The following Fedora EPEL 7 Security updates need testing: Age URL 652 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d condor-8.6.11-1.el7 394 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-c499781e80 python-gnupg-0.4.4-1.el7 392 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-bc0182548b bubblewrap-0.3.3-2.el7 101 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-fa8a2e97c6 python-waitress-1.4.3-1.el7 41 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-19d171a465 python34-3.4.10-5.el7 13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ff94ccbdec openssl11-1.1.1c-2.el7 13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-624f38e579 qbittorrent-3.3.16-2.el7 12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-235a51a239 clamav-0.102.3-1.el7 11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ae83e43288 log4net-2.0.8-10.el7 11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-567eda5296 exim-4.93-3.el7 10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-134c471656 json-c12-0.12.1-4.el7 10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ff11142989 netdata-1.22.1-3.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-e7814b7723 transmission-2.94-9.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-19de895038 knot-resolver-5.1.1-1.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-ed6bc3c8d4 golang-1.13.11-1.el7 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-05b9f2eac5 sympa-6.2.56-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
cacti-1.2.12-1.el7 cacti-spine-1.2.12-1.el7 gfal2-2.17.3-1.el7 mbedtls-2.7.15-1.el7
Details about builds:
================================================================================ cacti-1.2.12-1.el7 (FEDORA-EPEL-2020-c47d3538f7) An rrd based graphing tool -------------------------------------------------------------------------------- Update Information:
- Update to 1.2.12 Release notes: https://www.cacti.net/release_notes.php?version=1.2.12 -------------------------------------------------------------------------------- ChangeLog:
* Wed May 27 2020 Morten Stevens mstevens@fedoraproject.org - 1.2.12-1 - Update to 1.2.12 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1840313 - CVE-2020-13231 cacti: CSRF at admin email [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1840313 [ 2 ] Bug #1840318 - CVE-2020-13230 cacti: improper access control on disabling a user [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1840318 --------------------------------------------------------------------------------
================================================================================ cacti-spine-1.2.12-1.el7 (FEDORA-EPEL-2020-c47d3538f7) Threaded poller for Cacti written in C -------------------------------------------------------------------------------- Update Information:
- Update to 1.2.12 Release notes: https://www.cacti.net/release_notes.php?version=1.2.12 -------------------------------------------------------------------------------- ChangeLog:
* Wed May 27 2020 Morten Stevens mstevens@fedoraproject.org - 1.2.12-1 - Update to 1.2.12 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1840313 - CVE-2020-13231 cacti: CSRF at admin email [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1840313 [ 2 ] Bug #1840318 - CVE-2020-13230 cacti: improper access control on disabling a user [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1840318 --------------------------------------------------------------------------------
================================================================================ gfal2-2.17.3-1.el7 (FEDORA-EPEL-2020-716bc4ecbc) Grid file access library 2.0 -------------------------------------------------------------------------------- Update Information:
Upgrade to upstream release 2.17.3 -------------------------------------------------------------------------------- ChangeLog:
* Fri May 15 2020 Michal Simon michal.simon@cern.ch - 2.17.3-1 - Upgrade to upstream release 2.17.3 * Tue Apr 21 2020 Bj��rn Esser besser82@fedoraproject.org - 2.17.2-2 - Rebuild (json-c) --------------------------------------------------------------------------------
================================================================================ mbedtls-2.7.15-1.el7 (FEDORA-EPEL-2020-6f2a4db251) Light-weight cryptographic and SSL/TLS library -------------------------------------------------------------------------------- Update Information:
- Update to 2.7.15 Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.16.6-and-2.7.15-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2020-04 -------------------------------------------------------------------------------- ChangeLog:
* Wed May 27 2020 Morten Stevens mstevens@fedoraproject.org - 2.7.15-1 - Update to 2.7.15 - Security Advisory 2020-04 (CVE-2020-10932) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1838552 - CVE-2020-10932 mbedtls: side channel attack possibly leading to information disclosure [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1838552 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org