The following Fedora EPEL 7 Security updates need testing:
Age URL
714 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
477 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
195 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-23fa04bf1c redis-3.2.3-1.el7
179 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e8f4ff76b3 chicken-4.11.0-3.el7
59 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e2cea1c22d python-cjson-1.1.0-9.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-920059d2ed mingw-wavpack-5.1.0-1.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d5fe44714a cacti-1.0.3-2.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d1c56cd592 xrdp-0.9.1-4.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
activemq-cpp-3.9.3-3.el7
fusioninventory-agent-2.3.19-2.el7
gfal2-2.13.1-1.el7
gfal2-python-1.9.1-1.el7
gfal2-util-1.5.0-1.el7
ocserv-0.11.7-3.el7
po-debconf-1.0.16-9.nmu3.el7
srm-ifce-1.24.2-1.el7
xrdp-0.9.1-4.el7
Details about builds:
================================================================================
activemq-cpp-3.9.3-3.el7 (FEDORA-EPEL-2017-ee27d3d4e2)
C++ implementation of JMS-like messaging client
--------------------------------------------------------------------------------
Update Information:
* Upstream to 3.9.3 * Add activemqcpp-lib3.8 package to provide old version so.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1369701 - Please upgrade to upstream version
https://bugzilla.redhat.com/show_bug.cgi?id=1369701
--------------------------------------------------------------------------------
================================================================================
fusioninventory-agent-2.3.19-2.el7 (FEDORA-EPEL-2017-e965d500af)
FusionInventory agent
--------------------------------------------------------------------------------
Update Information:
Update to last upstream release on EL6 Fix a setup/path issue ---- Last
upstream release ---- Update systemd files to use "systemctl edit" Make cron
mode work again; re-add sysconfig file comments
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1424664 - fusioninventory-agent-2.3.19 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1424664
--------------------------------------------------------------------------------
================================================================================
gfal2-2.13.1-1.el7 (FEDORA-EPEL-2017-c019168ed1)
Grid file access library 2.0
--------------------------------------------------------------------------------
Update Information:
New upstream release
--------------------------------------------------------------------------------
================================================================================
gfal2-python-1.9.1-1.el7 (FEDORA-EPEL-2017-7967eacea2)
Python bindings for gfal 2
--------------------------------------------------------------------------------
Update Information:
New upstream release
--------------------------------------------------------------------------------
================================================================================
gfal2-util-1.5.0-1.el7 (FEDORA-EPEL-2017-b3b809787d)
GFAL2 utility tools
--------------------------------------------------------------------------------
Update Information:
New upstream release
--------------------------------------------------------------------------------
================================================================================
ocserv-0.11.7-3.el7 (FEDORA-EPEL-2017-89d24ea7a4)
OpenConnect SSL VPN server
--------------------------------------------------------------------------------
Update Information:
Included liboath in the build ---- - Update to upstream 0.11.7 release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1423880 - Liboath Support is Missing from Ocserv Binaries
https://bugzilla.redhat.com/show_bug.cgi?id=1423880
--------------------------------------------------------------------------------
================================================================================
po-debconf-1.0.16-9.nmu3.el7 (FEDORA-EPEL-2017-2ef0ea428d)
Tool for managing templates file translations with gettext
--------------------------------------------------------------------------------
Update Information:
We already may have Requires: perl(Mail::Box::Manager) on epel7
--------------------------------------------------------------------------------
================================================================================
srm-ifce-1.24.2-1.el7 (FEDORA-EPEL-2017-431720c89d)
SRM client side library
--------------------------------------------------------------------------------
Update Information:
Upstream release 1.24.2
--------------------------------------------------------------------------------
================================================================================
xrdp-0.9.1-4.el7 (FEDORA-EPEL-2017-d1c56cd592)
Open source remote desktop protocol (RDP) server
--------------------------------------------------------------------------------
Update Information:
WARNING: Please note that this update comes with a slightly different syntax of
sesman.ini file, so if you edited this file by hand, you may need to look at the
.rpmnew file and merge any required changes by hand. This release also creates
three files in /etc/xrdp directory if they don't already exist or are empty: -
rsakeys.ini - cert.pem - key.pem Also note that in Fedora, the only backend
that will really work is still Xvnc for now. New features - New xorgxrdp
backend using existing Xorg with additional modules - Improvements to X11rdp
backend - Support for IPv6 (disabled by default) - Initial support for RemoteFX
Codec (disabled by default) - Support for TLS security layer (preferred over RDP
layer if supported by the client) - Support for disabling deprecated SSLv3
protocol and for selecting custom cipher suites in xrdp.ini - Support for
bidirectional fastpath (enabled in both directions by default) - Support clients
that don't support drawing orders, such as MS RDP client for Android, ChromeRDP
(disabled by default) - More configurable login screen - Support for new virtual
channels: - - rdpdr: device redirection - - rdpsnd: audio output - - cliprdr:
clipboard - - xrdpvr: xrdp video redirection channel (can be used along with
NeutrinoRDP client) - Support for disabling virtual channels globally or by
