Vulnerability Remediation Synopsis Version 0.4Russ Klanke Page 1

Total Page:16

File Type:pdf, Size:1020Kb

Vulnerability Remediation Synopsis Version 0.4Russ Klanke Page 1 Contents Qualys as a mitigation recommendation tool (Knowledge Base) ........................................................... 21 Adobe Flash Vulnerabilities .................................................................................................................... 23 Adobe Flash Player Multiple Vulnerabilities (QID 116536) ................................................................ 23 Adobe Reader Vulnerabilities ................................................................................................................. 24 Adobe Acrobat/Reader "util.printf()" Buffer Overflow Vulnerability (QID 116027)........................... 24 Sun Solaris Adobe Reader Multiple Vulnerabilities (QID 116386) ...................................................... 24 Sun Solaris Adobe Reader Multiple Vulnerabilities (QID 116437) ...................................................... 25 Apache Vulnerabilities ............................................................................................................................ 27 Discovery of Unix Account Names Vulnerability (QID 5001) .............................................................. 27 "test-cgi" CGI Vulnerability (QID 10015) ............................................................................................. 27 Apache HTTP Server Multiple Cross-Site Scripting Vulnerabilities (QID 12260) ................................. 28 Apache Axis2/Java "modules" Cross-Site Scripting (XSS) Vulnerability (QID 12370).......................... 29 Apache Axis2 Default Administrative Access (QID 12499) ................................................................. 29 Apache HTTP Server APR "apr_fnmatch()" Denial of Service Vulnerability (QID 12500) ................... 30 Apache HTTP Server Mod_Proxy Denial of Service Vulnerability (QID 62057) .................................. 30 Apache CGI Source Code Viewing Vulnerability (QID 86054) ............................................................. 31 Apache Webserver /server-status Information Disclosure Vulnerability (QID 86410) ...................... 31 Apache 2.x HTTP Server Linefeed Memory Allocation Denial of Service Vulnerability (QID 86482) . 32 Apache 2.x Web Server File Descriptor Leakage Vulnerability (QID 86483) ....................................... 32 Apache Basic Authentication Module Valid User Login Denial of Service Vulnerability (QID 86532) 33 Miscellaneous Apache Vulnerabilities (2.0.46 and earlier) (QID 86562) ............................................ 33 Apache HTTP Server Buffer Overflow Vulnerabilities In mod_alias And mod_rewrite (QID 86600) . 34 Apache2 MOD_CGI STDERR Denial of Service Vulnerability (QID 86636) .......................................... 34 Apache Web Server Type-Map Recursive Loop Denial of Service Vulnerability (QID 86637) ............ 35 Apache 2.0.49 And Earlier Miscellaneous Vulnerabilities (QID 86643) .............................................. 35 Multiple Apache Web Server Vulnerabilities prior to version 2.0.51 (QID 86678) ............................. 36 Multiple Apache 1.3.32 and Earlier Web Server Local Buffer Overflow Vulnerabilities (QID 86680) 36 Apache 2.0.35-2.0.52 Memory Consumption Denial of Service and mod_ssl SSLCipherSuite Bypass (QID 86683) ......................................................................................................................................... 37 Apache CGI Byterange Request Denial of Service Vulnerability (QID 86713) .................................... 37 Vulnerability Remediation Synopsis version 0.4Russ Klanke Page 1 Apache Tomcat Simultaneous Directory Listing Denial of Service Vulnerability (QID 86724) ........... 38 Apache MPM Worker.C Denial of Service Vulnerability (QID 86726) ................................................ 39 Apache Mod_IMAP Referer Cross-Site Scripting Vulnerability (QID 86727) ...................................... 40 Apache Web Server fails to sanitize Escape Sequence Injection into its Access Logs (QID 86744) .... 41 Apache Web Server fails to sanitize Escape Sequence Injection into its Error Logs (QID 86745) ...... 41 Apache Mod_Rewrite Off-By-One Buffer Overflow Vulnerability (QID 86746) ................................. 