• [RFR] wml://www.debian.org/News/2024/20241109.wml

    From Carlos Henrique Lima Melara@21:1/5 to All on Sat Nov 9 05:00:02 2024
    --jgdxcviyyauy75eo
    Content-Type: text/plain; charset=utf-8
    Content-Disposition: inline
    Content-Transfer-Encoding: quoted-printable

    Boa noite,

    Amanhã será lançado o Debian 12.8 e aqui vai a tradução inicial que fiz baseada no anúncio anterior para revisão.

    Abraços,
    Charles

    --jgdxcviyyauy75eo
    Content-Type: text/vnd.wap.wml; charset=utf-8
    Content-Disposition: attachment; filename="20241109.wml" Content-Transfer-Encoding: quoted-printable

    <define-tag pagetitle>Atualização Debian 12: 12.8 lançado</define-tag> <define-tag release_date>2024-11-09</define-tag>
    #use wml::debian::news
    # $Id:

    <define-tag release>12</define-tag>
    <define-tag codename>bookworm</define-tag>
    <define-tag revision>12.8</define-tag>

    <define-tag dsa>
    <tr><td align="center"><a href="$(HOME)/security/%0/dsa-%1">DSA-%1</a></td>
    <td align="center"><:
    my @p = ();
    for my $p (split (/,\s*/, "%2")) {
    push (@p, sprintf ('<a href="https://packages.debian.org/src:%s">%s</a>', $p, $p));
    }
    print join (", ", @p);
    </td></tr>
    </define-tag>

    <define-tag correction>
    <tr><td><a href="https://packages.debian.org/src:%0">%0</a></td> <td>%1</td></tr>
    </define-tag>

    <define-tag srcpkg><a href="https://packages.debian.org/src:%0">%0</a></define-tag>

    <p>O projeto Debian está feliz em anunciar a oitava atualização de sua versão estável (stable) do Debian <release> (codinome <q><codename></q>). Esta versão pontual adiciona principalmente correções para problemas de segurança, além de pequenos ajustes para problemas mais sérios. Avisos de segurança já foram publicados em separado e são referenciados quando necessário.</p>

    <p>Por favor, note que a versão pontual não constitui uma nova versão do Debian
    <release>, mas apenas atualiza alguns dos pacotes já incluídos. Não há necessidade de jogar fora as antigas mídias do <q><codename></q>. Após a instalação, os pacotes podem ser atualizados para as versões atuais usando um
    espelho atualizado do Debian.</p>

    <p>Aquelas pessoas que frequentemente instalam atualizações a partir de security.debian.org não terão que atualizar muitos pacotes, e a maioria de tais
    atualizações estão incluídas na versão pontual.</p>

    <p>Novas imagens de instalação logo estarão disponíveis nos locais habituais.</p>

    <p>A atualização de uma instalação existente para esta revisão pode ser feita
    apontando o sistema de gerenciamento de pacotes para um dos muitos espelhos HTTP do Debian. Uma lista abrangente de espelhos está disponível em:</p>

    <div class="center">
    <a href="$(HOME)/mirror/list">https://www.debian.org/mirror/list</a>
    </div>


    <h2>Correções gerais de bugs</h2>

    <p>Esta atualização da versão estável (stable) adiciona algumas correções importantes para os seguintes pacotes:</p>

