The following Fedora EPEL 7 Security updates need testing:
Age URL
1081
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087
dokuwiki-0-0.24.20140929c.el7
843
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f
mcollective-2.8.4-1.el7
426
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d
libbsd-0.8.3-1.el7
323
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe
mod_cluster-1.3.3-10.el7
155
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23
libmspack-0.6-0.1.alpha.el7
92
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e64eeb6ece
nagios-4.3.4-5.el7
42
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-73ee944e65
rootsh-1.5.3-17.el7
16
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-7134fc92a1
jhead-3.00-7.el7
15
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-069884a87f
p7zip-16.02-10.el7
5
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-72e5d3ef89
suricata-4.0.4-1.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-276ec6ee2b
exim-4.90.1-2.el7
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-e50c94a832
seamonkey-2.49.2-2.el7
2
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-525417d3d4
mbedtls-2.7.0-1.el7
2
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-cee77fc9b3
knot-resolver-2.1.0-1.el7
1
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-b7a74678b1
openjpeg2-2.3.0-6.el7
0
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-50566f0a39
uwsgi-2.0.16-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
GMT-5.4.3-1.el7
argparse-manpage-1.0.0-1.el7
cargo-0.25.0-1.el7
fldigi-4.0.16-1.el7.1
freedv-1.2.2-1.el7.1
getdns-1.4.0-1.el7
hamlib-3.1-11.el7
ima-evm-utils-1.1-1.el7
llvm5.0-5.0.1-5.el7
lynis-2.6.1-1.el7
mingw-wavpack-5.1.0-4.el7
nova-agent-2.1.12-1.el7
perl-HTTP-Lite-2.44-12.el7
python-certbot-dns-cloudflare-0.21.1-1.el7
python-certbot-dns-cloudxns-0.21.1-1.el7
python-certbot-dns-luadns-0.21.1-1.el7
qsstv-9.2.6-1.el7.1
rust-1.24.0-2.el7
Details about builds:
================================================================================
GMT-5.4.3-1.el7 (FEDORA-EPEL-2018-0c8e266959)
Generic Mapping Tools
--------------------------------------------------------------------------------
Update Information:
- Update to 5.4.3 - Fix GSHHG_ROOT (bug #1545256)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1545256 - gmt cannot find gshhg files
https://bugzilla.redhat.com/show_bug.cgi?id=1545256
[ 2 ] Bug #1449426 - GMT-5.4.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1449426
--------------------------------------------------------------------------------
================================================================================
argparse-manpage-1.0.0-1.el7 (FEDORA-EPEL-2018-d274033e1d)
Build manual page from Python ArgumentParser object
--------------------------------------------------------------------------------
Update Information:
build man page from python ArgParse object
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1546801 - Review Request: argparse-manpage - Build manual page from Python
ArgumentParser object
https://bugzilla.redhat.com/show_bug.cgi?id=1546801
--------------------------------------------------------------------------------
================================================================================
cargo-0.25.0-1.el7 (FEDORA-EPEL-2018-592dd11f3d)
Rust's package manager and build tool
--------------------------------------------------------------------------------
Update Information:
New versions of Rust and Cargo -- see the release notes for [1.24](https://blog
.rust-lang.org/2018/02/15/Rust-1.24.html).
