The following Fedora EPEL 5 Security updates need testing:
Age URL
837
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2013-11893
libguestfs-1.20.12-1.el5
601
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2014-1626 puppet-2.7.26-1.el5
451
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2014-3849
sblim-sfcb-1.3.8-2.el5
94
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-edbea40516
mcollective-2.8.4-1.el5
66
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-582c8075e6
thttpd-2.25b-24.el5
47
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-d1309b0eb2
libsndfile-1.0.17-8.el5
5
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-5a2146a2dd
prosody-0.9.10-1.el5
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-2a457c3d5b
phpMyAdmin4-4.0.10.14-1.el5
0
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-991b4f1f7d
wordpress-4.4.2-1.el5
The following builds have been pushed to Fedora EPEL 5 updates-testing
pcp-3.11.0-1.el5
wordpress-4.4.2-1.el5
Details about builds:
================================================================================
pcp-3.11.0-1.el5 (FEDORA-EPEL-2016-57b7efb2d7)
System-level performance monitoring and performance management
--------------------------------------------------------------------------------
Update Information:
* containers: add a pcp-pmwebd container image * pmcd: start PMDAs via pmdaroot,
allowing restart on PMDA failure without restarting pmcd itself * pmcd: tenfold
speed up of the shutdown process * pmcd: ensure startup before zabbix-agent,
with systemd * pmdafreebsd: use getifaddrs() for network interface * pmdalinux:
fix /proc/interrupts parsing on s390x platforms * pmdalinux: fix i386 buffer
overflow in softnet stats * pmdalinux: support additional vmstat kernel metrics
(virt balloon, transparent-huge-page zero page alloc counters) * pmdaxfs:
support the per-device XFS metrics * pmdanamed: fix SELinux AVC denials during
Install * pmdavmware: updates to work with current VMWare perl API * libpcp:
improvements to derived metrics error handling * libpcp: rework interp logic
arond <mark> records * libpcp: fix bug in interp mode record caching * libpcp:
pthread_mutexattr_destroy, pthread_mutex_destroy calls * libpcp: added a new
fetchgroup API * libpcp: fix dup-context-with-attrs memory corruption bug *
libpcp: fix derived metric PMNS navigation mem leak * libpcp: unconditional
registration of anon (event.*) metrics * pcp-iostat: use py3 and py3 compatible
pipe exception handlers * pcp-iostat: improve incorrect counter rate conversion
* pcp-iostat: improve BrokenPipeError exception handling * pmmgr: add general
monitor-program launching option * pmmgr: resolved a couple of small memory
leaks * pmrep: fix first sample reporting, instant/discrete metrics * pmrep: fix
string valued metric reporting, with python3 * pmval: improve reporting in the
region of <mark> records * pmwebd: add an option to disable service advertising
* pmwebd: support for http compression * pmwebd: add units/sem to legend in
graphite/png mode * pmwebd: enable graphite image-mode caching via redirection *
pmwebd: add an option for alternative name encodings * sar2pcp: support
additional mem.util metrics * docs: updates to the system CPU performance
tutorial * packaging: add missing dependencies on some perl modules * packaging:
drop the pcp-compat subpackage ---- Add -V/--version support to several more
commands (BZ 1284411) ---- pcp-3.10.8-1.fc21 - Update pmlogger to log an
immediate sample first (BZ 1269921) - Add pmOption host and archive setter
python APIs (BZ 1270176) - Replace old pmatop(1) man page with pcp-atop(1) (BZ
1270761) - Update to latest PCP sources. - CHANGELOG : - pmdaslurm: new PMDA
exporting HPC scheduler metrics - pmdalinux: correctly report high speed
network link speeds - pmdalinux: support for wireless network interfaces
- pmdalinux: add support for NVME devices - pmie: fqdn functionality, added
%c for action strings - pmlogextract: runtime reducing instance
optimizations - pmlogrewrite: metric name lex pattern change - pmlogger:
change semantics for first logging operation - rc_pmlogger: shell escape for
control file "directory" field - pcp-atop: update with latest atop features