    <table border=0>
    <tr><th>Pacote</th> <th>Justificativa</th></tr>
    <correction 7zip "Fix heap buffer overflow in NTFS handler [CVE-2023-52168]; fix out-of-bounds read in NTFS handler [CVE-2023-52169]">
    <correction amanda "Update incomplete fix for CVE-2022-37704, restoring operation with xfsdump">
    <correction apr "Use 0600 perms for named shared mem consistently [CVE-2023-49582]">
    <correction base-files "Update for the point release">
    <correction btrfs-progs "Fix checksum calculation errors during volume conversion in btrfs-convert">
    <correction calamares-settings-debian "Fix missing launcher on KDE desktops; fix btrfs mounts">
    <correction cjson "Fix segmentation violation issue [CVE-2024-31755]"> <correction clamav "New upstream stable release; fix denial of service issue [CVE-2024-20505], file corruption issue [CVE-2024-20506]">
    <correction cloud-init "Add support for multiple networkd Route sections"> <correction cloud-initramfs-tools "Add missing dependencies in the initramfs"> <correction curl "Fix incorrect handling of some OCSP responses [CVE-2024-8096]">
    <correction debian-installer "Reinstate some armel netboot targets (openrd); increase Linux kernel ABI to 6.1.0-27; rebuild against proposed-updates">
    <correction debian-installer-netboot-images "Rebuild against proposed-updates"> <correction devscripts "bts: always upgrade to STARTTLS on 587/tcp; build-rdeps: add support for non-free-firmware; chdist: update sources.list examples with non-free-firmware; build-rdeps: use all available distros by default">
    <correction diffoscope "Fix build failure when processing a deliberately overlapping zip file in tests">
    <correction distro-info-data "Add Ubuntu 25.04">
    <correction docker.io "Fix bypassing of AuthZ plugins in some circumstances [CVE-2024-41110]">
    <correction dpdk "New upstream stable release">
    <correction exim4 "Fix crash in dbmnz when looking up keys with no content"> <correction fcgiwrap "Set proper ownership on repositories in git backend"> <correction galera-4 "New upstream stable release">
    <correction glib2.0 "Provide libgio-2.0-dev from libglib2.0-dev, and libgio-2.0-dev-bin from libglib2.0-dev-bin">
    <correction glibc "Change Croatian locale to use Euro as currency; revert upstream commit that modified the GLIBC_PRIVATE ABI, causing crashes with some static binaries on arm64; vfscanf(): fix matches longer than INT_MAX; ungetc(): fix uninitialized
    read when putting into unused streams, backup buffer leak on program exit; mremap(): fix support for the MREMAP_DONTUNMAP option; resolv: fix timeouts caused by short error responses or when single-request mode is enabled in resolv.conf">
    <correction gtk+3.0 "Fix letting Orca announce initial focus">
    <correction ikiwiki-hosting "Allow reading of all user repositories"> <correction intel-microcode "New upstream release; security fixes [CVE-2024-23984 CVE-2024-24968]">
    <correction ipmitool "Fix a buffer overrun in <q>open</q> interface; fix <q>lan print fails on unsupported parameters</q>; fix reading of temperature sensors; fix using hex values when sending raw data">
    <correction iputils "Fix incorrect handling of ICMP responses intended for other processes">
    <correction kexec-tools "Mask kexec.service to prevent the init.d script handling kexec process on a systemd enabled system">
    <correction lemonldap-ng "Fix cross-site scripting vulnerability on login page [CVE-2024-48933]">
    <correction lgogdownloader "Fix parsing of Galaxy URLs">
    <correction libskk "Prevent crash on invalid JSON escape">
    <correction libvirt "Fix running i686 VMs with AppArmor on the host; prevent certain guests from becoming unbootable or disappearing during upgrade">
    <correction linux "New upstream release; bump ABI to 27">
    <correction linux-signed-amd64 "New upstream release; bump ABI to 27"> <correction linux-signed-arm64 "New upstream release; bump ABI to 27"> <correction linux-signed-i386 "New upstream release; bump ABI to 27"> <correction llvm-toolchain-15 "Architecture-specific rebuild on mips64el to sync version with other architectures">
    <correction nghttp2 "Fix denial of service issue [CVE-2024-28182]">
    <correction ninja-build "Support large inode numbers on 32-bit systems"> <correction node-dompurify "Fix prototype pollution issues [CVE-2024-45801 CVE-2024-48910]">
    <correction node-es-module-lexer "Fix build failure">
    <correction node-globby "Fix build failure">
    <correction node-mdn-browser-compat-data "Fix build failure">
    <correction node-rollup-plugin-node-polyfills "Fix build failure">
    <correction node-tap "Fix build failure">
    <correction node-xterm "Fix TypeScript declarations">
    <correction node-y-protocols "Fix build failure">
    <correction node-y-websocket "Fix build failure">
    <correction node-ytdl-core "Fix build failure">
    <correction notify-osd "Correct executable path in desktop launcher file"> <correction ntfs-3g "Fix use-after-free in <q>ntfs-uppercase-mbs</q>; re-classify fuse as Depends, not Pre-Depends">
    <correction openssl "New upstream stable release; fix buffer overread issue [CVE-2024-5535], out of bounds memory access [CVE-2024-9143]">
    <correction ostree "Prevent crashing libflatpak when using curl 8.10"> <correction puppetserver "Reinstate scheduled job to clean reports after 30 days, avoiding disk space exhaustion">
    <correction puredata "Fix privilege escalation issue [CVE-2023-47480]"> <correction python-cryptography "Fix NULL dereference when loading PKCS7 certificates [CVE-2023-49083]; fix NULL dereference when PKCS#12 key and cert don't match [CVE-2024-26130]">
    <correction python3.11 "Fix regression in zipfile.Path; prevent ReDoS vulnerability with crafted tar archives">
    <correction reprepro "Prevent hangs when running unzstd">
    <correction sqlite3 "Fix a buffer overread issue [CVE-2023-7104], a stack overflow issue and an integer overflow issue">
    <correction sumo "Fix a race condition when building documentation"> <correction systemd "New upstream stable release">
    <correction tgt "chap: Use proper entropy source [CVE-2024-45751]">
    <correction timeshift "Add missing dependency on pkexec">
    <correction util-linux "Allow lscpu to identify new Arm cores">
    <correction vmdb2 "Set locale to UTF-8">
    <correction wireshark "New upstream security release [CVE-2024-0208, CVE-2024-0209, CVE-2024-2955, CVE-2024-4853, CVE-2024-4854, CVE-2024-4855, CVE-2024-8250, CVE-2024-8645]">
    <correction xfpt "Fix buffer overflow issue [CVE-2024-43700]">
    </table>