session type - Allow to specify the path for backends (Xorg, X11rdp, Xvnc) -
Added files for systemd support - Multi-monitor support - xrdp-chansrv stroes
logs in ${XDG_DATA_HOME}/xrdp now Security fixes - User's password could be
recovered from the Xvnc password file - X11 authentication was not used
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1404972 - CVE-2013-1430 xrdp: Cleartext password shown in file after logging into xrdp session [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1404972
[ 2 ] Bug #1404971 - CVE-2013-1430 xrdp: Cleartext password shown in file after logging into xrdp session [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1404971
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
712 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
475 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
193 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-23fa04bf1c redis-3.2.3-1.el7
177 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e8f4ff76b3 chicken-4.11.0-3.el7
57 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-0f3297a19b nagios-4.2.4-2.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e2cea1c22d python-cjson-1.1.0-9.el7
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-920059d2ed mingw-wavpack-5.1.0-1.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d1c56cd592 xrdp-0.9.1-3.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8e1a030633 suricata-3.2.1-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
dillo-3.0.5-1.el7
fedfind-3.5.0-1.el7
lua-sec-0.6-1.el7
lynis-2.4.2-1.el7
memkind-1.4.0-1.el7
mozilla-https-everywhere-5.2.11-1.el7
python-cached_property-1.3.0-7.el7
python-freezegun-0.1.19-1.el7
python-productmd-1.4-2.el7
qca-2.1.3-3.el7
Details about builds:
================================================================================
dillo-3.0.5-1.el7 (FEDORA-EPEL-2017-28aada4d17)
Very small and fast GUI web browser
--------------------------------------------------------------------------------
Update Information:
Initial build for 3.0.5
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1238891 - dillo-3.0.5 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1238891
--------------------------------------------------------------------------------
================================================================================
fedfind-3.5.0-1.el7 (FEDORA-EPEL-2017-3d9caeaaae)
Fedora compose and image finder
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. If
this change causes you trouble, please report an issue or contact me and it may
be possible to restore the old behaviour as an option. On EPEL 7, there is now
a Python 3 build of the fedfind library (currently `python34-fedfind`), and the
`fedfind` CLI tool now uses the Python 3 library. The other updated packages
also gain Python 3 builds of their libraries (they are all in fedfind's
dependency chains). `freezegun` is updated to the last release in the 0.1
series, 0.1.19, which should be compatible with the previously-packaged version
(0.1.12).
--------------------------------------------------------------------------------
================================================================================
lua-sec-0.6-1.el7 (FEDORA-EPEL-2017-68b8dd001a)
Lua binding for OpenSSL library
--------------------------------------------------------------------------------
Update Information:
LuaSec 0.6 ========== * Lua 5.2 and 5.3 compatibility * Context module: -
Add ctx:checkkey() * SSL module: - Add conn:sni() and conn:getsniname() *
Context options: - Add "any" protocol ("sslv23" is deprecated) * HTTPS
module: - Using "any" protocol without SSLv2/SSLv3, by default * X509
module: - Human readable IP address - Add cert:issued() - Add
cert:pubkey() * Some bug fixes
--------------------------------------------------------------------------------
================================================================================
lynis-2.4.2-1.el7 (FEDORA-EPEL-2017-4f919b021f)
Security and system auditing tool
--------------------------------------------------------------------------------
Update Information:
Update to 2.4.2 ---- Update to 2.4.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1422705 - lynis-2.4.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1422705
[ 2 ] Bug #1421133 - lynis-2.4.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1421133
--------------------------------------------------------------------------------
================================================================================
memkind-1.4.0-1.el7 (FEDORA-EPEL-2017-7fbfa72534)
User Extensible Heap Manager
--------------------------------------------------------------------------------
Update Information:
Update memkind source file to 1.4.0 upstream
--------------------------------------------------------------------------------
================================================================================
mozilla-https-everywhere-5.2.11-1.el7 (FEDORA-EPEL-2017-e56795d6b0)
HTTPS/HSTS enforcement extension for Mozilla Firefox and SeaMonkey
--------------------------------------------------------------------------------
Update Information:
Apparently not all moving companies know that if you want the seat for your
recliner, you probably want the back of the chair, too.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1400517 - mozilla-https-everywhere-5.2.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1400517
--------------------------------------------------------------------------------
================================================================================
python-cached_property-1.3.0-7.el7 (FEDORA-EPEL-2017-3d9caeaaae)
A cached-property for decorating methods in Python classes
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. If
this change causes you trouble, please report an issue or contact me and it may
be possible to restore the old behaviour as an option. On EPEL 7, there is now
a Python 3 build of the fedfind library (currently `python34-fedfind`), and the
`fedfind` CLI tool now uses the Python 3 library. The other updated packages
also gain Python 3 builds of their libraries (they are all in fedfind's
dependency chains). `freezegun` is updated to the last release in the 0.1
series, 0.1.19, which should be compatible with the previously-packaged version
(0.1.12).
