahh，只是目前只有簡體中文的PO檔<br />出處: http://magicdesign.blogspot.com/2010/08/linuxpos-lemonpos.html 魔法設計師]]></description>
            <author>魔法設計師</author>
            <pubDate>Sat, 28 Aug 2010 10:17:00 +1600</pubDate>
        </item>
        <item>
            <title>USN-974-2: Linux kernel regression</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2360</link>
            <description><![CDATA[<div class="field field-type-text field-field-description"><br />      <div class="field-label">Description:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    <div class="usn"><br />===========================================================<br />Ubuntu Security Notice USN-974-2            August 26, 2010<br />linux regression<br /><a href="https://launchpad.net/bugs/620994" target="_blank">https://launchpad.net/bugs/620994</a><br />===========================================================<br /><br />A security issue affects the following Ubuntu releases:<br /><br />Ubuntu 8.04 LTS<br /><br />This advisory also applies to the corresponding versions of<br />Kubuntu, Edubuntu, and Xubuntu.<br /><br />The problem can be corrected by upgrading your system to the<br />following package versions:<br /><br />Ubuntu 8.04 LTS:<br />  linux-image-2.6.24-28-386       2.6.24-28.77<br />  linux-image-2.6.24-28-generic   2.6.24-28.77<br />  linux-image-2.6.24-28-hppa32    2.6.24-28.77<br />  linux-image-2.6.24-28-hppa64    2.6.24-28.77<br />  linux-image-2.6.24-28-itanium   2.6.24-28.77<br />  linux-image-2.6.24-28-lpia      2.6.24-28.77<br />  linux-image-2.6.24-28-lpiacompat  2.6.24-28.77<br />  linux-image-2.6.24-28-mckinley  2.6.24-28.77<br />  linux-image-2.6.24-28-openvz    2.6.24-28.77<br />  linux-image-2.6.24-28-powerpc   2.6.24-28.77<br />  linux-image-2.6.24-28-powerpc-smp  2.6.24-28.77<br />  linux-image-2.6.24-28-powerpc64-smp  2.6.24-28.77<br />  linux-image-2.6.24-28-rt        2.6.24-28.77<br />  linux-image-2.6.24-28-server    2.6.24-28.77<br />  linux-image-2.6.24-28-sparc64   2.6.24-28.77<br />  linux-image-2.6.24-28-sparc64-smp  2.6.24-28.77<br />  linux-image-2.6.24-28-virtual   2.6.24-28.77<br />  linux-image-2.6.24-28-xen       2.6.24-28.77<br /><br />After a standard system update you need to reboot your computer to make<br />all the necessary changes.<br /><br />Details follow:<br /><br />USN-974-1 fixed vulnerabilities in the Linux kernel. The fixes for<br />CVE-2010-2240 caused failures for Xen hosts. This update fixes the<br />problem.<br /><br />We apologize for the inconvenience.<br /><br />Original advisory details:<br /><br /> Gael Delalleu, Rafal Wojtczuk, and Brad Spengler discovered that the memory<br /> manager did not properly handle when applications grow stacks into adjacent<br /> memory regions. A local attacker could exploit this to gain control of<br /> certain applications, potentially leading to privilege escalation, as<br /> demonstrated in attacks against the X server. (CVE-2010-2240)<br /> <br /> Kees Cook discovered that under certain situations the ioctl subsystem for<br /> DRM did not properly sanitize its arguments. A local attacker could exploit<br /> this to read previously freed kernel memory, leading to a loss of privacy.<br /> (CVE-2010-2803)<br /> <br /> Ben Hawkes discovered an integer overflow in the Controller Area Network<br /> (CAN) subsystem when setting up frame content and filtering certain<br /> messages. An attacker could send specially crafted CAN traffic to crash the<br /> system or gain root privileges. (CVE-2010-2959)<br /></div>        </div><br />        </div><br /></div><br />出處: http://www.ubuntu.com/usn/usn-974-2 SecurityTeam]]></description>
            <author>SecurityTeam</author>
            <pubDate>Fri, 27 Aug 2010 02:36:03 +1600</pubDate>
        </item>
        <item>
            <title>我的ThinkpadX201i A22+Ubuntu10.04 webcam問題的解法</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2358</link>
            <description><![CDATA[之前提到發現webcam的問題已經解除了，開啟webcam導致xwindow崩潰的問題（其實開totem也會）我測試過只發生在Ubuntu官方包的rt kernel（一般的kernel不會），因為該rt kernel是舊的9.10 原碼tree編出來的，有不少問題，改用falk-t-j的PPA裡面的realtime kernel問題就解決了，唉，Ubuntu官方不太在意RT  kernel的運作XD自己要多努力了。我的機器也到了一個星期，機器用一個星期狀況很好，於是就給它貼上了貼紙，貼紙是 上上星期COSCUP2010第一天研討會晚上Ubutu BOF上拿的，看起來像好吃的日本便當吧？打開裡面裝著（偽）初音未來然後這一台可是Powered by Ubuntu，可沒有windows貼紙喔:)真的很推薦大家Thinkpad x201i A22，便宜（三萬有找）、沒OS、有傳統Thinkpad<br />出處: http://magicdesign.blogspot.com/2010/08/thinkpadx201i-a22ubuntu1004-webcam.html 魔法設計師]]></description>
            <author>魔法設計師</author>
            <pubDate>Thu, 26 Aug 2010 10:27:00 +1600</pubDate>
        </item>
        <item>
            <title>USN-977-1: MoinMoin vulnerabilities</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2356</link>
