The following Fedora EPEL 7 Security updates need testing:
Age URL
74
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3835d39d1a
unrtf-0.21.9-8.el7
68
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-15b7dc35af
pass-1.7.2-1.el7
42
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-d2e0971e9b
uwsgi-2.0.17.1-1.el7
25
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-f9d6ff695a
bibutils-6.6-1.el7 ghc-hs-bibutils-6.6.0.0-1.el7 pandoc-citeproc-0.3.0.1-4.el7
24
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-5346e2123a
dpkg-1.18.25-1.el7
15
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-0be0127779
libgit2-0.26.6-1.el7
12
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-33f460bd9c
moodle-3.1.13-2.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d
condor-8.6.11-1.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-dce803ff0d
lighttpd-1.4.50-1.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-69993b3f45
sleuthkit-4.6.2-1.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-6f182ddbf7
python34-3.4.9-1.el7
0
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-8e10f21fa8
yubico-piv-tool-1.6.1-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
chromium-68.0.3440.106-3.el7
dragonegg-3.4-6.el7
duplicity-0.7.18-1.el7
Details about builds:
================================================================================
chromium-68.0.3440.106-3.el7 (FEDORA-EPEL-2018-3a3c72c5e5)
A WebKit (Blink) powered web browser
--------------------------------------------------------------------------------
Update Information:
Update to Chromium 68. Security fix for CVE-2018-4117 CVE-2018-6044
CVE-2018-6150 CVE-2018-6151 CVE-2018-6152 CVE-2018-6153 CVE-2018-6154
CVE-2018-6155 CVE-2018-6156 CVE-2018-6157 CVE-2018-6158 CVE-2018-6159
CVE-2018-6161 CVE-2018-6162 CVE-2018-6163 CVE-2018-6149
--------------------------------------------------------------------------------
ChangeLog:
* Sun Aug 19 2018 Tom Callaway <spot(a)fedoraproject.org> - 68.0.3440.106-3
- fix library filters
* Fri Aug 17 2018 Tom Callaway <spot(a)fedoraproject.org> - 68.0.3440.106-2
- fix error with defaulting on redeclaration
* Thu Aug 9 2018 Tom Callaway <spot(a)fedoraproject.org> - 68.0.3440.106-1
- update to 68.0.3440.106
* Wed Aug 8 2018 Tom Callaway <spot(a)fedoraproject.org> - 68.0.3440.84-1
- update to 68.0.3440.84
* Mon Jul 30 2018 Tom Callaway <spot(a)fedoraproject.org> - 68.0.3440.75-1
- update to 68.0.3440.75
* Thu Jul 12 2018 Fedora Release Engineering <releng(a)fedoraproject.org> -
67.0.3396.99-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Mon Jul 9 2018 Tom Callaway <spot(a)fedoraproject.org> 67.0.3396.99-1
- update to 67.0.3396.99
* Mon Jun 25 2018 Tom Callaway <spot(a)fedoraproject.org> 67.0.3396.87-2
- add "Fedora" to the user agent string
* Tue Jun 19 2018 Tom Callaway <spot(a)fedoraproject.org> 67.0.3396.87-1
- update to 67.0.3396.87
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1608208 - CVE-2018-6152 chromium-browser: Local file write in DevTools
https://bugzilla.redhat.com/show_bug.cgi?id=1608208
[ 2 ] Bug #1608207 - CVE-2018-6151 chromium-browser: Bad cast in DevTools
https://bugzilla.redhat.com/show_bug.cgi?id=1608207
[ 3 ] Bug #1608206 - CVE-2018-6150 chromium-browser: Cross origin information disclosure
in Service Workers
https://bugzilla.redhat.com/show_bug.cgi?id=1608206
[ 4 ] Bug #1608205 - CVE-2018-4117 chromium-browser: Cross origin information leak in
Blink
https://bugzilla.redhat.com/show_bug.cgi?id=1608205
[ 5 ] Bug #1608204 - CVE-2018-6044 chromium-browser: Request privilege escalation in
Extensions
https://bugzilla.redhat.com/show_bug.cgi?id=1608204
[ 6 ] Bug #1608203 - CVE-2018-6179 chromium-browser: Local file information leak in
Extensions
https://bugzilla.redhat.com/show_bug.cgi?id=1608203
[ 7 ] Bug #1608202 - CVE-2018-6178 chromium-browser: UI spoof in Extensions
https://bugzilla.redhat.com/show_bug.cgi?id=1608202
[ 8 ] Bug #1608201 - CVE-2018-6177 chromium-browser: Cross origin information leak in
Blink
https://bugzilla.redhat.com/show_bug.cgi?id=1608201
[ 9 ] Bug #1608200 - CVE-2018-6176 chromium-browser: Local user privilege escalation in
Extensions
https://bugzilla.redhat.com/show_bug.cgi?id=1608200
[ 10 ] Bug #1608199 - CVE-2018-6175 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608199
