The following Fedora EPEL 6 Security updates need testing:
Age URL
160
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-b6c663378c
unrtf-0.21.9-8.el6
16
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-4b684248e8
drupal7-7.60-2.el6
14
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-1ab12c426a
ansible-2.6.7-1.el6
10
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-018b328024
icecast-2.4.4-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
distribution-gpg-keys-1.26-1.el6
globus-common-18.0-2.el6
globus-ftp-client-9.1-2.el6
globus-gass-copy-10.3-2.el6
globus-gram-job-manager-15.1-2.el6
globus-gram-job-manager-scripts-7.1-1.el6
globus-gridftp-server-13.9-1.el6
globus-gsi-cert-utils-10.1-1.el6
globus-gssapi-gsi-14.9-1.el6
php-PHPMailer-5.2.27-1.el6
python-modestmaps-1.4.7-1.el6
Details about builds:
================================================================================
distribution-gpg-keys-1.26-1.el6 (FEDORA-EPEL-2018-d9e40ceab7)
GPG keys of various Linux distributions
--------------------------------------------------------------------------------
Update Information:
add RHEL8 release gpg key add virtual module to rhelbeta-8 config ---- mock-
core-configs: - add rhelbeta-8-* configs - move EOLed configs to /etc/mock/eol
directory - Add source repos to all fedora configs (sfowler(a)redhat.com) - add
epel-7-ppc64.cfg distribution-gpg-keys: - update copr keys - add RPM-GPG-KEY-
redhat8-beta key - add RPM-GPG-KEY-redhat-auxiliary2 ---- * updated Copr keys
* added Microsoft key
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Miroslav Such�� <msuchy(a)redhat.com> 1.26-1
- add RPM-GPG-KEY-redhat8-release
* Thu Nov 15 2018 Miroslav Such�� <msuchy(a)redhat.com> 1.25-1
- update copr keys
- add RPM-GPG-KEY-redhat8-beta key
- add RPM-GPG-KEY-redhat-auxiliary2
* Thu Nov 8 2018 Miroslav Such�� <msuchy(a)redhat.com> 1.24-1
- update Copr keys
- add Microsoft key
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1637059 - epel-7-ppc64 config is missing despite ppc64 being a supported EL7
target
https://bugzilla.redhat.com/show_bug.cgi?id=1637059
[ 2 ] Bug #1615178 - distribution-gpg-keys-1.22-1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1615178
--------------------------------------------------------------------------------
================================================================================
globus-common-18.0-2.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - Common Library
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 18.0-2
- Bump GCT release version to 6.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-ftp-client-9.1-2.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - GridFTP Client Library
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 9.1-2
- Bump GCT release version to 6.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-gass-copy-10.3-2.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - Globus Gass Copy
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 10.3-2
- Bump GCT release version to 6.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-gram-job-manager-15.1-2.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - GRAM Jobmanager
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 15.1-2
- Bump GCT release version to 6.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-gram-job-manager-scripts-7.1-1.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - GRAM Job ManagerScripts
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 7.1-1
- Architecture independent package should not depend on libtool
- Drop BR on gcc
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-gridftp-server-13.9-1.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - Globus GridFTP Server
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 13.9-1
- Fix data_node restrict path
- Bump GCT release version to 6.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-gsi-cert-utils-10.1-1.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - Globus GSI Cert Utils Library
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 10.1-1
- Fix broken subject in grid-cert-request
- Bump GCT release version to 6.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
globus-gssapi-gsi-14.9-1.el6 (FEDORA-EPEL-2018-b251cecde1)
Grid Community Toolkit - GSSAPI library
--------------------------------------------------------------------------------
Update Information:
globus-common-18.0-2, globus-ftp-client-9.1-2, globus-gass-copy-10.3-2, globus-
gram-job-manager-15.1-2 * Bump GCT release version to 6.2 globus-gram-job-
manager-scripts-7.1-1 * Architecture independent package should not depend on
libtool * Drop BR on gcc globus-gridftp-server-13.9-1 * Fix data_node restrict
path * Bump GCT release version to 6.2 globus-gsi-cert-utils-10.1-1 * Fix
broken subject in grid-cert-request * Bump GCT release version to 6.2 globus-
gssapi-gsi-14.9-1 * Allow TLS 1.0/1.1 * Fix leaks * Drop patch globus-gssapi-
gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 14.9-1
- Allow TLS 1.0/1.1
- Fix leaks
- Drop patch globus-gssapi-gsi-allow-tls-1.0-1.1.patch accepted upstream
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1640939 - grid-cert-request creates signing request with broken subject
https://bugzilla.redhat.com/show_bug.cgi?id=1640939
--------------------------------------------------------------------------------
================================================================================
php-PHPMailer-5.2.27-1.el6 (FEDORA-EPEL-2018-307ddb503d)
PHP email transport class with a lot of features
--------------------------------------------------------------------------------
Update Information:
**Version 5.2.27** * SECURITY Fix potential object injection vulnerability.
**CVE-2018-19296**. Reported by Sehun Oh of cyberone.kr. Note that the 5.2
branch is deprecated and will not receive security updates after 31st December
2018.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Remi Collet <remi(a)remirepo.net> - 5.2.27-1
- update to 5.2.27
--------------------------------------------------------------------------------
================================================================================
python-modestmaps-1.4.7-1.el6 (FEDORA-EPEL-2018-cdf4ff7d0b)
Modest Maps python port
--------------------------------------------------------------------------------
Update Information:
Update to 1.4.7 and add a python3 package to Fedora
--------------------------------------------------------------------------------
ChangeLog:
* Fri Nov 16 2018 Scott K Logan <logans(a)cottsay.net> - 1.4.7-1
- Update to 1.4.7
- Add python3 package
- Switch to Github upstream
--------------------------------------------------------------------------------