--------------------------------------------------------------------------------
================================================================================
fldigi-4.0.16-1.el7.1 (FEDORA-EPEL-2018-cf02b4f677)
Digital modem program for Linux
--------------------------------------------------------------------------------
Update Information:
Updating hamlib to 3.1 as it is required for wsjtx. ---- * Changed the .pro
file for autodetecing correct libopenjpg2 (DL1JBE -Tom) * ftp transfer -
initialize bug fix (VK6MN- Mike) * Help manual -> path correction and corrected
some typo's (DJ0MBA- Marinus) * SSTV initialize bug fix (Adrian) * Camera
support for Raspberry PI Cam * fixed audio loopback use * fixed transmission
after stop, image was not restarted at top ---- Version 4.0.16 - Maintenance
release wo seg fault * fix seg fault in waterfall only mode 8psk
lockup problem * correct lockup associated with S/N and IMD disply when
using 8psk mode. Code change fixes problem reported by K0OG. I was not
able to replicate the lockup on test machines. Miscellaneous menu *
provide access to various miscellaneous config tabs pskrep autostart *
allow user to control pskrep start during program initialization OS X build
script * Modified to only build dmg with dylibs Grid Square Contest *
Add Grid Square to generic contest log fields Logbook Export * Add LoTW
sent/rcvd to export values * Create unverified.txt flat file when LoTW
download contains unmatched records - notifier dialog shows #
records # matched # unmatched Greek translation update *
update to el.po Alert timeouts * FSQ change message received alert from
fl_alert2 to notify(...) - notify dialog is not modal - can be set
to a timeout interval - displays timeout sequencing as clock dial -
does not inhibit decoding or UI with main dialog. * LoTW changed - fl_alert2
to notify_dialog * Logbook merger - changed fl_alert2 to notify_dialog
video * Correct lock up caused by waterfall video stream
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1428966 - "Repeater" config Dialog has no function
https://bugzilla.redhat.com/show_bug.cgi?id=1428966
[ 2 ] Bug #1514286 - qsstv-9.2.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1514286
[ 3 ] Bug #1536703 - fldigi-4.0.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1536703
--------------------------------------------------------------------------------
================================================================================
freedv-1.2.2-1.el7.1 (FEDORA-EPEL-2018-cf02b4f677)
FreeDV Digital Voice
--------------------------------------------------------------------------------
Update Information:
Updating hamlib to 3.1 as it is required for wsjtx. ---- * Changed the .pro
file for autodetecing correct libopenjpg2 (DL1JBE -Tom) * ftp transfer -
initialize bug fix (VK6MN- Mike) * Help manual -> path correction and corrected
some typo's (DJ0MBA- Marinus) * SSTV initialize bug fix (Adrian) * Camera
support for Raspberry PI Cam * fixed audio loopback use * fixed transmission
after stop, image was not restarted at top ---- Version 4.0.16 - Maintenance
release wo seg fault * fix seg fault in waterfall only mode 8psk
lockup problem * correct lockup associated with S/N and IMD disply when
using 8psk mode. Code change fixes problem reported by K0OG. I was not
able to replicate the lockup on test machines. Miscellaneous menu *
provide access to various miscellaneous config tabs pskrep autostart *
allow user to control pskrep start during program initialization OS X build
script * Modified to only build dmg with dylibs Grid Square Contest *
Add Grid Square to generic contest log fields Logbook Export * Add LoTW
sent/rcvd to export values * Create unverified.txt flat file when LoTW
download contains unmatched records - notifier dialog shows #
records # matched # unmatched Greek translation update *
update to el.po Alert timeouts * FSQ change message received alert from
fl_alert2 to notify(...) - notify dialog is not modal - can be set
to a timeout interval - displays timeout sequencing as clock dial -
does not inhibit decoding or UI with main dialog. * LoTW changed - fl_alert2
to notify_dialog * Logbook merger - changed fl_alert2 to notify_dialog
video * Correct lock up caused by waterfall video stream
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1428966 - "Repeater" config Dialog has no function
https://bugzilla.redhat.com/show_bug.cgi?id=1428966
[ 2 ] Bug #1514286 - qsstv-9.2.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1514286
[ 3 ] Bug #1536703 - fldigi-4.0.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1536703
--------------------------------------------------------------------------------
================================================================================
getdns-1.4.0-1.el7 (FEDORA-EPEL-2018-92eec623b7)
Modern asynchronous API to the DNS
--------------------------------------------------------------------------------
Update Information:
Updated to 1.4.0 (which includes previous patch)
--------------------------------------------------------------------------------
