The following Fedora EPEL 7 Security updates need testing: Age URL 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-03b316a546 qemu-2.0.0-5.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
anope-2.0.13-1.el7 prosody-0.12.3-1.el7 protonvpn-cli-2.2.11-7.el7 sympa-6.2.72-2.el7
Details about builds:
================================================================================ anope-2.0.13-1.el7 (FEDORA-EPEL-2023-d30ee5c0be) IRC services designed for flexibility and ease of use -------------------------------------------------------------------------------- Update Information:
# Anope 2.0.13 - Fixed a crash on some compilers when trying to call methods on a null pointer - Fixed a crash when encountering an unterminated commented config block - Fixed erroneously rejecting spaces in fantasy:name - Fixed marking services pseudoclients as an oper on InspIRCd - Fixed not checking user@ip as well as user@host when logging into an operator account - Fixed setting the vhost/vident during SASL on UnrealIRCd - Updated the German translation - Updated the Italian translation -------------------------------------------------------------------------------- ChangeLog:
* Fri Jun 2 2023 Robert Scheck robert@fedoraproject.org 2.0.13-1 - Upgrade to 2.0.13 (#2211864) * Wed Jan 18 2023 Fedora Release Engineering releng@fedoraproject.org - 2.0.12-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2211864 - anope-2.0.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=2211864 --------------------------------------------------------------------------------
================================================================================ prosody-0.12.3-1.el7 (FEDORA-EPEL-2023-02e841c57a) Flexible communications server for Jabber/XMPP -------------------------------------------------------------------------------- Update Information:
# Prosody 0.12.3 Upstream is pleased to announce a new minor release from their stable branch. This is a bugfix release for the stable 0.12 series. Most notably, it fixes a regression for SQL users introduced in 0.12.2, and a separate long-standing compatibility issue with archive stores on certain MySQL/MariaDB versions. It also fixes an issue with websockets discovered by the Jitsi team, some issues with the internal HTTP client API, and upstream improved the accuracy of `prosodyctl check dns` in certain configurations. # Fixes and improvements - mod_storage_sql: Don���t avoid initialization under `prosodyctl` (fix mod_storage_sql changes breaking `prosodyctl`) - mod_storage_sql: Fix for breaking change in certain MySQL versions - `prosodyctl check dns`: Check for Direct TLS SRV records even if not configured # Minor changes - mod_websocket: Fire pre-session-close event (fixes: cleanly- closed sessions are hibernated by mod_smacks) - sessionmanager: Mark session as destroyed to prevent reentry - mod_admin_socket: Return error on unhandled input to prevent apparent freeze - configure: Fix quoting of `$LUA_SUFFIX` - net.http.parser: Improve handling of responses without content-length - net.http.parser: Fix off-by-one error in chunk parser - net.http.server: Add new API to get HTTP request from a connection - net.http.server: Fix double close of file handle in chunked mode with opportunistic writes - util.prosodyctl.shell: Close state on exit to fix saving shell history - mod_invites: Prefer landing page over xmpp URI in shell command - mod_muc_mam: Add mam#extended form fields - mod_muc_mam: Copy ���include total��� behavior from mod_mam - util.startup: Close state on exit to ensure GC finalizers are called -------------------------------------------------------------------------------- ChangeLog:
* Fri Jun 2 2023 Robert Scheck robert@fedoraproject.org 0.12.3-1 - Upgrade to 0.12.3 (#2172143) * Fri Jan 20 2023 Fedora Release Engineering releng@fedoraproject.org - 0.12.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Sat Dec 31 2022 Pete Walter pwalter@fedoraproject.org - 0.12.2-2 - Rebuild for ICU 72 --------------------------------------------------------------------------------
================================================================================ protonvpn-cli-2.2.11-7.el7 (FEDORA-EPEL-2023-92d2ab20dd) Linux command-line client for ProtonVPN written in Python -------------------------------------------------------------------------------- Update Information:
Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- ChangeLog:
* Fri Jan 20 2023 Fedora Release Engineering releng@fedoraproject.org - 2.2.11-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Jul 22 2022 Fedora Release Engineering releng@fedoraproject.org - 2.2.11-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Jun 13 2022 Python Maint python-maint@redhat.com - 2.2.11-5 - Rebuilt for Python 3.11 * Fri Jan 21 2022 Fedora Release Engineering releng@fedoraproject.org - 2.2.11-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ sympa-6.2.72-2.el7 (FEDORA-EPEL-2023-64b282dfaf) Powerful multilingual List Manager -------------------------------------------------------------------------------- Update Information:
Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 -------------------------------------------------------------------------------- ChangeLog:
* Thu Jun 1 2023 Xavier Bachelot xavier@bachelot.org 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX * Sat Jan 21 2023 Fedora Release Engineering releng@fedoraproject.org - 6.2.70-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2156474 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156474 [ 2 ] Bug #2171950 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171950 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org