    <h2>Atualizações de segurança</h2>

    <p>Esta revisão adiciona as seguintes atualizações de segurança para a versão
    estável (stable).
    A equipe de segurança já lançou um aviso para cada uma dessas atualizações:</p>

    <table border=0>
    <tr><th>ID do aviso</th> <th>Pacote</th></tr>
    <dsa 2024 5729 apache2>
    <dsa 2024 5733 thunderbird>
    <dsa 2024 5744 thunderbird>
    <dsa 2024 5758 trafficserver>
    <dsa 2024 5759 python3.11>
    <dsa 2024 5760 ghostscript>
    <dsa 2024 5761 chromium>
    <dsa 2024 5762 webkit2gtk>
    <dsa 2024 5763 pymatgen>
    <dsa 2024 5764 openssl>
    <dsa 2024 5765 firefox-esr>
    <dsa 2024 5766 chromium>
    <dsa 2024 5767 thunderbird>
    <dsa 2024 5768 chromium>
    <dsa 2024 5769 git>
    <dsa 2024 5770 expat>
    <dsa 2024 5771 php-twig>
    <dsa 2024 5772 libreoffice>
    <dsa 2024 5773 chromium>
    <dsa 2024 5774 ruby-saml>
    <dsa 2024 5775 chromium>
    <dsa 2024 5776 tryton-server>
    <dsa 2024 5777 booth>
    <dsa 2024 5778 cups-filters>
    <dsa 2024 5779 cups>
    <dsa 2024 5780 php8.2>
    <dsa 2024 5781 chromium>
    <dsa 2024 5782 linux-signed-amd64>
    <dsa 2024 5782 linux-signed-arm64>
    <dsa 2024 5782 linux-signed-i386>
    <dsa 2024 5782 linux>
    <dsa 2024 5783 firefox-esr>
    <dsa 2024 5784 oath-toolkit>
    <dsa 2024 5785 mediawiki>
    <dsa 2024 5786 libgsf>
    <dsa 2024 5787 chromium>
    <dsa 2024 5788 firefox-esr>
    <dsa 2024 5789 thunderbird>
    <dsa 2024 5790 node-dompurify>
    <dsa 2024 5791 python-reportlab>
    <dsa 2024 5792 webkit2gtk>
    <dsa 2024 5793 chromium>
    <dsa 2024 5794 openjdk-17>
    <dsa 2024 5795 python-sql>
    <dsa 2024 5796 libheif>
    <dsa 2024 5797 twisted>
    <dsa 2024 5798 activemq>
    <dsa 2024 5799 chromium>
    <dsa 2024 5800 xorg-server>
    <dsa 2024 5802 chromium>
    </table>