--------------------------------------------------------------------------------
================================================================================
python-freezegun-0.1.19-1.el7 (FEDORA-EPEL-2017-3d9caeaaae)
Let your Python tests travel through time
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. If
this change causes you trouble, please report an issue or contact me and it may
be possible to restore the old behaviour as an option. On EPEL 7, there is now
a Python 3 build of the fedfind library (currently `python34-fedfind`), and the
`fedfind` CLI tool now uses the Python 3 library. The other updated packages
also gain Python 3 builds of their libraries (they are all in fedfind's
dependency chains). `freezegun` is updated to the last release in the 0.1
series, 0.1.19, which should be compatible with the previously-packaged version
(0.1.12).
--------------------------------------------------------------------------------
================================================================================
python-productmd-1.4-2.el7 (FEDORA-EPEL-2017-3d9caeaaae)
Library providing parsers for metadata related to OS installation
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. If
this change causes you trouble, please report an issue or contact me and it may
be possible to restore the old behaviour as an option. On EPEL 7, there is now
a Python 3 build of the fedfind library (currently `python34-fedfind`), and the
`fedfind` CLI tool now uses the Python 3 library. The other updated packages
also gain Python 3 builds of their libraries (they are all in fedfind's
dependency chains). `freezegun` is updated to the last release in the 0.1
series, 0.1.19, which should be compatible with the previously-packaged version
(0.1.12).
--------------------------------------------------------------------------------
================================================================================
qca-2.1.3-3.el7 (FEDORA-EPEL-2017-48055c07a6)
Qt Cryptographic Architecture
--------------------------------------------------------------------------------
Update Information:
Introduce qca-qt5 to epel
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1419662 - Update to 2.1.3
https://bugzilla.redhat.com/show_bug.cgi?id=1419662
--------------------------------------------------------------------------------
The following Fedora EPEL 5 Security updates need testing:
Age URL
832 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2014-3849 sblim-sfcb-1.3.8-2.el5
475 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-edbea40516 mcollective-2.8.4-1.el5
446 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-582c8075e6 thttpd-2.25b-24.el5
57 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-ce45574ab6 libbsd-0.8.3-2.el5
The following builds have been pushed to Fedora EPEL 5 updates-testing
carbon-c-relay-2.6-1.el5
mozilla-https-everywhere-5.2.11-1.el5
Details about builds:
================================================================================
carbon-c-relay-2.6-1.el5 (FEDORA-EPEL-2017-64666201d5)
Enhanced C implementation of Carbon relay, aggregator and rewriter
--------------------------------------------------------------------------------
Update Information:
Update to 2.6
--------------------------------------------------------------------------------
================================================================================
mozilla-https-everywhere-5.2.11-1.el5 (FEDORA-EPEL-2017-0a9b2856b9)
HTTPS/HSTS enforcement extension for Mozilla Firefox and SeaMonkey
--------------------------------------------------------------------------------
Update Information:
Apparently not all moving companies know that if you want the seat for your
recliner, you probably want the back of the chair, too.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1400517 - mozilla-https-everywhere-5.2.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1400517
--------------------------------------------------------------------------------
The following Fedora EPEL 6 Security updates need testing:
Age URL
591 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7031 python-virtualenv-12.0.7-1.el6
585 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7168 rubygem-crack-0.3.2-2.el6
475 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-e2b4b5b2fb mcollective-2.8.4-1.el6
446 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-35e240edd9 thttpd-2.25b-24.el6
177 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-8594ed3a53 chicken-4.11.0-3.el6
57 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e3e50897ac libbsd-0.8.3-2.el6
41 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8c6c7bf06e dbus-sharp-0.7.0-16.el6 dbus-sharp-glib-0.5.0-14.el6 mono-4.2.4-9.el6
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-acd2c2af0d nagios-4.2.4-4.el6
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-2f218dd2b9 python-cjson-1.1.0-9.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-c3b112eb9e tomcat-7.0.75-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