42 Apache Tomcat JK Web Server Connector Security Bypass Vulnerability (QID 86764) ...................... 42 Apache HTTP Server 413 Error HTTP Request Method Cross-Site Scripting (XSS) Weakness (QID 86771) ................................................................................................................................................. 43 Apache mod_ssl Denial of Service Vulnerability (QID 86773) ............................................................ 44 Apache Tomcat Information Disclosure Vulnerability (QID 86775).................................................... 44 Apache Tomcat Absolute Path Traversal Vulnerability (QID 86776) .................................................. 45 Apache Tomcat Accept-Language Cross-Site Scripting (XSS) Vulnerability (QID 86777) .................... 46 Apache Tomcat SingleSignOn Remote Information Disclosure Vulnerability (QID 86779) ................ 47 Apache Tomcat 4, 5 and 6 Examples Web Application Multiple Cross-Site Scripting (XSS) Vulnerabilities (QID 86781) ................................................................................................................. 47 Apache Tomcat Multiple Cross-Site Scripting (XSS) Vulnerabilities in Manager and Host Manager Web Applications (QID 86782) ............................................................................................................ 48 Apache Tomcat 4.1 Cross-Site Scripting (XSS) Vulnerability (QID 86783) .......................................... 49 Apache Tomcat 4 and 5 Cross-Site Scripting (XSS) Vulnerability in Calendar Application in JSP Examples (QID 86785) ......................................................................................................................... 49 Apache Tomcat Servlet Host Manager Servlet Cross-Site Scripting (XSS) Vulnerability (QID 86786) 50 Apache 2.2 Multiple Vulnerabilities (QID 86788) ............................................................................... 51 Apache Tomcat Multiple Content Length Headers Information Disclosure Vulnerability (QID 86789) ............................................................................................................................................................ 52 Apache Tomcat 4 Denial of Service Vulnerability (QID 86790) ........................................................... 52 Apache Tomcat 4 Information Disclosure Vulnerability (QID 86791) ................................................. 52 Apache Tomcat 6 Information Disclosure Vulnerability (QID 86792) ................................................. 53 Apache Tomcat Session Hi-jacking Vulnerability (QID 86794) ............................................................ 53 Apache mod_ssl Certificate Revocation List Off-By-One Buffer Overflow Vulnerability (QID 86801) 54 Apache Tomcat 5 and 6 Host Manager Web Application Cross-Site Scripting (XSS) Vulnerability (QID 86803) ................................................................................................................................................. 54 Apache Tomcat 4, 5 and 6 Multiple Vulnerabilities (QID 86804) ....................................................... 55 Vulnerability Remediation Synopsis version 0.4Russ Klanke Page 2 Apache Tomcat RequestDispatcher Information Disclosure Vulnerability (QID 86808) .................... 56 Apache 1.3, 2.0 and 2.2 HTTP Server Multiple Vulnerabilities (QID 86809) ....................................... 57 Apache 2.0 HTTP Server PCRE Integer Overflow Vulnerability (QID 86812) ...................................... 58 Apache 2.0 HTTP Server mod_ssl Stack Buffer Overflow Vulnerability (QID 86814) ......................... 58 Apache HTTP Server Expect Header Cross-Site Scripting (XSS) (QID 86821) ...................................... 59 Apache Tomcat "RemoteFilterValve" Security Bypass Vulnerability (QID 86823) ............................. 60 Apache HTTP Server AllowOverride Options Security Bypass (QID 86840) ........................................ 60 Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability (QID 86842) ..... 61 Apache Partial HTTP Request Denial of Service Vulnerability - Zero Day (QID 86847) ...................... 62 Apache Tomcat Multiple Vulnerabilities (QID 86851) ........................................................................ 63 APR-util Library Integer Overflow Vulnerabilities (QID 86852) .......................................................... 