(esp. NFS) - pcp-atop: fix initial fetch time offset for the globals -
pcp-atop: fix -b/-e options to match man page description - docs: update
Quick Ref Guide with pcp-atop/pcp-atopsar - docs: remove outdated pmatop man
page, see pcp-atop(1) - python api: fix local-context mode type error -
python api: improve handling of non-ascii instance names - python api:
simple debugging interface to access pmDebug - python api: ensure an
interruptible sleep is used - python api: add single host/archive pmOption
setter methods - libpcp: add $PCP_DEBUG to initialize pmDebug - libpcp:
extend __pmAF* family with __pmAFsetup - libpcp: resolve false-context-
sharing corner cases - pcp2graphite: provide a local-context mode option
- pmmgr: add the subtarget-containers option - pmmgr: add pmlogreduce
support - rc_pmcd: be more careful with auto-install/-remove - pmcd:
allow dynamic switching of monitored containers - pmdapmcd: add
pmcd.client.container diagnostic metric - pmdaroot: new metric mapping
containers to their cgroups - pmdaroot: add cgroup heuristics for non-
systemd setups - pmdaroot: fix timeliness of creation of socket connection
- pmdads389: add normalized dn cache metrics - pmdads389: instantaneous vs
discrete metric corrections - pmdads389: send correct error codes when not
connected - pmdamounts: correct a number of 32-bit unsafe calculations -
pmdanfsclient: improve PMDA error handling - pmdaperfevent: fix invalid
metric names - pmdaperfevent: add reference clock cycles for NHM and WSM
- docs: added upgrade instructions to pmdaperfevent man page - containers:
bindmount /dev/log for syslog messages - build: fix FreeBSD 10.2 with dtrace
probes auto-enabled pcp-3.10.8-1.fc22 - Update pmlogger to log an immediate
sample first (BZ 1269921) - Add pmOption host and archive setter python APIs (BZ
1270176) - Replace old pmatop(1) man page with pcp-atop(1) (BZ 1270761) - Update
to latest PCP sources. - CHANGELOG - pmdaslurm: new PMDA exporting HPC
scheduler metrics - pmdalinux: correctly report high speed network link
speeds - pmdalinux: support for wireless network interfaces - pmdalinux:
add support for NVME devices - pmie: fqdn functionality, added %c for action
strings - pmlogextract: runtime reducing instance optimizations -
pmlogrewrite: metric name lex pattern change - pmlogger: change semantics
for first logging operation - rc_pmlogger: shell escape for control file
"directory" field - pcp-atop: update with latest atop features (esp. NFS)
- pcp-atop: fix initial fetch time offset for the globals - pcp-atop: fix
-b/-e options to match man page description - docs: update Quick Ref Guide
with pcp-atop/pcp-atopsar - docs: remove outdated pmatop man page, see pcp-
atop(1) - python api: fix local-context mode type error - python api:
improve handling of non-ascii instance names - python api: simple debugging
interface to access pmDebug - python api: ensure an interruptible sleep is
used - python api: add single host/archive pmOption setter methods -
libpcp: add $PCP_DEBUG to initialize pmDebug - libpcp: extend __pmAF* family
with __pmAFsetup - libpcp: resolve false-context-sharing corner cases -
pcp2graphite: provide a local-context mode option - pmmgr: add the
subtarget-containers option - pmmgr: add pmlogreduce support - rc_pmcd:
be more careful with auto-install/-remove - pmcd: allow dynamic switching of
monitored containers - pmdapmcd: add pmcd.client.container diagnostic metric
- pmdaroot: new metric mapping containers to their cgroups - pmdaroot: add
cgroup heuristics for non-systemd setups - pmdaroot: fix timeliness of
creation of socket connection - pmdads389: add normalized dn cache metrics
- pmdads389: instantaneous vs discrete metric corrections - pmdads389: send
correct error codes when not connected - pmdamounts: correct a number of
32-bit unsafe calculations - pmdanfsclient: improve PMDA error handling
- pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference
clock cycles for NHM and WSM - docs: added upgrade instructions to
pmdaperfevent man page - containers: bindmount /dev/log for syslog messages
- build: fix FreeBSD 10.2 with dtrace probes auto-enabled pcp-3.10.8-1.el5 -
Update pmlogger to log an immediate sample first (BZ 1269921) - Add pmOption
