Fedora 14 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Sun Jul 31 04:05:23 UTC 2011


The following Fedora 14 Security updates need testing:

    https://admin.fedoraproject.org/updates/foomatic-4.0.7-2.fc14
    https://admin.fedoraproject.org/updates/java-1.6.0-openjdk-1.6.0.0-54.1.9.9.fc14
    https://admin.fedoraproject.org/updates/freetype-2.4.2-5.fc14
    https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-2.git20110622.fc14
    https://admin.fedoraproject.org/updates/cifs-utils-4.8.1-7.fc14
    https://admin.fedoraproject.org/updates/drupal7-7.6-1.fc14
    https://admin.fedoraproject.org/updates/cgit-0.9.0.2-2.fc14
    https://admin.fedoraproject.org/updates/wireshark-1.4.8-1.fc14
    https://admin.fedoraproject.org/updates/system-config-firewall-1.2.27-2.fc14
    https://admin.fedoraproject.org/updates/libsndfile-1.0.25-1.fc14
    https://admin.fedoraproject.org/updates/glpi-0.78.5-2.svn14966.fc14,glpi-data-injection-2.0.2-1.fc14,glpi-mass-ocs-import-1.4.2-1.fc14,glpi-pdf-0.7.2-1.fc14
    https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.3.2-1.fc14
    https://admin.fedoraproject.org/updates/libcap-2.22-1.fc14
    https://admin.fedoraproject.org/updates/quake3-1.36-11.svn2102.fc14,openarena-0.8.5-4.fc14
    https://admin.fedoraproject.org/updates/libsoup-2.32.2-2.fc14
    https://admin.fedoraproject.org/updates/dbus-1.4.0-3.fc14
    https://admin.fedoraproject.org/updates/tomcat6-6.0.26-21.fc14
    https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14
    https://admin.fedoraproject.org/updates/gdk-pixbuf2-2.22.0-2.fc14


The following Fedora 14 Critical Path updates have yet to be approved:

    https://admin.fedoraproject.org/updates/dbus-1.4.0-3.fc14
    https://admin.fedoraproject.org/updates/libsoup-2.32.2-2.fc14
    https://admin.fedoraproject.org/updates/libcap-2.22-1.fc14
    https://admin.fedoraproject.org/updates/pinentry-0.8.1-4.fc14
    https://admin.fedoraproject.org/updates/freetype-2.4.2-5.fc14
    https://admin.fedoraproject.org/updates/mdadm-3.1.3-0.git20100804.3.fc14
    https://admin.fedoraproject.org/updates/libsndfile-1.0.25-1.fc14
    https://admin.fedoraproject.org/updates/sed-4.2.1-6.fc14
    https://admin.fedoraproject.org/updates/ModemManager-0.4.998-1.git20110706.fc14
    https://admin.fedoraproject.org/updates/unique-1.1.6-3.fc14
    https://admin.fedoraproject.org/updates/xorg-x11-drv-savage-2.3.2-3.fc14
    https://admin.fedoraproject.org/updates/mash-0.5.22-1.fc14
    https://admin.fedoraproject.org/updates/python-slip-0.2.17-1.fc14
    https://admin.fedoraproject.org/updates/gdk-pixbuf2-2.22.0-2.fc14
    https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-2.git20110622.fc14
    https://admin.fedoraproject.org/updates/perl-5.12.4-146.fc14
    https://admin.fedoraproject.org/updates/policycoreutils-2.0.85-30.2.fc14
    https://admin.fedoraproject.org/updates/system-config-keyboard-1.3.1-5.fc14
    https://admin.fedoraproject.org/updates/fedora-logos-14.0.2-1.fc14
    https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-8.fc14.2
    https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-3.fc14
    https://admin.fedoraproject.org/updates/evolution-exchange-2.32.3-1.fc14,evolution-data-server-2.32.3-1.fc14,evolution-2.32.3-1.fc14
    https://admin.fedoraproject.org/updates/xorg-x11-drv-nouveau-0.0.16-14.20101010git8c8f15c.fc14
    https://admin.fedoraproject.org/updates/libconcord-0.23-5.fc14,udev-161-9.fc14,concordance-0.23-2.fc14
    https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14


The following builds have been pushed to Fedora 14 updates-testing

    BackupPC-3.2.1-1.fc14
    OpenImageIO-0.10.0-2.fc14
    abattis-cantarell-fonts-0.0.6-1.fc14
    alure-1.2-1.fc14
    apcupsd-3.14.9-1.fc14
    augeas-0.9.0-1.fc14
    bitlbee-3.0.3-2.fc14
    bluedevil-1.1.1-1.fc14
    choqok-1.0.1-2.fc14
    cifs-utils-4.8.1-7.fc14
    clex-4.6-1.fc14
    cups-1.4.8-1.fc14
    curlpp-0.7.3-4.fc14
    dbus-1.4.0-3.fc14
    diffpdf-1.2.2-1.fc14
    drupal7-7.6-1.fc14
    euca2ools-1.3.1-12.fc14
    facter-1.6.0-2.fc14
    gambit-c-4.6.1-1.fc14
    gbrainy-2.00-1.fc14
    gdcm-2.0.16-14.fc14.1
    goobook-1.3-8.fc14
    groonga-1.2.4-1.fc14
    kdelibs-4.6.5-2.fc14
    kmetronome-0.10.0-3.fc14
    kwebkitpart-1.1-0.1.20110720.fc14
    libcap-2.22-1.fc14
    libertas-sd8686-firmware-9.70.20.p0-1.fc14
    libguestfs-1.8.10-1.fc14
    libjingle-0.5.8-1.fc14
    libsoup-2.32.2-2.fc14
    lilypond-2.14.2-1.fc14
    lilypond-doc-2.14.2-1.fc14
    mfiler3-4.4.1-1.fc14
    mksh-40b-2.fc14
    mock-1.1.12-1.fc14
    ncrack-0.4-0.1.ALPHA.fc14
    nifticlib-2.0.0-2.fc14
    nss-pam-ldapd-0.7.13-1.fc14
    openarena-0.8.5-4.fc14
    openscap-0.7.4-1.fc14
    paco-2.0.9-6.fc14
    perl-Cache-FastMmap-1.39-1.fc14
    perl-Data-Serializer-0.59-1.fc14
    perl-Dist-Zilla-4.200012-1.fc14
    perl-HTML-FormatText-WithLinks-AndTables-0.01-2.fc14
    perl-NetPacket-1.2.0-1.fc14
    perl-RPM-VersionCompare-0.1.1-1.fc14
    php-pecl-xdebug-2.1.2-1.fc14
    pinentry-0.8.1-4.fc14
    publican-2.6-3.fc14
    python-confparser-1.0.0-3.fc14
    python-confparser-1.0.0-4.fc14
    python-fedora-0.3.24-1.fc14
    qcodeedit-2.2.3-7.fc14
    qodem-0.3.2-1.fc14
    quake3-1.36-11.svn2102.fc14
    rekonq-0.7.0-1.fc14
    rubygem-aws-sdk-1.0.2-1.fc14
    saphire-3.3.5-1.fc14
    scheme2js-20110717-1.fc14
    shorewall-4.4.21.1-3.fc14.1
    slapi-nis-0.25-1.fc14
    starcal-1.9.3-2.fc14
    subtitleeditor-0.39.0-1.fc14
    sysprof-1.1.8-1.fc14
    vtk-5.6.1-9.fc14.1

Details about builds:


================================================================================
 BackupPC-3.2.1-1.fc14 (FEDORA-2011-9902)
 High-performance backup system
--------------------------------------------------------------------------------
Update Information:

- v 3.2.1
- add lower case script URL alias for typing impaired
- cleanup selinux macros
- spec cleanup
- make samba dependency on actual files required to EL5 can use samba-client
  or samba3x-client (bz #667479)
- unbundle perl(Net::FTP::AutoReconnect) and perl(Net::FTP::RetrHandle)
- remove old patch that is no longer needed
- attempt to make sure $Conf{TopDir} is listed in updatedb PRUNEPATHS,
  otherwise at least generate a warning on statup (bz #554491)
- move sockets to /var/run (bz #719499)
- add support for systemd starting at F16 (bz #699441)
- patch to move pid dir under /var/run
- unbundle Net::FTP::*
- add support for tmpfiles.d

--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul  8 2011 Bernard Johnson <bjohnson at symetrix.com> - 3.2.1-1
- v 3.2.1
- add lower case script URL alias for typing impaired
- cleanup selinux macros
- spec cleanup
- make samba dependency on actual files required to EL5 can use samba-client
  or samba3x-client (bz #667479)
- unbundle perl(Net::FTP::AutoReconnect) and perl(Net::FTP::RetrHandle)
- remove old patch that is no longer needed
- attempt to make sure $Conf{TopDir} is listed in updatedb PRUNEPATHS,
  otherwise at least generate a warning on statup (bz #554491)
- move sockets to /var/run (bz #719499)
- add support for systemd starting at F16 (bz #699441)
- patch to move pid dir under /var/run
- unbundle Net::FTP::*
- add support for tmpfiles.d
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 3.1.0-17
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #667479 - BackupPC incompatible with samba3x
        https://bugzilla.redhat.com/show_bug.cgi?id=667479
  [ 2 ] Bug #554491 - /var/lib/BackupPC should be excluded from locate(1) database
        https://bugzilla.redhat.com/show_bug.cgi?id=554491
  [ 3 ] Bug #719499 - Socket file should be in /var/run/BackupPC/ instead of /var/log/
        https://bugzilla.redhat.com/show_bug.cgi?id=719499
  [ 4 ] Bug #699441 - Providing native systemd file for upcoming F15 Feature Systemd
        https://bugzilla.redhat.com/show_bug.cgi?id=699441
--------------------------------------------------------------------------------


