Fedora 13 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Sun Apr 17 21:26:13 UTC 2011


The following Fedora 13 Security updates need testing:

    https://admin.fedoraproject.org/updates/tor-0.2.1.29-1300.fc13
    https://admin.fedoraproject.org/updates/kdelibs-4.5.5-2.fc13
    https://admin.fedoraproject.org/updates/mediawiki-1.16.4-57.fc13
    https://admin.fedoraproject.org/updates/libmodplug-0.8.7-3.fc13
    https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc13
    https://admin.fedoraproject.org/updates/perl-Mojolicious-0.999925-3.fc13
    https://admin.fedoraproject.org/updates/perl-5.10.1-123.fc13
    https://admin.fedoraproject.org/updates/openldap-2.4.21-12.fc13
    https://admin.fedoraproject.org/updates/dhcp-4.1.2-4.ESV.R2.fc13
    https://admin.fedoraproject.org/updates/seamonkey-2.0.13-1.fc13
    https://admin.fedoraproject.org/updates/kdenetwork-4.5.5-2.fc13
    https://admin.fedoraproject.org/updates/libcgroup-0.35.1-5.fc13
    https://admin.fedoraproject.org/updates/libtiff-3.9.5-1.fc13
    https://admin.fedoraproject.org/updates/python-feedparser-5.0.1-1.fc13
    https://admin.fedoraproject.org/updates/libvirt-0.8.2-6.fc13
    https://admin.fedoraproject.org/updates/xorg-x11-server-utils-7.4-17.fc13
    https://admin.fedoraproject.org/updates/krb5-1.7.1-19.fc13
    https://admin.fedoraproject.org/updates/ikiwiki-3.20100815.7-1.fc13
    https://admin.fedoraproject.org/updates/tmux-1.4-3.fc13
    https://admin.fedoraproject.org/updates/fail2ban-0.8.4-27.fc13


The following Fedora 13 Critical Path updates have yet to be approved:

    https://admin.fedoraproject.org/updates/python-ethtool-0.7-2.fc13
    https://admin.fedoraproject.org/updates/libtiff-3.9.5-1.fc13
    https://admin.fedoraproject.org/updates/pygtk2-2.17.0-8.fc13
    https://admin.fedoraproject.org/updates/dosfstools-3.0.9-5.fc13
    https://admin.fedoraproject.org/updates/tzdata-2011d-3.fc13
    https://admin.fedoraproject.org/updates/policycoreutils-2.0.83-33.8.fc13
    https://admin.fedoraproject.org/updates/libimobiledevice-1.0.6-1.fc13
    https://admin.fedoraproject.org/updates/usbmuxd-1.0.7-1.fc13
    https://admin.fedoraproject.org/updates/fuse-2.8.5-5.fc13
    https://admin.fedoraproject.org/updates/libcgroup-0.35.1-5.fc13
    https://admin.fedoraproject.org/updates/openldap-2.4.21-12.fc13
    https://admin.fedoraproject.org/updates/livecd-tools-13.2-1.fc13
    https://admin.fedoraproject.org/updates/lua-5.1.4-7.fc13
    https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-7.fc13
    https://admin.fedoraproject.org/updates/lldpad-0.9.26-2.fc13


The following builds have been pushed to Fedora 13 updates-testing

    fail2ban-0.8.4-27.fc13
    libburn-1.0.6-1.fc13
    mfiler3-4.2.7-2.fc13
    perl-Mojolicious-0.999925-3.fc13
    perl-Test-CheckManifest-1.24-1.fc13
    saphire-1.4.0-1.fc13

Details about builds:


================================================================================
 fail2ban-0.8.4-27.fc13 (FEDORA-2011-5151)
 Ban IPs that make too many password failures
--------------------------------------------------------------------------------
Update Information:

fail2ban used predictable /tmp files which a local user can allocate before fail2ban does. All tmp files have been moved to /var/lib/fail2ban. This also helps with selinux policies.

Another security related fix is that fail2ban defaulted to gamin which conflicts with selinux, so users had to typically choose between fail2ban and selinux. fail2ban now defaults to inotify (thanks to Jonathan Underwood).

