Nitrux 3.5.1 schraubt an seiner NetworkManager-Konfiguration
Die auf Debian basierende Distribution Nitrux liegt in einer neuen Version vor, die zahlreiche kleine Änderungen mitbringt.
Die auf Debian basierende Distribution Nitrux liegt in einer neuen Version vor, die zahlreiche kleine Änderungen mitbringt.
Folge 093 des CIW Podcasts.
FOSSWELT, mergen statt forken


Eine Sicherheitslücke in OpenSSH ermöglicht es nicht authentifizierten Angreifern aus der Ferne Root-Zugriff zu erlangen. Die ursprünglich im Jahr 2006 beseitigte Lücke wurde im Jahr 2020 unbeabsichtigt wieder geöffnet. Über 14 Millionen Systeme im Internet sind potentiell durch „regreSSHion“ gefährdet.
Konkurrenz belebt bekanntermaßen das Geschäft. Somit ist der neue Browser Ladybird hochwillkommen. Gerade hat die Entwicklung verstärkt Fahrt aufgenommen.
Nicht immer lässt sich zeitnah über jede Neuigkeit rund um das freie Betriebssystem berichten, manche Ereignisse sind es aber dennoch wert, Erwähnung zu finden. In dieser Zusammenfassung überblickt die Redaktion alle wichtigen Meldungen aus der Linux-Welt der vorangegangenen Woche.

The July issue is full of news! We continue to monitor and raise our concerns about DMA compliance. We call upon the EU to use Free Software for its digital infrastructure and are asking for your experiences with openwashing. And we also bring you updates on REUSE, YH4F, Ada & Zangemann...
Table of contents
“I have received the package, the T-shirts are great. Thank you for including the stickers in the pack, your work is amazing".
A Free Software supporter who bought merchandise in our Summer SaleTogether with seven stakeholders organisations, the FSFE has submitted a joint position paper to the European Commission, with whom we are working on the implementation of the Digital Markets Act. This paper, supported by legal and data-backed arguments, addresses Apple’s non-compliance with the law, particularly concerning software freedom, alternative Free Software app stores and interoperability obligations.
The FSFE calls upon the European Commission to use Free Software to ensure a secure and resilient digital infrastructure. Also the economy, civil society and democracy will benefit from software freedom.
REUSE helps make a project's licensing and copyright status more transparent, ensure that third-party code is properly attributed and make the project's code easily reusable. This tool is currently used worldwide and its specification has been adopted by several corporate and institutional projects. We spoke to Matija Šuklje of Liferay International, one of the companies that has adopted REUSE.
We are working on the topic of openwashing to learn more about current market practices, and we need your help! Openwashing has become a growing issue for the Free Software community. Many companies claim to be working on "Open Source" or "Free Software", while at the same time distributing proprietary software products. We have already received many valuable responses, but more input is welcome! You can still share your views and experiences on openwashing.
Please spread the word!
The 2024 edition of Youth Hacking 4 Freedom has reached its peak with the end of the programming period. After six months of working on their projects, the young participants of this third edition submitted their projects at the end of June. Now it is the turn of the YH4F jury to evaluate the submissions and choose the six projects that will be awarded prizes in Brussels in October. Keep up to date with our news! Meanwhile, take a closer look at one of our winning projects from last year, ArduPlot.
Interested in participating in the next edition? You can already register!
Thanks to the Volkswagen Group in Spain, the story of Ada & Zangemann is now being printed in Spanish! The company will be distributing 500 copies to its employees and, from September, its STEM team will be embarking on a 'STEM tour', visiting schools in several Spanish cities around the country to distribute the book. We can't wait to hear more about these readings and the children's feedback! And maybe this translation of the book will find a publisher soon, so that it can make its way into bookshops!
Besides, Ada ready-to-go slides are currently available in Spanish and Portuguese! These resources are really helpful when doing a reading.
With its kick-off online meeting last month, the FSFE has started a pilot project in Italy to educate primary school kids about Free Software. This project is creating a set of tools for Italian volunteers to organize a pedagogic event with a reading of the book “Ada & Zangemann”.
If you are in Italy and you want to participate, please get in touch with the FSFE ItalyTelegram channel. Check out the recording of the kick-off session and download all the documentation and tools to kick off the project in your area!
Donate nowOur mission is in jeopardy due to lack of funding. Inflation has also hit us hard, so in order to continue to fight successfully for you and your freedom, we need individual, regular contributions.
To continue to be a thorn in the side of deep-pocketed tech giants and a watchdog for governments, it is important that individual regular donations are a cornerstone of our income so we keep our independence.
If you value our work and have the means to do so, please do not hesitate to make a donation; any amount you can contribute would really help us to continue to work consistently and tirelessly for Software Freedom.
We got an email, a few weeks ago, that caught our attention. It came with a donation explaining that it was made in the name of an employee network at SUSE. We decided to investigate and asked the people responsible, and we want to share this awesome story with you. (Note - this is also a great idea for an initiative to ask your company about).
Our summer sale is over and now is the time for us to restock! Remember that you can still order our merchandise online and also get it at our booth at several events! Also, if you are wearing our t-shirt and socks this summer, do not forget to post about it in your social media channels and tag us! We love to see our products all around the world, and it is a great way to spread the message about Free Software and Software Freedom!
The FSFE participated in the Trento Open Festival conference (Italy) giving some talks, participating in panel discussions and with reading of the book ‘Ada & Zangemann: a Tale of Software, Skateboards, and Raspberry Ice Cream'. Besides, the outcome of the ZOOOM project was validated with different stakeholders.
Also, the FSFE went to Tübingen (Germany) to participate in this yearly event around GNU/Linux and Free Software. We had a reading of the book ‘Ada & Zangemann: a Tale of Software, Skateboards, and Raspberry Ice Cream’ and a talk about banks and Free Software. And of course, a booth.
Last month, we also had an Ada & Zangemann reading, in Offenburg (Germany). The reading was opened by Offenburg's mayor and attended by more than 200 third graders in Offenburg's largest cinema. The 200 pupils had the chance to discuss the book with the author after the reading.
The illustrated book was also present at DevConf.CZ, where the FSFE shared experiences from readings, and discussed how to engage with younger audiences about Free Software https://www.offenburg.de/de/detail/nachricht-seite/id/19191-digitaltag-kommt-an/?default=true (DE)
We would love to hear from you. If you have any thoughts, pictures, or news to share, please send them to us at newsletter@fsfe.org. You can also support us, contribute to our work, and join our community. We would like to thank our community and all the volunteers, supporters, and donors who make our work possible, with a special mention to our translators who make it possible for you to read this newsletter in your mother tongue.
Your editor, Ana
Linux Mint 22 Beta steht mit Cinnamon 6.2. zum Test bereit. Viele GNOME-Apps wurden auf GTK3 zurückgeführt, um der Designbibliothek Libadweita zu entgehen.
Wer seinen Rechner ausschalten möchte, muss nicht viermal klicken. Eine Tastenkombination erledigt den Job.