================================================================================
 OpenImageIO-0.10.0-2.fc14 (FEDORA-2011-9896)
 Library for reading and writing images
--------------------------------------------------------------------------------
Update Information:

OpenImageIO is a library for reading and writing images, and a bunch of related
classes, utilities, and applications. Main features include:
- Extremely simple but powerful ImageInput and ImageOutput APIs for reading and
  writing 2D images that is format agnostic.
- Format plugins for TIFF, JPEG/JFIF, OpenEXR, PNG, HDR/RGBE, Targa, JPEG-2000,
  DPX, Cineon, FITS, BMP, ICO, RMan Zfile, Softimage PIC, DDS, SGI,
  PNM/PPM/PGM/PBM, Field3d.
- An ImageCache class that transparently manages a cache so that it can access
  truly vast amounts of image data.
- A really nice image viewer, iv, also based on OpenImageIO classes (and so 
  will work with any formats for which plugins are available).
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #720411 - Review Request: OpenImageIO - Library for reading and writing images
        https://bugzilla.redhat.com/show_bug.cgi?id=720411
--------------------------------------------------------------------------------


================================================================================
 abattis-cantarell-fonts-0.0.6-1.fc14 (FEDORA-2011-9784)
 Cantarell, a Humanist sans-serif font family
--------------------------------------------------------------------------------
Update Information:

Build Cantarell for F14.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #713610 - Please build for Fedora 14
        https://bugzilla.redhat.com/show_bug.cgi?id=713610
--------------------------------------------------------------------------------


================================================================================
 alure-1.2-1.fc14 (FEDORA-2011-9775)
 Audio Library Tools REloaded
--------------------------------------------------------------------------------
Update Information:

Update to latest upstream
release.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 29 2011 Julian Aloofi <julian at fedoraproject.org> - 1.2-1
- update to latest upstream release
--------------------------------------------------------------------------------


================================================================================
 apcupsd-3.14.9-1.fc14 (FEDORA-2011-9821)
 APC UPS Power Control Daemon for Linux
--------------------------------------------------------------------------------
Update Information:

- updated to 3.14.9
- a lot of fixes in SNMP area
- fix shutdown command when utility power has been restored
- rework signal handling to eliminate crashes and hangs
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Michal Hlavinka <mhlavink at redhat.com> - 3.14.9-1
- apcupsd updated to 3.14.9
* Wed Feb  9 2011 Michal Hlavinka <mhlavink at redhat.com> - 3.14.8-4
- add readme file to doc explaining needed configuration of halt script
--------------------------------------------------------------------------------


================================================================================
 augeas-0.9.0-1.fc14 (FEDORA-2011-9858)
 A library for changing configuration files
--------------------------------------------------------------------------------
Update Information:

See http://augeas.net/news.html for details
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 David Lutterkort <lutter at redhat.com> - 0.9.0-1
- New version; removed patch pathx-whitespace-ea010d8
--------------------------------------------------------------------------------


================================================================================
 bitlbee-3.0.3-2.fc14 (FEDORA-2011-9846)
 IRC to other chat networks gateway
--------------------------------------------------------------------------------
Update Information:

New upstream release to make Twitter working again.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Matěj Cepl <mcepl at redhat.com> - 3.0.3-2
- One more fix to the systemd unit files (#705096)
* Wed Mar  9 2011 Matěj Cepl <mcepl at redhat.com> - 3.0.2-1
- New upstream release. We can eliminate parts which were already merged
  upstream (ssl_pending patch)
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 3.0.1-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Sun Jan  9 2011 Matěj Cepl <mcepl at redhat.com> - 3.0.1-8
- Fix crash when no SRV record is provided (#668190); fix by Ricky Zhou
* Wed Dec 29 2010 Matěj Cepl <mcepl at redhat.com> - 3.0.1-7
- Adding more missing systemd-support pieces and eliminate xinetd on F<15
--------------------------------------------------------------------------------


================================================================================
 bluedevil-1.1.1-1.fc14 (FEDORA-2011-9816)
 Bluetooth stack for KDE
--------------------------------------------------------------------------------
Update Information:

This is a bugfix release of Bluedevil. 

* Fixed  bugs (KDE bz): 277665, 277451, 277878
 * Fixed some bahaviors in kio_obexftp while copying files
 * Show the file size and the speed in the file transfer (in kio)

--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Jaroslav Reznik <jreznik at redhat.com> - 1.1.1-1
- update to 1.1.1
--------------------------------------------------------------------------------


================================================================================
 choqok-1.0.1-2.fc14 (FEDORA-2011-9709)
 KDE Micro-Blogging Client
--------------------------------------------------------------------------------
Update Information:

kwebkitpart-1.1 bugfix update.
See https://projects.kde.org/news/21
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Alexey Kurov <nucleo at fedoraproject.org> - 1.0.1-2
- drop kwebkitpart support
--------------------------------------------------------------------------------


================================================================================
 cifs-utils-4.8.1-7.fc14 (FEDORA-2011-9847)
 Utilities for mounting and managing CIFS mounts
--------------------------------------------------------------------------------
Update Information:

This is an update that fixes a problem with handling embedded newlines in share names or mountpoints.

--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 29 2011 Jeff Layton <jlayton at redhat.com> 4.8.1-7
- mount.cifs: fix check_newline retcode check (bz# 726717)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #726717 - CVE-2011-2724 samba, cifs-utils (mount.cifs): check_newline returns EX_USAGE on error, not -1 (incomplete fix for CVE-2010-0547) [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=726717
--------------------------------------------------------------------------------


================================================================================
 clex-4.6-1.fc14 (FEDORA-2011-9873)
 A free file manager with a full-screen user interface
--------------------------------------------------------------------------------
Update Information:

Updated to latest version fixes bug listed.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Nathan Owe <ndowens at fedoraproject.org> 4.6-1
- Updated version to 4.6
- Cleaned Spec file
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 3.18-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #527269 - wishlist: please upgrade to a recent version
        https://bugzilla.redhat.com/show_bug.cgi?id=527269
--------------------------------------------------------------------------------


================================================================================
 cups-1.4.8-1.fc14 (FEDORA-2011-8916)
 Common Unix Printing System
--------------------------------------------------------------------------------
Update Information:

The new upstream release fixes a number of scheduler, driver, and backend issues.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Jiri Popelka <jpopelka at redhat.com> 1:1.4.8-1
- 1.4.8
* Wed Jul 20 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-8
- Don't delete job data files when restarted (STR #3880).
* Fri Jul 15 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-7
- Ship an rpm macro for where to put driver executables.
* Wed Jul 13 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-6
- Avoid busy loop in cups-polld (bug #720921).
* Thu Jul  7 2011 Jiri Popelka <jpopelka at redhat.com> 1:1.4.7-5
- Fix SNMP supply level crasher (STR #3875, bug #719057).
* Thu Jul  7 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-4
- Undo last change which had no effect.  We already remove the .SILENT
  target from the Makefile as part of the build.
* Thu Jul  7 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-3
- Make build log verbose enough to include compiler flags used.
* Wed Jun 29 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-2
- Tag localization files correctly (bug #716421).
* Tue Jun 28 2011 Jiri Popelka <jpopelka at redhat.com> 1:1.4.7-1
- 1.4.7.
* Thu Mar 10 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-7
- LSPP: only warn when unable to get printer context.
* Fri Feb 25 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-6
- Fixed build failure due to php_zend_api macro type.
* Fri Feb 25 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-5
- Fixed dbus notifier support for job-state-changed.
* Thu Feb 10 2011 Jiri Popelka <jpopelka at redhat.com> 1:1.4.6-4
- Remove testing cups-usb-buffer-size.patch (bug #661814).
* Tue Jan 18 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-3
- Don't use --enable-pie configure option as it has been removed and
  is now assumed.  See STR #3691.
* Mon Jan 10 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-2
- Use a smaller buffer when writing to USB devices (bug #661814).
- Handle EAI_NONAME when resolving hostnames (bug #617208).
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #716421 - cups package doesn't tag localization files correctly
        https://bugzilla.redhat.com/show_bug.cgi?id=716421
  [ 2 ] Bug #719057 - 1:1.4.7-3.fc15 trap divide error
        https://bugzilla.redhat.com/show_bug.cgi?id=719057
  [ 3 ] Bug #720921 - cups-polld busy-loops in recvfrom() after suspend/resume
        https://bugzilla.redhat.com/show_bug.cgi?id=720921
--------------------------------------------------------------------------------