================================================================================
hamlib-3.1-11.el7 (FEDORA-EPEL-2018-cf02b4f677)
Run-time library to control radio transceivers and receivers
--------------------------------------------------------------------------------
Update Information:
Updating hamlib to 3.1 as it is required for wsjtx. ---- * Changed the .pro
file for autodetecing correct libopenjpg2 (DL1JBE -Tom) * ftp transfer -
initialize bug fix (VK6MN- Mike) * Help manual -> path correction and corrected
some typo's (DJ0MBA- Marinus) * SSTV initialize bug fix (Adrian) * Camera
support for Raspberry PI Cam * fixed audio loopback use * fixed transmission
after stop, image was not restarted at top ---- Version 4.0.16 - Maintenance
release wo seg fault * fix seg fault in waterfall only mode 8psk
lockup problem * correct lockup associated with S/N and IMD disply when
using 8psk mode. Code change fixes problem reported by K0OG. I was not
able to replicate the lockup on test machines. Miscellaneous menu *
provide access to various miscellaneous config tabs pskrep autostart *
allow user to control pskrep start during program initialization OS X build
script * Modified to only build dmg with dylibs Grid Square Contest *
Add Grid Square to generic contest log fields Logbook Export * Add LoTW
sent/rcvd to export values * Create unverified.txt flat file when LoTW
download contains unmatched records - notifier dialog shows #
records # matched # unmatched Greek translation update *
update to el.po Alert timeouts * FSQ change message received alert from
fl_alert2 to notify(...) - notify dialog is not modal - can be set
to a timeout interval - displays timeout sequencing as clock dial -
does not inhibit decoding or UI with main dialog. * LoTW changed - fl_alert2
to notify_dialog * Logbook merger - changed fl_alert2 to notify_dialog
video * Correct lock up caused by waterfall video stream
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1428966 - "Repeater" config Dialog has no function
https://bugzilla.redhat.com/show_bug.cgi?id=1428966
[ 2 ] Bug #1514286 - qsstv-9.2.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1514286
[ 3 ] Bug #1536703 - fldigi-4.0.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1536703
--------------------------------------------------------------------------------
================================================================================
ima-evm-utils-1.1-1.el7 (FEDORA-EPEL-2018-6e526ba359)
IMA/EVM support utilities
--------------------------------------------------------------------------------
Update Information:
New upstream release
--------------------------------------------------------------------------------
================================================================================
llvm5.0-5.0.1-5.el7 (FEDORA-EPEL-2018-592dd11f3d)
The Low Level Virtual Machine
--------------------------------------------------------------------------------
Update Information:
New versions of Rust and Cargo -- see the release notes for [1.24](https://blog
.rust-lang.org/2018/02/15/Rust-1.24.html).
--------------------------------------------------------------------------------
================================================================================
lynis-2.6.1-1.el7 (FEDORA-EPEL-2018-2fabdd3a4a)
Security and system auditing tool
--------------------------------------------------------------------------------
Update Information:
Update to 2.6.1 (rhbz #1539272)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1539272 - lynis-2.6.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1539272
--------------------------------------------------------------------------------
================================================================================
mingw-wavpack-5.1.0-4.el7 (FEDORA-EPEL-2018-0296296d7c)
Completely open audiocodec
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2018-6767, CVE-2018-7253, and CVE-2018-7254
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1547735 - CVE-2018-7254 wavpack: Heap-based buffer over-read in
ParseCaffHeaderConfig function in cli/caff.c
https://bugzilla.redhat.com/show_bug.cgi?id=1547735
[ 2 ] Bug #1547719 - CVE-2018-7253 wavpack: Heap-based buffer over-read in
ParseDsdiffHeaderConfig function in cli/dsdiff.c
https://bugzilla.redhat.com/show_bug.cgi?id=1547719
[ 3 ] Bug #1542550 - CVE-2018-6767 wavpack: stack buffer overread via crafted wav file
https://bugzilla.redhat.com/show_bug.cgi?id=1542550
--------------------------------------------------------------------------------
================================================================================
nova-agent-2.1.12-1.el7 (FEDORA-EPEL-2018-ce9f5c5759)
Agent for setting up clean servers on Xen
--------------------------------------------------------------------------------
Update Information:
- Latest upstream
--------------------------------------------------------------------------------
================================================================================