[ 11 ] Bug #1608198 - CVE-2018-6174 chromium-browser: Integer overflow in SwiftShader
https://bugzilla.redhat.com/show_bug.cgi?id=1608198
[ 12 ] Bug #1608197 - CVE-2018-6173 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608197
[ 13 ] Bug #1608196 - CVE-2018-6172 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608196
[ 14 ] Bug #1608195 - CVE-2018-6171 chromium-browser: Use after free in WebBluetooth
https://bugzilla.redhat.com/show_bug.cgi?id=1608195
[ 15 ] Bug #1608194 - CVE-2018-6170 chromium-browser: Type confusion in PDFium
https://bugzilla.redhat.com/show_bug.cgi?id=1608194
[ 16 ] Bug #1608193 - CVE-2018-6169 chromium-browser: Permissions bypass in extension
installation
https://bugzilla.redhat.com/show_bug.cgi?id=1608193
[ 17 ] Bug #1608192 - CVE-2018-6168 chromium-browser: CORS bypass in Blink
https://bugzilla.redhat.com/show_bug.cgi?id=1608192
[ 18 ] Bug #1608191 - CVE-2018-6167 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608191
[ 19 ] Bug #1608190 - CVE-2018-6166 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608190
[ 20 ] Bug #1608189 - CVE-2018-6165 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608189
[ 21 ] Bug #1608188 - CVE-2018-6164 chromium-browser: Same origin policy bypass in
ServiceWorker
https://bugzilla.redhat.com/show_bug.cgi?id=1608188
[ 22 ] Bug #1608187 - CVE-2018-6163 chromium-browser: URL spoof in Omnibox
https://bugzilla.redhat.com/show_bug.cgi?id=1608187
[ 23 ] Bug #1608186 - CVE-2018-6162 chromium-browser: Heap buffer overflow in WebGL
https://bugzilla.redhat.com/show_bug.cgi?id=1608186
[ 24 ] Bug #1608185 - CVE-2018-6161 chromium-browser: Same origin policy bypass in
WebAudio
https://bugzilla.redhat.com/show_bug.cgi?id=1608185
[ 25 ] Bug #1608184 - CVE-2018-6160 chromium-browser: URL spoof in Chrome on iOS
https://bugzilla.redhat.com/show_bug.cgi?id=1608184
[ 26 ] Bug #1608183 - CVE-2018-6159 chromium-browser: Same origin policy bypass in
ServiceWorker
https://bugzilla.redhat.com/show_bug.cgi?id=1608183
[ 27 ] Bug #1608182 - CVE-2018-6158 chromium-browser: Use after free in Blink
https://bugzilla.redhat.com/show_bug.cgi?id=1608182
[ 28 ] Bug #1608181 - CVE-2018-6157 chromium-browser: Type confusion in WebRTC
https://bugzilla.redhat.com/show_bug.cgi?id=1608181
[ 29 ] Bug #1608180 - CVE-2018-6156 chromium-browser: Heap buffer overflow in WebRTC
https://bugzilla.redhat.com/show_bug.cgi?id=1608180
[ 30 ] Bug #1608179 - CVE-2018-6155 chromium-browser: Use after free in WebRTC
https://bugzilla.redhat.com/show_bug.cgi?id=1608179
[ 31 ] Bug #1608178 - CVE-2018-6154 chromium-browser: Heap buffer overflow in WebGL
https://bugzilla.redhat.com/show_bug.cgi?id=1608178
[ 32 ] Bug #1608177 - CVE-2018-6153 chromium-browser: Stack buffer overflow in Skia
https://bugzilla.redhat.com/show_bug.cgi?id=1608177
--------------------------------------------------------------------------------
================================================================================
dragonegg-3.4-6.el7 (FEDORA-EPEL-2018-2431df82d2)
GCC plugin to use LLVM optimizers and code generators
--------------------------------------------------------------------------------
Update Information:
Rebuild for gcc-4.8.5-28.el7
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 22 2018 Eric Smith <brouhaha(a)fedoraproject.org> - 3.4-6
- Rebuild for gcc-4.8.5-28.el7
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1288278 - dragonegg needs to be updated for new GCC in EL 7.2
https://bugzilla.redhat.com/show_bug.cgi?id=1288278
--------------------------------------------------------------------------------
================================================================================
duplicity-0.7.18-1.el7 (FEDORA-EPEL-2018-1b7aef7506)
Encrypted bandwidth-efficient backup using rsync algorithm
--------------------------------------------------------------------------------
Update Information:
https://launchpad.net/duplicity/+announcement/15043
--------------------------------------------------------------------------------
ChangeLog:
* Wed Aug 22 2018 Gwyn Ciesla <limburgher(a)gmail.com> - 0.7.18-1
- 0.7.18.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1619861 - duplicity-0.7.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1619861
--------------------------------------------------------------------------------