================================================================================
 curlpp-0.7.3-4.fc14 (FEDORA-2011-9808)
 A C++ wrapper for libcURL
--------------------------------------------------------------------------------
Update Information:

New package
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #723053 - Review Request: curlpp - a C++ wrapper for libcURL
        https://bugzilla.redhat.com/show_bug.cgi?id=723053
--------------------------------------------------------------------------------


================================================================================
 dbus-1.4.0-3.fc14 (FEDORA-2011-9817)
 D-BUS message bus
--------------------------------------------------------------------------------
Update Information:

- Merge fixes from upstream for CVE-2011-2200

--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Colin Walters <walters at verbum.org> - 1:1.4.0-3
- CVE-2011-2200
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #712678 - CVE-2011-2200 dbus: Local DoS via messages with non-native byte order [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=712678
--------------------------------------------------------------------------------


================================================================================
 diffpdf-1.2.2-1.fc14 (FEDORA-2011-9802)
 PDF files comparator
--------------------------------------------------------------------------------
Update Information:

New upstream release with several bugfixes for this previously orphaned package.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Till Maas <opensource at till.name> - 1.2.2-1
- Update to new release
* Fri Jul 15 2011 Marek Kasik <mkasik at redhat.com> - 1.0.0-3
- Rebuild (poppler-0.17.0)
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.0.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 drupal7-7.6-1.fc14 (FEDORA-2011-9893)
 An open-source content-management platform
--------------------------------------------------------------------------------
Update Information:

Remember to log in as the admin user prior to RPM upgrade to perform DB upgrade.

* Advisory ID: DRUPAL-SA-CORE-2011-003
  * Project: Drupal core [1]
  * Version: 7.x
  * Date: 2011-July-27
  * Security risk: Less critical [2]
  * Exploitable from: Remote
  * Vulnerability: Access bypass

-------- DESCRIPTION  
---------------------------------------------------------

.... Access bypass in private file fields on comments.

Drupal 7 contains two new features: the ability to attach File upload fields
to any entity type in the system and the ability to point individual File
upload fields to the private file directory.

If a Drupal site is using these features on comments, and the parent node is
denied access (either by a node access module or by being unpublished), the
file attached to the comment can still be downloaded by non-privileged users
if they know or guess its direct URL.

This issue affects Drupal 7.x only.

-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Drupal 7.x before version 7.5.

-------- SOLUTION  
------------------------------------------------------------

Install the latest version:

  * If you are running Drupal 7.x then upgrade to Drupal 7.5 or 7.6.

The Security Team has released both a pure security update without other bug
fixes and a security update combined with other bug fixes and improvements.
You can choose to either only include the security update for an immediate
fix (which might require less quality assurance and testing) or more fixes
and improvements alongside the security fixes by choosing between Drupal 7.5
and Drupal 7.6. Read the announcement [3] for more information.

See also the Drupal core [4] project page.

-------- REPORTED BY  
---------------------------------------------------------

  * The File access bypass was reported by Florian Weber [5].

-------- FIXED BY  
------------------------------------------------------------

  * The File access bypass was fixed by Stéphane Corlosquet [6] and Károly
    Négyesi [7], both members of the Drupal security team.

-------- CONTACT AND MORE INFORMATION  
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [8].

Learn more about the Drupal Security team and their policies [9], writing
secure code for Drupal [10], and securing your site [11].


[1] http://drupal.org/project/drupal
[2] http://drupal.org/security-team/risk-levels
[3] http://drupal.org/drupal-7.6
[4] http://drupal.org/project/drupal
[5] http://drupal.org/user/254778
[6] http://drupal.org/user/52142
[7] http://drupal.org/user/9446
[8] http://drupal.org/contact
[9] http://drupal.org/security-team
[10] http://drupal.org/writing-secure-code
[11] http://drupal.org/security/secure-configuration

--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Jon Ciesla <limb at jcomserv.net> - 7.6-1
- New upstream, SA-CORE-2011-003, BZ 726243.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #726222 - drupal7: access bypass vulnerability in 7.x  (SA-CORE-2011-003)
        https://bugzilla.redhat.com/show_bug.cgi?id=726222
--------------------------------------------------------------------------------


================================================================================
 euca2ools-1.3.1-12.fc14 (FEDORA-2011-9909)
 Elastic Utility Computing Architecture Command-Line Tools
--------------------------------------------------------------------------------
Update Information:

This update fixes registration of EBS-backed images and adds support for bundle-upload location constraints.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 22 2011 Garrett Holmstrom <gholms at fedoraprojecto.rg> - 1.3.1-12
- Fixed registration of EBS-backed images
* Fri Jul  1 2011 Garrett Holmstrom <gholms at fedoraproject.org> - 1.3.1-11
- Backported support for bundle upload location constraints [LP:704658]
* Fri Jun 10 2011 Garrett Holmstrom <gholms at fedoraproject.org> - 1.3.1-11
- Fixed handling of empty block device sizes
- Fixed euca-describe-image-attribute -B output [LP:795395]
--------------------------------------------------------------------------------


================================================================================
 facter-1.6.0-2.fc14 (FEDORA-2011-9813)
 Ruby module for collecting simple facts about a host operating system
--------------------------------------------------------------------------------
Update Information:

Upstream bugfix release.  Highlights:

* Change license from GPLv2+ to ASL 2.0
* Speed Improvements
* Fact Detection Improvements
* Documentation

Refer to the upstream release notes for more details:

http://projects.puppetlabs.com/projects/facter/wiki
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Todd Zullinger <tmz at pobox.com> - 1.6.0-2
- Update license tag, GPLv2+ -> ASL 2.0
* Thu Jul 14 2011 Todd Zullinger <tmz at pobox.com> - 1.6.0-1
- Update to 1.6.0
--------------------------------------------------------------------------------


================================================================================
 gambit-c-4.6.1-1.fc14 (FEDORA-2011-9915)
 Scheme programming system
--------------------------------------------------------------------------------
Update Information:

Latest upstream release
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Michel Salim <salimma at fedoraproject.org> - 4.6.1-1
- Update to 4.6.1
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 4.6.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #691035 - gambit-c-4.6.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=691035
--------------------------------------------------------------------------------


================================================================================
 gbrainy-2.00-1.fc14 (FEDORA-2011-9862)
 A brain teaser game and trainer to keep your brain trained
--------------------------------------------------------------------------------
Update Information:

Required update to 2.00
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Benoît Marcelin <sereinity at online.fr> 2.00-1
- Update to 2.00
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #583266 - Upgrade gbrainy to latest stable version (currently 2.00)
        https://bugzilla.redhat.com/show_bug.cgi?id=583266
--------------------------------------------------------------------------------


================================================================================
 gdcm-2.0.16-14.fc14.1 (FEDORA-2011-9918)
 Grassroots DiCoM is a C++ library to parse DICOM medical files
--------------------------------------------------------------------------------
Update Information:

- Update to 5.6.1
- Remove dependency of vtk on vtk-devel via libvtkNetCDF_cxx.so 
- Turn on boost, mysql, postgres, ogg theora, and text analysis support.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Orion Poplawski <orion at cora.nwra.com> - 2.0.16-14.1
- Rebuild for new vtk with fixed sonames
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #705885 - vtkpython: libVPIC.so: cannot open shared object file
        https://bugzilla.redhat.com/show_bug.cgi?id=705885
--------------------------------------------------------------------------------


================================================================================
 goobook-1.3-8.fc14 (FEDORA-2011-9781)
 Abook-style interface for google contacts for mutt
--------------------------------------------------------------------------------
Update Information:

Remove argparse dependency.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Howard Ning <mrlhwliberty at gmail.com> - 1.3-8
- Remove argparser in the setup.py so it will work on F15
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.3-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Sun Jan  2 2011 Howard Ning <mrlhwliberty at gmail.com> - 1.3-6
- Remove argparser requirement
--------------------------------------------------------------------------------


================================================================================
 groonga-1.2.4-1.fc14 (FEDORA-2011-9882)
 An Embeddable Fulltext Search Engine
--------------------------------------------------------------------------------
Update Information:

new upstream release
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 29 2011 Daiki Ueno <dueno at redhat.com> - 1.2.4-1
- build in fedora
* Fri Jul 29 2011 Kouhei Sutou <kou at clear-code.com> - 1.2.4-0
- new upstream release.
--------------------------------------------------------------------------------


================================================================================
 kdelibs-4.6.5-2.fc14 (FEDORA-2011-9771)
 KDE Libraries
--------------------------------------------------------------------------------
Update Information:

This update fixes autocompletion in edit fields in KHTML forms
getting undone when leaving the edit field without typing anything
in addition (kde#277457, a regression in 4.6.5).
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Kevin Kofler <Kevin at tigcc.ticalc.org> 4.6.5-2
- fix KHTML form completion regression (kde#277457, patch by Andrea Iacovitti)
--------------------------------------------------------------------------------


================================================================================
 kmetronome-0.10.0-3.fc14 (FEDORA-2011-9795)
 KDE MIDI Metronome using ALSA Sequencer
--------------------------------------------------------------------------------
Update Information:

KMetronome is a MIDI metronome with KDE interface, based on the ALSA
sequencer. The intended audience is musicians and music students. Like
solid, real metronomes it is a tool to keep the rhythm while playing musical
instruments. It uses MIDI for sound generation instead of digital audio,
allowing low CPU usage, and very accurate timing thanks to the ALSA sequencer.
--------------------------------------------------------------------------------


================================================================================
 kwebkitpart-1.1-0.1.20110720.fc14 (FEDORA-2011-9709)
 A KPart based on QtWebKit
--------------------------------------------------------------------------------
Update Information:

kwebkitpart-1.1 bugfix update.
See https://projects.kde.org/news/21
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 21 2011 Alexey Kurov <nucleo at fedoraproject.org> - 1.1-0.1.20110720
- kwebkitpart 1.1 20110720 snapshot
- drop kwebkitpart-devel
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.9.6-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 libcap-2.22-1.fc14 (FEDORA-2011-9836)
 Library for getting and setting POSIX.1e capabilities
--------------------------------------------------------------------------------
Update Information:

Update to libcap-2.22, includes fixes for http://cwe.mitre.org/data/definitions/243.html
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Karsten Hopp <karsten at redhat.com> 2.22-1
- update to 2.22 (#689752)
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 2.17-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #689752 - libcap-2.22 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=689752
--------------------------------------------------------------------------------


================================================================================
 libertas-sd8686-firmware-9.70.20.p0-1.fc14 (FEDORA-2011-9811)
 Firmware for Marvell Libertas SD 8686 Network Adapter
--------------------------------------------------------------------------------
Update Information:

New version.
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------


================================================================================
 libguestfs-1.8.10-1.fc14 (FEDORA-2011-9815)
 Access and modify virtual machine disk images
--------------------------------------------------------------------------------
Update Information:

New upstream stable branch version 1.8.10.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Richard W.M. Jones <rjones at redhat.com> - 1:1.8.10-1
- New upstream stable branch version 1.8.10.
--------------------------------------------------------------------------------


================================================================================
 libjingle-0.5.8-1.fc14 (FEDORA-2011-9910)
 GoogleTalk implementation of Jingle
--------------------------------------------------------------------------------
Update Information:

Updated libjingle to 0.5.8, minimizes patching a bit and adds necessary support for Chromium 14.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Tom Callaway <spot at fedoraproject.org> - 0.5.8-1
- update to 0.5.8
- merge Google's unpublished Chromium 14 changes
--------------------------------------------------------------------------------


================================================================================
 libsoup-2.32.2-2.fc14 (FEDORA-2011-9820)
 Soup, an HTTP library implementation
--------------------------------------------------------------------------------
Update Information:

Fix CVE-2011-2524
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Dan Winship <danw at redhat.com> - 2.32.2-2
- Add patch for CVE-2011-2524
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #726469 - CVE-2011-2524 libsoup: SoupServer directory traversal flaw [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=726469
--------------------------------------------------------------------------------


================================================================================
 lilypond-2.14.2-1.fc14 (FEDORA-2011-9788)
 A typesetting system for music notation
--------------------------------------------------------------------------------
Update Information:

New upstream stable.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Jon Ciesla <limb at jcomserv.net> - 2.14.2-1
- New upstream.
--------------------------------------------------------------------------------


================================================================================
 lilypond-doc-2.14.2-1.fc14 (FEDORA-2011-9788)
 HTML documentation for LilyPond
--------------------------------------------------------------------------------
Update Information:

New upstream stable.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Jon Ciesla <limb at jcomserv.net> 2.14.2-1
- Update to 2.14.2.
--------------------------------------------------------------------------------


================================================================================
 mfiler3-4.4.1-1.fc14 (FEDORA-2011-9796)
 Two pane file manager under UNIX console
--------------------------------------------------------------------------------
Update Information:

saphire 3.3.5 / mfiler3 4.4.1 are released.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jul 29 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 4.4.1-1
- 4.4.1
--------------------------------------------------------------------------------


================================================================================
 mksh-40b-2.fc14 (FEDORA-2011-9792)
 MirBSD enhanced version of the Korn Shell
--------------------------------------------------------------------------------
Update Information:

mksh R40b introduces several desired fixes:

 * Don’t busy-loop on nameref ARY=ARY (LHS = RHS)
 * Tabcomplete ~foo like $FOO (LP: #710539)
 * Code cleanup, style, and minor assorted fixes
 * Tabcomplete ~foo/M↹ (with slash) economically
 * Add new experimental global builtin, doing the same as local (typeset, really – but that doesn’t deserve its name) does, except localising all parameters it touches
 * Better error messages with non-integral environment imports
 * $RANDOM environment import accepts any string now
 * Add setenv cshism to dot.mkshrc
 * Allow ^C to interrupt the built-in cat(1)
 * Fix mksh taking down the entire terminal, hard, when scripts use $COLUMNS and fork off utilities; regression introduced in mksh R37 (sorry, no regression test possible)
 * Properly mark need-ctty regression tests
 * MKSH_NO_EXTERNAL_CAT – Quell the external cat(1) calls magic
 * Yes, “echo” is not portable, document
 * Improve content and look of the manual page
 * Move /etc/{,suid_}profile to /system/etc/ on Android
 * Prevent more compiler warnings; catch build errors earlier


mksh R40 is a major everything release:

 * Correct small mistakes in manpage and build script
 * Port to Haiku (and probably, implicitly, BeOS; this is not tested though)
 * Add Haiku specific RLIMIT_NOVMON as ‘V’ to ulimit builtin
 * Let Build.sh cope with dirname(1) unavailability
 * In the Emacs editing mode, hi-bit7 octets are now considered “motion characters” for word boundaries – Esc+b, Esc+f, ^W, …
 * Make EXECSHELL default configurable at compile time (embedded)
 * If MKSH_SMALL do not compile in “set -o bgnice” by default
 * Rework how RLIMIT_{AS,RSS,VMEM} map to ‘m’ and ‘v’ ulimits
 * Add some more OS specific limits seen in zsh
 * SUSv4 ${v=a\ b} and "${v=a\ b}" and ${v-a\ b} compliance, tests
 * Make "~/.mkshrc" path configurable at compile time (embedded)
 * Fix SUNWcc 12.1 error message scan in build phase=u
 * Fix variable assignment scope during command execution (expansion vs. assignment execution environment); [Herbert Xu, Geoff Clare] Add more regression tests for this
 * Fix single quotes in "${foo#bar}" (differs from "${foo-bar}")
 * Fix mknod(8) usage message: b|c are not optional
 * Fix "${x#?}" expansion when quoted (quotes, space)
 * Make default temporary directory configurable at compile time
 * Fix performance deficiencies in the built-in realpath function
 * Deprecate Build.sh -longoptions in favour of short ones: -valgrind becomes -g (like debug), -combine and -llvm become -c {combine,llvm} and the LLVM optimiser flags are passed via -O = -o -std-compile-opts
 * New Build.sh options -c dragonegg (for using the LLVM plugin to GCC 4.5 with inter-module optimisation), -v (version)
 * Document another way to get a coloured PS1 in the manpage
 * Disallow some more kinds to trim a vector; Debian #581867
 * Simplify some code; RCSID and comment sync with OpenBSD ksh
 * Apply diff from manuel giraud to keep track of LINENO in a trap
 * Remove arc4random(3) functionality; seed an LCG depending on the OS doing Address Space Layout Randomisation; speed up (we will use either arc4random_pushb_fast(3) if it exists or arc4random_pushb(3) if forced by the user with -DMKSH_A4PB e.g. on Cygwin)
 * Fix spelling mistakes in dot.mkshrc
 * Implement “live” window resize for the Emacs editing mode
 * More fixes for bugs found by Valgrind and LLVM+Clang scan-build
 * For script compatibility support “set ±o arc4random” during a transition period until R40 is out (but issue a warning to stderr)
 * Add (, ), (( to reserved words in the manual page and fix some formatting errors with GNU groff’s mdoc
 * Make printf.c.1.15 use mksh’s shf_* routines instead of stdio
 * Fix -Wc++-compat except implicit casts from/to "void *"
 * Correct shf buffer I/O routines to avoid a memory corruption bug discovered by Waldemar Brodkorb and other bad effects
 * Fix NULL pointer dereference during iteration loop when checking for alias recursion; discovered by Michal Hlavinka
 * More int → bool conversion, whitespace and general code cleanup
 * Fix window size not being checked during runtime of external programmes by not relying on SIGWINCH so much but instead checking before every interactive editing of a command line
 * Improve mksh(1) manpage coverage, remove mentions of not-mksh
 * Use wcwidth() from system on MirBSD
 * u_int32_t is no longer needed (only for OpenBSD’s pre-ISO-C99 arc4random API, which we no longer call), so don’t provide it from Build.sh any longer
 * Scan for uint8_t and provide if not found
 * Fix realpath builtin for “/file/” arguments wrt. POSIX
 * Do not generate <stdint.h> from Build.sh as file any more if it is missing; rather let sh.h define the types appropriately and fix related compiler warnings
 * Add “cat” builtin (defers to external if options are given)
 * Reduce size by improved string pooling, improving struct packing, lowering size of some allocation chunks, and better code
 * Document 「x=$(eval $(cat)) <<'EOF'」 workaround for the $(…) parsing bug in the mksh(1) manual page and on the Red Hat Bugzilla
 * Add support for handling a “--” argument to more builtins
 * Correct some error messages and typos
 * Don’t alias stop, suspend on Android (system specific conflict for stop; suspend just joined the boat)
 * Address what few concerns Chris Palmer (Android security team) had: check all multiplications and some additions for integer overflows, mostly in allocation context, and check setres{u,g}id/setuid for EAGAIN iff the target OS is known to be returning it (Linux only, right now)
 * Some small manpage fixes
 * Clean up mirtoconf and build warnings with some compilers
 * Fix \c? vs. \c~ mis-documentation in mksh(1)
 * Remove the somewhat-portable setmode.c from the mksh source distribution and demote mknod(8) to an optional builtin, disabled by default, manually re-enabled in the installer only on MirBSD
 * Regenerate wcwidth table from Unicode 6.0.0
 * Change behaviour of argument-less exit in traps to match SUSv4, original patch from Jonathan Nieder (Debian Closes: #599484)
 * dot.mkshrc no longer exports $PS1, as recommended by Frank Terbeck, to avoid confusing other shells
 * The character width table is now in sync with Unicode 6.0.0
 * MKSH_SMALL doesn’t imply HAVE_REVOKE=0 any longer
 * Ignore a ‘$’ preceding ‘"…"’ (like bash, ksh93)
 * Make “foo=<<EOF” a direct assignment of here document (or here string) to string variable
 * Add KSHEGID, KSHGID, KSHUID variables (idea from Richard K.)
 * Option -d to read specifies a delimiter, like ksh93 (10x dgk)
 * Extension ${foo@#} expands to hash of $foo (mksh specific)
 * Emacs prev-hist-word resets the counter if other editing commands were run in between; repeat calling works, even together with arguments, now; arguments are 0-based (Debian Closes: #603801)
 * Introduce MKSH_NOPROSPECTOFWORK which implies MKSH_UNEMPLOYED and additionally disables job signals, |&, sigprocmask(2), etc.
 * POSIX: trap 'echo foo' UNKNOWN is not a syntax error
 * Do not use <sys/file.h> unless it exists
 * dot.mkshrc: When we set a UTF-8 locale (e.g. for the GNU OS), we must also set -o utf8-mode to match it
 * Don’t append a space after tab-completing a parameter substitution that doesn’t contain a glob/extglob (LP: #710539)
 * Limit history file size to 1 GiB for sanity
 * Add smores, a more(1)-like pager, as shell function to dot.mkshrc (not control character safe but tty aware)
 * Make builtins directly callable; utf8-mode is determined by LC_ALL/LC_CTYPE/LANG environment variables in that case
 * If the interactive shell uses setlocale(3)/nl_langinfo(3) to divine utf8-mode, fall back to environment variables unless success
 * From a direct builtin call, echo(1) behaves POSIXish
 * Replace some MirBSD utilities with links to mksh(1) and ensure some integration to keep compatibility
 * Add a microsecond capable sleep(1) builtin [updated 20110213]
 * If the built-in cat is invoked from a direct builtin call, it now properly handles the POSIXly demanded ‘-u’ option (as a no-op)
 * Support the PIPESTATUS array (like GNU bash)
 * Port to MiNT / FreeMiNT (Atari m68k operating system)
 * Do not close filedescriptor #3 (controlling tty) on UWIN
 * Make the tree printing code safe for re-entrancy of output
 * Implement recursive parser for $(…) to fix RedHat BZ#496791
 * Use the existing state machine, a recursive parser and retracing the input stream for correct x=(…$((…$(…)…))…) parsing
 * complain about ${x:1:2:3} instead of crashing
 * make optional printf(1) builtin __CRAZY=Yes clean and prevent it from crashing by reading past end of (invalid) format strings
 * abort(3) on rogue pointers #ifdef DEBUG
 * Correct some documentation, code commentary, etc.
 * Handle the UTF-8 Byte Order Mark in $(…) expressions
 * Speed up reading input by checking for the BOM only once
 * Fix mis-detection of gcc format attribute (false negative)
 * Include some Android specific hacks (no change on other OEs)
 * In ${foo/bar/baz} expressions, when adjourning empty patterns to avoid running into a busy-wait loop, remember to skip the anchor characters (‘#’ or ‘%’) at the beginning, yet keep the special meaning replacing a string begin or end with a string has
 * Write a pattern optimiser that is run internally before calls to the pattern matching code always (currently, replaces a@(b@(c)d)e with abcde but keeps @(a|a), then (in a second pass) collapses adjacent asterisk (‘*’) wildcards into a single one; this fixes some of the symptoms of severe performance issues our pattern matching code has to the extent that it can prevent busy-looping (found by Jb_boin)
 * Handle pathnames with exactly two leading slashes well (SUSv4 3.266)
 * Fix here documents, add testcases
 * Fix corner case ${##1}, add tests for that and ${##} and ${#?}
 * Bring back “test -H” ifdef S_ISCDF (for HP-UX) from pdksh
 * Align read-only variable behaviour with (future) POSIX
 * Permit ${foo%(*} on FSH (Debian Closes: #619947)
 * Allow skipping testcases that need a controlling tty
 * Correct skipping the UTF-8 BOM when identifying a file
 * Do not use <stdbool.h> any longer
 * Use double-underscore-framed __attribute__s
 * Always catch SIGALRM (for the sleep builtin)
 * Functions now inherit a global set -x
 * Do not explicitly initialise static globals to 0/NULL
 * Eliminate some dead code (functions, globals)
 * Correct more tree handling bugs and merge similar code
 * Add “+=” to concatenate scalars and append to arrays
 * Support empty here document delimiters
 * Fix the four-argument form of test(1)
 * Drop the pre-POSIX ability to “test -t” without specifying “fd”
 * Defer dropping an alias in favour of a POSIX function to when the function is actually defined and check for the closing parenthesis too
 * Implement a new regression test attribute need-pass: {yes|no} and exit 1 if unexpected fails occur
 * Add ;& and ;| for case
 * Rewrite the read builtin and its documentation; adding -A (read IFS words into array), -a (read octets/wide characters into array), -N/-n (read only / up to z bytes), -t (read with timeout)
 * Add -e option to cd -P (POSIX 2011)
 * Update dot.mkshrc to use the new features
 * Fix gsf’s ifs.sh tests of the read builtin
 * Improve support for AIX, Cygwin, IBM XL C
 * Add tests for x+=(y z) and ;;& extensions
 * Fix regression in tab completion result display
 * Fix parsing x=(…) expressions
 * Increase hash table limit; don’t crash when reaching the limit; work around bug in GCC 4.1 on Debian Etch
 * New -c lto option to use Link Time Optimisation (GCC) with automatic fallback to -c combine if unavailable
 * Improvements for -c dragonegg, -c llvm (with gcc+dragonegg, or llvm-gcc and clang, respectively), and TenDRA
 * Let code samples in check.t and dot.mkshrc take care of the new features; fix some longstanding bugs in them
 * Add missing flush in rewritten read builtin for prompting
 * Minix builds now automatically disable the ulimit builtin
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Robert Scheck <robert at fedoraproject.org> 40b-2
- Use new "Build.sh -r -c lto" rather "Build.sh -r -combine"
* Thu Jul 28 2011 Robert Scheck <robert at fedoraproject.org> 40b-1
- Upgrade to 40b
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 39c-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 mock-1.1.12-1.fc14 (FEDORA-2011-9797)
 Builds packages inside chroots
--------------------------------------------------------------------------------
Update Information:

* Tue Jul 26 2011 Clark Williams <williams at redhat.com> - 1.0.19-1
- fixed incorrect python version requirement [BZ# 718376]
- remove f13 configs
- added exception for unshare(2) failures [BZ# 718714]
- added back 'newinstance' mount option to devpts (with symlink logic)
- fixed epel-6-* configurations [BZ# 679885, 719740]
- from Matt Domsch <Matt_Domsch at dell.com>
  - tmpfs plugin typo fix

removed 'newinstance' option from devpts mount in chroot
added Fedora 16 configuration files
Fix inconsistent permissions fixing on /var/cache/mock in SPEC template
modify --chroot command to print command output
update the python requirement to >= 2.6 for 1.1.x mock branch

--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Clark Williams <williams at redhat.com> - 1.1.12-1
- remove f13 configs
- added exception for unshare(2) failures [BZ# 718714]
- added back 'newinstance' mount option to devpts (with symlink logic)
- fixed epel-6-* configurations [BZ# 679885, 719740]
- from Matt Domsch <Matt_Domsch at dell.com>
  - tmpfs plugin typo fix
* Wed Jun 22 2011 Clark Williams <williams at redhat.com> - 1.1.11-1
- remove 'newinstance' mount parameter from devpts filesystem mount (BZ# 711175)
- modify --chroot command to print command output
- update the python requirement to >= 2.6 for 1.1.x mock branch
- updated build procedure using fedpkg
- added Fedora 16 configuration files
- from James Laska <jlaska at redhat.com>
  - fix log message typo in SELinux plugin
- from Yury V. Zaytsev <yury at shurup.com>
  - Fix inconsistent permissions fixing on /var/cache/mock in SPEC template (BZ 715286)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #718376 - Unsatisfied dependency on python >= 2.6
        https://bugzilla.redhat.com/show_bug.cgi?id=718376
  [ 2 ] Bug #718714 - INFO: Namespace unshare failed => build failure
        https://bugzilla.redhat.com/show_bug.cgi?id=718714
  [ 3 ] Bug #679885 - mock fails to build packages for EPEL 6
        https://bugzilla.redhat.com/show_bug.cgi?id=679885
--------------------------------------------------------------------------------


================================================================================
 ncrack-0.4-0.1.ALPHA.fc14 (FEDORA-2011-9799)
 High-speed network auth cracking tool
--------------------------------------------------------------------------------
Update Information:

Update for upstream release.