RackTables-0.20.12-2.el6
fail2ban-0.9.6-1.el6.1
fedfind-3.5.0-1.el6
lua-sec-0.6-1.el6
lynis-2.4.2-1.el6
mozilla-https-everywhere-5.2.11-1.el6
python-cached_property-1.3.0-7.el6
python-productmd-1.4-2.el6
tomcat-7.0.75-1.el6
Details about builds:
================================================================================
RackTables-0.20.12-2.el6 (FEDORA-EPEL-2017-0d03dfd411)
A data-center asset management system
--------------------------------------------------------------------------------
Update Information:
Correct distro macro usage ---- Rebase to 0.20.12
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1305396 - RackTables-0.20.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1305396
--------------------------------------------------------------------------------
================================================================================
fail2ban-0.9.6-1.el6.1 (FEDORA-EPEL-2017-8cbc2bd81b)
Ban IPs that make too many password failures
--------------------------------------------------------------------------------
Update Information:
Restore proper backend on EL6
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1424639 - paths-fedora.conf refers to systemd on non-systemd build
https://bugzilla.redhat.com/show_bug.cgi?id=1424639
--------------------------------------------------------------------------------
================================================================================
fedfind-3.5.0-1.el6 (FEDORA-EPEL-2017-0a935d4db5)
Fedora compose and image finder
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. On
EPEL 6, the other packages don't change significantly, but the package spec
files were adjusted a bit so I went ahead and built the packages.
--------------------------------------------------------------------------------
================================================================================
lua-sec-0.6-1.el6 (FEDORA-EPEL-2017-3e0831a324)
Lua binding for OpenSSL library
--------------------------------------------------------------------------------
Update Information:
LuaSec 0.6 ========== * Lua 5.2 and 5.3 compatibility * Context module: -
Add ctx:checkkey() * SSL module: - Add conn:sni() and conn:getsniname() *
Context options: - Add "any" protocol ("sslv23" is deprecated) * HTTPS
module: - Using "any" protocol without SSLv2/SSLv3, by default * X509
module: - Human readable IP address - Add cert:issued() - Add
cert:pubkey() * Some bug fixes
--------------------------------------------------------------------------------
================================================================================
lynis-2.4.2-1.el6 (FEDORA-EPEL-2017-e5760c4a67)
Security and system auditing tool
--------------------------------------------------------------------------------
Update Information:
Update to 2.4.2 ---- Update to 2.4.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1422705 - lynis-2.4.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1422705
[ 2 ] Bug #1421133 - lynis-2.4.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1421133
--------------------------------------------------------------------------------
================================================================================
mozilla-https-everywhere-5.2.11-1.el6 (FEDORA-EPEL-2017-7631c7b2ff)
HTTPS/HSTS enforcement extension for Mozilla Firefox and SeaMonkey
--------------------------------------------------------------------------------
Update Information:
Apparently not all moving companies know that if you want the seat for your
recliner, you probably want the back of the chair, too. ---- Many ruleset
fixes.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1400517 - mozilla-https-everywhere-5.2.11 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1400517
--------------------------------------------------------------------------------
================================================================================
python-cached_property-1.3.0-7.el6 (FEDORA-EPEL-2017-0a935d4db5)
A cached-property for decorating methods in Python classes
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. On
EPEL 6, the other packages don't change significantly, but the package spec
files were adjusted a bit so I went ahead and built the packages.
--------------------------------------------------------------------------------
================================================================================
python-productmd-1.4-2.el6 (FEDORA-EPEL-2017-0a935d4db5)
Library providing parsers for metadata related to OS installation
--------------------------------------------------------------------------------
Update Information:
This update provides a new version of fedfind. The main changes are: * The
synthesized metadata for non-Pungi 4 composes has been enhanced to include a
`composeinfo` dict, and `disc_number` items in the image dicts. These changes
are necessary for `resultsdb_conventions` to work with the synthesized metadata.
