Issues on Linux and Security
button Other -->

mp3riot (formerly known as


I decided to rename into mp3riot. the reason is, that the name does not clearly indicate, for what the program is best suited for. Because the program has grown so much (and because the the name should be more attractive to get more users), a renaming seems to be a must to me.

There are some important news about mp3riot / f2htmlpl. Please see the NEWS for further details.


Mp3riot (formerly known as is a command line utility that searches recursively through directories, builds a file list (with additional file information), and generates html files, plylists, etc. The output can be controlled, links can be corrected, and more. The script is mainly desigend to create Web pages, playlists, and databases for mp3-files, but can also used for other purposes.

Read the manual for further details.

Main Features:

  • supports playlists in m3u, pls, and xml format
  • supports sql output
  • creates html pages, templates can be used
  • supports advanced grouping methods
  • supports slection by date ranges, file extensions, and by random
  • supports renaming of mp3 files using id3tag information, templates or guessing can be used
  • advanced string manipulation methods
  • and much more ...


Latest version:

Older versions of mp3riot /

For Windows-Users:

You can also download a windows executable compiled with perl2exe. Then you need not to install perl. But I have not testet the functionality of the executable in detail. So it is best to use perl and the source of mp3riot!

Windows binaries of mp3riot:


perl mp3riot [options]

  • -h, --help: Show this screen and exit
  • -k, --mkconf:Use an assistant to write a config file
  • -o, --os win/unix: Default "unix", otherwise windows
  • -Q, --sortby value: Default is NAME (the filename). You can sort the filelist by the following criteria: URLNAME, SHOWNAME, DIR, NAME, TITLE, ARTIST, ALBUM, YEAR, COMMENT, GENRE, TRACKNUM, SIZE, MODTIME, VBR, BITRATE, FREQUENCY, MINUTES, SECONDS, FIRSTCHAR
  • -n, --doublicates: Check for doublicates of files by their filename
  • -D, --md5doublicates: Check for doublicates of files by their MD5 sum
  • -V, --seekvalues <n,+-n,n>: Three values that have to be seperated by ",". This is an useful option for --md5doublicates. The first one is the offset in bytes, the second is the number of bytes to seek (and the direction), and the last value tells the program where to start from (1 means to start from the begining of a file, 2 means to start from the end of a file. So, a combination of 1000,-1128,2 tells the programm to start 1128 bytes before the file ends (id3v1 tag is 128 bytes long!) and use 1000 bytes for calculation of md5 sums.
  • -b, --dbfile file: Write database to a file for searching it
  • -m --m3u file: Write a m3u playlist file. Directory and filename or GROUPPATH for writing m3u files for groups.
  • -X --xml file: Write a xml playlist file. Directory and filename or GROUPPATH for writing xml files for groups.
  • -L --pls file: Write a pls playlist file. Directory and filename or GROUPPATH for writing pls files for groups.
  • -W, --b4s file: Write a b4s playlist file. Directory and filename or GROUPPATH for writing b4s files for groups.
  • -t, --html file: Write a html file. Directory and filename or GROUPPATH for writing html files for groups.
  • -a, --http name: Define the http address for url
  • -r, --remove: Remove id3tags (do you know what you are doing?)
  • -i, --mp3info: Use mp3/ogg info for html output
  • -e, --ext: Remove file extensions in html output
  • -f, --filesize: Use filesize for html output
  • -c, --check ext: Select files by their extension(s) (e.g. mp3). For every extension use a seperate flag!
  • -z, --skip number: Skip n elements of mount/directories/names
  • -p, --conf file: Use a config file
  • -w, --utf8 file: File with UTF-8 code for replacements in links
  • -q, --nocs: Do sorting not case sensitive
  • -j, --statfile file: Write statistics to file
  • -d, --dir directory: Define the (multiple) directory(ies) the mp3s are stored in. For every directory use a seperate flag!
  • -g, --sql file: Filename to store sql table in (only for mp3 and ogg!)
  • -y, --replace file: Name of replacement file; in the file use <string_1>=<string_2> to transform <string_1> into <string_2>; special characters like a backslash have to be preceeded by a backslash "\\" (used for directories)
  • -s, --seperate path: Write seperate html files for every character
  • -R, --rename: Renames mp3 and ogg file using their id3tag. The use of rename_template in the configfile is optional. If rename_template is not used, the program tries to create a filename like: ARTIST - ALBUM - TRACKNUMBER - TITLE by using the id3tag. It assumes, that the filenames have a similar format and tries to guess, whether the id3tag has enough information to create a better filename. Old and new filenames are stored in RENAME.bak
  • -B, --renameback: Renames files back using the file RENAME.bak
  • -T, --templatesHtml templates are used. They have to be defined in the conmfig file using the commands html_head, html_change, html_body, html_footer, html_sep_head. See the README for avalable templates!
  • -G, --groupfile file: Filename for grouping information: <groupname1>=<TYPE>=<string1>,<string2>,...
  • -P, --grouppath path: The path, where to write the html files for group
  • -O, --older number: Only files are selected, having a modification time higher than the specified days
  • -Y, --younger number: Only files are selected, having a modification time less than the specified days
  • -I, --id3tag: Use the id3 tag to get infos
  • -S, --random number: Percentage of file to select randomly (e.g. 50 to select 50% of files/every second file)
You can use nearly all commands in a config file (and it is the best to do it this way!). The syntax then changes sligthly, so that, for example, --dir changes to dir=
Additionally, in the config file it is possible to use the commands:
  • exec= param: Execute system command. This command can be used multiple times
  • rename_template=string:string with templates for renaming files by their id3tag (to be used together with --rename)
    The following rename templates are available: **TITLE**, **ARTIST**, **ALBUM**, **YEAR**, **COMMENT**, **GENRE**. **TRACKNUM**
  • html_head= string: Html code for the head
  • html_change= string: Html code if the first character between two file names change
  • html_body= string: Html code for each filename
  • html_footer= string: Html code for the foot
  • html_sep_head= string: Html code for the head seperate html files by first character
    The following html templates are available: **SUMOFFILES**, **SUMOFMEGS**, **DATE**, **URLNAME**, **SHOWNAME**, **DIR**, **NAME**, **TITLE**, **ARTIST**, **ALBUM**, **YEAR**, **COMMENT**, **GENRE**, **TRACKNUM**, **SIZE**, **MODTIME**, **VBR**, **BITRATE**, **FREQUENCY**, **MINUTES**, **SECONDS**, **HTMLINDEX**, **FIRSTCHAR**