Eine von Qualys entdeckte Sicherheitslücke im OpenSSH-Server mit einem CVSS-Score von 9 wurde geschlossen. Erfolgreiche Angreifer erhalten automatisch Root-Rechte.
Dem Forscherteam von Qualys ist es gelungen, eine ältere Sicherheitslücke in OpenSSH, die schon eigentlich längst geschlossen war, erneut auszunutzen. Die neue Lücke wird als CVE-2024-6387 geführt und ist deswegen brisant, weil Sie bei Erfolg dem Angreifer Root-Rechte ohne vorherige Authentifizierung ermöglicht. Die nötigen Bedingungen für ein Ausnutzen der Lücke sind allerdings nicht ganz trivial.
Die gesamte Erläuterung der Sicherheitslücke ist im Bericht von Qualys umfangreich erläutert wollen. Wenn wir es schaffen, werden wir diesen schon Mittwoch im Risikozone-Podcast detaillierter erläutern.
So viel sei gesagt: die Lücke existierte schon mal als CVE-2006-5051, wurde dann gefixt und konnte jetzt (erstmals) ausgenutzt werden, da der eigentlich kritische Teil 2020 wieder versehentlich eingebaut wurde.
Der Fehler selber baut darauf, dass syslog() zur Protokollierung asynchron aufgerufen wird, obwohl die Funktion nicht "async-signal-safe" ist. Kann ein Angreifer Timingeigenschaften ausnutzen, wird er in die Lage versetzt, Code einzuschleusen, der in einem privilegierten Teil von OpenSSH ausgeführt wird. Der Zeitaufwand ist allerdings hierfür nicht zu unterschätzen, da das Codefragment nur bei einem Verbindungstimeout aufgerufen wird.
Es ist gemäß des Qualys-Berichtes hervorzuheben:
Mit anderen Worten: abhängig von eurem System ist die Schwachstelle vorhanden, weswegen ihr in eure Distribution schauen solltet, ob es Updates gibt.
OpenSSH ist nichtsdestotrotz im Hinblick auf seine Rolle und Exposition eines der sichersten Programme der Welt. Die Software ist ein sehr stringent abgesicherter Dienst, der u. a. auf Sandboxing-Mechansimen setzt, um den Umfang der Codesegmente, die als root ausgeführt werden, gering zu halten. Diese Lücke ist eine der seltenen Situationen, in der trotzdem ein Security-Bug vorhanden ist. Dabei ist eine Ausnutzung vergleichsweise aufwändig.
Sommer, Sonne, Fediverse.
Bereits zum 3. Mal findet das Fedicamp in Gedelitz statt. Was ist so besonders an dem freien Netzwerk, dass sich jedes Jahr Menschen nicht nur online sondern auch offline treffen und ihren Urlaub miteinander verbringen?