    <h2>Instalador do Debian</h2>

    <p>O instalador foi atualizado para incluir as correções incorporadas
    na versão estável (stable) pela versão pontual.</p>


    <h2>URLs</h2>

    <p>As listas completas dos pacotes que foram alterados por esta revisão:</p>

    <div class="center">
    <url "https://deb.debian.org/debian/dists/<downcase <codename>>/ChangeLog"> </div>

    <p>A atual versão estável (stable):</p>

    <div class="center">
    <url "https://deb.debian.org/debian/dists/stable/">
    </div>

    <p>Atualizações propostas (proposed updates) para a versão estável (stable):</p>

    <div class="center">
    <url "https://deb.debian.org/debian/dists/proposed-updates">
    </div>

    <p>Informações da versão estável (stable) (notas de lançamento, errata, etc):</p>

    <div class="center">
    <a
    href="$(HOME)/releases/stable/">https://www.debian.org/releases/stable/</a> </div>

    <p>Anúncios de segurança e informações:</p>

    <div class="center">
    <a href="$(HOME)/security/">https://www.debian.org/security/</a>
    </div>


    <h2>Sobre o Debian</h2>

    <p>O projeto Debian é uma associação de desenvolvedores(as) de Software Livre
    que dedicam seu tempo e esforço como voluntários(as) para produzir o sistema operacional completamente livre Debian.</p>


    <h2>Informações de contato</h2>

    <p>Para mais informações, por favor visite as páginas web do Debian em
    <a href="$(HOME)/">https://www.debian.org/</a>, envie um e-mail (em inglês) para
    &lt;press@debian.org&gt;, ou entre em contato (em inglês) com a equipe de lançamento da versão estável (stable) em &lt;debian-release@lists.debian.org&gt;.</p>

    --jgdxcviyyauy75eo--

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmcu3EkACgkQt4M9ggJ8 mQvB2Q/9E18o967Q1saR7zgky2uFND/koFNMgbjszqOssHaB679rQNVY1UX4Zcg0 VX0cJYKUCX1CjCxLxm/p/w3RrMWXq2opQNvKCD0FMHa5BQq+2V48xzCRxhdqwsoZ dBkbIxZAMl5Dz506+oJEr/zwPAdAP01ZtSsIPaOATnWQSoxMH0ugTBf1UXPV0rCW Z3EWOQI3WE6JWFa9cF+Y1g5/NFZTGpevMlR5EHNx+sz0XH2GVGdI0TXfCnezm8YE kBuAZTp290BmTZUeMuZtiD3g49kjcCZLjP8vur/kG01Qms3NK96iThVQFRw+AUTp YFTik/UGjOX+I6iUH6FJBQDdKOE4BlkcxOzktQeNzQFMRT5sF8qhF0lSVc3ihWSC 3F4z70VETOhbTlDHgNC9y8rPIiOrTps5bgKKZx6KeAu5uR2vper+plpMq3M3nIAY w/REJ7kUGOI4VrjRBenkMq6cDkhi71Dj7MHjH5/WZ2wM+JOVBawXQn4x0fnga9E6 djde4qET7bq7Sumv97/N6VO2wvt5H/f5S5DE3m2UZkVpEX0Zvzz7VBWVCIt6xKGW eAv1jlR8iLAJQdqEg8ia/TvycypsjxMgz+LYzCuLnA6loszPj8dya47FIEmS4vPs Kmee0vJN6RaW9xjokQDgC6uwqwlnNPHN/mdiPF0HBH7YZc11uVc=
    =1YIf
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Carlos Henrique Lima Melara@21:1/5 to Carlos Henrique Lima Melara on Sat Nov 9 06:00:01 2024
    Boa noite de novo,

    On Sat, Nov 09, 2024 at 12:51:38AM -0300, Carlos Henrique Lima Melara wrote:
    Amanhã será lançado o Debian 12.8 e aqui vai a tradução inicial que fiz baseada no anúncio anterior para revisão.