mp3riot 1.3-20041220

  • extended grouping fuction for all playlistfiles
  • renaming of special characters for filenames og groups
  • support of b4s playlistformat
  • sorting of filelist by various criterias of id3tag, mp3 and
  • file information (e.g. ARTIST, BITRATE etc.)
  • extended output of doublicate function by diretory names
  • added FIRSTCHAR as a value for grouping

mp3riot 1.2-20041007

  • Fixed bug in sql output
  • Flexible search for doublicate files using md5 sums
  • search for doublicates by filenames seperated from search function
  • fixed bug in xml output
  • filesize in html output is now rouded
  • replaced progress bar by counter in percentage
  • added counter for collected files
  • fixed bug in index in html output
  • fixed bug in html output for grouping
  • extended grouping function by new type EQUAL
  • bugfix in pls output

mp3riot 1.1-20030728

  • Renamed into mp3riot
  • Fixed output of playlist in M3U format, so that the M3U file is now containing full information
  • Fixed bug for retreaving the TITLE of an id3tag
  • Added output of playlist in XML format
  • Added output of playlist in PLS format
  • Added random fileselection for random playlists
  • Added the tracknumber for sql output
  • Added **TRACKNUM** (tracknumber) and as a template variable for html output
  • Added TRACKNUM (tracknumber) as a variable for groupings
  • Added tracknumber and comment for db output
  • Fixed bug in renaming function when special characters are present in the id3tag
  • Added rename_template to do renaming of files using their id3tag in a flexible way
  • Fixed a bug in renameback 1.0-20030319

