The following Fedora EPEL 8 Security updates need testing: Age URL 16 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-02f03affd4 ansible-2.9.6-1.el8 12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-1402a55654 nethack-3.6.6-1.el8 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-0316f810ac python-twisted-19.10.0-2.el8 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-79bd0a6b28 chromium-80.0.3987.149-1.el8 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-f16ad37b5e tor-0.4.2.7-1.el8
The following builds have been pushed to Fedora EPEL 8 updates-testing
coturn-4.5.1.1-3.el8 gnuradio-3.8.0.0-6.el8 okular-18.12.2-2.el8 openfortivpn-1.13.1-1.el8 pg-semver-0.21.0-1.el8 python-ana-0.06-1.el8 python-geopy-1.21.0-1.el8 python-moksha-common-1.2.5-14.el8 python-stomper-0.4.3-6.el8 tmt-0.11-1.el8 wfuzz-2.4.5-3.el8 xrdcl-http-4.11.3-1.el8 xrootd-4.11.3-1.el8 zork-1.0.2-3.el8
Details about builds:
================================================================================ coturn-4.5.1.1-3.el8 (FEDORA-EPEL-2020-913d6d1779) TURN/STUN & ICE Server -------------------------------------------------------------------------------- Update Information:
* An exploitable heap overflow vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. * An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Robert Scheck robert@fedoraproject.org - 4.5.1.1-3 - Added upstream patch for CVE-2020-6061 (#1816159) - Backported upstream patch for CVE-2020-6062 (#1816163) * Tue Jan 28 2020 Fedora Release Engineering releng@fedoraproject.org - 4.5.1.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1816159 - CVE-2020-6061 coturn: specially crafted HTTP POST request can lead to heap overflow which can result in information leak https://bugzilla.redhat.com/show_bug.cgi?id=1816159 --------------------------------------------------------------------------------
================================================================================ gnuradio-3.8.0.0-6.el8 (FEDORA-EPEL-2020-1c2eb314d9) Software defined radio framework -------------------------------------------------------------------------------- Update Information:
This is an update dropping python3-pyopengl dependency on RHEL. -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Jaroslav ��karvada jskarvad@redhat.com - 3.8.0.0-6 - Dropped python3-pyopengl on RHEL Resolves: rhbz#1816179 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1816179 - Missing dependency 'python3-pyopengl' for 'gnuradio-3.8.0.0-5' on CentOS8 https://bugzilla.redhat.com/show_bug.cgi?id=1816179 --------------------------------------------------------------------------------
================================================================================ okular-18.12.2-2.el8 (FEDORA-EPEL-2020-2cb1029c5a) A document viewer -------------------------------------------------------------------------------- Update Information:
Security fix for CVE-2020-9359 -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Than Ngo than@redhat.com - 18.12.2-2 - Fixed bz#1815653, Security fix for CVE-2020-9359 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1815653 - CVE-2020-9359 okular: local binary execution via specially crafted PDF files [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=1815653 --------------------------------------------------------------------------------
================================================================================ openfortivpn-1.13.1-1.el8 (FEDORA-EPEL-2020-b35926f6de) Client for PPP+SSL VPN tunnel services -------------------------------------------------------------------------------- Update Information:
Update to latest upstream version. -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Adrien Verg�� adrienverge@gmail.com - 1.13.1-1 - Update to latest upstream version --------------------------------------------------------------------------------
================================================================================ pg-semver-0.21.0-1.el8 (FEDORA-EPEL-2020-a9838021cf) A semantic version data type for PostgreSQL -------------------------------------------------------------------------------- Update Information:
Update to 0.21.0 -------------------------------------------------------------------------------- ChangeLog:
* Sun Mar 22 2020 Ernestas Kulik ekulik@redhat.com - 0.21.0-1 - Update to 0.21.0 - Change %setup to %setup -q -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1815859 - pg-semver-0.21.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1815859 --------------------------------------------------------------------------------
================================================================================ python-ana-0.06-1.el8 (FEDORA-EPEL-2020-962c5a23a4) Python module to provide easy distributed data storage -------------------------------------------------------------------------------- Update Information:
Initial package for Fedora -------------------------------------------------------------------------------- ChangeLog:
--------------------------------------------------------------------------------