* The new Cloud nightly composes are now supported. This is necessary to prevent
some of the things that react to 'compose complete' messages doing wacky stuff
when they encounter such a compose. Another change is that
`fedfind.release.get_release(url='someurl')` will no longer return generic
`Pungi4Compose` instances for URLs in unknown domains, as Patrick van Uiterwijk
suggested it may constitute a potential security problem in some use cases. On
EPEL 6, the other packages don't change significantly, but the package spec
files were adjusted a bit so I went ahead and built the packages.
--------------------------------------------------------------------------------
================================================================================
tomcat-7.0.75-1.el6 (FEDORA-EPEL-2017-c3b112eb9e)
Apache Servlet/JSP Engine, RI for Servlet 3.0/JSP 2.2 API
--------------------------------------------------------------------------------
Update Information:
This updates includes a rebase from tomcat 7.0.73 up to 7.0.75. The update
resolves a single CVE and one bug: * rhbz#1420223 - CVE-2016-6325 tomcat
writable config files allow privilege escalation * rhbz#1372789 - init script
status gives incorrect results
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1367447 - CVE-2016-6325 tomcat: tomcat writable config files allow privilege escalation
https://bugzilla.redhat.com/show_bug.cgi?id=1367447
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
711 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
474 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
192 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-23fa04bf1c redis-3.2.3-1.el7
176 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e8f4ff76b3 chicken-4.11.0-3.el7
56 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-0f3297a19b nagios-4.2.4-2.el7
6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e2cea1c22d python-cjson-1.1.0-9.el7
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-920059d2ed mingw-wavpack-5.1.0-1.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d1c56cd592 xrdp-0.9.1-3.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d5fe44714a cacti-1.0.3-1.el7
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8e1a030633 suricata-3.2.1-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
cacti-1.0.3-1.el7
irc-otr-1.0.2-2.el7
mate-power-manager-1.16.2-1.el7
nagios-plugins-2.1.4-7.el7
proftpd-1.3.5d-2.el7
python-openqa_client-1.3.0-1.el7
shigofumi-0.8-1.el7
suricata-3.2.1-1.el7
xrootd-4.6.0-4.el7
youtube-dl-2017.02.16-1.el7
Details about builds:
================================================================================
cacti-1.0.3-1.el7 (FEDORA-EPEL-2017-d5fe44714a)
An rrd based graphing tool
--------------------------------------------------------------------------------
Update Information:
- Update to 1.0.3 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.php
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1400364 - Graph export tree view is broken
https://bugzilla.redhat.com/show_bug.cgi?id=1400364
[ 2 ] Bug #1417494 - cacti-1.0.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1417494
[ 3 ] Bug #1417605 - CVE-2014-4000 cacti: Multiple issues fixed in 1.0.0 version [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1417605
[ 4 ] Bug #1422854 - cacti-1.0.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1422854
--------------------------------------------------------------------------------
================================================================================
irc-otr-1.0.2-2.el7 (FEDORA-EPEL-2017-aa2ce809c2)
Off-The-Record Messaging plugin for irssi
--------------------------------------------------------------------------------
Update Information:
Initial EL7 release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1419328 - Please build an EL7 release
https://bugzilla.redhat.com/show_bug.cgi?id=1419328
--------------------------------------------------------------------------------
================================================================================
mate-power-manager-1.16.2-1.el7 (FEDORA-EPEL-2017-cd0b18e402)
MATE power management service
--------------------------------------------------------------------------------
Update Information:
- update to 1.16.2 ---- - update to 1.16.1 release
--------------------------------------------------------------------------------
================================================================================
nagios-plugins-2.1.4-7.el7 (FEDORA-EPEL-2017-d35ac726be)
Host/service/network monitoring program plugins for Nagios
--------------------------------------------------------------------------------
Update Information:
Got feedback on bz 1422993. Put in fix from github ---- Start collecting and
fixing bugzilla reports. This one fixes ipv6 for check_snmp ---- Grab other
fixes from git maintenance branch to fix other check_ problems ---- Put in
patch to fix check_file_age
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1422993 - check_snmp missing support for IPv6
https://bugzilla.redhat.com/show_bug.cgi?id=1422993
[ 2 ] Bug #1159891 - When trying to install nagios-plugins-all (with OSP5 enabled) it fails due to dependency issue
