The following Fedora EPEL 7 Security updates need testing:
Age URL
1086
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087
dokuwiki-0-0.24.20140929c.el7
849
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f
mcollective-2.8.4-1.el7
431
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d
libbsd-0.8.3-1.el7
328
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe
mod_cluster-1.3.3-10.el7
160
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23
libmspack-0.6-0.1.alpha.el7
98
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e64eeb6ece
nagios-4.3.4-5.el7
47
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-73ee944e65
rootsh-1.5.3-17.el7
21
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-7134fc92a1
jhead-3.00-7.el7
9
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-276ec6ee2b
exim-4.90.1-2.el7
9
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-e50c94a832
seamonkey-2.49.2-2.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-525417d3d4
mbedtls-2.7.0-1.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-cee77fc9b3
knot-resolver-2.1.0-1.el7
7
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-b7a74678b1
openjpeg2-2.3.0-6.el7
6
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-50566f0a39
uwsgi-2.0.16-1.el7
5
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-0296296d7c
mingw-wavpack-5.1.0-4.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-9111777f91
freexl-1.0.5-1.el7
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3e70a38ad4
drupal7-7.57-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
duplicity-0.7.17-1.el7
golang-bazil-fuse-0-0.2.20160811git371fbbd.el7
golang-github-VividCortex-ewma-1.1.1-3.el7
golang-github-billziss-gh-cgofuse-1.0.4-2.el7
golang-github-jlaffaye-ftp-0-0.2.20170927git299b7ff.el7
golang-github-rfjakob-eme-1.1-2.el7
golang-github-skratchdot-open-golang-0-0.11.gitba570a1.el7
lighttpd-1.4.48-2.el7
nx-libs-3.5.0.33-4.el7
python-recaptcha-client-2.0.0-1.el7
rpkg-1.52-1.el7
ucarp-1.5.2-22.el7
x2goserver-4.0.1.22-2.el7
youtube-dl-2018.02.26-1.el7
Details about builds:
================================================================================
duplicity-0.7.17-1.el7 (FEDORA-EPEL-2018-ef1ab5bae4)
Encrypted bandwidth-efficient backup using rsync algorithm
--------------------------------------------------------------------------------
Update Information:
New in v0.7.17 (2018/02/26) --------------------------- * Removed changes made
in bug #1044715 Provide a file history feature - Changes required too much
memory to carry in the manifest - The option --file-changed in collection-
status is now invalid - This will close bugs: #1730451, #896728, #1526557,
#1550176 - Starting a full backup will be needed to fully utilize this fix *
Fix update of Launchpad Translations. Translations were not being picked up on
a daily basis and we got several months behind.
--------------------------------------------------------------------------------
================================================================================
golang-bazil-fuse-0-0.2.20160811git371fbbd.el7 (FEDORA-EPEL-2018-9c6158fb98)
Go library for writing FUSE userspace filesystems
--------------------------------------------------------------------------------
Update Information:
Branch for epel7
--------------------------------------------------------------------------------
================================================================================
golang-github-VividCortex-ewma-1.1.1-3.el7 (FEDORA-EPEL-2018-4a246994bd)
Exponentially Weighted Moving Average algorithms for Go
--------------------------------------------------------------------------------
Update Information:
Branch for epel7
--------------------------------------------------------------------------------
================================================================================
golang-github-billziss-gh-cgofuse-1.0.4-2.el7 (FEDORA-EPEL-2018-8138a3ce44)
Cross-platform FUSE library for Go
--------------------------------------------------------------------------------
Update Information:
Branch for epel7
--------------------------------------------------------------------------------
================================================================================
golang-github-jlaffaye-ftp-0-0.2.20170927git299b7ff.el7 (FEDORA-EPEL-2018-01d570764f)
A FTP client package for Go
--------------------------------------------------------------------------------
Update Information:
Branch for epel7
--------------------------------------------------------------------------------
================================================================================
golang-github-rfjakob-eme-1.1-2.el7 (FEDORA-EPEL-2018-fe2eb27228)
Encrypt-Mix-Encrypt for Go
--------------------------------------------------------------------------------
Update Information:
Branch for epel7
--------------------------------------------------------------------------------
================================================================================
golang-github-skratchdot-open-golang-0-0.11.gitba570a1.el7 (FEDORA-EPEL-2018-ffb901cd33)
Open a file, directory, or URI using the OS's default application
--------------------------------------------------------------------------------
Update Information:
Branch for epel7
--------------------------------------------------------------------------------
================================================================================
lighttpd-1.4.48-2.el7 (FEDORA-EPEL-2018-c5863bfbf2)
Lightning fast webserver with light system requirements
--------------------------------------------------------------------------------
Update Information:
Require psmisc
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1546558 - None
https://bugzilla.redhat.com/show_bug.cgi?id=1546558
--------------------------------------------------------------------------------
================================================================================
nx-libs-3.5.0.33-4.el7 (FEDORA-EPEL-2018-db21e861fe)
NX X11 protocol compression libraries
--------------------------------------------------------------------------------
Update Information:
nx-libs 3.5.0.33: - Don't allow overriding of X.Org Server UNIX sockets via
TEMP/NX_TEMP environment variables. Fixes problems on machines that use
pam_tempdir.so. - Fix CVE-2017-2624 (timingsafe_memcmp) by Ulrich Sibiller. -
Potentially improve LAN- and WAN-type connection speed settings scenarios.