This includes bugfixes and new features.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Steve Milner <smilner at fedoraproject.org> 0.4-0.1.ALPHA
- Update for upstream release.
- Update spec changelog to fedora address
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #722772 - New ncrack release available
        https://bugzilla.redhat.com/show_bug.cgi?id=722772
--------------------------------------------------------------------------------


================================================================================
 nifticlib-2.0.0-2.fc14 (FEDORA-2011-9917)
 A set of i/o libraries for reading and writing files in the nifti-1 data format
--------------------------------------------------------------------------------
Update Information:

* Initial push to updates
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #714047 - Review Request: nifticlib - A set of i/o libraries for reading and writing files in the nifti-1 data format
        https://bugzilla.redhat.com/show_bug.cgi?id=714047
--------------------------------------------------------------------------------


================================================================================
 nss-pam-ldapd-0.7.13-1.fc14 (FEDORA-2011-9807)
 An nsswitch module which uses directory servers
--------------------------------------------------------------------------------
Update Information:

This update upgrades the package to the latest stable release, incorporates fixes for multiple packaging bugs, and backports a fix for parsing group IDs retrieved from user entries.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 21 2011 Nalin Dahyabhai <nalin at redhat.com> 0.7.13-1
- switch to only munging the contents of /etc/nslcd.conf on the very first
  install (#706454)
- make sure that we have enough space to parse any valid GID value when
  parsing a user's primary GID (#716822)
- change the file path Requires: we have for pam_ldap into a package name
  Requires: (#601931)
- tag nslcd.conf with %verify(not md5 size mtime), since we always tweak
  it in %post (#692225)
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.7.13-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Mon Dec 13 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.13-1
- update to 0.7.13
* Fri Oct 29 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.12-1
- update to 0.7.12
* Fri Oct 15 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.11-1
- update to 0.7.11
* Wed Sep 29 2010 jkeating - 0.7.10-2
- Rebuilt for gcc bug 634757
* Fri Sep 24 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.10-1
- update to 0.7.10
* Thu Sep 23 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.9-2
- when creating /var/run/nslcd in the buildroot, specify that 0755 is a
  permissions value and not another directory name (#636880)
* Mon Aug 30 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.9-1
- update to 0.7.9
* Wed Aug 18 2010 Nalin Dahyabhai <nalin at redhat.com> 0.7.8-1
- update to 0.7.8
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #601931 - please change requires in nss-pam-ldapd from a file requires to a %{_isa} requires
        https://bugzilla.redhat.com/show_bug.cgi?id=601931
  [ 2 ] Bug #636880 - mkdir command in nss-pam-ldapd.spec needs -m option
        https://bugzilla.redhat.com/show_bug.cgi?id=636880
--------------------------------------------------------------------------------


================================================================================
 openarena-0.8.5-4.fc14 (FEDORA-2011-9898)
 Open source first person shooter
--------------------------------------------------------------------------------
Update Information:

- Update to 1.36 svn snapshot r2102
- This fixes 2 security issues where a malicious server could execute arbitrary code on connecting clients (rhbz#725951):
- CVE-2011-1412: Execute arbitrary shell commands on connecting clients
- CVE-2011-2764: Arbitrary code execution when native-code DLLs are enabled
- Update the autodownload + launch script for UrbanTerror to 4.1.1

--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Hans de Goede <hdegoede at redhat.com> - 0.8.5-3
- Update launcher script to work with newer quake3 package + require this
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.8.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #725951 - CVE-2011-1412 CVE-2011-2764 quake3: arbitrary code execution vulnerabilites in ioquake3
        https://bugzilla.redhat.com/show_bug.cgi?id=725951
--------------------------------------------------------------------------------


================================================================================
 openscap-0.7.4-1.fc14 (FEDORA-2011-9887)
 Set of open source libraries enabling integration of the SCAP line of standards
--------------------------------------------------------------------------------
Update Information:

Upgrade to new upstream release
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Peter Vrabec <pvrabec at redhat.com> 0.7.4-1
- upgrade
--------------------------------------------------------------------------------


================================================================================
 paco-2.0.9-6.fc14 (FEDORA-2011-9904)
 A source code package organizer for Unix/Linux
--------------------------------------------------------------------------------
Update Information:

New package
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #705043 - Review Request: paco - a source code package organizer for Unix
        https://bugzilla.redhat.com/show_bug.cgi?id=705043
--------------------------------------------------------------------------------


================================================================================
 perl-Cache-FastMmap-1.39-1.fc14 (FEDORA-2011-9830)
 Uses an mmap'ed file to act as a shared memory interprocess cache
--------------------------------------------------------------------------------
Update Information:

This update fixes a problem that could lead to erroneously locked pages.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Iain Arnell <iarnell at gmail.com> 1.39-1
- update to latest upstream
- clean up spec for modern rpmbuild
- re-enable leak test t/6.t
* Mon Jun 20 2011 Marcela Mašláňová <mmaslano at redhat.com> - 1.36-3
- Perl mass rebuild
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.36-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 perl-Data-Serializer-0.59-1.fc14 (FEDORA-2011-9906)
 Modules that serialize data structures
--------------------------------------------------------------------------------
Update Information:

This update improves handling of utf8-encoded JSON data.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Iain Arnell <iarnell at gmail.com> 0.59-1
- update to latest upstream
* Wed Jul 20 2011 Petr Sabata <contyk at redhat.com> - 0.57-3
- Perl mass rebuild
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.57-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Jan 20 2011 Iain Arnell <iarnell at gmail.com> 0.57-1
- update to latest upstream version
- BR perl(Bencode), perl(Convert::Bencode), and perl(Convert::Bencode_XS)
* Fri Jan 14 2011 Iain Arnell <iarnell at gmail.com> 0.54-1
- update to latest upstream version
--------------------------------------------------------------------------------


================================================================================
 perl-Dist-Zilla-4.200012-1.fc14 (FEDORA-2011-9881)
 Distribution builder; installer not included!
--------------------------------------------------------------------------------
Update Information:

This update fixes [rt#68223](https://rt.cpan.org/Public/Bug/Display.html?id=68223) -- Test::Dzil built tarballs with bad root dirs, and includes several additional minor enhancements. See the [upstream changelog](http://cpansearch.perl.org/src/RJBS/Dist-Zilla-4.200012/Changes) for full details.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Iain Arnell <iarnell at gmail.com> 4.200012-1
- update to latest upstream
* Wed Jul 20 2011 Petr Sabata <contyk at redhat.com> - 4.200008-2
- Perl mass rebuild
--------------------------------------------------------------------------------


================================================================================
 perl-HTML-FormatText-WithLinks-AndTables-0.01-2.fc14 (FEDORA-2011-9866)
 Converts HTML to Text with tables in tact
--------------------------------------------------------------------------------
Update Information:

New package
--------------------------------------------------------------------------------


================================================================================
 perl-NetPacket-1.2.0-1.fc14 (FEDORA-2011-9886)
 Assemble/disassemble network packets at the protocol level
--------------------------------------------------------------------------------
Update Information:

Update to version 1.2.0
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 30 2011 Jose Pedro Oliveira <jpo at di.uminho.pt> - 1.2.0-1
- Update to 1.2.0.
* Fri Jun 17 2011 Marcela Mašláňová <mmaslano at redhat.com> - 1.1.1-2
- Perl mass rebuild
* Thu Feb 10 2011 Jose Pedro Oliveira <jpo at di.uminho.pt> - 1.1.1-1
- Update to 1.1.1.
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.1.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Jan 20 2011 Jose Pedro Oliveira <jpo at di.uminho.pt> - 1.1.0-1
- Update to 1.1.0.
--------------------------------------------------------------------------------


================================================================================
 perl-RPM-VersionCompare-0.1.1-1.fc14 (FEDORA-2011-9765)
 Compare RPM version strings
--------------------------------------------------------------------------------
Update Information:

Parse long epoch correctly
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #725608 - Module does not parse epoch correctly
        https://bugzilla.redhat.com/show_bug.cgi?id=725608
--------------------------------------------------------------------------------


================================================================================
 php-pecl-xdebug-2.1.2-1.fc14 (FEDORA-2011-9827)
 PECL package for debugging PHP scripts
--------------------------------------------------------------------------------
Update Information:

Upstream changelog:

Version 2.1.2:

* Fixed bug #622: Working with eval() code is inconvenient and difficult.
* Fixed bug #684: xdebug_var_dump - IE does not support &.
* Fixed bug #693: Cachegrind files not written when filename is very long.
* Fixed bug #697: Incorrect code coverage of function arguments when using XDEBUG_CC_UNUSED.
* Fixed bug #699: Xdebug gets the filename wrong for the countable interface.
* Fixed bug #703 by adding another opcode to the list that needs to be overridden.