================================================================================ python-geopy-1.21.0-1.el8 (FEDORA-EPEL-2020-e38e0105da) Python client for several popular geocoding web services -------------------------------------------------------------------------------- Update Information:
Update to latest upstream release 1.21.0 -------------------------------------------------------------------------------- ChangeLog:
--------------------------------------------------------------------------------
================================================================================ python-moksha-common-1.2.5-14.el8 (FEDORA-EPEL-2020-48c4b81b16) Common components for Moksha -------------------------------------------------------------------------------- Update Information:
Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild -------------------------------------------------------------------------------- ChangeLog:
-------------------------------------------------------------------------------- References:
[ 1 ] Bug #1815838 - please, provide epel8 update https://bugzilla.redhat.com/show_bug.cgi?id=1815838 --------------------------------------------------------------------------------
================================================================================ python-stomper-0.4.3-6.el8 (FEDORA-EPEL-2020-c97300b1a1) A python client implementation of the STOMP protocol -------------------------------------------------------------------------------- Update Information:
Initial release for EPEL 8 -------------------------------------------------------------------------------- ChangeLog:
-------------------------------------------------------------------------------- References:
[ 1 ] Bug #1815834 - please, provide epel8 update https://bugzilla.redhat.com/show_bug.cgi?id=1815834 --------------------------------------------------------------------------------
================================================================================ tmt-0.11-1.el8 (FEDORA-EPEL-2020-fcf5a8da2e) Test Management Tool -------------------------------------------------------------------------------- Update Information:
Test import/export, podman/testcloud support, environment... -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 23 2020 Petr ��pl��chal psplicha@redhat.com - 0.11-1 - Merge default images for podman/testcloud [#169] - Do not export empty environment to run.sh - Merge vagrant check for running connection [#156] - Adjust vagrant check for running connection - Merge test export into nitrate [#118] - Adjust 'tmt test export --nitrate' implementation - Use fedora as a default image for podman/testcloud - Move testcloud back to the extra requires - Always copy directory tree to the workdir - Add an example with test and plan in a single file - Do not run tests with an empty environment - Check for non-zero status upon yaml syntax errors - Export test cases to nitrate - Merge test import using testinfo.desc [#160] - Adjust test import using testinfo.desc - Use testinfo.desc as source of metadata - Add environment support to the discover step (#145) - Add a new story describing user and system config (#143) - Check if connection is running in Vagrant Provision * Wed Mar 11 2020 Petr ��pl��chal psplicha@redhat.com - 0.10-1 - Merge fixed environment support in run.sh [#99] - Add container and testcloud to tmt-all requires (#157) - Rename dict_to_shell() to better match content - Make path mandatory in run.sh. - Handle execution better in run.sh - Implement --env for testcloud provisioner - Merge run --environment support for podman [#132] - Fix container destroy, plus some minor adjustments - Use cache 'unsafe' for testcloud (#150) - Add --env option and support in podman provisioner - Warn about missing metadata tree before importing - Move testcloud to base requires, update README (#153) - Destroy container in finish only if there is any - Merge tmt test import --nitrate --disabled [#146] - Adjust the disabled test import implementation - Add an overview of classes (where are we heading) - Import non-disabled tests - Add a 'Provision Options' section, update coverage - Support selecting objects under the current folder - Add a link to details about fmf inheritance - Move requirements under the Install section - Mock testcloud modules to successfully build docs - Include examples of plan inheritance [fix #127] - Update implementation coverage for cli stories - Add testcloud provisioner (#134) - Merge the new story for 'tmt run --latest' [#136] - Move run --latest story under run, fix code block - Fix invalid variable name in the convert example - Use 'skip' instead of 'without', simplify default - Add rerun cli shortcut - Make sure we run finish always - Update the docs making '--name=' necessary (#138) - Clarify environment priority, fix release typo - Add environment specification - Remove copr build job from packit (not necessary) - Use the 'extra-summary' in the output as well - Use 'nitrate' consistently for tcms-related stuff - Prefix all non-specification keys [fix #120] - Show a nice error for an invalid