  • Fixed some smaller bugs
  • Rebuild the internal data structure completely
  • Removed option for fast sorting (not necessary any more)
  • Implemented selection of files by their modification time (younger and/or older than days from now)
  • Implemented grouping of files by string matching between group defninitions by various types
  • Implemented variable html-code dsefinitions and templates
  • Changed definition for string replacement
  • now comes with a new version of from MP3-Info-1.02 by Chris Nandor
  • The use of the id3tag for sql and html output is now optional
  • Manpage is not supported any more. 0.9-20030313

  • Fixed a commandline parameter bug where the parameters were handled non case sensitive. Now there are handled case sensitive. As a result the functions RENAME and RENAMEBACK did not work when called with the short command line argument.
  • Fixed a commandline parameter bug that occured with Perl 5.8.0 and Getopt::Long 2.32. The -s flag in line 1 of the perl script causes the program to count the command line parameters in an usual way, so that command line parameters got disturbed and did not work any more. 0.8-20021105

  • Some changes in the documentation.
  • New option to rename files using their id3tag.
  • New option to rename files back.
  • Some code fixes.
  • Usage of the replace option has changed. 0.7-20021016

  • Bug for the option "check" in config file and configuration wizard fixed
  • Bug for the check of the mp3 extension when mp3info was enabled fixed.
  • Bug of sum of megs in html output fixed.
  • Bug in mp3table.sql fixed.
  • Basic ogg vorbis support implemented (thanks to Jens Burkal). 0.6-20020718

  • New method (experimental) for faster sorting. Useful for indexing huge number of files or mp3 files with additional information.
  • New option for checking for dublicates of filenames.
  • Now comes wioth a new version of from MP3-Info-1.01 by Chris Nandor. 0.5-20020626

  • Fixed problem with sql data output when files contain the charakter " ' ".
  • Name of option "hex" changed to "utf8".
  • Implemeted progress bar for prepating html files.
  • More information about what the program is doing. 0.4-20011127

  • Now f2html comes with a new version of from MP3-Info-0.91 by Chris Nandor.
  • Minor Bugfixes.
  • New option to create sql database.
  • New option to create a config file. 0.3-20010628

  • Some checks and corrections for pathnames.
  • Only existing characters are written out at the top of a html file.
  • Rewrite of sum of files and sizes. Important for writing seperate html files for every character.
  • The option -q has been implemented and allows for doing the procedures in a non case sensitive way.
  • The option -j has been implemented. A html file with statistics can be written out. 0.2-20010117

  • The manual has been updated.
  • The option -c has been updated. Now this option can be used more than only one time. So one is able to select file by different extensions. 0.1-20001127

  • Initial release.

back to top

button Whats New
[2005-02-18] mp3riot version 1.3 released
[2004-10-08] mp3riot version 1.2 is out.
[2004-04-30] Added section Bridging
[2004-01-09] working progress on mp3riot version 1.2
In a thought-provoking?and characteristically amusing?talk at the Vault conference, Dave Chinner looked at the history of XFS, its current status, and where the filesystem may be heading. In keeping with the title of the talk (shared by this article), he sees parallels in what drove the original development of XFS and what will be driving new filesystems. Chinner's vision of the future for today's filesystems, and not just of XFS, may be a bit surprising or controversial?possibly both.
[$] XFS: There and back ... and there again?

