[EPEL-devel] Fedora EPEL 5 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Wed Oct 22 18:49:29 UTC 2014


The following Fedora EPEL 5 Security updates need testing:
 Age  URL
 913  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2012-5630/bugzilla-3.2.10-5.el5
 368  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2013-11893/libguestfs-1.20.12-1.el5
 132  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-1626/puppet-2.7.26-1.el5
  28  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-2669/check-mk-1.2.4p5-1.el5
  27  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-2853/mediawiki119-1.19.18-1.el5
  12  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-3206/phpMyAdmin4-4.0.10.4-1.el5
   8  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-3333/catdoc-0.94.2-10.el5
   5  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-3455/drupal7-7.32-1.el5
   0  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-3549/rubygem-actionpack-2.3.18-1.el5,rubygem-activerecord-2.3.18-1.el5,rubygem-activesupport-2.3.18-1.el5


The following builds have been pushed to Fedora EPEL 5 updates-testing

    gfal2-util-1.0.0-2.el5
    globus-gram-audit-4.3-2.el5
    rubygem-actionpack-2.3.18-1.el5
    rubygem-activerecord-2.3.18-1.el5
    rubygem-activesupport-2.3.18-1.el5

Details about builds:


================================================================================
 gfal2-util-1.0.0-2.el5 (FEDORA-EPEL-2014-3532)
 GFAL2 utility tools
--------------------------------------------------------------------------------
Update Information:

Patch for is_alive
--------------------------------------------------------------------------------
ChangeLog:

* Wed Oct 22 2014 Alejandro Alvarez <aalvarez at cern.ch> - 1.0.0-2
- Patch for wrong use of is_alive (not available in Python 2.4)
--------------------------------------------------------------------------------


================================================================================
 globus-gram-audit-4.3-2.el5 (FEDORA-EPEL-2014-3529)
 Globus Toolkit - GRAM Jobmanager Auditing
--------------------------------------------------------------------------------
Update Information:

Remove unexpanded configure macro.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 19 2014 Mattias Ellert <mattias.ellert at fysast.uu.se> - 4.3-2
- Remove unexpanded configure macro
--------------------------------------------------------------------------------


================================================================================
 rubygem-actionpack-2.3.18-1.el5 (FEDORA-EPEL-2014-3549)
 Web-flow and rendering framework putting the VC in MVC
--------------------------------------------------------------------------------
Update Information:

Rebase to 2.3.18 in EPEL5. This is a security rollup. 

 - Bug 1095122 - CVE-2014-0130
 - Bug 1095125 - CVE-2014-0130
 - Bug 677626 - CVE-2011-0446
 - Bug 677629 - CVE-2011-0446, CVE-2011-0447
 - Bug 677631 - CVE-2011-0447
 - Bug 731435 - CVE-2011-2932
 - Bug 731438  -  CVE-2011-2930
 - Bug 731450 - CVE-2011-2932
 - Bug 731453  -  CVE-2011-2930
 - Bug 744706  - CVE-2010-3933
 - Bug 831583  - CVE-2012-2695
 - Bug 843924  - CVE-2012-3424
 - Bug 847202 - CVE-2013-0156
 - Bug 891468  - CVE-2012-5664
 - Bug 905373 - CVE-2013-0333
 - Bug 921329  - CVE-2013-1854
 - Bug 924297 - CVE-2013-1855, CVE-2013-1857
 - Bug 924318  - CVE-2013-1854
 - Bug 948706  - CVE-2013-0276
--------------------------------------------------------------------------------
ChangeLog:

* Tue Oct 21 2014 Michael Stahnke <stahnma at fedoraproject.org> - 2.3.18-1
- Updated to 2.3.18
- Bug 677629 - CVE-2011-0446, CVE-2011-0447 fixed in 2.3.11
- Bug 847202 - CVE-2013-0156 fixed in 2.3.15
- Bug 924297 - CVE-2013-1855, CVE-2013-1857 fixed 2.3.18
- Bug 677626 - CVE-2011-0446 fixed in 2.3.11
- Bug 677631 - CVE-2011-0447 fixed in 2.3.11
- Bug 843924 - CVE-2012-3424 fixed by updating to 2.3.18
- Bug 1095122 - CVE-2014-0130 fixed in 2.3.18
* Fri Apr 30 2010 Jeroen van Meeuwen <kanarip at kanarip.com> -2.1.1-6
- Apply fix for CVE-2009-3086 (bz #522162)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #677626 - CVE-2011-0446 rubygem-actionpack: Multiple XSS flaws via crafted name or email value in the mail_to_helper
        https://bugzilla.redhat.com/show_bug.cgi?id=677626
  [ 2 ] Bug #677631 - CVE-2011-0447 rubygem-actionpack: CSRF flaws due improper validation of HTTP headers containing X-Requested-With header
        https://bugzilla.redhat.com/show_bug.cgi?id=677631
  [ 3 ] Bug #731435 - CVE-2011-2932 rubygem-activesupport: XSS vulnerability in escaping function (Ruby on Rails)
        https://bugzilla.redhat.com/show_bug.cgi?id=731435
  [ 4 ] Bug #731438 - CVE-2011-2930 rubygem-activerecord: SQL injection vulnerability in quote_table_name (Ruby on Rails)
        https://bugzilla.redhat.com/show_bug.cgi?id=731438
  [ 5 ] Bug #744706 - CVE-2010-3933 rubygem-activerecord: Improper nested attributes management
        https://bugzilla.redhat.com/show_bug.cgi?id=744706
  [ 6 ] Bug #921329 - CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
        https://bugzilla.redhat.com/show_bug.cgi?id=921329
--------------------------------------------------------------------------------


================================================================================
 rubygem-activerecord-2.3.18-1.el5 (FEDORA-EPEL-2014-3549)
 Implements the ActiveRecord pattern for ORM
--------------------------------------------------------------------------------
Update Information:

Rebase to 2.3.18 in EPEL5. This is a security rollup. 

