Fedora EPEL 6 updates-testing report
by updates@fedoraproject.org
The following Fedora EPEL 6 Security updates need testing:
Age URL
88 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-b7556983e8 tomcat-7.0.92-1.el6
12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-06b243cced guacamole-server-1.0.0-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
lcgdm-1.12.0-2.el6
ocserv-0.12.3-1.el6
pam_ssh-2.3-1.el6
tcpreplay-4.3.2-1.el6
wordpress-5.1.1-1.el6
Details about builds:
================================================================================
lcgdm-1.12.0-2.el6 (FEDORA-EPEL-2019-7b5144fde4)
LHC Computing Grid Data Management
--------------------------------------------------------------------------------
Update Information:
A fix for multi-protocol space divergence issues :
https://its.cern.ch/jira/browse/LCGDM-2752 ---- A fix for multi-protocol space
divergence issues : https://its.cern.ch/jira/browse/LCGDM-2752
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 13 2019 Oliver Keeble <oliver.keeble(a)cern.ch> - 1.12.0-2
- Add isa provides for python2 packages
* Fri Mar 8 2019 Oliver Keeble <oliver.keeble(a)cern.ch> - 1.12.0-1
- New upstream release 1.12.0
- Drop patch lcgdm-1.10.0-explicit-python2
* Fri Feb 1 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.10.0-16
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Mon Jan 14 2019 Bj��rn Esser <besser82(a)fedoraproject.org> - 1.10.0-15
- Rebuilt for libcrypt.so.2 (#1666033)
* Fri Jan 4 2019 Bj��rn Esser <besser82(a)fedoraproject.org> - 1.10.0-14
- Add patch to use explicit python2 shebangs, fixes FTBFS for Fedora 30
- Link the c compiled python modules with proper LDFLAGS
* Thu Aug 9 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 1.10.0-13
- Use explicit --with-python=/usr/bin/python2 in configure (fixes rawhide)
- Remove redundant macro definitions for old Fedora and EPEL releases
- Only filter provides on EPEL 6 - the others filter correctly by default
- Add python34-lfc and python34-dnf packages for EPEL 7
- Remove obsolete Group tags
- Fix more python subpackage names
- Fix shebang in dpm-listspaces script
- Use %license, %ldconfig_scriptlets and %systemd_requires
* Mon Jul 16 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 1.10.0-12
- Fix python subpackage names
* Fri Jul 13 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.10.0-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Tue Jul 3 2018 Petr Pisar <ppisar(a)redhat.com> - 1.10.0-10
- Perl 5.28 rebuild
* Wed Jun 27 2018 Jitka Plesnikova <jplesnik(a)redhat.com> - 1.10.0-9
- Perl 5.28 rebuild
* Tue Jun 19 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 1.10.0-8
- Rebuilt for Python 3.7
* Fri Mar 16 2018 Oliver Keeble <oliver.keeble(a)cern.ch> - 1.10.0-7
- Python fix Bug 1436812
* Thu Mar 15 2018 Oliver Keeble <oliver.keeble(a)cern.ch> - 1.10.0-6
- New upstream 1.10.0e
* Wed Mar 7 2018 Adam Williamson <awilliam(a)redhat.com> - 1.10.0-5
- Rebuild to fix GCC 8 mis-compilation
See https://da.gd/YJVwk ("GCC 8 ABI change on x86_64")
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1600711 - lcgdm: dpm-python3 requires both Python 2 and Python 3
https://bugzilla.redhat.com/show_bug.cgi?id=1600711
--------------------------------------------------------------------------------
================================================================================
ocserv-0.12.3-1.el6 (FEDORA-EPEL-2019-79977fbbbc)
OpenConnect SSL VPN server
--------------------------------------------------------------------------------
Update Information:
Bugfix release
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 12 2019 Nikos Mavrogiannopoulos <nmav(a)gnutls.org> - 0.12.3-1
- Update to upstream 0.12.3 release
--------------------------------------------------------------------------------
================================================================================
pam_ssh-2.3-1.el6 (FEDORA-EPEL-2019-36893b1ff0)
PAM module for use with SSH keys and ssh-agent
--------------------------------------------------------------------------------
Update Information:
Upgrade to 2.3 NOTE: If you used pam_ssh for authentication against a key (ie.
anything but not "optional" in "auth optional pam_ssh.so ..."), then you must
replace (or link) your auth keys under .ssh/login-keys.d/ directory. See
pam_ssh(8) for more info.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 12 2019 Dmitry Butskoy <Dmitry(a)Butskoy.name> - 2.3-1
- Upgrade to 2.3
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1687472 - Please update to newest version
https://bugzilla.redhat.com/show_bug.cgi?id=1687472
--------------------------------------------------------------------------------
================================================================================
tcpreplay-4.3.2-1.el6 (FEDORA-EPEL-2019-d8d946a765)
Replay captured network traffic
--------------------------------------------------------------------------------
Update Information:
Patch CVE-2019-8376, CVE-2019-8377 and CVE-2019-8381.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 13 2019 Bojan Smojver <bojan@rexursive com> - 4.3.2-1
- bump up to 4.3.2
* Wed Mar 13 2019 Bojan Smojver <bojan@rexursive com> - 4.3.1-3
- patch CVE-2019-8376, CVE-2019-8377 and CVE-2019-8381
* Sun Feb 3 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.3.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sat Dec 29 2018 Bojan Smojver <bojan@rexursive com> - 4.3.1-1
- bump up to 4.3.1
* Sat Jul 14 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.2.5-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Fri Mar 9 2018 Bojan Smojver <bojan@rexursive com> - 4.2.5-5
- add gcc build requirement
* Fri Feb 9 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.2.5-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Thu Aug 3 2017 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.2.5-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Thu Jul 27 2017 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.2.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1678245 - CVE-2019-8377 tcpreplay: null pointer dereference in function get_ipv6_l4proto() in get.c [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1678245
[ 2 ] Bug #1678242 - CVE-2019-8376 tcpreplay: null pointer dereference in function get_layer4_v6() in get.c [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1678242
[ 3 ] Bug #1678231 - CVE-2019-8381 tcpreplay: invalid memory access in function do_checksum in checksum.c [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1678231
[ 4 ] Bug #1646408 - CVE-2018-18408 tcpreplay: use-after-free in post_args function in tcpbridge.c [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1646408
[ 5 ] Bug #1646403 - CVE-2018-18407 tcpreplay: tcpreplay: heap-based buffer over-read in csum_replace4 function in incremental_checksum.h [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1646403
[ 6 ] Bug #1678244 - CVE-2019-8377 tcpreplay: null pointer dereference in function get_ipv6_l4proto() in get.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1678244
[ 7 ] Bug #1678241 - CVE-2019-8376 tcpreplay: null pointer dereference in function get_layer4_v6() in get.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1678241
[ 8 ] Bug #1678230 - CVE-2019-8381 tcpreplay: invalid memory access in function do_checksum in checksum.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1678230
--------------------------------------------------------------------------------
================================================================================
wordpress-5.1.1-1.el6 (FEDORA-EPEL-2019-05098a716b)
Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:
Upstream announcement: [WordPress 5.1.1 Security and Maintenance
Release](https://wordpress.org/news/2019/03/wordpress-5-1-1-security-and-
maintenance-release/)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Mar 13 2019 Remi Collet <remi(a)remirepo.net> - 5.1.1-1
- WordPress 5.1.1 Security and Maintenance Release
--------------------------------------------------------------------------------