The following Fedora EPEL 7 Security updates need testing:
Age URL
19
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-1f259a45ef
openjpeg2-2.3.1-11.el7
19
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-9eaea6f65c
audacious-plugins-4.0.5-4.el7 fluidsynth-2.1.8-4.el7
13
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-8c50b78c57
nginx-1.20.1-2.el7
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-c4678a5e4b
radare2-5.3.1-1.el7
2
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-49226a1ff0
aom-3.1.1-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
dmlite-1.15.0-2.el7
golang-github-prometheus-2.24.1-5.el7
lua-readline-3.0-1.el7
python-blessed-1.18.1-1.el7
remmina-1.4.18-1.el7
singularity-3.8.0-1.el7
tini-0.19.0-2.el7
unrealircd-5.2.0-1.el7
Details about builds:
================================================================================
dmlite-1.15.0-2.el7 (FEDORA-EPEL-2021-b01fdaaee5)
Lcgdm grid data management and storage framework
--------------------------------------------------------------------------------
Update Information:
Add fix for puppet TokenId configuration
--------------------------------------------------------------------------------
ChangeLog:
* Mon Jun 14 2021 Petr Vokac <petr.vokac(a)cern.ch> - 1.15.0-1
- New release with few additional bugfixes LCGDM-2975, LCGDM-2974
* Fri Jun 4 2021 Python Maint <python-maint(a)redhat.com> - 1.14.2-8
- Rebuilt for Python 3.10
* Sun Mar 28 2021 Petr Vokac <petr.vokac(a)cern.ch> - 1.14.2-7
- Cleanup and CentOS8 support
* Sat Mar 27 2021 Petr Vokac <petr.vokac(a)cern.ch> - 1.14.2-6
- Bugfixes: LCGDM-2958, LCGDM-2961, LCGDM-2963, LCGDM-2964, OOB reads
- Improvements: LCGDM-2943, LCGDM-2959, LCGDM-2962, LCGDM-2967, davs speed
* Tue Jan 26 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.14.2-5
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Fri Jan 22 2021 Jonathan Wakely <jwakely(a)redhat.com> - 1.14.2-4
- Rebuilt for Boost 1.75
* Thu Jan 14 2021 Adrian Reber <adrian(a)lisas.de> - 1.14.2-3
- Rebuilt for protobuf 3.14
* Tue Dec 29 2020 Petr Vokac <petr.vokac(a)cern.ch> - 1.14.2-2
- Bugfixes: LCGDM-2948, LCGDM-2949, LCGDM-2950, LCGDM-2954, LCGDM-2953, LCGDM-2955,
LCGDM-2957
--------------------------------------------------------------------------------
================================================================================
golang-github-prometheus-2.24.1-5.el7 (FEDORA-EPEL-2021-6b829490aa)
Prometheus monitoring system and time series database
--------------------------------------------------------------------------------
Update Information:
Add systemd-sysusers as Requires
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jun 15 2021 Robert-Andr�� Mauchin <zebob.m(a)gmail.com> - 2.24.1-5
- Add systemd-sysusers as Requires
- Fix: rhbz#1972026
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1972026 - does not depend on `Requires(pre): /usr/bin/systemctl`
https://bugzilla.redhat.com/show_bug.cgi?id=1972026
--------------------------------------------------------------------------------
================================================================================
lua-readline-3.0-1.el7 (FEDORA-EPEL-2021-1b91460525)
Lua interface to the readline and history libraries
--------------------------------------------------------------------------------
Update Information:
- Update to 3.0 (#1950886)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Jun 16 2021 Robert Scheck <robert(a)fedoraproject.org> - 3.0-1
- Update to 3.0 (#1950886)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1950886 - lua-readline-3.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1950886
--------------------------------------------------------------------------------
================================================================================
python-blessed-1.18.1-1.el7 (FEDORA-EPEL-2021-08717cc686)
A thin, practical wrapper around terminal capabilities in Python
--------------------------------------------------------------------------------
Update Information:
Update to 1.18.1 (#1932716)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jun 15 2021 Fedora Release Monitoring <aviso(a)rockhopper.net> - 1.18.1-1
- Update to 1.18.1 (#1932716)
* Fri Jun 4 2021 Python Maint <python-maint(a)redhat.com> - 1.17.12-3
- Rebuilt for Python 3.10
* Wed Jan 27 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.17.12-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Sun Jan 17 2021 Avram Lubkin <aviso(a)rockhopper.net> - 1.17.12-1
- Updated to 1.17.12
--------------------------------------------------------------------------------
================================================================================
remmina-1.4.18-1.el7 (FEDORA-EPEL-2021-facbfe0168)
Remote Desktop Client
--------------------------------------------------------------------------------
Update Information:
Update to bugfix release 1.4.18.