https://bugzilla.redhat.com/show_bug.cgi?id=1159891
[ 3 ] Bug #1298766 - check_dhcp segfaults while parsing arguments
https://bugzilla.redhat.com/show_bug.cgi?id=1298766
[ 4 ] Bug #1409932 - nagios-plugins-dns-2.1.4-2.el7.x86_64 broke reverse lookup (PTR) checks
https://bugzilla.redhat.com/show_bug.cgi?id=1409932
[ 5 ] Bug #1410324 - nagios-plugins 2.1.4: check_dns lost MX priority on output
https://bugzilla.redhat.com/show_bug.cgi?id=1410324
[ 6 ] Bug #1417259 - nagios-plugins-2.1.4-stable check_snmp rate calculation expects strange path
https://bugzilla.redhat.com/show_bug.cgi?id=1417259
[ 7 ] Bug #1410039 - check_file_age is broken in recent update
https://bugzilla.redhat.com/show_bug.cgi?id=1410039
--------------------------------------------------------------------------------
================================================================================
proftpd-1.3.5d-2.el7 (FEDORA-EPEL-2017-68cac04c59)
Flexible, stable and highly-configurable FTP server
--------------------------------------------------------------------------------
Update Information:
This update is an attempt to fix segfaults when using mod_sftp. *
http://bugs.proftpd.org/show_bug.cgi?id=4287 *
https://github.com/proftpd/proftpd/issues/408
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1420365 - ProFTPD 1.3.5d on CentOS7 segfault soon after sftp connection
https://bugzilla.redhat.com/show_bug.cgi?id=1420365
--------------------------------------------------------------------------------
================================================================================
python-openqa_client-1.3.0-1.el7 (FEDORA-EPEL-2017-a53219e6d6)
Python client library for openQA API
--------------------------------------------------------------------------------
Update Information:
This update introduces a new package containing the [Python client
library](https://github.com/os-autoinst/openQA-python-client) for the
[openQA](http://open.qa) web API. It handles authentication for administrative
requests, and provides a couple of convenience functions for job queries. This
library is already used for scheduling jobs, forwarding results to
[Wikitcms](https://fedoraproject.org/wiki/Wikitcms) and
[ResultsDB](https://fedoraproject.org/wiki/ResultsDB) and generating the
'compose check report' emails and [nightly compose finder
page](https://www.happyassassin.net/nightlies.html), but had not formerly been
packaged.
--------------------------------------------------------------------------------
================================================================================
shigofumi-0.8-1.el7 (FEDORA-EPEL-2017-8f1058b17f)
Command line client for accessing the Czech Data Boxes
--------------------------------------------------------------------------------
Update Information:
This release fixes a check for an empty password when changing the password. It
fixes build script. It updates documentation and it enables support for storing
and retrieving file types from file extended attributes.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1423056 - shigofumi-0.8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1423056
--------------------------------------------------------------------------------
================================================================================
suricata-3.2.1-1.el7 (FEDORA-EPEL-2017-8e1a030633)
Intrusion Detection System
--------------------------------------------------------------------------------
Update Information:
This is a new upstream feature and security release. Improvements include:
bypass; pre-filter -- fast packet keywords; TLS improvements; ICS protocol
additions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;
NIC offloading disabled by default; unix socket enabled by default; and App
Layer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1396150 - Fix ownership of /run/suricata
https://bugzilla.redhat.com/show_bug.cgi?id=1396150
[ 2 ] Bug #1396151 - Rotate /var/log/suricata/eve.json
https://bugzilla.redhat.com/show_bug.cgi?id=1396151
--------------------------------------------------------------------------------
================================================================================
xrootd-4.6.0-4.el7 (FEDORA-EPEL-2017-9b2cd39ee3)
Extended ROOT file server
--------------------------------------------------------------------------------
Update Information:
New version 4.6.0, release notes are here:
https://github.com/xrootd/xrootd/blob/v4.6.0/docs/ReleaseNotes.txt
--------------------------------------------------------------------------------
================================================================================
youtube-dl-2017.02.16-1.el7 (FEDORA-EPEL-2017-9aec471979)
A small command-line program to download online videos
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1420965 - youtube-dl cannot find pycrypto, even though it is installed
https://bugzilla.redhat.com/show_bug.cgi?id=1420965
[ 2 ] Bug #1418496 - youtube-dl-2017.02.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1418496
--------------------------------------------------------------------------------