    Agora que percebi que deveria ter colocado o repo announcements no
    título... segue a url para acessar a tradução [1]. O orinal está no
    mesmo repo em en/.

    Abraços,
    Charles

    [1] https://salsa.debian.org/publicity-team/announcements/-/blob/master/pt/2024/20241109.wml

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Carlos Henrique Lima Melara@21:1/5 to Carlos Henrique Lima Melara on Wed Nov 13 19:30:01 2024
    Boa tarde!

    On Sat, Nov 09, 2024 at 12:51:38AM -0300, Carlos Henrique Lima Melara wrote:
    Amanhã será lançado o Debian 12.8 e aqui vai a tradução inicial que fiz baseada no anúncio anterior para revisão.

    Obrigado pela revisão, pessoal!

    Abraços,
    Charles

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmc07p0ACgkQt4M9ggJ8 mQsy4A//VyD5tyAIzmIkyxI7CnwDlNBSXiYKZYo2Tnwo8Ac+dWC20EIYIGte9j3C IHEDsQT2udBL7FkyIn2AoS3a5NE6WaoGOlB1mzfdHBZcyrh3yG5gZ79xjTA9f8CH vLekSt+dTdPuGGUVNLPXRonPTnR1HPEPbGf12kFrZh2QJm3Iss+IwccGTrzIqikd VaoBPNuG2iXPBPgB2m61rnr9GrcLVgQ3xPX+xCO318xQw93bLXKbb+7c2HR/9hpJ Dw9OhvbUiwZqibAL/u7ezeKmfrhgkqeLBuWCb6TmCdWQ5JSRQro/BZTbZ/OvVK3l uyWehVwzb146i0mBnxqpM45I/6oM2GRXhrS5PDp8sAt7WfEOpT23Kcra2zoa9BRR k92iEbDGQa3xkNnSDleF3SJAa6efETp5ek5SjjCrwE8Wi/JpboJxxbGwVhAOzYYJ 7nOeKKZkqGfdsxgBhla98wQ/zm67KUSYRGiyGqTiasIdGMLOknFMJjYK4+VI1xbz auhR6RqMzuK8tTOZLrFwFehE165sWgiBmRrK484xEHvhphhcmZl687SltDz6ta8O n4tGHRa944Q4GOm4/lswSkml49hLetBJFx2ectz1GogBB2GYMDu04EUiy03Zsk6C JD5Rt4PzekvzJgevXExvmJGI6RfPkHAY6ze9kBqeKlhCBwfKZzs=
    =V9k2
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Thiago Pezzo@21:1/5 to All on Wed Nov 13 19:20:01 2024
    Salve, Charles. Revisão feita, nada a sugerir.
    Obrigado pelo trabalho!

    Abraços,
    Thiago Pezzo (Tico)



    November 9, 2024 at 1:38 AM, "Carlos Henrique Lima Melara" <charles@debian.org mailto:charles@debian.org?to=%22Carlos%20Henrique%20Lima%20Melara%22%20%3Ccharles%40debian.org%3E > wrote:




    Boa noite de novo,

    On Sat, Nov 09, 2024 at 12:51:38AM -0300, Carlos Henrique Lima Melara wrote:


    Amanhã será lançado o Debian 12.8 e aqui vai a tradução inicial que fiz
    baseada no anúncio anterior para revisão.

    Agora que percebi que deveria ter colocado o repo announcements no
    título... segue a url para acessar a tradução [1]. O orinal está no
    mesmo repo em en/.

