The following Fedora EPEL 7 Security updates need testing:
Age URL
692
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087
dokuwiki-0-0.24.20140929c.el7
454
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f
mcollective-2.8.4-1.el7
172
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-23fa04bf1c
redis-3.2.3-1.el7
156
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e8f4ff76b3
chicken-4.11.0-3.el7
36
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d
libbsd-0.8.3-1.el7
12
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-6e3dadcb1d
pdns-recursor-3.7.4-1.el7
12
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-9bcc7b6164
mingw-nsis-3.01-1.el7
11
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-ad7467bd9c
pdns-3.4.11-1.el7
9
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8cb1dcd776
python-crypto-2.6.1-13.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-09ddf72aaa
percona-xtrabackup-2.3.6-1.el7
8
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-cd2af02aae
rabbitmq-server-3.3.5-31.el7
7
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8533f605ab
bubblewrap-0.1.7-1.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-555b5847ec
drupal7-title-1.0-0.7.alpha9.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-7fb94fc97a
exim-4.88-3.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-b498a4859e
moodle-3.1.4-1.el7
0
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-cc2d96d683
wordpress-4.7.2-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
composer-1.3.2-1.el7
euca2ools-3.4.1-1.el7
janino-2.7.8-7.el7
libidn2-0.16-1.el7
pam_mapi-0.3.1-1.el7
perl-CHI-0.56-1.el7
perl-Mail-POP3Client-2.19-5.el7
perl-String-RewritePrefix-0.007-5.el7
perl-Test-Email-0.07-1.el7
php-PsrLog-1.0.2-2.el7
portmidi-217-15.el7
python-httpretty-0.8.14-2.20161011git70af1f8.el7
python-networkmanager-1.2.1-3.el7
wordpress-4.7.2-1.el7
Details about builds:
================================================================================
composer-1.3.2-1.el7 (FEDORA-EPEL-2017-ed9cef3635)
Dependency Manager for PHP
--------------------------------------------------------------------------------
Update Information:
**Version 1.3.2** - 2017-01-27 * Added `COMPOSER_BINARY` env var that is
defined within the scope of a Composer run automatically with the path to the
phar file * Fixed create-project ending in a detached HEAD when installing
aliased packages * Fixed composer show not returning non-zero exit code when
the package does not exist * Fixed `@composer` handling in scripts when
--working-dir is used together with it * Fixed private-GitLab handling of
repos with dashes in them
--------------------------------------------------------------------------------
================================================================================
euca2ools-3.4.1-1.el7 (FEDORA-EPEL-2017-52d0b822e3)
Eucalyptus/AWS-compatible command line tools
--------------------------------------------------------------------------------
Update Information:
This update adds support for NAT gateways, CloudFormation template attributes,
new AWS regions, and more. For a complete list of changes, see the [upstream
release
notes](https://docs.eucalyptus.com/eucalyptus/4.3.1/#euca2ools-release-
notes/rn_index_3.4.0.html).
--------------------------------------------------------------------------------
================================================================================
janino-2.7.8-7.el7 (FEDORA-EPEL-2017-4260551a2e)
An embedded Java compiler
--------------------------------------------------------------------------------
Update Information:
Package janino for EPEL7 (bz#1288319)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1288319 - Branch and build janino for EPEL7
https://bugzilla.redhat.com/show_bug.cgi?id=1288319
--------------------------------------------------------------------------------
================================================================================
libidn2-0.16-1.el7 (FEDORA-EPEL-2017-7ed806af72)
Library to support IDNA2008 internationalized domain names
--------------------------------------------------------------------------------
Update Information:
Libidn2 0.16 (released 2017-01-16) ================================== *
build: Fix idn2_cmd.h build rule * API and ABI is backwards compatible with
the previous version Libidn2 0.15 (released 2017-01-14)
================================== * Fix out-of-bounds read * Fix NFC input
conversion (regression) * Shrink TR46 static mapping data * API and ABI is
backwards compatible with the previous version Libidn2 0.14 (released
2016-12-30) ================================== * build: Fix gentr46map build
* API and ABI is backwards compatible with the previous version Libidn2 0.13
(released 2016-12-29) ================================== * build: Doesn't
download external files during build * doc: Clarify license * build:
Generate ChangeLog file properly * doc: API documentation related to TR46
flags * API and ABI is backwards compatible with the previous version
Libidn2 0.12 (released 2016-12-26) ================================== * All
changes by Tim R��hsen <tim.ruehsen(a)gmx.de> except stated otherwise *
Builds/links with libunistring * Fix two possible crashes with unchecked NULL
pointers * Memleak fix, reported by Hanno B��ck <hanno(a)hboeck.de> * Binary
search for codepoints in tables * Do not taint output variable on error in
idn2_register_u8() * Do not taint output variable on error in idn2_lookup_u8()
* Update to Unicode 6.3.0 IDNA tables * Add TR46 / UTS#46 support to API and
idn2 utility * Add NFC quick check * Add make target 'check-coverage' for
test coverage report * Add tests to increase test code coverage * API and
ABI is backwards compatible with the previous version
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1416642 - libidn2-0.16 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1416642
--------------------------------------------------------------------------------
================================================================================
pam_mapi-0.3.1-1.el7 (FEDORA-EPEL-2017-0ddb3083cd)
PAM module for authentication via MAPI against a Zarafa server
--------------------------------------------------------------------------------
Update Information:
Update to pam_mapi 0.3.1
--------------------------------------------------------------------------------
================================================================================
perl-CHI-0.56-1.el7 (FEDORA-EPEL-2017-7f17ee4e9a)
Unified cache handling interface
--------------------------------------------------------------------------------
Update Information:
First EPEL 7 build.