Version 2.1.1:

= Debugger
* Fixed bug #518: Removed CLASSNAME pseudo-property optional.
* Fixed bug #592: Xdebug crashes with run after detach.
* Fixed bug #596: Call breakpoint never works with instance methods, only static methods.
* Fixed JIT mode in the debugger so that it works for xdebug_break() too.

= Profiler
* Fixed bug #631: Summary not written when script ended with "exit()".
* Fixed bug #639: Xdebug profiling: output not correct - missing 'cfl='.
* Fixed bug #642: Fixed line numbers for offsetGet, offsetSet, __get/__set/__isset/__unset and __call in profile files and stack traces/function traces.
* Fixed bug #643: Profiler gets line numbers wrong.
* Fixed bug #653: XDebug profiler crashes with %H in file name and non standard port.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Remi Collet <Fedora at FamilleCollet.com> - 2.1.2-1
- update to 2.1.2
- improved description
- add filter_provides to avoid private-shared-object-provides xdebug.so
- add %check section (minimal load test)
- always use libedit
--------------------------------------------------------------------------------


================================================================================
 pinentry-0.8.1-4.fc14 (FEDORA-2011-9912)
 Collection of simple PIN or passphrase entry dialogs
--------------------------------------------------------------------------------
Update Information:

Improve wrapper to fallback to curses even with DISPLAY set when on terminal
    
- improved wrapper provided by Ben Boeckel

--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Stanislav Ochotnicky <sochotnicky at redhat.com> - 0.8.1-4
- Improve wrapper to fallback to curses even with DISPLAY set (#622077)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #622077 - [PATCH] Don't force GUI dialog if TTY available
        https://bugzilla.redhat.com/show_bug.cgi?id=622077
--------------------------------------------------------------------------------


================================================================================
 publican-2.6-3.fc14 (FEDORA-2011-9791)
 Common files and scripts for publishing with DocBook XML
--------------------------------------------------------------------------------
Update Information:

Supply missing rpmlint config file
Rebase on upstream 2.6

  - Catch FOP failing. BZ #661551
  - Have XmlClean treat address element as verbatim. BZ #662907
  - Fix task missing ID. BZ #672439
  - Fix startinglinenumber ignored & XML entites not being escaped. BZ #653432
  - Fix perl critic encoding check failing. BZ #684509
  - Update docbook-style-xsl req to 1.76.1 for epub change. BZ #697382
  - Add keep_id to steps. BZ #697370
  - Update BZ links to point to Publican component.
  - Catch empty tags that break packaging. (abstract, subtitle) BZ #663206
  - Add rpmlint check for mock builds. BZ #663203
  - Fix web menu localisation being lost on rebuild from package. BZ #662897
  - Fix UTF8 issue in TXT output. BZ #673855
  - Fix some set validation errors. BZ #673402
  - Fix packaging of stand alone sets. BZ #689347
  - Switch normal output to STDOUT, added croak call. BZ #688447
  - Added mainfile parameter. BZ #688585
  - Add rename action. BZ #694698
  - Added detection of mixed_mode tags to XmlClean. BZ #688286
  - Add update_db action to allow more robust packaging. BZ #661948
  - Fix show_unknown not working. BZ #662162
  - Fix version 0 not installing on web site. BZ #702550
  - Don't validate xml parsed as text in print_unused. BZ #705956
  - Add manual_toc_update config for web-sites. BZ #719573
  - Use the force option for cvs-import.sh BZ #718102
  - Fix admonition layout. BZ #715158
  - Fix indexterm tag causes a line split in PDF. BZ #713669
  - Add no_embedtoc config for brands. BZ #723725

Rebase on upstream 2.6

  - Catch FOP failing. BZ #661551
  - Have XmlClean treat address element as verbatim. BZ #662907
  - Fix task missing ID. BZ #672439
  - Fix startinglinenumber ignored & XML entites not being escaped. BZ #653432
  - Fix perl critic encoding check failing. BZ #684509
  - Update docbook-style-xsl req to 1.76.1 for epub change. BZ #697382
  - Add keep_id to steps. BZ #697370
  - Update BZ links to point to Publican component.
  - Catch empty tags that break packaging. (abstract, subtitle) BZ #663206
  - Add rpmlint check for mock builds. BZ #663203
  - Fix web menu localisation being lost on rebuild from package. BZ #662897
  - Fix UTF8 issue in TXT output. BZ #673855
  - Fix some set validation errors. BZ #673402
  - Fix packaging of stand alone sets. BZ #689347
  - Switch normal output to STDOUT, added croak call. BZ #688447
  - Added mainfile parameter. BZ #688585
  - Add rename action. BZ #694698
  - Added detection of mixed_mode tags to XmlClean. BZ #688286
  - Add update_db action to allow more robust packaging. BZ #661948
  - Fix show_unknown not working. BZ #662162
  - Fix version 0 not installing on web site. BZ #702550
  - Don't validate xml parsed as text in print_unused. BZ #705956
  - Add manual_toc_update config for web-sites. BZ #719573
  - Use the force option for cvs-import.sh BZ #718102
  - Fix admonition layout. BZ #715158
  - Fix indexterm tag causes a line split in PDF. BZ #713669
  - Add no_embedtoc config for brands. BZ #723725

--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Jeff Fearn <jfearn at redhat.com> 2.6-3
- Force publican to use UTF8 for command line options.
- Add rpmlint cfg for brew checks.
* Wed Jul 27 2011 Jeff Fearn <jfearn at redhat.com> 2.6-2
- Fix archness ... java hate increases
* Mon Jul 25 2011 Jeff Fearn <jfearn at redhat.com> 2.6-1
- New Version, see Changes file.
--------------------------------------------------------------------------------


================================================================================
 python-confparser-1.0.0-3.fc14 (FEDORA-2011-9764)
 A KISS python module to parse *nix config files
--------------------------------------------------------------------------------
Update Information:

new package
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #725552 - Review Request: python-confparser - A KISS parse to *nix config files
        https://bugzilla.redhat.com/show_bug.cgi?id=725552
--------------------------------------------------------------------------------


================================================================================
 python-confparser-1.0.0-4.fc14 (FEDORA-2011-9907)
 A KISS python module to parse *nix config files
--------------------------------------------------------------------------------
Update Information:

updated spec to compile EPEL5
--------------------------------------------------------------------------------


================================================================================
 python-fedora-0.3.24-1.fc14 (FEDORA-2011-9903)
 Python modules for talking to Fedora Infrastructure Services
--------------------------------------------------------------------------------
Update Information:

* Fix a bug with auth for TG2 servers
* Fix a bug in client auth using F15+ pycurl
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 20 2011 Toshio Kuratomi <toshio at fedoraproject.org> - 0.3.24-1
- Upstream 0.3.24 release bugfixing TG2 server utils and clients with
  session cookie auth.
--------------------------------------------------------------------------------


================================================================================
 qcodeedit-2.2.3-7.fc14 (FEDORA-2011-9783)
 Qt-Framework for code editing
--------------------------------------------------------------------------------
Update Information:

Initial upload to the repos
--------------------------------------------------------------------------------


================================================================================
 qodem-0.3.2-1.fc14 (FEDORA-2011-9826)
 Terminal emulator and communications package
--------------------------------------------------------------------------------
Update Information:

Qodem is an open-source re-implementation of the Qmodem(tm)
shareware communications package, updated for more modern uses.
Major features include:
    * Unicode display: translation of CP437 (PC VGA), VT100 DEC
      Special Graphics characters, VT220 National Replacement
      Character sets, etc., to Unicode
    * Terminal interface conveniences: scrollback buffer, capture
      file, screen dump, dialing directory, keyboard macros, script
      support
    * Connection methods: serial, local shell, command line, telnet,
      ssh, rlogin, rsh
    * Emulations: ANSI.SYS (including "ANSI music"), Avatar, VT52,
      VT100/102, VT220, Linux, and XTerm
    * Transfer protocols: Xmodem, Ymodem, Zmodem, and Kermit

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #725267 - Review Request: qodem - Qodem terminal emulator and communications package
        https://bugzilla.redhat.com/show_bug.cgi?id=725267
--------------------------------------------------------------------------------


================================================================================
 quake3-1.36-11.svn2102.fc14 (FEDORA-2011-9898)
 Quake 3 Arena engine (ioquake3 version)
--------------------------------------------------------------------------------
Update Information:

- Update to 1.36 svn snapshot r2102
- This fixes 2 security issues where a malicious server could execute arbitrary code on connecting clients (rhbz#725951):
- CVE-2011-1412: Execute arbitrary shell commands on connecting clients
- CVE-2011-2764: Arbitrary code execution when native-code DLLs are enabled
- Update the autodownload + launch script for UrbanTerror to 4.1.1

--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Hans de Goede <hdegoede at redhat.com> - 1.36-11.svn2102
- Update to 1.36 svn snapshot r2102
- This fixes 2 security issues where a malicious server could execute arbitrary
  code on connecting clients (rhbz#725951):
  CVE-2011-1412: Execute arbitrary shell commands on connecting clients
  CVE-2011-2764: Arbitrary code execution when native-code DLLs are enabled
- Update the autodownload + launch script for UrbanTerror to 4.1.1
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.36-10.svn1802
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Jan  4 2011 Hans de Goede <hdegoede at redhat.com> 1.36-9.svn1802
- Update worldofpadman autodownloader files and wrapper script to
  download and play World of Padman version 1.5
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #725951 - CVE-2011-1412 CVE-2011-2764 quake3: arbitrary code execution vulnerabilites in ioquake3
        https://bugzilla.redhat.com/show_bug.cgi?id=725951
--------------------------------------------------------------------------------


================================================================================
 rekonq-0.7.0-1.fc14 (FEDORA-2011-9777)
 KDE browser based on QtWebkit
--------------------------------------------------------------------------------
Update Information:

This is a new upstream version of rekonq 0.7. The following things have been changed and improved:

- General Cleanup
- OpenSearch support (XML & JSON parsers)
- Better cache management (WebKit Page Cache feature support)
- enhanced Private Browsing mode (needs KDE SC 4.6)
- new restore session notification system
- Images in visual suggestions
- Various improvements in bookmarks management
- Optional tab list menu entry
- User Agent switch support
- Save zoom settings per host
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Eelko Berkenpies <fedora at berkenpi.es> 0.7.0-1
- new upstream version
- dropped rekonq_fix_CVE-2010-2536.patch, fixed upstream
* Wed Feb  9 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 rubygem-aws-sdk-1.0.2-1.fc14 (FEDORA-2011-9851)
 AWS SDK for Ruby
--------------------------------------------------------------------------------
Update Information:

New upstream version: 1.0.2.
New package: rubygem-aws-sdk - AWS SDK for Ruby
New package: rubygem-aws-sdk - AWS SDK for Ruby
New package: rubygem-aws-sdk - AWS SDK for Ruby
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #723472 - Review Request: rubygem-aws-sdk - AWS SDK for Ruby
        https://bugzilla.redhat.com/show_bug.cgi?id=723472
--------------------------------------------------------------------------------


================================================================================
 saphire-3.3.5-1.fc14 (FEDORA-2011-9796)
 Yet another shell
--------------------------------------------------------------------------------
Update Information:

saphire 3.3.5 / mfiler3 4.4.1 are released.
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 30 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 3.3.5-1
- 3.3.5
* Tue Jul 26 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 3.3.3-1
- 3.3.3
--------------------------------------------------------------------------------


================================================================================
 scheme2js-20110717-1.fc14 (FEDORA-2011-9913)
 Scheme to JavaScript compiler
--------------------------------------------------------------------------------
Update Information:

Latest stand-alone release from the upstream HOP project
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 25 2011 Michel Salim <salimma at fedoraproject.org> - 20110717-1
- Update to 20110717
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #723190 - scheme2js-20110717 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=723190
--------------------------------------------------------------------------------


================================================================================
 shorewall-4.4.21.1-3.fc14.1 (FEDORA-2011-9869)
 An iptables front end for firewall configuration
--------------------------------------------------------------------------------
Update Information:

Fix executable flags on helper programs
Release notes: 

http://www1.shorewall.net/pub/shorewall/4.4/shorewall-4.4.21/releasenotes.txt
--------------------------------------------------------------------------------
ChangeLog:

* Sat Jul 23 2011 Jonathan G. Underwood <jonathan.underwood at gmail.com> - 4.4.21.1-3.1
- Make files in libexec directory executable
* Thu Jul 21 2011 Jonathan G. Underwood <jonathan.underwood at gmail.com> - 4.4.21-3
- Properly use PERLLIB environment variable for installation of the perl libraries
* Thu Jul 21 2011 Jonathan G. Underwood <jonathan.underwood at gmail.com> - 4.4.21-2
- Fix Source URL versioning in spec file
* Thu Jul 21 2011 Jonathan G. Underwood <jonathan.underwood at gmail.com> - 4.4.21-1
- Update to 4.4.21.1
- Fix BZ 720713 (incorrect init file LSB headers)
* Wed May 25 2011 Orion Poplawski <orion at cora.nwra.com> - 4.4.19.4-1
- Update to 4.4.19.4
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #720713 - Copy-and-paste error in /etc/rc.d/init.d/shorewall6
        https://bugzilla.redhat.com/show_bug.cgi?id=720713
  [ 2 ] Bug #654787 - shorewall-4.4.21 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=654787
--------------------------------------------------------------------------------


================================================================================
 slapi-nis-0.25-1.fc14 (FEDORA-2011-9779)
 NIS Server and Schema Compatibility plugins for Directory Server
--------------------------------------------------------------------------------
Update Information:

This update improves the speed at which the Schema Compatibility plugin can compute entries which contain attributes with large numbers of literal values, and entries which reference large numbers of other entries.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jul 27 2011 Nalin Dahyabhai <nalin at redhat.com> - 0.25-1
- speed up building compat entries which reference thousands of other entries
  (more of #692690)
* Fri May 13 2011 Nalin Dahyabhai <nalin at redhat.com> - 0.24-1
- carry our own yp.x, so that we don't get bitten if libc doesn't include
  yp client routines
- we need rpcgen at build-time now
--------------------------------------------------------------------------------


================================================================================
 starcal-1.9.3-2.fc14 (FEDORA-2011-9828)
 A full-featured international calendar written in Python
--------------------------------------------------------------------------------
Update Information:

Fixes a small bug in the first run
Update to the second generation of starcal (aka starcal2)
Update to the second generation of starcal (aka starcal2)
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #714722 - [abrt] starcal-1.5.3-1.fc15: starcal.py:2031:updateTrayClock:AttributeError: 'StarCal' object has no attribute 'clockTr'
        https://bugzilla.redhat.com/show_bug.cgi?id=714722
--------------------------------------------------------------------------------


================================================================================
 subtitleeditor-0.39.0-1.fc14 (FEDORA-2011-9832)
 GTK+2 tool to edit subtitles for GNU/Linux/*BSD
--------------------------------------------------------------------------------
Update Information:

Update to 0.39.0.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jul 18 2011 Martin Sourada <mso at fedoraproject.org> - 0.39.0-1
- New upstream release 0.39.0
- adds support for SAMI subtitle format
- detects movie fps
- various fixes and improvements
* Wed Feb  9 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.37.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 sysprof-1.1.8-1.fc14 (FEDORA-2011-9916)
 A system-wide Linux profiler
--------------------------------------------------------------------------------
Update Information:

Upgrade to new upstream release
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jul 28 2011 Gianluca Sforna <giallu at gmail.com> 1.1.8-1
- New upstream release
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #725589 - sysprof 1.1.8 released. Please update.
        https://bugzilla.redhat.com/show_bug.cgi?id=725589
--------------------------------------------------------------------------------


================================================================================
 vtk-5.6.1-9.fc14.1 (FEDORA-2011-9918)
 The Visualization Toolkit - A high level 3D visualization library
--------------------------------------------------------------------------------
Update Information:

- Update to 5.6.1
- Remove dependency of vtk on vtk-devel via libvtkNetCDF_cxx.so 
- Turn on boost, mysql, postgres, ogg theora, and text analysis support.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 26 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-9.1
- Rebuild
* Thu May 19 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-9
- Update soversion patch to add soversion to libvtkNetCDF.so
* Mon Mar 28 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-8
- Rebuild for new mysql
* Thu Mar 17 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-7
- Add needed requires to vtk-devel
* Wed Mar 16 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-6
- Turn on boost, mysql, postgres, ogg theora, and text analysis support,
  bug 688275.
* Wed Mar 16 2011 Marek Kasik <mkasik at redhat.com> - 5.6.1-5
- Add backslashes to VTK_INSTALL_LIB_DIR and
- VTK_INSTALL_INCLUDE_DIR (#687895)
* Tue Mar 15 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-4
- Set VTK_INSTALL_LIB_DIR, fix bug 687895
* Fri Feb 18 2011 Orion Poplawski <orion at cora.nwra.com> - 5.6.1-3
- Add patch to support gcc 4.6
- Add patch to make using system libraries easier
- Update pythondestdir patch to use --prefix and --root
- Use system gl2ps and libxml2
- Use standard cmake build macro, out of tree builds
- Add patch from upstream to add sonames to libCosmo and libVPIC (bug #622840)
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 5.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #705885 - vtkpython: libVPIC.so: cannot open shared object file
        https://bugzilla.redhat.com/show_bug.cgi?id=705885
--------------------------------------------------------------------------------



More information about the test mailing list