pPlusieurs vulnérabilités ont été découvertes dans Libvirt, une bibliothèque
d'abstraction de virtualisation.

Le projet « Common Vulnerabilities and Exposures » (CVE) identifie les
problèmes suivants./p


lia href=https://security-tracker.debian.org/tracker/CVE-2014-0179;CVE-2014-0179/a

pRichard Jones et Daniel P. Berrange ont découvert que libvirt passe l'option
XML_PARSE_NOENT quand il analyse les documents XML en utilisant la bibliothèque
libxml2, auquel cas, toutes les entités XML des documents analysés sont
extraites. Un utilisateur pouvant forcer libvirtd à analyser un document XML
avec une entité pointant vers un fichier spécial qui bloque les accès en lecture
pourrait utiliser ce défaut pour forcer libvirtd à être indéfiniment suspendu,
aboutissant à un déni de service à l'encontre du système./p/li

lia href=https://security-tracker.debian.org/tracker/CVE-2014-3633;CVE-2014-3633/a

pLuyao Huang de Red Hat a découvert que l'implémentation de qemu
virDomainGetBlockIoTune calculait un index dans le tableau des disques pour la
définition éphémère, puis l'utilisait comme index dans le tableau des disques
pour la définition persistante, ce qui pourrait résulter en un accès en lecture
hors limites dans qemuDomainGetBlockIoTune()./p

pUn attaquant distant, pouvant établir une connexion en lecture seule avec
libvirtd, pourrait utiliser ce défaut pour faire planter libvirtd ou,
éventuellement, provoquer une fuite de mémoire à partir du processus libvirtd./p/li


pPour la distribution stable (Wheezy), ces problèmes ont été corrigés dans la version

pPour la distribution unstable (Sid), ces problèmes ont été corrigés dans la version 1.2.8-2./p

pNous vous recommandons de mettre à jour vos paquets libvirt./p

pAntoine Delignat-Lavaud de l'Inria a découvert un problème dans la façon
dont la bibliothèque qNetwork Security Service/q de Mozilla (NSS) embarquée
dans la version d'Icedove de Wheezy, analysait les données ASN.1 utilisées dans
les signatures, la rendant vulnérable à une attaque par signature contrefaite./p

pUn attaquant pourrait créer des données ASN.1 pour contrefaire des
certificats RSA avec une chaîne de certification valide vers une autorité de
certification de confiance./p

pPour la distribution stable (Wheezy), ce problème a été corrigé dans la version 24.8.1-1~deb7u1./p

pPour les distributions testing (Jessie) et unstable (Sid), Icedove utilise la
bibliothèque NSS du système, traitée par l'annonce de sécurité DSA 3033-1./p

pNous vous recommandons de mettre à jour vos paquets icedove./p

We just finished the last bits of the
new issue of DPN to be released on Monday September 29, after 20:00 UTC.
As we haven't released an issue for several weeks, a lot of contents
accumulated and this issue is quite long. We would very much appreciate
reviews and translations.

Instructions are available on the wiki:

The last updated version is available on the publicity
Subversion repository, even via HTTP:

If you're willing to contribute to the redaction of the next issue,
don't hesitate, and join #debian-publicity IRC channel or send a message
to debian-public...@lists.debian.org.


intro issue=thirteen /

toc-add-entry name=rtbitsBits from the release team and Jessie's freeze/toc-add-entry

Adam D. Barrat sent
a href=https://lists.debian.org/debian-devel-announce/2014/09/msg2.html;some
new of the release team/a. The window for new transitions closed on September
5. Ongoing transitions should be completed as quickly as possible. The final
architecture check was completed mid September, and the current agreed list
list of architectures for Jessie is amd64, armel and armhf, i386,
kfreebsd-amd64 and kfreebsd-i386, mips, mipsel, powerpc and s390x. The final
decision for kFreeBSD ports, for which human resources is a concern, and arm64
and ppc64el ports, which made good progress and have strong support is expected
in the very beginning of November.
The freeze for Jessie is scheduled for November 5. In order to get their
packages in Jessie before the freeze, maintainers of packages should take into
account the fact that starting from October 5, the migration delay for all
packages uploaded to unstable to enter Jessie will be 10 days. 

On a related topic,
Lucas Nussbaum asks, qWill the packages you rely on be part of Debian Jessie?/q, 
with a helpful a href=http://www.lucas-nussbaum.net/blog/?p=837;series of steps/a you can use to be prepared.
Please also read the a href=https://release.debian.org/jessie/freeze_policy.html;Freeze Policy for jessie/a to ensure you are in fact ready, 
prepared, and are aware of the procedures taking place. 

toc-add-entry name=DebConf14DebConf14: Talks, thoughts, comments and progress/toc-add-entry

The annual Debian developer meeting took place in Portland, Oregon, 23 to 31
August 2014. a href=http://debconf14.debconf.org/;DebConf14/a attendees
participated in talks, discussions, workshops and programming sessions. Video
teams captured a lot of the main talks and discussions for streaming for
interactive attendees and for the a
href=http://meetings-archive.debian.net/pub/debian-meetings/;Debian video
archive/a. Between the video, presentations, and handouts the coverage came
from the attendees in blogs, posts, and project updates of which we've
gathered a few for your reading over on the a
href=http://blog.debconf.org/debconf14/wrap-up.dc;DebConf blog/a.

toc-add-entry name=DebConf-fundraisingHelp DebConf15 raise funds/toc-add-entry

The DebConf team is well into the organization of
a href=http://debconf15.debconf.org;DebConf15/a which will take place in Heidelberg,
Germany, in August of 2015. They are now contacting potential sponsors from
all around the globe and have prepared
brochure/a that summarises DebConf and the available sponsoring benefits. If
you can think of interested organizations, please consider asking them to
sponsor. If you would prefer not to ask directly, please contact the
a href=mailto:spons...@debconf.orgfundraising team/a with any leads.

Please have a look at a
announcement/a for more information.

toc-add-entry name=DebConf15-announcedDebConf15 dates are set, come and join us!/toc-add-entry

DebConf15 dates are set: the conference will take place from 15 to 22 August
2015 in Heidelberg. Members of the public are invited to the Opening Weekend,
where a wide range of content and events will be offered. DebConf will also be
preceeded by DebCamp.

The DebConf15 team presented their conference plans in a full session at
DebConf14 (watch a
video/a), and provided an executive summary during the closing ceremony (a

passage non traduit.


