The following Fedora EPEL 7 Security updates need testing: Age URL 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-3cc28d5469 php-horde-Horde-Text-Filter-2.3.7-1.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-bb1731457c prosody-0.11.8-1.el7 7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-f93d3d26db privoxy-3.0.31-1.el7 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-389d1fe8e6 libmysofa-1.2-4.el7 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-4dda69dcf1 rubygem-rack-cors-1.0.6-1.el7 2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-9ec8ceb857 ansible-2.9.18-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
atop-2.6.0-3.el7 chromium-88.0.4324.182-1.el7 gnome-shell-extension-topicons-plus-22-9.20200414.bfa3fe3.el7 inxi-3.3.01-1.el7 mkrdns-3.3-5.20210224gitf6e8414.el7 mono-6.8.0-2.el7 nagios-4.4.6-2.el7 nordugrid-arc6-6.10.2-1.el7 oval-graph-1.2.5-1.el7 php-horde-Horde-Db-2.4.1-1.el7 python-amqp-2.4.2-1.el7 python-apprise-0.9.1-2.el7 python-billiard-3.5.0.5-2.el7 python-celery-4.2.2-1.el7 python-kombu-4.3.0-1.el7 python-vine-1.3.0-1.el7 reg-0.15.5-8.el7 rpkg-1.62-3.el7 wireguard-tools-1.0.20210223-1.el7
Details about builds:
================================================================================ atop-2.6.0-3.el7 (FEDORA-EPEL-2021-5fb965db2b) An advanced interactive monitor to view the load on system and process level -------------------------------------------------------------------------------- Update Information:
Don't ship atopgpud on EL-7 -------------------------------------------------------------------------------- ChangeLog:
* Mon Feb 22 2021 Gwyn Ciesla gwync@protonmail.com - 2.6.0-3 - Dpn't ship atopgpud on EL-7 * Tue Jan 26 2021 Fedora Release Engineering releng@fedoraproject.org - 2.6.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Mon Dec 21 2020 Gwyn Ciesla gwync@protonmail.com - 2.6.0-1 - 2.6.0 * Mon Jul 27 2020 Fedora Release Engineering releng@fedoraproject.org - 2.5.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri May 29 2020 Gwyn Ciesla gwync@protonmail.com - 2.5.1-1 - Fix unit file path. * Tue Jan 28 2020 Fedora Release Engineering releng@fedoraproject.org - 2.5.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Sun Nov 3 2019 Gwyn Ciesla gwync@protonmail.com - 2.5.0-1 - 2.5.0 --------------------------------------------------------------------------------
================================================================================ chromium-88.0.4324.182-1.el7 (FEDORA-EPEL-2021-5261c4f487) A WebKit (Blink) powered web browser -------------------------------------------------------------------------------- Update Information:
Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157 -------------------------------------------------------------------------------- ChangeLog:
* Wed Feb 17 2021 Tom Callaway spot@fedoraproject.org - 88.0.4234.182-1 - update to 88.0.4234.182 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1929523 - CVE-2021-21149 chromium-browser: Stack overflow in Data Transfer https://bugzilla.redhat.com/show_bug.cgi?id=1929523 [ 2 ] Bug #1929524 - CVE-2021-21150 chromium-browser: Use after free in Downloads https://bugzilla.redhat.com/show_bug.cgi?id=1929524 [ 3 ] Bug #1929525 - CVE-2021-21151 chromium-browser: Use after free in Payments https://bugzilla.redhat.com/show_bug.cgi?id=1929525 [ 4 ] Bug #1929526 - CVE-2021-21152 chromium-browser: Heap buffer overflow in Media https://bugzilla.redhat.com/show_bug.cgi?id=1929526 [ 5 ] Bug #1929527 - CVE-2021-21153 chromium-browser: Stack overflow in GPU Process https://bugzilla.redhat.com/show_bug.cgi?id=1929527 [ 6 ] Bug #1929528 - CVE-2021-21154 chromium-browser: Heap buffer overflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929528 [ 7 ] Bug #1929529 - CVE-2021-21155 chromium-browser: Heap buffer overflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929529 [ 8 ] Bug #1929530 - CVE-2021-21156 chromium-browser: Heap buffer overflow in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1929530 [ 9 ] Bug #1929531 - CVE-2021-21157 chromium-browser: Use after free in Web Sockets https://bugzilla.redhat.com/show_bug.cgi?id=1929531 --------------------------------------------------------------------------------
================================================================================ gnome-shell-extension-topicons-plus-22-9.20200414.bfa3fe3.el7 (FEDORA-EPEL-2021-47fe0bf91f) Move all legacy tray icons to the top panel -------------------------------------------------------------------------------- Update Information:
Build TopIcons Plus at the latest versions compatible for EPEL7 and EPEL8. -------------------------------------------------------------------------------- ChangeLog:
--------------------------------------------------------------------------------
================================================================================ inxi-3.3.01-1.el7 (FEDORA-EPEL-2021-8436bb1058) A full featured system information script -------------------------------------------------------------------------------- Update Information:
Updato to 3.3.01. -------------------------------------------------------------------------------- ChangeLog:
* Mon Feb 22 2021 Vasiliy N. Glazov vascom2@gmail.com - 3.3.01-1 - Update to 3.3.01 * Tue Jan 26 2021 Fedora Release Engineering releng@fedoraproject.org - 3.2.01-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Sun Jan 10 2021 Vasiliy N. Glazov vascom2@gmail.com - 3.2.01-1 - Update to 3.2.01 * Thu Dec 17 2020 Vasiliy N. Glazov vascom2@gmail.com - 3.2.00-1 - Update to 3.2.00 --------------------------------------------------------------------------------
================================================================================ mkrdns-3.3-5.20210224gitf6e8414.el7 (FEDORA-EPEL-2021-33b9ff9ceb) Automatic reverse DNS zone generator -------------------------------------------------------------------------------- Update Information:
Updated to latest git commit to include license file -------------------------------------------------------------------------------- ChangeLog:
* Wed Feb 24 2021 Christian Schuermann spike@fedoraproject.org 3.3-5.20210224gitf6e8414 - Updated to latest git commit to include license file * Tue Jan 26 2021 Fedora Release Engineering releng@fedoraproject.org - 3.3-4.20190902git6b3f3a4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Tue Jul 28 2020 Fedora Release Engineering releng@fedoraproject.org - 3.3-3.20190902git6b3f3a4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Wed Jan 29 2020 Fedora Release Engineering releng@fedoraproject.org - 3.3-2.20190902git6b3f3a4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ mono-6.8.0-2.el7 (FEDORA-EPEL-2021-0d0df7a3d3) Cross-platform, Open Source, .NET development framework -------------------------------------------------------------------------------- Update Information:
fix for Process.Start -------------------------------------------------------------------------------- ChangeLog:
* Mon Feb 22 2021 Timotheus Pokorra timotheus.pokorra@solidcharity.com - 6.8.0-2 - backport patch: fix early return in Process.Start (#1839410) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1839410 - URLs don't open: Cannot find the specified file https://bugzilla.redhat.com/show_bug.cgi?id=1839410 --------------------------------------------------------------------------------
================================================================================ nagios-4.4.6-2.el7 (FEDORA-EPEL-2021-0d9a06b878) Host/service/network monitoring program -------------------------------------------------------------------------------- Update Information:
Fix for CVE-2020-13977 BZ1849087 Fix systemd unit file permissions BZ1676334 Update to 4.4.6 -------------------------------------------------------------------------------- ChangeLog:
* Tue Feb 23 2021 Guido Aulisi guido.aulisi@gmail.com - 4.4.6-2 - Fix systemd unit file permissions #1676334 * Sat Feb 20 2021 Guido Aulisi guido.aulisi@gmail.com - 4.4.6-1 - Update to 4.4.6 - Fix for CVE-2020-13977 #BZ1849087 - Some spec cleanup -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1676334 - /usr/lib/systemd/system/nagios.service marked executable; please remove executable permission bits https://bugzilla.redhat.com/show_bug.cgi?id=1676334 [ 2 ] Bug #1829114 - nagios-4.4.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1829114 [ 3 ] Bug #1849087 - CVE-2020-13977 nagios: URL injection (post-authentication) vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1849087 --------------------------------------------------------------------------------
================================================================================ nordugrid-arc6-6.10.2-1.el7 (FEDORA-EPEL-2021-34ad34aead) Advanced Resource Connector Middleware -------------------------------------------------------------------------------- Update Information:
NorduGrid ARC 6.10.2 -------------------------------------------------------------------------------- ChangeLog:
* Wed Feb 24 2021 Mattias Ellert mattias.ellert@physics.uu.se - 6.10.2-1 - Update to version 6.10.2 * Mon Feb 15 2021 Mattias Ellert mattias.ellert@physics.uu.se - 6.10.1-1 - Update to version 6.10.1 * Wed Feb 10 2021 Mattias Ellert mattias.ellert@physics.uu.se - 6.10.0-1 - Update to version 6.10.0 - Drop RHEL6 support from spec file (EOL) --------------------------------------------------------------------------------
================================================================================ oval-graph-1.2.5-1.el7 (FEDORA-EPEL-2021-34f5f649a1) Tool for visualization of SCAP rule evaluation results -------------------------------------------------------------------------------- Update Information:
1.2.5 (Jan Rodak) -------------------------------------------------------------------------------- ChangeLog:
* Tue Feb 23 2021 Packit Service user-cont-team+packit-service@redhat.com - 1.2.5-1 - 1.2.5 (Jan Rodak) - Removes unnecessary parameter verbose (Jan Rodak) - Creates tests for search rules ids (Jan Rodak) - Updates referenc result data json (Jan Rodak) - Reworks clients uint tests (Jan Rodak) - Fixes problem displaying test information (Jan Rodak) - Appends missing gif to css (Jan Rodak) - Fixes errors in the browser console (Jan Rodak) - Moves client tests to a separate directory (Jan Rodak) - Fixes imports in tests (Jan Rodak) - Reworks classes for processing commands (Jan Rodak) - Reworks the client class and create children according to input and output (Jan Rodak) - Moves client parts to a separate directory (Jan Rodak) - Fixes problem with entry points (Jan Rodak) - Fixes links (Jan Rodak) - Adds information about test suite (Jan Rodak) - Fixes tests and removes skip missing lib (Jan Rodak) - Creates requirements (Jan Rodak) - Creates flake8 config (Jan Rodak) - Creates tox config (Jan Rodak) - Fix loading of ARF results when comment node is missing. (Gabriel Becker) - Updates gitignore (Jan Rodak) * Tue Jan 26 2021 Fedora Release Engineering releng@fedoraproject.org - 1.2.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ php-horde-Horde-Db-2.4.1-1.el7 (FEDORA-EPEL-2021-8ae24bc0a9) Horde Database Libraries -------------------------------------------------------------------------------- Update Information:
**Horde_Db 2.4.1** * [jan] Fix compatibility with PostgreSQL 12+ (Ivan Sergio Borgonovo). * [jan] Fix sequences on PostgreSQL 10+ (Ivan Sergio Borgonovo). * [mjr] Fix connecting over SSL with MySQLi driver (PR #2, PaulSzymanski). -------------------------------------------------------------------------------- ChangeLog:
* Wed Feb 24 2021 Remi Collet remi@remirepo.net - 2.4.1-1 - update to 2.4.1 - use weak and range dependencies --------------------------------------------------------------------------------
================================================================================ python-amqp-2.4.2-1.el7 (FEDORA-EPEL-2021-f29aced25b) Low-level AMQP client for Python (fork of amqplib) -------------------------------------------------------------------------------- Update Information:
- Enabled Python 3 support for entire celery stack - Updated kombu to 4.3.0 : https://github.com/celery/kombu/blob/master/Changelog.rst#430 - Updated vine to 1.3.0 : https://github.com/celery/vine/blob/master/Changelog#L40 - Updated celery to 4.2.2 : https://github.com/celery/celery/blob/c3ba8856b2c6f33a2ec35869 4180ddd56c86cabd/Changelog#L11 - Updated amqp to 2.4.2 : https://github.com/celery/py-amqp/blob/master/Changelog#L221 -------------------------------------------------------------------------------- ChangeLog:
* Sat Oct 3 2020 Frantisek Zatloukal fzatlouk@redhat.com - 2.4.2-1 - Update to 2.4.2 - Enable Python 3 on RHEL 7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1794858 - Request for python3-celery.noarch on EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1794858 --------------------------------------------------------------------------------
================================================================================ python-apprise-0.9.1-2.el7 (FEDORA-EPEL-2021-8e23cd2aeb) A simple wrapper to many popular notification services used today -------------------------------------------------------------------------------- Update Information:
Added missing cryptography dependency -------------------------------------------------------------------------------- ChangeLog:
* Tue Feb 23 2021 Chris Caron lead2gold@gmail.com - 0.9.1-2 - Added missing cryptography dependency * Tue Feb 23 2021 Chris Caron lead2gold@gmail.com - 0.9.1-1 - Updated to v0.9.1
-* Wed Jan 27 2021 Fedora Release Engineering releng@fedoraproject.org - 0.9.0-3 -- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ python-billiard-3.5.0.5-2.el7 (FEDORA-EPEL-2021-f29aced25b) Multiprocessing Pool Extensions -------------------------------------------------------------------------------- Update Information:
- Enabled Python 3 support for entire celery stack - Updated kombu to 4.3.0 : https://github.com/celery/kombu/blob/master/Changelog.rst#430 - Updated vine to 1.3.0 : https://github.com/celery/vine/blob/master/Changelog#L40 - Updated celery to 4.2.2 : https://github.com/celery/celery/blob/c3ba8856b2c6f33a2ec35869 4180ddd56c86cabd/Changelog#L11 - Updated amqp to 2.4.2 : https://github.com/celery/py-amqp/blob/master/Changelog#L221 -------------------------------------------------------------------------------- ChangeLog:
* Sat Oct 3 2020 Frantisek Zatloukal fzatlouk@redhat.com - 1:3.5.0.5-2 - Enable Python 3 on RHEL 7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1794858 - Request for python3-celery.noarch on EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1794858 --------------------------------------------------------------------------------
================================================================================ python-celery-4.2.2-1.el7 (FEDORA-EPEL-2021-f29aced25b) Distributed Task Queue -------------------------------------------------------------------------------- Update Information:
- Enabled Python 3 support for entire celery stack - Updated kombu to 4.3.0 : https://github.com/celery/kombu/blob/master/Changelog.rst#430 - Updated vine to 1.3.0 : https://github.com/celery/vine/blob/master/Changelog#L40 - Updated celery to 4.2.2 : https://github.com/celery/celery/blob/c3ba8856b2c6f33a2ec35869 4180ddd56c86cabd/Changelog#L11 - Updated amqp to 2.4.2 : https://github.com/celery/py-amqp/blob/master/Changelog#L221 -------------------------------------------------------------------------------- ChangeLog:
* Sat Oct 3 2020 Frantisek Zatloukal fzatlouk@redhat.com - 4.2.2-1 - Update to 4.2.2 - Enable Python 3 on RHEL 7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1794858 - Request for python3-celery.noarch on EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1794858 --------------------------------------------------------------------------------
================================================================================ python-kombu-4.3.0-1.el7 (FEDORA-EPEL-2021-f29aced25b) An AMQP Messaging Framework for Python -------------------------------------------------------------------------------- Update Information:
- Enabled Python 3 support for entire celery stack - Updated kombu to 4.3.0 : https://github.com/celery/kombu/blob/master/Changelog.rst#430 - Updated vine to 1.3.0 : https://github.com/celery/vine/blob/master/Changelog#L40 - Updated celery to 4.2.2 : https://github.com/celery/celery/blob/c3ba8856b2c6f33a2ec35869 4180ddd56c86cabd/Changelog#L11 - Updated amqp to 2.4.2 : https://github.com/celery/py-amqp/blob/master/Changelog#L221 -------------------------------------------------------------------------------- ChangeLog:
* Sat Oct 3 2020 Frantisek Zatloukal fzatlouk@redhat.com - 1:4.3.0-1 - Update to 4.3.0 - Enable Python 3 on RHEL 7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1794858 - Request for python3-celery.noarch on EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1794858 --------------------------------------------------------------------------------
================================================================================ python-vine-1.3.0-1.el7 (FEDORA-EPEL-2021-f29aced25b) Promises, promises, promises -------------------------------------------------------------------------------- Update Information:
- Enabled Python 3 support for entire celery stack - Updated kombu to 4.3.0 : https://github.com/celery/kombu/blob/master/Changelog.rst#430 - Updated vine to 1.3.0 : https://github.com/celery/vine/blob/master/Changelog#L40 - Updated celery to 4.2.2 : https://github.com/celery/celery/blob/c3ba8856b2c6f33a2ec35869 4180ddd56c86cabd/Changelog#L11 - Updated amqp to 2.4.2 : https://github.com/celery/py-amqp/blob/master/Changelog#L221 -------------------------------------------------------------------------------- ChangeLog:
* Sat Oct 3 2020 Frantisek Zatloukal fzatlouk@redhat.com - 1.3.0-1 - Update to 1.3.0 - Enable Python 3 on RHEL 7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1794858 - Request for python3-celery.noarch on EPEL7 https://bugzilla.redhat.com/show_bug.cgi?id=1794858 --------------------------------------------------------------------------------
================================================================================ reg-0.15.5-8.el7 (FEDORA-EPEL-2021-1a4a1045f5) Docker registry v2 command line client -------------------------------------------------------------------------------- Update Information:
Fix %postun directive. Apply patch to js sources to fix webpage search (https://pagure.io/fedora-infrastructure/issue/9678). -------------------------------------------------------------------------------- ChangeLog:
* Wed Jan 27 2021 Fedora Release Engineering releng@fedoraproject.org - 0.15.5-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Wed Jul 29 2020 Fedora Release Engineering releng@fedoraproject.org - 0.15.5-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Sun Jun 14 2020 Athos Ribeiro athoscr@fedoraproject.org - 0.15.5-6 - Fix image search * Thu Apr 23 2020 Mattia Verga mattia.verga@protonmail.com - 0.15.5-5 - Fix %postun directive * Thu Jan 30 2020 Fedora Release Engineering releng@fedoraproject.org - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Fri Jul 26 2019 Fedora Release Engineering releng@fedoraproject.org - 0.15.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Feb 2 2019 Fedora Release Engineering releng@fedoraproject.org - 0.15.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ rpkg-1.62-3.el7 (FEDORA-EPEL-2021-47ecb8d826) Python library for interacting with rpm+git -------------------------------------------------------------------------------- Update Information:
A small patch that fixes connecting rpkg to koji via SSL (login_koji_session). The method is used when koji.conf has "authtype = ssl". This mode is not enabled by default, but for example, rfpkg tool uses this. The issue happened when koji-1.24 removed deprecated argument ('ca') from method login_koji_session. -------------------------------------------------------------------------------- ChangeLog:
* Wed Feb 24 2021 Ond��ej Nosek onosek@redhat.com - 1.62-3 - Patch: ca cert was removed on koji-1.24.0 * Wed Jan 27 2021 Fedora Release Engineering releng@fedoraproject.org - 1.62-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ wireguard-tools-1.0.20210223-1.el7 (FEDORA-EPEL-2021-3d2fa6f006) Fast, modern, secure VPN tunnel -------------------------------------------------------------------------------- Update Information:
- wg-quick: android: do not free iterated pointer - wg-quick: openbsd: no use for userspace support - embeddable-wg-library: sync latest from netlink.h - wincompat: recent mingw has inet_ntop/inet_pton - wincompat: add resource and manifest and enable lto - wincompat: do not elevate by default - completion: add help and syncconf completions - sticky-sockets: do not use SO_REUSEADDR - man: LOG_LEVEL variables changed name - ipc: do not use fscanf with trailing \n - ipc: read trailing responses after set operation -------------------------------------------------------------------------------- ChangeLog:
* Tue Feb 23 2021 Joe Doss joe@solidadmin.com - 1.0.20210223-1 - wg-quick: android: do not free iterated pointer - wg-quick: openbsd: no use for userspace support - embeddable-wg-library: sync latest from netlink.h - wincompat: recent mingw has inet_ntop/inet_pton - wincompat: add resource and manifest and enable lto - wincompat: do not elevate by default - completion: add help and syncconf completions - sticky-sockets: do not use SO_REUSEADDR - man: LOG_LEVEL variables changed name - ipc: do not use fscanf with trailing \n - ipc: read trailing responses after set operation * Wed Jan 27 2021 Fedora Release Engineering releng@fedoraproject.org - 1.0.20200827-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Fri Oct 2 2020 Joe Doss joe@solidadmin.com - 1.0.20200827-2 - Disable contrib/dns-hatchet/apply.sh on Fedora 33+ and RHEL9+ - Prevent RPM from including python3 from doc macro for EPEL7 --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org