 - Bug 1095122 - CVE-2014-0130
 - Bug 1095125 - CVE-2014-0130
 - Bug 677626 - CVE-2011-0446
 - Bug 677629 - CVE-2011-0446, CVE-2011-0447
 - Bug 677631 - CVE-2011-0447
 - Bug 731435 - CVE-2011-2932
 - Bug 731438  -  CVE-2011-2930
 - Bug 731450 - CVE-2011-2932
 - Bug 731453  -  CVE-2011-2930
 - Bug 744706  - CVE-2010-3933
 - Bug 831583  - CVE-2012-2695
 - Bug 843924  - CVE-2012-3424
 - Bug 847202 - CVE-2013-0156
 - Bug 891468  - CVE-2012-5664
 - Bug 905373 - CVE-2013-0333
 - Bug 921329  - CVE-2013-1854
 - Bug 924297 - CVE-2013-1855, CVE-2013-1857
 - Bug 924318  - CVE-2013-1854
 - Bug 948706  - CVE-2013-0276
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #677626 - CVE-2011-0446 rubygem-actionpack: Multiple XSS flaws via crafted name or email value in the mail_to_helper
        https://bugzilla.redhat.com/show_bug.cgi?id=677626
  [ 2 ] Bug #677631 - CVE-2011-0447 rubygem-actionpack: CSRF flaws due improper validation of HTTP headers containing X-Requested-With header
        https://bugzilla.redhat.com/show_bug.cgi?id=677631
  [ 3 ] Bug #731435 - CVE-2011-2932 rubygem-activesupport: XSS vulnerability in escaping function (Ruby on Rails)
        https://bugzilla.redhat.com/show_bug.cgi?id=731435
  [ 4 ] Bug #731438 - CVE-2011-2930 rubygem-activerecord: SQL injection vulnerability in quote_table_name (Ruby on Rails)
        https://bugzilla.redhat.com/show_bug.cgi?id=731438
  [ 5 ] Bug #744706 - CVE-2010-3933 rubygem-activerecord: Improper nested attributes management
        https://bugzilla.redhat.com/show_bug.cgi?id=744706
  [ 6 ] Bug #921329 - CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
        https://bugzilla.redhat.com/show_bug.cgi?id=921329
--------------------------------------------------------------------------------


================================================================================
 rubygem-activesupport-2.3.18-1.el5 (FEDORA-EPEL-2014-3549)
 Support and utility classes used by the Rails framework
--------------------------------------------------------------------------------
Update Information:

Rebase to 2.3.18 in EPEL5. This is a security rollup. 

 - Bug 1095122 - CVE-2014-0130
 - Bug 1095125 - CVE-2014-0130
 - Bug 677626 - CVE-2011-0446
 - Bug 677629 - CVE-2011-0446, CVE-2011-0447
 - Bug 677631 - CVE-2011-0447
 - Bug 731435 - CVE-2011-2932
 - Bug 731438  -  CVE-2011-2930
 - Bug 731450 - CVE-2011-2932
 - Bug 731453  -  CVE-2011-2930
 - Bug 744706  - CVE-2010-3933
 - Bug 831583  - CVE-2012-2695
 - Bug 843924  - CVE-2012-3424
 - Bug 847202 - CVE-2013-0156
 - Bug 891468  - CVE-2012-5664
 - Bug 905373 - CVE-2013-0333
 - Bug 921329  - CVE-2013-1854
 - Bug 924297 - CVE-2013-1855, CVE-2013-1857
 - Bug 924318  - CVE-2013-1854
 - Bug 948706  - CVE-2013-0276
--------------------------------------------------------------------------------
ChangeLog:

* Tue Oct 21 2014 Michael Stahnke <stahnma at fedoraproject.org> - -2.3.18-1
- Update to 2.3.18
- Obsolete patch for CVE-2009-3009 fixed in 2.3.4
- Bug 905373 - CVE-2013-0333 fixed in 2.3.16
- Bug 731435 - CVE-2011-2932
- Bug 731435, 731450 - CVE-2011-2932 fixed in 2.3.8
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #677626 - CVE-2011-0446 rubygem-actionpack: Multiple XSS flaws via crafted name or email value in the mail_to_helper
        https://bugzilla.redhat.com/show_bug.cgi?id=677626
  [ 2 ] Bug #677631 - CVE-2011-0447 rubygem-actionpack: CSRF flaws due improper validation of HTTP headers containing X-Requested-With header
        https://bugzilla.redhat.com/show_bug.cgi?id=677631
  [ 3 ] Bug #731435 - CVE-2011-2932 rubygem-activesupport: XSS vulnerability in escaping function (Ruby on Rails)
        https://bugzilla.redhat.com/show_bug.cgi?id=731435
  [ 4 ] Bug #731438 - CVE-2011-2930 rubygem-activerecord: SQL injection vulnerability in quote_table_name (Ruby on Rails)
        https://bugzilla.redhat.com/show_bug.cgi?id=731438
  [ 5 ] Bug #744706 - CVE-2010-3933 rubygem-activerecord: Improper nested attributes management
        https://bugzilla.redhat.com/show_bug.cgi?id=744706
  [ 6 ] Bug #921329 - CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability
        https://bugzilla.redhat.com/show_bug.cgi?id=921329
--------------------------------------------------------------------------------



More information about the epel-devel mailing list