64 Apache mod_proxy_ftp FTP Command Injection Vulnerability (QID 86855) ..................................... 65 Apache Tomcat Installer Insecure Password Vulnerability (QID 86857) ............................................ 66 Apache Tomcat Directory Traversal Weaknesses and Security Issue (QID 86865) ............................ 66 Apache 1.3 mod_proxy HTTP Chunked Encoding Integer Overflow Vulnerability (QID 86868)......... 68 Apache HTTP Server Prior to 2.2.15 Multiple Vulnerabilities (QID 86873)......................................... 68 Apache httpd "mod_proxy_http" Timeout Handling Information Disclosure Vulnerability (QID 86901) ................................................................................................................................................. 69 Apache HTTP Server 2.2.15 mod_cache and mod_dav Undisclosed DoS Vulnerability
Recommended publications
  • Increasing Automation in the Backporting of Linux Drivers Using Coccinelle
    Increasing Automation in the Backporting of Linux Drivers Using Coccinelle Luis R. Rodriguez Julia Lawall Rutgers University/SUSE Labs Sorbonne Universites/Inria/UPMC/LIP6´ [email protected] [email protected] [email protected], [email protected] Abstract—Software is continually evolving, to fix bugs and to a kernel upgrade. Upgrading a kernel may also require add new features. Industry users, however, often value stability, experience to understand what features to enable, disable, or and thus may not be able to update their code base to the tune to meet existing deployment criteria. In the worst case, latest versions. This raises the need to selectively backport new some systems may rely on components that have not yet been features to older software versions. Traditionally, backporting has merged into the mainline Linux kernel, potentially making it been done by cluttering the backported code with preprocessor impossible to upgrade the kernel without cooperation from the directives, to replace behaviors that are unsupported in an earlier version by appropriate workarounds. This approach however component vendor or a slew of partners that need to collaborate involves writing a lot of error-prone backporting code, and results on developing a new productized image for a system. As an in implementations that are hard to read and maintain. We example, development for 802.11n AR9003 chipset support consider this issue in the context of the Linux kernel, for which on the mainline ath9k device driver started on March 20, older versions are in wide use. We present a new backporting 2010 with an early version of the silicon, at which point the strategy that relies on the use of a backporting compatability most recent major release of the Linux kernel was v2.6.32.
    [Show full text]
  • Contributor's Guidelines
    Contributor’s Guidelines Release 17.11.10 Feb 27, 2020 CONTENTS 1 DPDK Coding Style1 1.1 Description.......................................1 1.2 General Guidelines..................................1 1.3 C Comment Style...................................1 1.4 C Preprocessor Directives..............................2 1.5 C Types.........................................4 1.6 C Indentation......................................7 1.7 C Function Definition, Declaration and Use.....................9 1.8 C Statement Style and Conventions......................... 11 1.9 Python Code...................................... 13 2 Design 14 2.1 Environment or Architecture-specific Sources.................... 14 2.2 Library Statistics.................................... 15 2.3 PF and VF Considerations.............................. 16 3 Managing ABI updates 18 3.1 Description....................................... 18 3.2 General Guidelines.................................. 18 3.3 What is an ABI..................................... 18 3.4 The DPDK ABI policy................................. 19 3.5 Examples of Deprecation Notices.......................... 20 3.6 Versioning Macros................................... 20 3.7 Setting a Major ABI version.............................. 21 3.8 Examples of ABI Macro use............................. 21 3.9 Running the ABI Validator............................... 25 4 DPDK Documentation Guidelines 27 4.1 Structure of the Documentation........................... 27 4.2 Role of the Documentation.............................