Includes a regression fix for VPN connections by Simon Matter. - Fix problems
in mate-color-picker and potentially also other applications that make heavy use
of RENDER trapezoids. x2goserver 4.0.1.22: - Fixed overzealous nxagent
socket removal. - Keyboard mapping fixes, including preparation for usage
with Arctica's nx-libs version (not supported in this version of X2Go Server,
yet). - Support for Devuan and RT OS full desktop session spawning. -
Always use short host name, don't rely on ${HOSTNAME} variable. Compatibility
with non-bash login shells. - Spawn full desktop sessions with a new dbus
user session instance. - Finnish translation update. - Added support for
LXQt full desktop sessions. - New command: x2golistshadowsessions.
--------------------------------------------------------------------------------
================================================================================
python-recaptcha-client-2.0.0-1.el7 (FEDORA-EPEL-2018-0f85ce1c1c)
Python module for reCAPTCHA and reCAPTCHA Mailhide
--------------------------------------------------------------------------------
Update Information:
1. add 'version=2' against displayhtml, load_scripts functions to make use of
reCAPTCHA v2 2. introduce the v2submit (along with submit to keep backwards
compatibility) function to support reCAPTCHA v2 3. upstream has been forked
into a new Github project
--------------------------------------------------------------------------------
================================================================================
rpkg-1.52-1.el7 (FEDORA-EPEL-2018-dd3af49e94)
Python library for interacting with rpm+git
--------------------------------------------------------------------------------
Update Information:
- Mock ThreadPool in test_module_overview (cqi) - Drop rpmfluff in test (cqi) -
Fix hardcoded directory name in test (lsedlar) - Improve testenv for py26 (cqi)
- Run tests with old GitPython in py26 testenv (cqi) - Compile pycurl with
openssl after F27 (cqi) - Ignore .egg/ from git (cqi) - Add py26 to testenv
(cqi) - Install koji from PyPI (cqi) - Make compose-id and repo-url to take one
or more values (csomh) - Let git ignore more directories (cqi) - Exclude pyc and
__pycache__ globally in sdist (cqi) - Handle nonexisting mbs-manager (cqi) - Add
dependent packages for Python 2.6 in setup.py (cqi) - Updated module cli API
(mcurlej) - Declare Python versions rpkg can work with - #278 (cqi) - Fix flake8
errors (cqi) - Fix tests that do not work with Python 3 (cqi) - Fix tests: not
impact by dict.items call (cqi) - Add py36 to testenv - #274 (cqi) - Run tox to
run tests and check code styles - #276 (cqi) - Use flake8 3.5.0 (cqi) - Add
files under requirements/ to sdist package (cqi) - Install Koji shared library
via setuptools (cqi) - Set install and tests requires in setup.py (cqi) - Split
pypi requirements and refine versions (cqi) - Change type of compose id from
string to int (bfontecc) - Install RPM Python binding from PyPI (cqi) - Fix test
test_lint_each_file_once (cqi) - Add compose-id and signing-intent arguments
(bfontecc) - Use env's python (lucarval) - Use progress callback and TaskWatcher
from koji_cli.lib (cqi) - Get buildhash from git+https:// url (lsedlar) - lint:
Avoid checking rpm's multiple times (tmz) - Fix giturl as well by calling
construct_build_url (cqi) - Fix construct anongiturl for chain-build (cqi) - Fix
mock openidc_client (cqi)
--------------------------------------------------------------------------------
================================================================================
ucarp-1.5.2-22.el7 (FEDORA-EPEL-2018-0bcb095e36)
Common Address Redundancy Protocol (CARP) for Unix
--------------------------------------------------------------------------------
Update Information:
Update config to use PASSFILE rather than PASSWORD
--------------------------------------------------------------------------------
================================================================================
x2goserver-4.0.1.22-2.el7 (FEDORA-EPEL-2018-db21e861fe)
X2Go Server
--------------------------------------------------------------------------------
Update Information:
nx-libs 3.5.0.33: - Don't allow overriding of X.Org Server UNIX sockets via
TEMP/NX_TEMP environment variables. Fixes problems on machines that use
pam_tempdir.so. - Fix CVE-2017-2624 (timingsafe_memcmp) by Ulrich Sibiller. -
Potentially improve LAN- and WAN-type connection speed settings scenarios.
Includes a regression fix for VPN connections by Simon Matter. - Fix problems
in mate-color-picker and potentially also other applications that make heavy use
of RENDER trapezoids. x2goserver 4.0.1.22: - Fixed overzealous nxagent
socket removal. - Keyboard mapping fixes, including preparation for usage
with Arctica's nx-libs version (not supported in this version of X2Go Server,
yet). - Support for Devuan and RT OS full desktop session spawning. -
Always use short host name, don't rely on ${HOSTNAME} variable. Compatibility
with non-bash login shells. - Spawn full desktop sessions with a new dbus
user session instance. - Finnish translation update. - Added support for
LXQt full desktop sessions. - New command: x2golistshadowsessions.
--------------------------------------------------------------------------------
================================================================================
youtube-dl-2018.02.26-1.el7 (FEDORA-EPEL-2018-67a8da31d7)
A small command-line program to download online videos
--------------------------------------------------------------------------------
Update Information:
Update to the latest upstream release.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1544291 - youtube-dl-2018.02.26 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1544291
--------------------------------------------------------------------------------