The following Fedora EPEL 7 Security updates need testing: Age URL 692 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7 454 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7 172 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-23fa04bf1c redis-3.2.3-1.el7 156 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e8f4ff76b3 chicken-4.11.0-3.el7 36 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7 12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-6e3dadcb1d pdns-recursor-3.7.4-1.el7 12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-9bcc7b6164 mingw-nsis-3.01-1.el7 11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-ad7467bd9c pdns-3.4.11-1.el7 9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8cb1dcd776 python-crypto-2.6.1-13.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-09ddf72aaa percona-xtrabackup-2.3.6-1.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-cd2af02aae rabbitmq-server-3.3.5-31.el7 7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8533f605ab bubblewrap-0.1.7-1.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-555b5847ec drupal7-title-1.0-0.7.alpha9.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-7fb94fc97a exim-4.88-3.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-b498a4859e moodle-3.1.4-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-cc2d96d683 wordpress-4.7.2-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
composer-1.3.2-1.el7 euca2ools-3.4.1-1.el7 janino-2.7.8-7.el7 libidn2-0.16-1.el7 pam_mapi-0.3.1-1.el7 perl-CHI-0.56-1.el7 perl-Mail-POP3Client-2.19-5.el7 perl-String-RewritePrefix-0.007-5.el7 perl-Test-Email-0.07-1.el7 php-PsrLog-1.0.2-2.el7 portmidi-217-15.el7 python-httpretty-0.8.14-2.20161011git70af1f8.el7 python-networkmanager-1.2.1-3.el7 wordpress-4.7.2-1.el7
Details about builds:
================================================================================ composer-1.3.2-1.el7 (FEDORA-EPEL-2017-ed9cef3635) Dependency Manager for PHP -------------------------------------------------------------------------------- Update Information:
**Version 1.3.2** - 2017-01-27 * Added `COMPOSER_BINARY` env var that is defined within the scope of a Composer run automatically with the path to the phar file * Fixed create-project ending in a detached HEAD when installing aliased packages * Fixed composer show not returning non-zero exit code when the package does not exist * Fixed `@composer` handling in scripts when --working-dir is used together with it * Fixed private-GitLab handling of repos with dashes in them --------------------------------------------------------------------------------
================================================================================ euca2ools-3.4.1-1.el7 (FEDORA-EPEL-2017-52d0b822e3) Eucalyptus/AWS-compatible command line tools -------------------------------------------------------------------------------- Update Information:
This update adds support for NAT gateways, CloudFormation template attributes, new AWS regions, and more. For a complete list of changes, see the [upstream release notes](https://docs.eucalyptus.com/eucalyptus/4.3.1/#euca2ools-release- notes/rn_index_3.4.0.html). --------------------------------------------------------------------------------
================================================================================ janino-2.7.8-7.el7 (FEDORA-EPEL-2017-4260551a2e) An embedded Java compiler -------------------------------------------------------------------------------- Update Information:
Package janino for EPEL7 (bz#1288319) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1288319 - Branch and build janino for EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1288319 --------------------------------------------------------------------------------
================================================================================ libidn2-0.16-1.el7 (FEDORA-EPEL-2017-7ed806af72) Library to support IDNA2008 internationalized domain names -------------------------------------------------------------------------------- Update Information:
Libidn2 0.16 (released 2017-01-16) ================================== * build: Fix idn2_cmd.h build rule * API and ABI is backwards compatible with the previous version Libidn2 0.15 (released 2017-01-14) ================================== * Fix out-of-bounds read * Fix NFC input conversion (regression) * Shrink TR46 static mapping data * API and ABI is backwards compatible with the previous version Libidn2 0.14 (released 2016-12-30) ================================== * build: Fix gentr46map build * API and ABI is backwards compatible with the previous version Libidn2 0.13 (released 2016-12-29) ================================== * build: Doesn't download external files during build * doc: Clarify license * build: Generate ChangeLog file properly * doc: API documentation related to TR46 flags * API and ABI is backwards compatible with the previous version Libidn2 0.12 (released 2016-12-26) ================================== * All changes by Tim R��hsen tim.ruehsen@gmx.de except stated otherwise * Builds/links with libunistring * Fix two possible crashes with unchecked NULL pointers * Memleak fix, reported by Hanno B��ck hanno@hboeck.de * Binary search for codepoints in tables * Do not taint output variable on error in idn2_register_u8() * Do not taint output variable on error in idn2_lookup_u8() * Update to Unicode 6.3.0 IDNA tables * Add TR46 / UTS#46 support to API and idn2 utility * Add NFC quick check * Add make target 'check-coverage' for test coverage report * Add tests to increase test code coverage * API and ABI is backwards compatible with the previous version -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1416642 - libidn2-0.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=1416642 --------------------------------------------------------------------------------
================================================================================ pam_mapi-0.3.1-1.el7 (FEDORA-EPEL-2017-0ddb3083cd) PAM module for authentication via MAPI against a Zarafa server -------------------------------------------------------------------------------- Update Information:
Update to pam_mapi 0.3.1 --------------------------------------------------------------------------------
================================================================================ perl-CHI-0.56-1.el7 (FEDORA-EPEL-2017-7f17ee4e9a) Unified cache handling interface -------------------------------------------------------------------------------- Update Information:
First EPEL 7 build. --------------------------------------------------------------------------------
================================================================================ perl-Mail-POP3Client-2.19-5.el7 (FEDORA-EPEL-2017-9d603f24bc) Perl 5 module to talk to a POP3 (RFC1939) server -------------------------------------------------------------------------------- Update Information:
First EPEL 7 build. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1108389 - Build perl-Mail-POP3Client for EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1108389 --------------------------------------------------------------------------------
================================================================================ perl-String-RewritePrefix-0.007-5.el7 (FEDORA-EPEL-2017-b29e3e60b1) Rewrite strings based on a set of known prefixes -------------------------------------------------------------------------------- Update Information:
First EPEL 7 build. --------------------------------------------------------------------------------
================================================================================ perl-Test-Email-0.07-1.el7 (FEDORA-EPEL-2017-3aee729190) Test Email Contents -------------------------------------------------------------------------------- Update Information:
First EPEL 7 build. --------------------------------------------------------------------------------
================================================================================ php-PsrLog-1.0.2-2.el7 (FEDORA-EPEL-2017-65219506d8) Common interface for logging libraries -------------------------------------------------------------------------------- Update Information:
### 1.0.2 * Fixed test suite fix in 1.0.1 to use a more appropriate phpunit method * Fixed return types to be void instead of null -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1416878 - package does not require autoloader https://bugzilla.redhat.com/show_bug.cgi?id=1416878 --------------------------------------------------------------------------------
================================================================================ portmidi-217-15.el7 (FEDORA-EPEL-2017-c4679da580) Real-time Midi I/O Library -------------------------------------------------------------------------------- Update Information:
First EPEL 7 build. --------------------------------------------------------------------------------
================================================================================ python-httpretty-0.8.14-2.20161011git70af1f8.el7 (FEDORA-EPEL-2017-c55ef90cdb) HTTP request mock tool for Python -------------------------------------------------------------------------------- Update Information:
This update fixes a bug Garrett Holmstrom noticed in the previous update, whereby the `setUp` and `tearDown` methods do not call `reset`. This could cause problems for some test suites. Thanks to Garrett for the report. --------------------------------------------------------------------------------
================================================================================ python-networkmanager-1.2.1-3.el7 (FEDORA-EPEL-2017-9c4df59192) Easy communication with NetworkManager -------------------------------------------------------------------------------- Update Information:
Initial packaging -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1412801 - Review Request: python-networkmanager - Easy communication with NetworkManager https://bugzilla.redhat.com/show_bug.cgi?id=1412801 --------------------------------------------------------------------------------
================================================================================ wordpress-4.7.2-1.el7 (FEDORA-EPEL-2017-cc2d96d683) Blog tool and publishing platform -------------------------------------------------------------------------------- Update Information:
**WordPress 4.7.2 Security Release** WordPress 4.7.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.7.1 and earlier are affected by three security issues: * The user interface for assigning taxonomy terms in Press This is shown to users who do not have permissions to use it. Reported by David Herrera of Alley Interactive. * WP_Query is vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is not directly vulnerable to this issue, but we���ve added hardening to prevent plugins and themes from accidentally causing a vulnerability. Reported by Mo Jangda (batmoo). * A cross-site scripting (XSS) vulnerability was discovered in the posts list table. Reported by Ian Dunn of the WordPress Security Team. ---- **WordPress 4.7.1** Security and Maintenance Release This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.7 and earlier are affected by eight security issues: * Remote code execution (RCE) in PHPMailer ��� No specific issue appears to affect WordPress or any of the major plugins we investigated but, out of an abundance of caution, we updated PHPMailer in this release. This issue was reported to PHPMailer by Dawid Golunski and Paul Buonopane. * The REST API exposed user data for all users who had authored a post of a public post type. WordPress 4.7.1 limits this to only post types which have specified that they should be shown within the REST API. Reported by Krogsgard and Chris Jean. * Cross-site scripting (XSS) via the plugin name or version header on update-core.php. Reported by Dominik Schilling of the WordPress Security Team. * Cross-site request forgery (CSRF) bypass via uploading a Flash file. Reported by Abdullah Hussam. * Cross-site scripting (XSS) via theme name fallback. Reported by Mehmet Ince. * Post via email checks mail.example.com if default settings aren���t changed. Reported by John Blackbourn of the WordPress Security Team. * A cross-site request forgery (CSRF) was discovered in the accessibility mode of widget editing. Reported by Ronnie Skansing. * Weak cryptographic security for multisite activation key. Reported by Jack. Thank you to the reporters for practicing responsible disclosure. In addition to the security issues above, WordPress 4.7.1 fixes 62 bugs from 4.7. For more information, see the [release notes](https://codex.wordpress.org/Version_4.7.1) or consult the [list of changes](https://core.trac.wordpress.org/query?milestone=4.7.1). -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1417158 - wordpress: Multiple security fixes in 4.7.2 https://bugzilla.redhat.com/show_bug.cgi?id=1417158 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org