    [Show full text]
  • KINTSUGI Identifying & Addressing Challenges in Embedded Binary
    KINTSUGI Identifying & addressing challenges in embedded binary security jos wetzels Supervisors: Prof. dr. Sandro Etalle Ali Abbasi, MSc. Department of Mathematics and Computer Science Eindhoven University of Technology (TU/e) June 2017 Jos Wetzels: Kintsugi, Identifying & addressing challenges in embed- ded binary security, © June 2017 To my family Kintsugi ("golden joinery"), is the Japanese art of repairing broken pottery with lacquer dusted or mixed with powdered gold, silver, or platinum. As a philosophy, it treats breakage and repair as part of the history of an object, rather than something to disguise. —[254] ABSTRACT Embedded systems are found everywhere from consumer electron- ics to critical infrastructure. And with the growth of the Internet of Things (IoT), these systems are increasingly interconnected. As a re- sult, embedded security is an area of growing concern. Yet a stream of offensive security research, as well as real-world incidents, contin- ues to demonstrate how vulnerable embedded systems actually are. This thesis focuses on binary security, the exploitation and miti- gation of memory corruption vulnerabilities. We look at the state of embedded binary security by means of quantitative and qualitative analysis and identify several gap areas and show embedded binary security to lag behind the general purpose world significantly. We then describe the challenges and limitations faced by embedded exploit mitigations and identify a clear open problem area that war- rants attention: deeply embedded systems. Next, we outline the cri- teria for a deeply embedded exploit mitigation baseline. Finally, as a first step to addressing this problem area, we designed, implemented and evaluated µArmor : an exploit mitigation baseline for deeply em- bedded systems.
    [Show full text]
  • Introducting Innovations in Open Source Projects
    Introducing Innovations into Open Source Projects Dissertation zur Erlangung des Grades eines Doktors der Naturwissenschaften (Dr. rer. nat.) am Fachbereich Mathematik und Informatik der Freien Universität Berlin von Sinan Christopher Özbek Berlin August 2010 2 Gutachter: Professor Dr. Lutz Prechelt, Freie Universität Berlin Professor Kevin Crowston, Syracuse University Datum der Disputation: 17.12.2010 4 Abstract This thesis presents a qualitative study using Grounded Theory Methodology on the question of how to change development processes in Open Source projects. The mailing list communication of thirteen medium-sized Open Source projects over the year 2007 was analyzed to answer this question. It resulted in eight main concepts revolving around the introduction of innovation, i.e. new processes, services, and tools, into the projects including topics such as the migration to new systems, the question on where to host services, how radical Open Source projects can change their ways, and how compliance to processes and conventions is enforced. These are complemented with (1) the result of five case studies in which innovation introductions were conducted with Open Source projects, and with (2) a theoretical comparison of the results of this thesis to four theories and scientific perspectives from the organizational and social sciences such as Path Dependence, the Garbage Can model, Social-Network analysis, and Actor-Network theory. The results show that innovation introduction is a multifaceted phenomenon, of which this thesis discusses the most salient conceptual aspects. The thesis concludes with practical advice for innovators and specialized hints for the most popular innovations. 5 6 Acknowledgements I want to thank the following individuals for contributing to the completion of this thesis: • Lutz Prechelt for advising me over these long five years.