perl-HTTP-Lite-2.44-12.el7 (FEDORA-EPEL-2018-2b6a247182)
Lightweight HTTP implementation
--------------------------------------------------------------------------------
Update Information:
This update allows EPEL7 to install the perl module HTTP::Lite.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1546268 - Please provide a package for EPEL7
https://bugzilla.redhat.com/show_bug.cgi?id=1546268
--------------------------------------------------------------------------------
================================================================================
python-certbot-dns-cloudflare-0.21.1-1.el7 (FEDORA-EPEL-2018-e936db8d39)
Cloudflare DNS Authenticator plugin for Certbot
--------------------------------------------------------------------------------
Update Information:
Initial build
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1547617 - Review Request: python-certbot-dns-cloudflare - Cloudflare DNS
Authenticator plugin for Certbot
https://bugzilla.redhat.com/show_bug.cgi?id=1547617
--------------------------------------------------------------------------------
================================================================================
python-certbot-dns-cloudxns-0.21.1-1.el7 (FEDORA-EPEL-2018-8485d945fc)
CloudXNS DNS Authenticator plugin for Certbot
--------------------------------------------------------------------------------
Update Information:
Initial build
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1547611 - Review Request: python-certbot-dns-cloudxns - CloudXNS DNS
Authenticator plugin for Certbot
https://bugzilla.redhat.com/show_bug.cgi?id=1547611
--------------------------------------------------------------------------------
================================================================================
python-certbot-dns-luadns-0.21.1-1.el7 (FEDORA-EPEL-2018-7c4aa35266)
LuaDNS Authenticator plugin for Certbot
--------------------------------------------------------------------------------
Update Information:
Initial build
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1547601 - Review Request: python-certbot-dns-luadns - LuaDNS Authenticator
plugin for Certbot
https://bugzilla.redhat.com/show_bug.cgi?id=1547601
--------------------------------------------------------------------------------
================================================================================
qsstv-9.2.6-1.el7.1 (FEDORA-EPEL-2018-cf02b4f677)
Qt-based slow-scan TV and fax
--------------------------------------------------------------------------------
Update Information:
Updating hamlib to 3.1 as it is required for wsjtx. ---- * Changed the .pro
file for autodetecing correct libopenjpg2 (DL1JBE -Tom) * ftp transfer -
initialize bug fix (VK6MN- Mike) * Help manual -> path correction and corrected
some typo's (DJ0MBA- Marinus) * SSTV initialize bug fix (Adrian) * Camera
support for Raspberry PI Cam * fixed audio loopback use * fixed transmission
after stop, image was not restarted at top ---- Version 4.0.16 - Maintenance
release wo seg fault * fix seg fault in waterfall only mode 8psk
lockup problem * correct lockup associated with S/N and IMD disply when
using 8psk mode. Code change fixes problem reported by K0OG. I was not
able to replicate the lockup on test machines. Miscellaneous menu *
provide access to various miscellaneous config tabs pskrep autostart *
allow user to control pskrep start during program initialization OS X build
script * Modified to only build dmg with dylibs Grid Square Contest *
Add Grid Square to generic contest log fields Logbook Export * Add LoTW
sent/rcvd to export values * Create unverified.txt flat file when LoTW
download contains unmatched records - notifier dialog shows #
records # matched # unmatched Greek translation update *
update to el.po Alert timeouts * FSQ change message received alert from
fl_alert2 to notify(...) - notify dialog is not modal - can be set
to a timeout interval - displays timeout sequencing as clock dial -
does not inhibit decoding or UI with main dialog. * LoTW changed - fl_alert2
to notify_dialog * Logbook merger - changed fl_alert2 to notify_dialog
video * Correct lock up caused by waterfall video stream
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1428966 - "Repeater" config Dialog has no function
https://bugzilla.redhat.com/show_bug.cgi?id=1428966
[ 2 ] Bug #1514286 - qsstv-9.2.6 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1514286
[ 3 ] Bug #1536703 - fldigi-4.0.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1536703
--------------------------------------------------------------------------------
================================================================================
rust-1.24.0-2.el7 (FEDORA-EPEL-2018-592dd11f3d)
The Rust Programming Language
--------------------------------------------------------------------------------
Update Information:
New versions of Rust and Cargo -- see the release notes for [1.24](https://blog
.rust-lang.org/2018/02/15/Rust-1.24.html).
--------------------------------------------------------------------------------