Arch Linuxhas updated firefox(multiple vulnerabilities). CentOShas updated bind(C7: denial of service), firefox(C7: two vulnerabilities), firefox(C6; C5; C7: multiple vulnerabilities), xulrunner(C7: multiple vulnerabilities), flac(C7; C6: two vulnerabilities), freetype(C7: multiple vulnerabilities), ipa(C7: two vulnerabilities), slapi-nis(C7: two vulnerabilities), kernel(C7: two vulnerabilities), libxml2(C7: denial of service), openssl(C7: multiple vulnerabilities), postgresql(C7: multiple vulnerabilities), setroubleshoot(C7: privilege escalation), thunderbird(C7; C7: multiple vulnerabilities), and unzip(C7: multiple vulnerabilities). Debianhas updated wireshark(multiple vulnerabilities). Debian-LTShas updated freetype(many vulnerabilities). Fedorahas updated drupal7-entity(F21; F20: cross-site scripting) and php(F20: multiple vulnerabilities). Mageiahas updated chromium-browser-stable(multiple vulnerabilities), owncloud(unspecified vulnerabilities), python-rope(code execution), and tor(denial of service). Oraclehas updated firefox(OL7; OL6: multiple vulnerabilities) and flac(OL7; OL6: two vulnerabilities). Red Hathas updated firefox(RHEL5,6,7: multiple vulnerabilities), flac(RHEL6,7: two vulnerabilities), and thunderbird(RHEL5,6,7: multiple vulnerabilities). Scientific Linuxhas updated firefox(SL5,6,7: multiple vulnerabilities) and flac(SL6,7: two vulnerabilities). Ubuntuhas updated firefox(14.10, 14.04, 12.04: multiple vulnerabilities), gnupg, gnupg2(14.10, 14.04, 12.04, 10.04: multiple vulnerabilities), libgcrypt11, libgcrypt20(14.10, 14.04, 12.04, 10.04: information leak), and tiff(14.10, 14.04, 12.04, 10.04: multiple vulnerabilities).
Security advisories for Wednesday

Firefox 37.0 has been released. This release features improved protection against site impersonation via OneCRL centralized certificate revocation, Bing search now uses HTTPS for secure searching, opportunistic encrypting of HTTP traffic where the server supports HTTP/2 AltSvc, and more. See the release notesfor details.
Firefox 37.0

Arch Linuxhas updated musl(code execution). Debianhas updated openldap(multiple vulnerabilities). Mandrivahas updated dokuwiki(MBS1.0: multiple vulnerabilities) and phpmyadmin(MBS1.0: information leak). openSUSEhas updated gd(13.2, 13.1: denial of service) and seamonkey(13.2, 13.1: two vulnerabilities). Oraclehas updated libxml2(OL7: denial of service) and postgresql(OL7; OL6: multiple vulnerabilities). SUSEhas updated firefox(SLE12: two vulnerabilities). Ubuntuhas updated jakarta-taglibs-standard(14.10, 14.04: code execution).
Tuesday's security updates

Linus has released4.0-rc6 right on schedule. "Things are calming down nicely, and there are fixes all over. The NUMA balancing performance regression is fixed, and things are looking up again in general. There were a number of i915 issues and a KVM double-fault thing that meant that for a while there I was pretty sure that this would be a release that will go to rc8, but that may be unnecessary."
Kernel prepatch 4.0-rc6

CentOShas updated postgresql(C6: multiple vulnerabilities). Debianhas updated freexl(code execution). Fedorahas updated drupal6(F21; F20: multiple vulnerabilities), drupal7(F21; F20: multiple vulnerabilities), libssh2(F20: information leak), mingw-xerces-c(F21; F20: denial of service), php(F21: multiple vulnerabilities), tcpdump(F21: multiple vulnerabilities), and xerces-c(F21; F20: denial of service). Gentoohas updated busybox(multiple vulnerabilities). Mandrivahas updated apache-mod_wsgi(MBS2.0: privilege escalation), bash(MBS2.0: multiple vulnerabilities), bind(MBS2.0: denial of service), binutils(MBS2.0: multiple vulnerabilities), clamav(MBS2.0: multiple vulnerabilities), coreutils(MBS1.0, MBS2.0: code execution), ctags(MBS2.0: denial of service), ctdb(MBS2.0: insecure temporary files), dbus(MBS2.0: multiple vulnerabilities), drupal(MBS1.0: multiple vulnerabilities), ejabberd(MBS2.0: incorrectly allows unencrypted connections), erlang(MBS2.0: command injection), ffmpeg(MBS2.0: multiple vulnerabilities), firebird(MBS2.0: denial of service), freerdp(MBS2.0: two vulnerabilities), gcc(MBS2.0: code execution), git(MBS2.0: code execution), glibc(MBS2.0: multiple vulnerabilities), glpi(MBS2.0: multiple vulnerabilities), grub2(MBS2.0: code execution), gtk+3.0(MBS2.0: screen lock bypass), icu(MBS2.0: multiple vulnerabilities), ipython(MBS2.0: code execution), jasper(MBS2.0: multiple vulnerabilities), jython(MBS2.0: code execution), libarchive(MBS1.0, MBS2.0: directory traversal), libtiff(MBS1.0: multiple vulnerabilities), libxfont(MBS1.0: multiple vulnerabilities), setup(MBS2.0: information disclosure), tcpdump(MBS1.0: multiple vulnerabilities), and wireshark(MBS1.0: multiple vulnerabilities). openSUSEhas updated freetype2(13.2, 13.1: many vulnerabilities), gnutls(13.2, 13.1: certificate algorithm consistency checking issue), and rubygem-bundler(13.2, 13.1: installs malicious gem files). Red Hathas updated kernel-rt(RHE MRG for RHEL6: two vulnerabilities), libxml2(RHEL7: denial of service), and postgresql(RHEL6, RHEL7: multiple vulnerabilities). Scientific Linuxhas updated libxml2(SL7: denial of service) and postgresql(SL6, SL7: multiple vulnerabilities).
Security advisories for Monday