    [Show full text]
  • Debian Packaging Tutorial
    Debian Packaging Tutorial Lucas Nussbaum [email protected] version 0.27 – 2021-01-08 Debian Packaging Tutorial 1 / 89 About this tutorial I Goal: tell you what you really need to know about Debian packaging I Modify existing packages I Create your own packages I Interact with the Debian community I Become a Debian power-user I Covers the most important points, but is not complete I You will need to read more documentation I Most of the content also applies to Debian derivative distributions I That includes Ubuntu Debian Packaging Tutorial 2 / 89 Outline 1 Introduction 2 Creating source packages 3 Building and testing packages 4 Practical session 1: modifying the grep package 5 Advanced packaging topics 6 Maintaining packages in Debian 7 Conclusions 8 Additional practical sessions 9 Answers to practical sessions Debian Packaging Tutorial 3 / 89 Outline 1 Introduction 2 Creating source packages 3 Building and testing packages 4 Practical session 1: modifying the grep package 5 Advanced packaging topics 6 Maintaining packages in Debian 7 Conclusions 8 Additional practical sessions 9 Answers to practical sessions Debian Packaging Tutorial 4 / 89 Debian I GNU/Linux distribution I 1st major distro developed “openly in the spirit of GNU” I Non-commercial, built collaboratively by over 1,000 volunteers I 3 main features: I Quality – culture of technical excellence We release when it’s ready I Freedom – devs and users bound by the Social Contract Promoting the culture of Free Software since 1993 I Independence – no (single)
    [Show full text]
  • Junos® OS Intrusion Detection and Prevention User Guide Copyright © 2021 Juniper Networks, Inc
    Junos® OS Intrusion Detection and Prevention User Guide Published 2021-09-21 ii Juniper Networks, Inc. 1133 Innovation Way Sunnyvale, California 94089 USA 408-745-2000 www.juniper.net Juniper Networks, the Juniper Networks logo, Juniper, and Junos are registered trademarks of Juniper Networks, Inc. in the United States and other countries. All other trademarks, service marks, registered marks, or registered service marks are the property of their respective owners. Juniper Networks assumes no responsibility for any inaccuracies in this document. Juniper Networks reserves the right to change, modify, transfer, or otherwise revise this publication without notice. Junos® OS Intrusion Detection and Prevention User Guide Copyright © 2021 Juniper Networks, Inc. All rights reserved. The information in this document is current as of the date on the title page. YEAR 2000 NOTICE Juniper Networks hardware and software products are Year 2000 compliant. Junos OS has no known time-related limitations through the year 2038. However, the NTP application is known to have some difficulty in the year 2036. END USER LICENSE AGREEMENT The Juniper Networks product that is the subject of this technical documentation consists of (or is intended for use with) Juniper Networks software. Use of such software is subject to the terms and conditions of the End User License Agreement ("EULA") posted at https://support.juniper.net/support/eula/. By downloading, installing or using such software, you agree to the terms and conditions of that EULA. iii Table of Contents
    [Show full text]
  • Impacting the Bioscience Progress by Backporting Software for Bio-Linux
    Impacting the bioscience progress by backporting software for Bio-Linux Sasa Paporovic [email protected] v0.9 What is Bio-Linux and what is it good for - also its drawbacks: If someone says to use or to have a Linux this is correct as like it is imprecise. It does not exist a Linux as full functional operating system by itself. What was originally meant by the term Linux was the operating system core[1]. The so called kernel, or in a case of a Linux operating system the Linux kernel. It is originally designed and programmed by Linus Torvalds, who is also today the developer in chef or to say it with his words, he is the “alpha-male” of all developers[2]. Anyway, what we have today are Distributions[3]. It has become common to call them simply “a Linux”. This means that there are organizations out there, mostly private, some funded and some other commercial, which gather all what is needed to design around the Linux kernel a full functional operating system. This targets mostly Software, but also web and service infrastructure. Some of them have a history that is nearly as long as the Linux kernel is alive, like Debian. Some others are younger like Ubuntu and some more others are very young, like Bio-Linux[4]. The last Linux, the Bio-Linux, especially its latest version Bio-Linux 7 we are focusing here[5]. In year 2006 Bio-Linux with the work of Tim Booth[42] and team gives its rising[6] and provide an operating system that was and still specialized in providing a bioinformatic specific software environment for the working needs in this corner of bioscience.