--------------------------------------------------------------------------------
================================================================================
perl-Mail-POP3Client-2.19-5.el7 (FEDORA-EPEL-2017-9d603f24bc)
Perl 5 module to talk to a POP3 (RFC1939) server
--------------------------------------------------------------------------------
Update Information:
First EPEL 7 build.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1108389 - Build perl-Mail-POP3Client for EPEL7
https://bugzilla.redhat.com/show_bug.cgi?id=1108389
--------------------------------------------------------------------------------
================================================================================
perl-String-RewritePrefix-0.007-5.el7 (FEDORA-EPEL-2017-b29e3e60b1)
Rewrite strings based on a set of known prefixes
--------------------------------------------------------------------------------
Update Information:
First EPEL 7 build.
--------------------------------------------------------------------------------
================================================================================
perl-Test-Email-0.07-1.el7 (FEDORA-EPEL-2017-3aee729190)
Test Email Contents
--------------------------------------------------------------------------------
Update Information:
First EPEL 7 build.
--------------------------------------------------------------------------------
================================================================================
php-PsrLog-1.0.2-2.el7 (FEDORA-EPEL-2017-65219506d8)
Common interface for logging libraries
--------------------------------------------------------------------------------
Update Information:
### 1.0.2 * Fixed test suite fix in 1.0.1 to use a more appropriate phpunit
method * Fixed return types to be void instead of null
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1416878 - package does not require autoloader
https://bugzilla.redhat.com/show_bug.cgi?id=1416878
--------------------------------------------------------------------------------
================================================================================
portmidi-217-15.el7 (FEDORA-EPEL-2017-c4679da580)
Real-time Midi I/O Library
--------------------------------------------------------------------------------
Update Information:
First EPEL 7 build.
--------------------------------------------------------------------------------
================================================================================
python-httpretty-0.8.14-2.20161011git70af1f8.el7 (FEDORA-EPEL-2017-c55ef90cdb)
HTTP request mock tool for Python
--------------------------------------------------------------------------------
Update Information:
This update fixes a bug Garrett Holmstrom noticed in the previous update,
whereby the `setUp` and `tearDown` methods do not call `reset`. This could cause
problems for some test suites. Thanks to Garrett for the report.
--------------------------------------------------------------------------------
================================================================================
python-networkmanager-1.2.1-3.el7 (FEDORA-EPEL-2017-9c4df59192)
Easy communication with NetworkManager
--------------------------------------------------------------------------------
Update Information:
Initial packaging
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1412801 - Review Request: python-networkmanager - Easy communication with
NetworkManager
https://bugzilla.redhat.com/show_bug.cgi?id=1412801
--------------------------------------------------------------------------------
================================================================================
wordpress-4.7.2-1.el7 (FEDORA-EPEL-2017-cc2d96d683)
Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:
**WordPress 4.7.2 Security Release** WordPress 4.7.2 is now available. This is
a security release for all previous versions and we strongly encourage you to
update your sites immediately. WordPress versions 4.7.1 and earlier are
affected by three security issues: * The user interface for assigning
taxonomy terms in Press This is shown to users who do not have permissions to
use it. Reported by David Herrera of Alley Interactive. * WP_Query is
vulnerable to a SQL injection (SQLi) when passing unsafe data. WordPress core is
not directly vulnerable to this issue, but we���ve added hardening to prevent
plugins and themes from accidentally causing a vulnerability. Reported by Mo
Jangda (batmoo). * A cross-site scripting (XSS) vulnerability was discovered
in the posts list table. Reported by Ian Dunn of the WordPress Security Team.
---- **WordPress 4.7.1** Security and Maintenance Release This is a security
release for all previous versions and we strongly encourage you to update your
sites immediately. WordPress versions 4.7 and earlier are affected by eight
security issues: * Remote code execution (RCE) in PHPMailer ��� No specific
issue appears to affect WordPress or any of the major plugins we investigated
but, out of an abundance of caution, we updated PHPMailer in this release. This
issue was reported to PHPMailer by Dawid Golunski and Paul Buonopane. * The
REST API exposed user data for all users who had authored a post of a public
post type. WordPress 4.7.1 limits this to only post types which have specified
that they should be shown within the REST API. Reported by Krogsgard and Chris
Jean. * Cross-site scripting (XSS) via the plugin name or version header on
update-core.php. Reported by Dominik Schilling of the WordPress Security Team. *
Cross-site request forgery (CSRF) bypass via uploading a Flash file. Reported by
Abdullah Hussam. * Cross-site scripting (XSS) via theme name fallback.
Reported by Mehmet Ince. * Post via email checks
mail.example.com if default
settings aren���t changed. Reported by John Blackbourn of the WordPress Security
Team. * A cross-site request forgery (CSRF) was discovered in the
accessibility mode of widget editing. Reported by Ronnie Skansing. * Weak
cryptographic security for multisite activation key. Reported by Jack. Thank
you to the reporters for practicing responsible disclosure. In addition to the
security issues above, WordPress 4.7.1 fixes 62 bugs from 4.7. For more
information, see the [release
notes](https://codex.wordpress.org/Version_4.7.1)
or consult the [list of
changes](https://core.trac.wordpress.org/query?milestone=4.7.1).
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1417158 - wordpress: Multiple security fixes in 4.7.2
https://bugzilla.redhat.com/show_bug.cgi?id=1417158
--------------------------------------------------------------------------------