--------------------------------------------------------------------------------
ChangeLog:
* Sat Jun 5 2021 Simone Caronni <negativo17(a)gmail.com> - 1.4.18-1
- Update to 1.4.18.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1967654 - remmina-1.4.18 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1967654
--------------------------------------------------------------------------------
================================================================================
singularity-3.8.0-1.el7 (FEDORA-EPEL-2021-e3bc70af07)
Application and environment virtualization
--------------------------------------------------------------------------------
Update Information:
Upgrade to upstream 3.8.0
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jun 15 2021 Dave Dykstra <dwd(a)fedoraproject.org> - 3.8.0-1
- Upgrade to upstream 3.8.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1963667 - singularity-3.8.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1963667
--------------------------------------------------------------------------------
================================================================================
tini-0.19.0-2.el7 (FEDORA-EPEL-2021-b253df10a9)
A tiny but valid init for containers
--------------------------------------------------------------------------------
Update Information:
Initial package
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1971386 - Review Request: tini - A tiny but valid init for containers
https://bugzilla.redhat.com/show_bug.cgi?id=1971386
--------------------------------------------------------------------------------
================================================================================
unrealircd-5.2.0-1.el7 (FEDORA-EPEL-2021-15e2fbe1e4)
Open Source IRC server
--------------------------------------------------------------------------------
Update Information:
UnrealIRCd 5.2.0 ================ This is UnrealIRCd 5.2.0, a release with lots
of new features. The two main new features are: an improved and more flexible
anti-flood block and channel history which can now be stored encrypted on disk
and allows clients to fetch hundreds/thousands of lines. Notice from upstream:
UnrealIRCd 5.2.0 is the direct successor to 5.0.9/5.0.9.1. There will be no
further 5.0.x releases, in particular there will be no 5.0.10. The only
configuration change is in the `set::anti-flood` block (as explained further
down under "Enhancements"). When starting UnrealIRCd will give clear
instructions if anything needs to be changed (and what). This process is really
minor, the server will usually tell to just delete a few old lines from the
configuration file. Enhancements ------------ * The `set::anti-flood` block
has been redone so you can have different limits for `unknown-users` and `known-
users`. * As a reminder, by default, `known-users` are users who are
identified to services OR are on an IP that has been connected for over 2 hours
in the past X days. The exact definition of "known-users" is in the security-
group block. * See
https://www.unrealircd.org/docs/Anti-flood_settings for
more information on the layout of the new set::anti-flood block. * All
violations of `target-flood`, `nick-flood`, `join-flood`, `away-flood`, `invite-
flood`, `knock-flood`, `max-concurrent-conversations` are now reported to opers
with the snomask `f` (flood). * Add support for database encryption. The way
this works is that you define an encryption password in a `secret { }` block.
Then from the various modules you can refer to this secret block, from
`set::reputation::db-secret`, `set::tkldb::db-secret` and `set::channeldb::db-
secret`. This way you can encrypt the reputation, TKL and channel database for
increased privacy. * Add optional support for persistent channel history:
* This stores channel history on disk for channels that have both `+H` and `+P`
set. * If you enable this then we ALWAYS require you to set an encryption
password, as we do not allow storing of channel history in plain text. * If
you enable the option, then the history is stored in `data/history/` in
individual .db files. No channel names are visible in the filenames for optimal
privacy. * See
https://www.unrealircd.org/docs/Set_block#Persistent_channel_history on how to
enable this. By default it is off. * Add support for IRCv3 draft/chathistory:
https://ircv3.net/specs/extensions/chathistory * The maximums for channel mode
`+H` have been raised and are now different for `+r` (registered) and `-r`
channels. For unregistered channels the limit is now 200 lines / 31 days. For
registered channels the limit is 5000 lines / 31 days. The old limit for both
was 200 lines / 7 days. These maximums can be changed in the now slightly
different `set::history::channel::max-storage-per-channel` block. * Add c-ares
and libsodium version output to boot screen and `/VERSION`. * `WHOX` now
supports displaying the reputation score. If you are an IRCOp then you can use
e.g. `WHO * %cuhsnfmdaRr`. * Add ability to spamfilter message tags via the
new `T` target. Right now it would be unusual to use this, but some day when we
have more message tags it may come in handy. * Support `+draft/reply` IRCv3
client tag. Can be used by bots (and others) to indicate to what message people
are replying to. This module, reply-tag, is loaded by default. * Send
`draft/bot` IRCv3 message tag if the user has mode `+B` set. * Websockets: add
support for clients to negotiate an explicit type via `Sec-WebSocket-Protocol`,
instead of only the default type from `listen::websocket::type`. This is based
on an IRCv3 websocket draft specification. Note that UnrealIRCd refuses type
text if your configuration allows non-UTF8 characters in channel or nick names
because it would lead to security and compatibility issues. * `set::restrict-
commands`: new option `exempt-tls` which allows SSL/TLS users to bypass a
restriction. Fixes ----- * Server squiting the wrong side. Often harmless,
but when (re)connecting rapidly to multiple servers with autoconnect this could
cause the network to fall apart. * Forbid using extended server bans in
`ZLINE`/`GZLINE` since they won't work there. * Extended server ban
`~a:accname` was not working for shun, and only partially working for
`KLINE`/`GLINE`. * More accurate `/ELINE` error message. Changed ------- *
Channel mode `+H` always showed time in minutes (`m`) until now. From now on it
will show it in minutes (`m`), hours (`h`) or days (`d`) depending on the actual
value. E.g. `+H 50:7d`. * If you have zero log blocks then we already
automatically logged errors to `ircd.log`. From now on we will log everything
(not only errors) to that file.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Jun 15 2021 Robert Scheck <robert(a)fedoraproject.org> 5.2.0-1
- Upgrade to 5.2.0 (#1967860)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1967860 - unrealircd-5.2.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1967860
--------------------------------------------------------------------------------