    [Show full text]
  • Oracle Unbreakable Linux: an Overview
    Oracle Unbreakable Linux: An Overview An Oracle White Paper September 2010 Oracle Unbreakable Linux: An Overview INTRODUCTION Oracle Unbreakable Linux is a support program that provides enterprises with industry-leading global support for the Linux operating system at significantly lower costs. The support program, which is available for any customer whether or not they’re running Oracle Unbreakable Linux currently includes support for three architectures: x86; x86-64 (e.g. the latest Intel Xeon and AMD Opteron chips, as used by most Linux customers); and Linux Itanium (ia64). The program offers support for any existing Red Hat Enterprise Linux installations and for new installations of Oracle Linux, an open source Linux operating system that is fully compatible— both source and binary—with Red Hat Enterprise Linux. Complete Support for the Complete Software Stack Oracle’s industry-leading support organization offers expertise that looks at the entire application stack running on top of Linux; only Oracle delivers complete support for the complete software stack—database, middleware, applications, management tools, and the operating system itself. By delivering enterprise-class quality support for Linux, Oracle addresses a key enterprise requirement from customers. When problems occur in a large, complex enterprise environment, it’s often impossible to reproduce such occurrences with very simple test cases. Customers need a support vendor who understands their full environment, and has the expertise to diagnose and resolve the problem by drawing from their knowledge of and familiarity with their framework, as opposed to requesting a simple reproducible test case. Another customer demand is for bug fixes to happen in a timely manner, as customers cannot always afford to wait for months to get a fix delivered to them.
    [Show full text]
  • A Guide to Kernel Exploitation Attacking the Core (2011
    A Guide to Kernel Exploitation This page intentionally left blank A Guide to Kernel Exploitation Attacking the Core Enrico Perla Massimiliano Oldani Technical Editor Graham Speake AMSTERDAM • BOSTON • HEIDELBERG • LONDON • • • NEW YORK OXFORD PARIS SAN DIEGO SYNGRESS SAN FRANCISCO • SINGAPORE • SYDNEY • TOKYO ® Syngress is an imprint of Elsevier Acquiring Editor: Rachel Roumeliotis Development Editor: Matthew Cater Project Manager: Julie Ochs Designer: Alisa Andreola Syngress is an imprint of Elsevier 30 Corporate Drive, Suite 400, Burlington, MA 01803, USA © 2011 Elsevier Inc. All rights reserved. No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying, recording, or any information storage and retrieval system, without permission in writing from the publisher. Details on how to seek permission, further information about the Publisher’s permissions policies and our arrangements with organizations such as the Copyright Clearance Center and the Copyright Licensing Agency, can be found at our website: www.elsevier.com/permissions. This book and the individual contributions contained in it are protected under copyright by the Publisher (other than as may be noted herein). Notices Knowledge and best practice in this field are constantly changing. As new research and experience broaden our understanding, changes in research methods or professional practices, may become necessary. Practitioners and researchers must always rely on their own experience and knowledge in evaluating and using any information or methods described herein. In using such information or methods they should be mindful of their own safety and the safety of others, including parties for whom they have a professional responsibility.
    [Show full text]
  • BIND 9 Administrator Reference Manual
    BIND 9 Administrator Reference Manual BIND 9.11.31 (Extended Support Version) Copyright (C) 2000-2021 Internet Systems Consortium, Inc. ("ISC") This Source Code Form is subject to the terms of the Mozilla Public License, v. 2.0. If a copy of the MPL was not distributed with this file, You can obtain one at http://mozilla.org/MPL/2.0/. Internet Systems Consortium, Inc. PO Box 360 Newmarket, NH 03857 USA https://www.isc.org/ Contents 1 Introduction 1 1.1 Scope of Document . .1 1.2 Organization of This Document . .1 1.3 Conventions Used in This Document . .1 1.4 The Domain Name System (DNS) . .2 DNS Fundamentals . .2 Domains and Domain Names . .2 Zones . .3 Authoritative Name Servers . .3 The Primary Server . .3 Secondary Servers . .4 Stealth Servers . .4 Caching Name Servers . .4 Forwarding . .5 Name Servers in Multiple Roles . .5 2 BIND Resource Requirements7 2.1 Hardware requirements . .7 2.2 CPU Requirements . .7 2.3 Memory Requirements . .7 2.4 Name Server-Intensive Environment Issues . .7 2.5 Supported Operating Systems . .8 iii BIND 9.11.31 CONTENTS CONTENTS 3 Name Server Configuration9 3.1 Sample Configurations . .9 A Caching-only Name Server . .9 An Authoritative-only Name Server . .9 3.2 Load Balancing . 10 3.3 Name Server Operations . 11 Tools for Use With the Name Server Daemon . 11 Diagnostic Tools . 11 Administrative Tools . 12 Signals . 13 4 Advanced DNS Features 15 4.1 Notify . 15 4.2 Dynamic Update . 15 The Journal File . 16 4.3 Incremental Zone Transfers (IXFR) . 16 4.4 Split DNS .
