The following Fedora EPEL 7 Security updates need testing: Age URL 587 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d condor-8.6.11-1.el7 329 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-c499781e80 python-gnupg-0.4.4-1.el7 327 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-bc0182548b bubblewrap-0.3.3-2.el7 36 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-fa8a2e97c6 python-waitress-1.4.3-1.el7 7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-7e106e25f9 timeshift-20.03-1.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-42d19f5f91 chromium-80.0.3987.149-1.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-33500a2742 tor-0.3.5.10-1.el7 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-7c64d8ca18 ckeditor-4.14.0-1.el7 2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-c513b3c1ca seamonkey-2.53.1-3.el7 2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-61faf4c2ff libmodsecurity-3.0.2-6.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
coturn-4.5.1.1-3.el7 php-phpseclib-2.0.26-1.el7 python-stomper-0.4.3-4.el7 wireguard-tools-1.0.20200319-1.el7 xrdcl-http-4.11.3-1.el7 xrootd-4.11.3-1.el7 zork-1.0.2-3.el7
Details about builds:
================================================================================ coturn-4.5.1.1-3.el7 (FEDORA-EPEL-2020-7bc15e9271) TURN/STUN & ICE Server -------------------------------------------------------------------------------- Update Information:
* An exploitable heap overflow vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. * An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Robert Scheck robert@fedoraproject.org - 4.5.1.1-3 - Added upstream patch for CVE-2020-6061 (#1816159) - Backported upstream patch for CVE-2020-6062 (#1816163) * Tue Jan 28 2020 Fedora Release Engineering releng@fedoraproject.org - 4.5.1.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1816159 - CVE-2020-6061 coturn: specially crafted HTTP POST request can lead to heap overflow which can result in information leak https://bugzilla.redhat.com/show_bug.cgi?id=1816159 --------------------------------------------------------------------------------
================================================================================ php-phpseclib-2.0.26-1.el7 (FEDORA-EPEL-2020-1dd81ecd2c) PHP Secure Communications Library -------------------------------------------------------------------------------- Update Information:
**Version 2.0.26** * SFTP: another attempt at speeding up uploads (#1455) * SSH2: try logging in with none as an auth method first (#1454) * ASN1: fix for malformed ASN1 strings (#1456) -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Remi Collet remi@remirepo.net - 2.0.26-1 - update to 2.0.26 --------------------------------------------------------------------------------
================================================================================ python-stomper-0.4.3-4.el7 (FEDORA-EPEL-2020-39121af5ae) A python client implementation of the STOMP protocol -------------------------------------------------------------------------------- Update Information:
Update to 0.4.3 This obsoletes the update to 0.4.1 in EPEL 7 from a year ago: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-b550475da5 -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 mprahl <mprahl@redhat.com< - 0.4.3-3 - Update to 0.4.3 in EPEL 7 * Fri Aug 2 2019 mprahl mprahl@redhat.com - 0.4.3-3 - Stop building Python 2 packages for F31+ * Fri Jul 26 2019 Fedora Release Engineering releng@fedoraproject.org - 0.4.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Jun 29 2019 Kevin Fenzi kevin@scrye.com - 0.4.3-1 - Update to 0.4.3. Fixes bug #1697989 * Sat Feb 2 2019 Fedora Release Engineering releng@fedoraproject.org - 0.4.1-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Wed Jan 2 2019 Igor Gnatenko ignatenkobrain@fedoraproject.org - 0.4.1-9 - Enable python dependency generator * Tue Dec 18 2018 Ralph Bean rbean@redhat.com - 0.4.1-8 - Complete py3 conditionals in preparation for a epel7 update. * Sat Jul 14 2018 Fedora Release Engineering releng@fedoraproject.org - 0.4.1-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Sun Jun 17 2018 Miro Hron��ok mhroncok@redhat.com - 0.4.1-6 - Rebuilt for Python 3.7 * Fri Feb 9 2018 Fedora Release Engineering releng@fedoraproject.org - 0.4.1-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Jul 27 2017 Fedora Release Engineering releng@fedoraproject.org - 0.4.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Sat Feb 11 2017 Fedora Release Engineering releng@fedoraproject.org - 0.4.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Mon Dec 19 2016 Miro Hron��ok mhroncok@redhat.com - 0.4.1-2 - Rebuild for Python 3.6 * Fri Jul 29 2016 Kevin Fenzi kevin@scrye.com - 0.4.1-1 - Update to 0.4.1. Fixes bug #1355749 * Mon Jul 11 2016 Ralph Bean rbean@redhat.com - 0.4.0-2 - Explicit py2 and py3 subpackages. - Patch implicit encoding in setup.py. * Mon Jul 11 2016 Ralph Bean rbean@redhat.com - 0.4.0-1 - new version - New dep on python-future * Thu Feb 4 2016 Fedora Release Engineering releng@fedoraproject.org - 0.3.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Thu Jun 18 2015 Fedora Release Engineering rel-eng@lists.fedoraproject.org - 0.3.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Sat Feb 21 2015 Ralph Bean rbean@redhat.com - 0.3.0-1 - new version -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1659073 - Update python-stomper to 0.4.1 https://bugzilla.redhat.com/show_bug.cgi?id=1659073 --------------------------------------------------------------------------------
================================================================================ wireguard-tools-1.0.20200319-1.el7 (FEDORA-EPEL-2020-52155b2596) Fast, modern, secure VPN tunnel -------------------------------------------------------------------------------- Update Information:
Update to 1.0.20200319 -------------------------------------------------------------------------------- ChangeLog:
* Fri Mar 20 2020 Joe Doss joe@solidadmin.com - 1.0.20200319-1 - Update to 1.0.20200319 --------------------------------------------------------------------------------
================================================================================ xrdcl-http-4.11.3-1.el7 (FEDORA-EPEL-2020-8512d1a387) HTTP client plug-in for XRootD -------------------------------------------------------------------------------- Update Information:
XrootD 4.11.3 -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 21 2020 Mattias Ellert mattias.ellert@physics.uu.se - 4.11.3-1 - Update to version 4.11.3 * Fri Jan 31 2020 Fedora Release Engineering releng@fedoraproject.org - 4.10.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ xrootd-4.11.3-1.el7 (FEDORA-EPEL-2020-8512d1a387) Extended ROOT file server -------------------------------------------------------------------------------- Update Information:
XrootD 4.11.3 -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 21 2020 Mattias Ellert mattias.ellert@physics.uu.se - 1:4.11.3-1 - Update to version 4.11.3 - Use libc semaphores for EPEL 7 build POSIX compliant semaphores were backported to glibc in RHEL 7.2 - Drop glibc version requirement for semaphores (backported to older version) - Move libXrdSsi{Lib,ShMap}.so.* to client-libs package (from server-libs) --------------------------------------------------------------------------------
================================================================================ zork-1.0.2-3.el7 (FEDORA-EPEL-2020-bd24cabef2) Public Domain original DUNGEON game (Zork I) -------------------------------------------------------------------------------- Update Information:
Add zork package -------------------------------------------------------------------------------- ChangeLog:
-------------------------------------------------------------------------------- References:
[ 1 ] Bug #1704522 - Review Request: zork - Public Domain source code to the original DUNGEON game (Zork I) https://bugzilla.redhat.com/show_bug.cgi?id=1704522 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org