host and archive setter python APIs (BZ 1270176) - Replace old pmatop(1) man
page with pcp-atop(1) (BZ 1270761) - Update to latest PCP sources. - CHANGELOG
- pmdaslurm: new PMDA exporting HPC scheduler metrics - pmdalinux: correctly
report high speed network link speeds - pmdalinux: support for wireless
network interfaces - pmdalinux: add support for NVME devices - pmie:
fqdn functionality, added %c for action strings - pmlogextract: runtime
reducing instance optimizations - pmlogrewrite: metric name lex pattern
change - pmlogger: change semantics for first logging operation -
rc_pmlogger: shell escape for control file "directory" field - pcp-atop:
update with latest atop features (esp. NFS) - pcp-atop: fix initial fetch
time offset for the globals - pcp-atop: fix -b/-e options to match man page
description - docs: update Quick Ref Guide with pcp-atop/pcp-atopsar -
docs: remove outdated pmatop man page, see pcp-atop(1) - python api: fix
local-context mode type error - python api: improve handling of non-ascii
instance names - python api: simple debugging interface to access pmDebug
- python api: ensure an interruptible sleep is used - python api: add single
host/archive pmOption setter methods - libpcp: add $PCP_DEBUG to initialize
pmDebug - libpcp: extend __pmAF* family with __pmAFsetup - libpcp:
resolve false-context-sharing corner cases - pcp2graphite: provide a local-
context mode option - pmmgr: add the subtarget-containers option -
pmmgr: add pmlogreduce support - rc_pmcd: be more careful with auto-
install/-remove - pmcd: allow dynamic switching of monitored containers
- pmdapmcd: add pmcd.client.container diagnostic metric - pmdaroot: new
metric mapping containers to their cgroups - pmdaroot: add cgroup heuristics
for non-systemd setups - pmdaroot: fix timeliness of creation of socket
connection - pmdads389: add normalized dn cache metrics - pmdads389:
instantaneous vs discrete metric corrections - pmdads389: send correct error
codes when not connected - pmdamounts: correct a number of 32-bit unsafe
calculations - pmdanfsclient: improve PMDA error handling -
pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference clock
cycles for NHM and WSM - docs: added upgrade instructions to pmdaperfevent
man page - containers: bindmount /dev/log for syslog messages - build:
fix FreeBSD 10.2 with dtrace probes auto-enabled pcp-3.10.8-1.fc23.1 - Update
pmlogger to log an immediate sample first (BZ 1269921) - Add pmOption host and
archive setter python APIs (BZ 1270176) - Replace old pmatop(1) man page with
pcp-atop(1) (BZ 1270761) - Update to latest PCP sources. - CHANGELOG -
pmdaslurm: new PMDA exporting HPC scheduler metrics - pmdalinux: correctly
report high speed network link speeds - pmdalinux: support for wireless
network interfaces - pmdalinux: add support for NVME devices - pmie:
fqdn functionality, added %c for action strings - pmlogextract: runtime
reducing instance optimizations - pmlogrewrite: metric name lex pattern
change - pmlogger: change semantics for first logging operation -
rc_pmlogger: shell escape for control file "directory" field - pcp-atop:
update with latest atop features (esp. NFS) - pcp-atop: fix initial fetch
time offset for the globals - pcp-atop: fix -b/-e options to match man page
description - docs: update Quick Ref Guide with pcp-atop/pcp-atopsar -
docs: remove outdated pmatop man page, see pcp-atop(1) - python api: fix
local-context mode type error - python api: improve handling of non-ascii
instance names - python api: simple debugging interface to access pmDebug
- python api: ensure an interruptible sleep is used - python api: add single
host/archive pmOption setter methods - libpcp: add $PCP_DEBUG to initialize
pmDebug - libpcp: extend __pmAF* family with __pmAFsetup - libpcp:
resolve false-context-sharing corner cases - pcp2graphite: provide a local-
context mode option - pmmgr: add the subtarget-containers option -
pmmgr: add pmlogreduce support - rc_pmcd: be more careful with auto-
install/-remove - pmcd: allow dynamic switching of monitored containers
- pmdapmcd: add pmcd.client.container diagnostic metric - pmdaroot: new
metric mapping containers to their cgroups - pmdaroot: add cgroup heuristics