The pile of security updates has gotten deep enough that it makes sense to shove them out now. The biggest pile is seemingly Mandriva catching up on numerous updates for its Mandriva Business Server (MBS) line of products. Debianhas updated batik(unauthorized file access), binutils(code execution), dulwich(code execution), libxfont(privilege escalation), php5(fix regression from previous update), shibboleth-sp2(denial of service), and xerces-c(denial of service). Fedorahas updated kernel(F21: code execution), mongodb(F21: denial of service), python-requests(F21: cookie stealing), python-urllib3(F21: cookie stealing), strongswan(F20, F21: denial of service), and webkitgtk4(F21: late certificate verification). Mageiahas updated docuwiki(cross-site scripting), drupal(authentication bypass), krb5(denial of service), python-requests(cookie stealing), setup(incorrect file protections), and wireshark(dissector issues). Mandrivahas updated apache(MBS2: 11 CVEs), apache-mod_security(MBS2: restriction bypass), cifs-utils(MBS2: code execution), cups(MBS2: six CVEs), cups-filters(MBS2: nine CVEs), curl(MBS2: seven CVEs), dovecot(MBS2: denial of service), egroupware(MBS2: code execution), elfutils(MBS2: code execution), emacs(MBS2: symbolic link vulnerability), freetype2(MBS2: 21 CVEs), gnupg(MBS1, MBS2: five CVEs), gnutls(MBS2: five CVEs), imagemagick(MBS2: five CVEs), jbigkit(MBS2: code execution), json-c(MBS2: denial of service), krb5(MBS1-2: five CVEs), lcms2(MBS2: denial of service), libcap-ng(MBS2: privilege escalation), libgd(MBS2: denial of service), libevent(MBS2: code execution), libjpeg(MBS2: code execution), libksba(MBS2: denial of service), liblzo(MBS2: code execution), libpng(MBS2: memory overwrite), libpng12(MBS2: three 2013 CVEs), libsndfile(MBS2: code execution), libssh(MBS2: information disclosure and denial of service), libssh2(MBS1, MBS2: MITM vulnerability), libtasn1(MBS2: denial of service), libtiff(MBS2: six CVEs), libvirt(MBS1, MBS2: denial of service and information leak), libvncserver(MBS2: six CVEs), libxfont(MBS2: six CVEs), libxml2(MBS2: denial of service), lua(MBS2: code execution), mariadb(MBS2: uncountable unexplained CVEs), mpfr(MBS2: code execution), mutt(MBS2: denial of service), net-snmp(MBS2: denial of service), nginx(MBS2: code execution), nodejs(MBS2: multiple unspecified vulnerabilities), not-yet-commons-ssl(MBS2: MITM vulnerability), ntp(MBS2: six CVEs), openldap(MBS1, MBS2: denial of service), openssh(MBS2: restriction and authentication bypass), openvpn(MBS2: denial of service), patch(MBS2: file overwrite), pcre(MBS2: denial of service), perl(MBS2: denial of service), php(MBS1, MBS2: lots of vulnerabilities), postgresql(MBS2: twelve CVEs), ppp(MBS2: privilege escalation), pulseaudio(MBS2: denial of service), python-django(MBS2: five CVEs), python-pillow(MBS2: five CVEs), python-requests(MBS2: cookie stealing), php-ZendFramework(MBS2: eight CVEs), python(MBS2: seven CVEs), python3(MBS2: five CVEs), python-lxml(MBS2: code injection), python-numpy(MBS2: temporary file vulnerability), readline(MBS2: symbolic link vulnerability), rsync(MBS2: denial of service), rsyslog(MBS2: denial of service), ruby(MBS2: denial of service), samba(MBS1, MBS2: code execution and more), samba4(MBS2: code execution), sendmail(MBS2: file descriptor access), serf(MBS2: MITM vulnerability), squid(MBS2: five CVEs), stunnel(MBS2: private key disclosure), subversion(MBS2: five CVEs), sudo(MBS2: file disclosure), tcpdump(MBS2: seven CVEs), tomcat(MBS2: eight CVEs), torque(MBS2: kill arbitrary processes), udisks2(MBS2: code execution), unzip(MBS2: code execution), util-linux(MBS2: command injection), wpa_supplicant(MBS2: command execution), wget(MBS2: symbolic link vulnerability), x11-server(MBS2: thirteen CVEs), and xlockmore(MBS2: lock bypass). openSUSEhas updated mercurial(command injection). SUSEhas updated firefox(SLES10-11: code execution) and mysql(SLES11: 33 vulnerabilities).
A massive weekend security update pile