yaml [fix #121] - Move container plan to common provision examples - Remove tmt-all dependency on vagrant-libvirt - Do not use red for import info messages [fix #125] - Show a nice error for weird Makefiles [fix #108] * Mon Feb 24 2020 Petr ��pl��chal psplicha@redhat.com - 0.9-1 - Rename the 'test convert' command to 'test import' - Include 'path' when importing virtual test cases - Extract test script from Makefile during convert - Do not import 'fmf-export' tag from nitrate [#119] - Merge the improved component import [#115] - Several adjustments to the component import - Merge the improved requires parsing [#113] - Fix parsing multiple requires from Makefile - Fail nicely if executed without provision (#112) - Make sure the copr command is available in dnf - Fix handling defaults for options, adjust wording - Read 'components' from nitrate when converting - Read requires as list when converting tests - Make it possible to pass script on cmdline - Mention libvirt and rsync in Fedora 30 workaround - Move podman image check and pull under go() - Simple destroy implementation for podman provision - Add Fedora 30 installation instructions [fix #105] - Merge podman support for the provision step [#106] - Several adjustments to the podman implementation - Fix _prepare_shell in podman provisioner - Add podman provisioner - Update the test case relevancy specification (#102) - Move copy_from_guest to provision/base.py (#75) - Several minor adjustments to the restraint story - Add user story for restraint - Merge different summaries for subpackages [#97] - Remove macro from the tmt-all subpackage summary - Add different summaries for sub-packages - Mention 'fmf-export' tag in the test export story - Merge optional PURPOSE in test convert [#89] - Handle missing duration or nitrate case in convert - Add support for wrap='auto' in utils.format() - Use local fmf repository for the basic plan (#94) - Merge test import documentation updates [#90] - Merge tag, status, pepa & hardware for test import - Several test import adjustments related to #91 - Fix deduplication bug when converting tests - Read more attributes from nitrate when converting - Update examples doc for converting tests - Update execute step examples for shell - Simplify packit configuration using 'fedora-all' (#88) - Optional attributes when converting. - Update execute and report step specification - Add spec for results.yaml and report.yaml (#66) - Add a story for exporting tests into nitrate (#83) - Add the 'require' attribute into the L1 Metadata - Update the Metadata Specification link in README - Improve 'tmt test convert' command implementation --------------------------------------------------------------------------------
================================================================================ wfuzz-2.4.5-3.el8 (FEDORA-EPEL-2020-3bad294630) Web fuzzer -------------------------------------------------------------------------------- Update Information:
Fix changelog entries -------------------------------------------------------------------------------- ChangeLog:
--------------------------------------------------------------------------------
================================================================================ xrdcl-http-4.11.3-1.el8 (FEDORA-EPEL-2020-eb94935693) HTTP client plug-in for XRootD -------------------------------------------------------------------------------- Update Information:
XrootD 4.11.3 -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 21 2020 Mattias Ellert mattias.ellert@physics.uu.se - 4.11.3-1 - Update to version 4.11.3 * Fri Jan 31 2020 Fedora Release Engineering releng@fedoraproject.org - 4.10.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ xrootd-4.11.3-1.el8 (FEDORA-EPEL-2020-eb94935693) Extended ROOT file server -------------------------------------------------------------------------------- Update Information:
XrootD 4.11.3 -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 21 2020 Mattias Ellert mattias.ellert@physics.uu.se - 1:4.11.3-1 - Update to version 4.11.3 - Use libc semaphores for EPEL 7 build POSIX compliant semaphores were backported to glibc in RHEL 7.2 - Drop glibc version requirement for semaphores (backported to older version) - Move libXrdSsi{Lib,ShMap}.so.* to client-libs package (from server-libs) --------------------------------------------------------------------------------
================================================================================ zork-1.0.2-3.el8 (FEDORA-EPEL-2020-7d28ec15d7) Public Domain original DUNGEON game (Zork I) -------------------------------------------------------------------------------- Update Information:
Add zork package -------------------------------------------------------------------------------- ChangeLog:
-------------------------------------------------------------------------------- References:
[ 1 ] Bug #1704522 - Review Request: zork - Public Domain source code to the original DUNGEON game (Zork I) https://bugzilla.redhat.com/show_bug.cgi?id=1704522 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org