for non-systemd setups - pmdaroot: fix timeliness of creation of socket
connection - pmdads389: add normalized dn cache metrics - pmdads389:
instantaneous vs discrete metric corrections - pmdads389: send correct error
codes when not connected - pmdamounts: correct a number of 32-bit unsafe
calculations - pmdanfsclient: improve PMDA error handling -
pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference clock
cycles for NHM and WSM - docs: added upgrade instructions to pmdaperfevent
man page - containers: bindmount /dev/log for syslog messages - build:
fix FreeBSD 10.2 with dtrace probes auto-enabled ---- Update to latest PCP and
Vector sources. pcp-3.10.7-1.el5 - Resolved pmchart sigsegv opening view
without context (BZ 1256708) - Fixed pmchart memory corruption restoring Saved
Hosts (BZ 1257009) - Fix perl PMDA API double-free on socket error path (BZ
1258862) - Fix python API pmGetOption(3) alignment interface (BZ 1262722) -
Added missing RPM dependencies to several PMDA sub-packages. - Update to latest
stable Vector release for pcp-vector-webapp. - Update to latest PCP sources.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1284411 - RFE: Add pcp -V
https://bugzilla.redhat.com/show_bug.cgi?id=1284411
[ 2 ] Bug #1249572 - pcp-iostat exception at the end of an archive
https://bugzilla.redhat.com/show_bug.cgi?id=1249572
[ 3 ] Bug #1163413 - RFE: pmdapipe
https://bugzilla.redhat.com/show_bug.cgi?id=1163413
[ 4 ] Bug #1284417 - Python PMAPI pmSetMode does not allow None timeval
https://bugzilla.redhat.com/show_bug.cgi?id=1284417
[ 5 ] Bug #1285371 - Python PMAPI pmiPutValue does not accept singular metrics
https://bugzilla.redhat.com/show_bug.cgi?id=1285371
[ 6 ] Bug #1286733 - Invalid Python PMAPI pmRegisterDerived call crashes libpcp
https://bugzilla.redhat.com/show_bug.cgi?id=1286733
[ 7 ] Bug #1287678 - pmstat -g SEGV
https://bugzilla.redhat.com/show_bug.cgi?id=1287678
[ 8 ] Bug #1287778 - Python PMAPI pmNonOptionsFromList cryptic error message
https://bugzilla.redhat.com/show_bug.cgi?id=1287778
[ 9 ] Bug #1289909 - pmdumptext -g / -p not working
https://bugzilla.redhat.com/show_bug.cgi?id=1289909
[ 10 ] Bug #1256125 - SELinux is preventing /usr/bin/pmlogger from 'open'
accesses on the file /var/lib/pcp/config/pmlogger/config.default.
https://bugzilla.redhat.com/show_bug.cgi?id=1256125
[ 11 ] Bug #1270761 - pmatop -h does not work
https://bugzilla.redhat.com/show_bug.cgi?id=1270761
[ 12 ] Bug #1270176 - Python PMAPI pmSetOptionHostList no workie
https://bugzilla.redhat.com/show_bug.cgi?id=1270176
[ 13 ] Bug #1269921 - pmRecordControl misses the first sample
https://bugzilla.redhat.com/show_bug.cgi?id=1269921
[ 14 ] Bug #1262722 - PCP Python PMAPI pmGetOptionAlignment fails
https://bugzilla.redhat.com/show_bug.cgi?id=1262722
[ 15 ] Bug #1258862 - local_sock() double free error
https://bugzilla.redhat.com/show_bug.cgi?id=1258862
[ 16 ] Bug #1257009 - pmchart connect incorrect host with savedHosts entry in
.config/PCP/pmchart.conf
https://bugzilla.redhat.com/show_bug.cgi?id=1257009
[ 17 ] Bug #1256708 - [abrt] pcp-gui: context(): pmchart killed by SIGSEGV
https://bugzilla.redhat.com/show_bug.cgi?id=1256708
--------------------------------------------------------------------------------
================================================================================
wordpress-4.4.2-1.el5 (FEDORA-EPEL-2016-991b4f1f7d)
Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:
**WordPress 4.4.2 Security and Maintenance Release** WordPress 4.4.2 is now
available. This is a security release for all previous versions and we strongly
encourage you to update your sites immediately. WordPress versions 4.4.1 and
earlier are affected by two security issues: a possible SSRF for certain local
URIs, reported by Ronni Skansing; and an open redirection attack, reported by
Shailesh Suthar. Thank you to both reporters for practicing responsible
disclosure. In addition to the security issues above, WordPress 4.4.2 fixes 17
bugs from 4.4 and 4.4.1. For more information, see the [release
notes](https://codex.wordpress.org/Version_4.4.2) or consult the [list of
changes](https://core.trac.wordpress.org/query?milestone=4.4.2).
--------------------------------------------------------------------------------