There are also some minor bugs fixed:
* tmpfiles.d support for tmpfs /var/run
* example mail domains changed to normalized example.com.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Apr  9 2011 Axel Thimm <Axel.Thimm at ATrpms.net> - 0.8.4-27
- Move tmp files to /var/lib (suggested by Phil Anderson).
- Enable inotify support (by Jonathan Underwood).
- Fixes RH bugs #669966, #669965, #551895, #552947, #658849, #656584.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #669966 - fail2ban can't work with tmp files
        https://bugzilla.redhat.com/show_bug.cgi?id=669966
  [ 2 ] Bug #669965 - unsafe use of /tmp
        https://bugzilla.redhat.com/show_bug.cgi?id=669965
  [ 3 ] Bug #551895 - RFE: Add patch to enable inotify support
        https://bugzilla.redhat.com/show_bug.cgi?id=551895
  [ 4 ] Bug #552947 - RFE: conform fail2ban example email sending domains to RFC 2606
        https://bugzilla.redhat.com/show_bug.cgi?id=552947
  [ 5 ] Bug #658849 - Please change fail2ban to not use gam_server
        https://bugzilla.redhat.com/show_bug.cgi?id=658849
  [ 6 ] Bug #656584 - Please Update Spec File to use %ghost on files in /var/run and /var/lock
        https://bugzilla.redhat.com/show_bug.cgi?id=656584
--------------------------------------------------------------------------------


================================================================================
 libburn-1.0.6-1.fc13 (FEDORA-2011-5511)
 Library for reading, mastering and writing optical discs
--------------------------------------------------------------------------------
Update Information:

Changes towards previous version 1.0.4:

  * Burning DVD-R DAO with 2 kB size granularity rather than 32 kB
  * New API call burn_allow_drive_role_4()


Changes towards previous version 1.0.2:

  * Bug fix: Read-only file descriptors were classified as write-only pseudo drives
--------------------------------------------------------------------------------
ChangeLog:

* Sun Apr 17 2011 Robert Scheck <robert at fedoraproject.org> 1.0.6-1
- Update to upstream 1.0.6
* Mon Feb 28 2011 Honza Horak <hhorak at redhat.com> - 1.0.2-1
- Update to upstream 1.0.2
* Thu Feb 17 2011 Honza Horak <hhorak at redhat.com> - 1.0.0-1
- Update to upstream 1.0.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.8.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Apr 22 2010 Nikola Pajkovsky <npajkovs at redhat.com> - 0.8.0-1
- Update to upstream 0.8.0
--------------------------------------------------------------------------------


================================================================================
 mfiler3-4.2.7-2.fc13 (FEDORA-2011-5510)
 Two pane file manager under UNIX console
--------------------------------------------------------------------------------
Update Information:

Update saphire to 1.4.0

Also saphire / mfiler3 will use less instead of lv for Japanese help page.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Apr 14 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 4.2.7-2
- Fix compilation error with saphire 1.4.0 (and actually fix
  symbol error)
- Prefer less over lv for help pager
--------------------------------------------------------------------------------


================================================================================
 perl-Mojolicious-0.999925-3.fc13 (FEDORA-2011-5505)
 A next generation web framework for Perl
--------------------------------------------------------------------------------
Update Information:

Security bugfix attempt
http://blog.kraih.com/mojolicious-116-emergency-release-please-upgr
--------------------------------------------------------------------------------
ChangeLog:

* Sun Apr 17 2011 Yanko Kaneti <yaneti at declera.com> 0.999925-3
- Security bugfix attempt.
--------------------------------------------------------------------------------


================================================================================
 perl-Test-CheckManifest-1.24-1.fc13 (FEDORA-2011-5499)
 Check if your Manifest matches your distro
--------------------------------------------------------------------------------
ChangeLog:

* Sun Apr 17 2011 Ralf Corsépius <corsepiu at fedoraproject.org> 1.24-1
- Upstream update.
--------------------------------------------------------------------------------


================================================================================
 saphire-1.4.0-1.fc13 (FEDORA-2011-5510)
 Yet another shell
--------------------------------------------------------------------------------
Update Information:

Update saphire to 1.4.0

Also saphire / mfiler3 will use less instead of lv for Japanese help page.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr 13 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 1.4.0-1
- 1.4.0
- Prefer less over lv for help pager
--------------------------------------------------------------------------------



More information about the test mailing list