    [Show full text]
  • Unix to Linux Migration
    UNIX TO LINUX MIGRATION RICHARD KEECH ABSTRACT This paper aims to show the benefits of choosing Linux and migrating existing UNIX environments to the Linux platform. This applies in particular to migrations from RISC-based platforms. It also shows the extent to which Linux is now a trusted, mainstream platform and how any technical risks associated with migrations can be mitigated. This paper addresses a technical audience. www.redhat.com UNIX to Linux migration | Richard Keech TABLE OF CONTENTS AIMS Page 3 INTRODUCTION TO LINUX Page 3 OpEN SOURCE AND LINUX Page 4 RED HAT ENTErprISE LINUX Page 5 UNIX VS LINUX Page 8 TrENDS Page 9 Server Virtualization Page 9 Clustering Page 10 Rapid provisioning and appliance OS Page 10 Instrumentation and debugging Page 10 MIGRATION CONSIDERATIONS Page 11 Qualify the stack Page 11 Porting Page 12 Training Page 12 Prepare a Linux standard build Page 12 Pilot deployment Page 13 CONCLUSIONS Page 13 REFERENCES Page 14 2 www.redhat.com UNIX to Linux migration | Richard Keech AIMS This paper aims to give an introduction to Linux for the technically inclined and educated reader at a level that can allow proper comparisons with UNIX. The paper provides an outline of the key considerations in selecting Linux and migrating from UNIX to Red Hat Enterprise Linux. The intended audience of this paper is enterprise infrastructure architects. INTRODUCTION TO LINUX Benefits. The Linux platform offers a low-risk, robust, and value-for-money alternative to traditional UNIX. Linux is now sufficiently mature enough to handle the most demanding workloads at a much lower cost than proprietary UNIX offerings.
    [Show full text]
  • Ubuntu-Packaging-Guide.Pdf
    Ubuntu Packaging Guide Release 1.0.3 bzr711 ubuntu14.04.1 Ubuntu Developers August 31, 2021 CONTENTS 1 Articles 2 1.1 Introduction to Ubuntu Development..................................2 1.2 Getting Set Up..............................................4 1.3 Fixing a bug in Ubuntu..........................................8 1.4 Packaging New Software......................................... 14 1.5 Security and Stable Release Updates.................................. 17 1.6 Patches to Packages........................................... 19 1.7 Fixing FTBFS packages......................................... 22 1.8 Shared Libraries............................................. 23 1.9 Backporting software updates...................................... 25 2 Knowledge Base 26 2.1 Communication in Ubuntu Development................................ 26 2.2 Basic Overview of the debian/ Directory............................... 26 2.3 ubuntu-dev-tools: Tools for Ubuntu developers............................. 32 2.4 autopkgtest: Automatic testing for packages.............................. 34 2.5 Using Chroots.............................................. 36 2.6 Setting up sbuild............................................. 37 2.7 KDE Packaging............................................. 40 3 Further Reading 42 i CONTENTS Ubuntu Packaging Guide Welcome to the Ubuntu Packaging and Development Guide! This is the official place for learning all about Ubuntu Development and packaging. After reading this guide you will have: • Heard about the most important players,
    [Show full text]