More than a decade after its last major rewrite, the GNU Mailmanmailing list manager project aims to release its 3.0 suite in April, during the sprints following PyCon North America. Mailman 3 is a major rewrite that includes a new user membership system, a RESTAPI, an archiver replacement for Pipermail, and a better web interface for subscriptions and settings ? but it carries with it a few new dependencies as well. Brave system administrators can try out the fifth beta versionnow. Subscribers can click below for the full story from next week's edition.
[$] Mailman 3.0 to modernize mailing lists

Hot on the heels of yesterday's 3.19.3 release, Greg Kroah-Hartman has released kernels 3.14.37and 3.10.73. Each contains a bevy of updates and fixes.
Two fresh stable kernels

CentOShas updated setroubleshoot(C6; C7: privilege escalation). Debianhas updated batik(information leak). Fedorahas updated dokuwiki(F20; F21; F22: access control bypass), drupal7(F22: multiple vulnerabilities), drupal7-views(F20; F21: multiple vulnerabilities), ettercap(F20; F21: multiple vulnerabilities), mingw-xerces-c(F22: denial of service), nx-libs(F20; F21: multiple vulnerabilities), php(F22: multiple vulnerabilities), and xerces-c(F22: denial of service). Mandrivahas updated cabextract(BS1,2: multiple vulnerabilities), cpio(BS1: multiple vulnerabilities; BS2: directory traversal), e2fsprogs(BS1; BS2: multiple vulnerabilities), and openssl(BS1; BS2: multiple vulnerabilities). openSUSEhas updated libXfont(13.1, 13.2: multiple vulnerabilities), libzip(13.1, 13.2: denial of service), and tcpdump(13.1, 13.2: multiple vulnerabilities). Oraclehas updated ipa and slapi-nis(O7: multiple vulnerabilities), kernel(O7: multiple vulnerabilities), and setroubleshoot(O5; O6; O7: privilege escalation). Red Hathas updated ipa, slapi-nis(RHEL7: multiple vulnerabilities), kernel(RHEL7: multiple vulnerabilities), kernel-rt(RHEL7: multiple vulnerabilities), and setroubleshoot(RHEL5,6,7: privilege escalation). Scientific Linuxhas updated ipa and slapi-nis(SL7:), kernel(SL7: multiple vulnerabilities), and setroubleshoot(SL5,6,7: privilege escalation). SUSEhas updated Xen(SLE12: multiple vulnerabilities).
Friday's security updates