    Abraços,
    Charles

    [1] https://salsa.debian.org/publicity-team/announcements/-/blob/master/pt/2024/20241109.wml

    <!DOCTYPE html><html><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8"></head><body>Salve, Charles. Revisão feita, nada a sugerir.<br>Obrigado pelo trabalho!<br><br><div class="rl-signature">Abraços,<br>Thiago Pezzo (Tico)</div><
    <br></div><div><br></div><p>November 9, 2024 at 1:38 AM, "Carlos Henrique Lima Melara" &lt;<a href="mailto:charles@debian.org?to=%22Carlos%20Henrique%20Lima%20Melara%22%20%3Ccharles%40debian.org%3E" target="_blank" tabindex="-1">charles@debian.org</a>
    &gt; wrote:<br></p><blockquote>Boa noite de novo,<div><br></div><div><br></div>On Sat, Nov 09, 2024 at 12:51:38AM -0300, Carlos Henrique Lima Melara wrote:<div><br></div><blockquote>Amanhã será lançado o Debian 12.8 e aqui vai a tradução inicial que
    fiz<div><br></div> baseada no anúncio anterior para revisão.</blockquote><div><br></div>Agora que percebi que deveria ter colocado o repo announcements no<div><br></div>título... segue a url para acessar a tradução [1]. O orinal está no<div><br></
    mesmo repo em en/.<div><br></div><div><br></div>Abraços,<div><br></div>Charles<div><br></div><div><br></div>[1] <a href="https://salsa.debian.org/publicity-team/announcements/-/blob/master/pt/2024/20241109.wml" target="_blank">https://salsa.debian.
    org/publicity-team/announcements/-/blob/master/pt/2024/20241109.wml</a></blockquote><div><br></div></body></html>

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Carlos Henrique Lima Melara@21:1/5 to Carlos Henrique Lima Melara on Tue Nov 19 13:30:01 2024
    Oi,

    On Wed, Nov 13, 2024 at 03:23:30PM -0300, Carlos Henrique Lima Melara wrote:
    On Sat, Nov 09, 2024 at 12:51:38AM -0300, Carlos Henrique Lima Melara wrote:
    Amanhã será lançado o Debian 12.8 e aqui vai a tradução inicial que fiz
    baseada no anúncio anterior para revisão.

    Obrigado pela revisão, pessoal!

    Fechando esta tradução.

    Abraços,
    Charles

    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmc8gv0ACgkQt4M9ggJ8 mQteRBAAt2Yo3+wboxFq1Ct0a1hofxQFuVDnEg8JEkWbTPJc4ABp2zQMrDcBRQWh FnKtAOpd0pLeFNSgSbhNDRXcXF9tV8EYuGA8QMVDvhbehKs58CaqD8WzsPRG0ux0 Pbs2FHBoBRLW9DOnc4MGjVBMSfN+q6AWCFKWhkM8Gzm1owTSuvz7OApuQiY0yI/B mLZGfjKzs+3EqyGWzRLAgt2fuGBwQ81nRjPn4LfYU7o9+7k4rgfX2vuVe540qgSl fWTWh057cLTw0JpYmygFE8HvoqyYze0bosKLoIA+RdRyM1/kEnsZBu8BdfJSAcal VMYtF55EvAfD0DnkSBk02wwlLPZNzJb4AcnqpGsd2xPxCSvpLdHok3riNWcKl91t /ZFvRzT3NhPBfffJW329jXFvCqZltZaNGOsgok9/cvCbW8tOJhscS3ipuffMMATz t/cvasUTowZsKqy6PgCTwKIi7xC1VeG/qqvGhB9dWijMlz43F8koKCpQhQOt/tKl GrUe8KHCkFHYfptGvoIsQmkY+M4qF/3nnIgIaw6X1N4KmfGQNhFWkytYo6rLUdYR rdDfooltKDtLOV7UcUDpysFYpRiESUiuPKXbPlEWTCPkmDAKwrEREp4olrtO+vk4 f4EnvXIX9Uj/FmvRJUOA2ViDmEO0MdBa+BIUkGOW8ds8V9H6+6U=
    =rf3x
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)