            <description><![CDATA[<div class="field field-type-text field-field-referenced-cves"><br />      <div class="field-label">Referenced CVEs:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    CVE-2010-2487, CVE-2010-2969, CVE-2010-2970        </div><br />        </div><br /></div><br /><div class="field field-type-text field-field-description"><br />      <div class="field-label">Description:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    <div class="usn"><br />===========================================================<br />Ubuntu Security Notice USN-977-1            August 25, 2010<br />moin vulnerabilities<br />CVE-2010-2487, CVE-2010-2969, CVE-2010-2970<br />===========================================================<br /><br />A security issue affects the following Ubuntu releases:<br /><br />Ubuntu 6.06 LTS<br />Ubuntu 8.04 LTS<br />Ubuntu 9.04<br />Ubuntu 9.10<br />Ubuntu 10.04 LTS<br /><br />This advisory also applies to the corresponding versions of<br />Kubuntu, Edubuntu, and Xubuntu.<br /><br />The problem can be corrected by upgrading your system to the<br />following package versions:<br /><br />Ubuntu 6.06 LTS:<br />  python2.4-moinmoin              1.5.2-1ubuntu2.7<br /><br />Ubuntu 8.04 LTS:<br />  python-moinmoin                 1.5.8-5.1ubuntu2.5<br /><br />Ubuntu 9.04:<br />  python-moinmoin                 1.8.2-2ubuntu2.5<br /><br />Ubuntu 9.10:<br />  python-moinmoin                 1.8.4-1ubuntu1.3<br /><br />Ubuntu 10.04 LTS:<br />  python-moinmoin                 1.9.2-2ubuntu3.1<br /><br />In general, a standard system update will make all the necessary changes.<br /><br />Details follow:<br /><br />It was discovered that MoinMoin did not properly sanitize its input,<br />resulting in cross-site scripting (XSS) vulnerabilities. With cross-site<br />scripting vulnerabilities, if a user were tricked into viewing server<br />output during a crafted server request, a remote attacker could exploit<br />this to modify the contents, or steal confidential data, within the same<br />domain.<br /></div>        </div><br />        </div><br /></div><br />出處: http://www.ubuntu.com/usn/usn-977-1 SecurityTeam]]></description>
            <author>SecurityTeam</author>
            <pubDate>Wed, 25 Aug 2010 23:46:03 +1600</pubDate>
        </item>
        <item>
            <title>USN-976-1: Tomcat vulnerability</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2354</link>
            <description><![CDATA[<div class="field field-type-text field-field-referenced-cves"><br />      <div class="field-label">Referenced CVEs:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    CVE-2010-2227        </div><br />        </div><br /></div><br /><div class="field field-type-text field-field-description"><br />      <div class="field-label">Description:&nbsp;</div><br />    <div class="field-items"><br />            <div class="field-item odd"><br />                    <div class="usn"><br />===========================================================<br />Ubuntu Security Notice USN-976-1            August 25, 2010<br />tomcat6 vulnerability<br />CVE-2010-2227<br />===========================================================<br /><br />A security issue affects the following Ubuntu releases:<br /><br />Ubuntu 9.04<br />Ubuntu 9.10<br />Ubuntu 10.04 LTS<br /><br />This advisory also applies to the corresponding versions of<br />Kubuntu, Edubuntu, and Xubuntu.<br /><br />The problem can be corrected by upgrading your system to the<br />following package versions:<br /><br />Ubuntu 9.04:<br />  libtomcat6-java                 6.0.18-0ubuntu6.3<br /><br />Ubuntu 9.10:<br />  libtomcat6-java                 6.0.20-2ubuntu2.2<br /><br />Ubuntu 10.04 LTS:<br />  libtomcat6-java                 6.0.24-2ubuntu1.3<br /><br />In general, a standard system update will make all the necessary changes.<br /><br />Details follow:<br /><br />It was discovered that Tomcat incorrectly handled invalid Transfer-Encoding<br />headers. A remote attacker could send specially crafted requests containing<br />invalid headers to the server and cause a denial of service, or possibly<br />obtain sensitive information from other requests.<br /></div>        </div><br />        </div><br /></div><br />出處: http://www.ubuntu.com/usn/usn-976-1 SecurityTeam]]></description>
            <author>SecurityTeam</author>
            <pubDate>Wed, 25 Aug 2010 23:38:36 +1600</pubDate>
        </item>
        <item>
            <title>Ubuntu Studio 10.04 進一步調校（音樂製作用）</title>
            <link>http://www.ubuntu-tw.org/modules/planet/view.article.php?2352</link>
            <description><![CDATA[為了音樂的製作，我們得把核心換成即時的核心，Ubuntu Studio 10.04目前有內附兩個即時核心，然而，他們是用Ubuntu 9.10的原碼tree編出來的，啟動時它們會抱怨：mount: mounting none on /dev failed No such device然後已經有人在PPA編譯了更好的即時核心，解決了這問題，可在falk-t-j的PPA找到，除了更好的即時核心以外，還有更多自由的sf2音色、取樣等等，全部共300多MB，對作音樂的幫助不小。<br />出處: http://magicdesign.blogspot.com/2010/08/ubuntu-studio-1004.html 魔法設計師]]></description>
            <author>魔法設計師</author>
            <pubDate>Tue, 24 Aug 2010 22:53:00 +1600</pubDate>
        </item>
    </channel>
</rss>