Die Raspberry Pi Foundation bietet mit Raspberry Pi Connect Zugriff über den Browser. Die aktuelle Beta-Version erweitert den Dienst auf alle Raspberry Pi-Modelle.
Ein Kurztest des auf der Engine Webkit basierten Browsers GNOME Web. Taugt er als Firefox-Ersatz?


The FSFE calls upon the European Commission to use Free Software to ensure a secure and resilient digital infrastructure. Software freedom will also benefit the economy, civil society and democracy.
The Free Software Foundation Europe (FSFE) provided last evening its input to the European Commission's consultation on the white paper "How to master Europe’s digital infrastructure needs?". As an advocate for software freedom, the FSFE underscores the crucial role of Free Software in building secure and resilient digital infrastructure for Europe while strengthening economy, democracy and civil society alike.
Challenges around digital infrastructure occur at global, regional and local levels, often revolving around control and access. Collaboration and openness are playing just as important role as the capability and skills to swiftly and effectively fix issues. Challenges addressed by the White paper could be addressed by redirecting IT investments in software freedom instead of procuring closed source, proprietary software. This approach not only boosts the European IT landscape and creates jobs but also saves costs and resources in the medium and long term by avoiding the need to repeatedly reinvent the the wheel.
“The European digital infrastructure, the European tech market, the IT skills of Europeans and civil society would greatly benefit if investments in software adhered to the principle of “Public money? Public Code!” We need software that fosters the sharing of good ideas and solutions. Like this we will be able to manage and improve IT services and digital infrastructure all over Europe. We need software that guarantees freedom of choice, access, and competition. We need software that helps public administrations regain full control of their critical digital infrastructure, allowing them to become and remain independent from a handful of companies. Therefore, laws and programs are needed, that publicly financed software developed for public sector must be made publicly available under a Free Software licence. Investment in the Free Software ecosystem will pay off quickly while strengthening Europe infrastructure, economy, democracy and civil society alike.” , demands Alexander Sander, FSFE’s Senior Policy Consultant.
The "Public Money? Public Code!" initiative aims to establish Free Software as the standard for publicly funded software. The "Public Money? Public Code!" initiative of the Free Software Foundation Europe is supported by over 200 organizations and administrations.
Die Macher des Vivaldi-Browsers entziehen sich dem Hype um KI und werden derzeit keine Large Language Models in den Browser einbauen.
Kurz notiert: Debian 10 mit dem Codenamen "buster" erreicht heute das End of Life. Die Unterstützung wurde bis 2022 vom Debian-Team bereitgestellt und dann bis zum heutigen Tage durch das LTS-Team sichergestellt. Damit wurde Debian 10 knapp fünf Jahre durchgängig unterstützt.
Debian 10 wurde am 6. Juli 2019 und somit vor knapp fünf Jahren veröffentlicht. Ausgeliefert wurde das Betriebssystem mit dem Linux-Kernel 4.19. Der letzte Point-Release erfolgte am 10. September 2022, damit endete auch der klassische Security-Support.
Anschließend hat das LTS-Team die Unterstützung am 1. August 2022 mit einer Teilmenge von Architekturen (amd64, i386, amd64, armhf) übernommen, damit Nutzer wichtige Sicherheitsupdates noch erhalten und die Gelegenheit haben, auf den Folge-Release umzustellen. Diese Unterstützung läuft am heutigen Tage aus.
Es ist somit an der Zeit, auf Debian 11 mit dem Codenamen "bullseye" umzustellen. Die Migrationsanleitung ist in den Release Notes für Debian 11 zu finden. Hier wird auch erläutert, mit welchen Breaking Changes zu rechnen ist. Wie üblich, lässt sich der Release über die APT-Konfiguration anheben, gefolgt von einem Upgrade über APT. Die wichtigste Änderung dabei ist, dass das Security-Archiv ein neues Layout hat. Ich habe einige Systeme schon aktualisiert, dabei gab es bei mir keine Probleme. Das sollte auch bei anderen Systemen keine Schwierigkeiten bereiten, wenn sich an den offiziellen Debian-Paketquellen orientiert wird. Die Backports sollte man aber kontrollieren, wenn z. B. ein Backports-Kernel genutzt wurde, um WireGuard schon mit Debian 10 nutzen zu können (erst Debian 11 hat eine Kernelversion, in der WireGuard integriert ist).
Aktuell werden vom Debian-Team die Versionen 11 (bullseye) und 12 (bookworm) als Hauptversionen gepflegt. Das LTS-Team ist eine Gruppe von Freiwilligen, die sich zum Ziel gesetzt hat, eine fünfjährige Unterstützung für Debian-Versionen sicherzustellen. Wer eine zehnjährige Unterstützung benötigt, kann auf entgeltliche ELTS-Angebote wie z. B. von Freexian zurückgreifen.
Heute soll es um unsere Kommentarkultur gehen, die in letzter Zeit leider zu Wünschen übrig lässt.
Mit InvoiceNinja schreibst Du professionell Deine Rechnung auch von unterwegs, einmal auf einen Server installiert und schon kann es losgehen. Free open Source und kostenfrei. Eine Kurzvorstellung