Greg Kroah-Hartman has announced the release of the 3.19.3kernel. A variety of important fixes and updates are included.
A new stable kernel release

CentOShas updated firefox(C6; C7: multiple vulnerabilities). openSUSEhas updated firefox(13.1,13.2: multiple vulnerabilities). Oraclehas updated firefox(O5: multiple vulnerabilities). Scientific Linuxhas updated 389-ds-base(SL7: multiple vulnerabilities), firefox(multiple vulnerabilities), freetype(SL6,7: multiple vulnerabilities), glibc(SL7: multiple vulnerabilities), GNOME Shell(SL7: lock screen bypass), hivex(SL7: privilege escalation), httpd(SL7: multiple vulnerabilities), ipa(SL7: multiple vulnerabilities), kernel(SL7: multiple vulnerabilities), krb5(SL7: multiple vulnerabilities), libreoffice(SL7: multiple vulnerabilities), libvirt(SL7: multiple vulnerabilities), openssh(SL7: multiple vulnerabilities), openssl(SL6; SL7: multiple vulnerabilities), pcre(SL7: information leak), qemu-kvm(SL7: multiple vulnerabilities), unzip(SL6,7: multiple vulnerabilities), and virt-who(SL7: information leak).
Thursday's security updates

The Weekly Edition for March 26, 2015 is available.
[$] Weekly Edition for March 26, 2015

The LibreOffice project was announcedwith great fanfare in September 2010. Nearly one year later, the project (from which LibreOffice was forked) was cut loose from Oracleand found a new home as an Apache project. It is fair to say that the rivalry between the two projects in the time since then has been strong. Predictions that one project or the other would fail have not been borne out, but that does not mean that the two projects are equally successful. A look at the two projects' development communities reveals some interesting differences. Click below (subscribers only) for the full article.
[$] Development activity in LibreOffice and OpenOffice

Debianhas updated openssl(regression in previous update) and python-django(cross-site scripting). Debian-LTShas updated gnutls26(multiple vulnerabilities). openSUSEhas updated less(13.2, 13.1: information leak) and tor(13.2, 13.1: denial of service). Oraclehas updated firefox(OL7; OL6: multiple vulnerabilities). SUSEhas updated firefox(SLE11 SP3: multiple vulnerabilities). Ubuntuhas updated batik(14.10, 14.04, 12.04: information leak) and libarchive(14.10, 14.04, 12.04: directory traversal).
Security advisories for Wednesday

GNU glibc CVE-2014-7817 Arbitrary Command Execution Vulnerability
Vuln: GNU glibc CVE-2014-7817 Arbitrary Command Execution Vulnerability

Linux Kernel CVE-2014-3687 Denial of Service Vulnerability
Vuln: Linux Kernel CVE-2014-3687 Denial of Service Vulnerability

Linux Kernel 'trace_syscalls.c' Multiple Local Denial of Service Vulnerabilities
Vuln: Linux Kernel 'trace_syscalls.c' Multiple Local Denial of Service Vulnerabilities

Linux Kernel 'espfix64' Local Denial of Service Vulnerability
Vuln: Linux Kernel 'espfix64' Local Denial of Service Vulnerability

TWiki Security Advisory - XSS Vulnerability - CVE-2014-9367
Bugtraq: TWiki Security Advisory - XSS Vulnerability - CVE-2014-9367

TWiki Security Advisory - XSS Vulnerability - CVE-2014-9325
Bugtraq: TWiki Security Advisory - XSS Vulnerability - CVE-2014-9325

Facebook BB #18 - IDOR Issue & Privacy Vulnerability
Bugtraq: Facebook BB #18 - IDOR Issue &Privacy Vulnerability

Mobilis MobiConnect 3G ZDServer v1.0.1.2 - Privilege Escalation Vulnerability
Bugtraq: Mobilis MobiConnect 3G ZDServer v1.0.1.2 - Privilege Escalation Vulnerability

News, Infocus, Columns, Vulnerabilities, Bugtraq ...
More rss feeds from SecurityFocus