https://bugzilla.redhat.com/show_bug.cgi?id=1737785
Bug ID: 1737785
Summary: CVE-2019-1010238 pango: heap based buffer overflow can
be used to get code execution
Product: Security Response
Hardware: All
OS: Linux
Status: NEW
Component: vulnerability
Keywords: Security
Severity: high
Priority: high
Assignee: security-response-team(a)redhat.com
Reporter: mrehak(a)redhat.com
CC: caillon+fedoraproject(a)gmail.com,
eng-i18n-bugs(a)redhat.com,
fonts-bugs(a)lists.fedoraproject.org,
gnome-sig(a)lists.fedoraproject.org,
i18n-bugs(a)lists.fedoraproject.org,
john.j5live(a)gmail.com, mclasen(a)redhat.com,
pwu(a)redhat.com, rhughes(a)redhat.com,
rstrode(a)redhat.com, sandmann(a)redhat.com,
tagoh(a)redhat.com
Target Milestone: ---
Classification: Other
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The
heap based buffer overflow can be used to get code execution. The component is:
function name: pango_log2vis_get_embedding_levels, assignment of nchars and the
loop condition. The attack vector is: Bug can be used when application pass
invalid utf-8 strings to functions like pango_itemize.
External References:
https://packetstormsecurity.com/files/153838/USN-4081-1.txt
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1735152
Bug ID: 1735152
Summary: eclipse-nls: FTBFS in Fedora rawhide/f31
Product: Fedora
Version: rawhide
Status: NEW
Component: eclipse-nls
Assignee: sean+rh(a)flanigan.org
Reporter: releng(a)fedoraproject.org
QA Contact: extras-qa(a)fedoraproject.org
CC: i18n-bugs(a)lists.fedoraproject.org,
petersen(a)redhat.com, sean+rh(a)flanigan.org
Blocks: 1732841
Target Milestone: ---
Classification: Fedora
eclipse-nls failed to build from source in Fedora rawhide/f31
https://koji.fedoraproject.org/koji/taskinfo?taskID=36633177
For details on the mass rebuild see:
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Please fix eclipse-nls at your earliest convenience and set the bug's status to
ASSIGNED when you start fixing it. If the bug remains in NEW state for 8 weeks,
eclipse-nls will be orphaned. Before branching of Fedora 32,
eclipse-nls will be retired, if it still fails to build.
For more details on the FTBFS policy, please visit:
https://fedoraproject.org/wiki/Fails_to_build_from_source
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1732841
[Bug 1732841] (F31FTBFS) - Fedora 31 FTBFS Tracker
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1739051
Bug ID: 1739051
Summary: tomoe-gtk depends on Python 2
Product: Fedora
Version: rawhide
Status: NEW
Component: tomoe-gtk
Assignee: extras-orphan(a)fedoraproject.org
Reporter: lbalhar(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: dingyichen(a)gmail.com, extras-orphan(a)fedoraproject.org,
i18n-bugs(a)lists.fedoraproject.org, tfujiwar(a)redhat.com
Blocks: 1698500 (F31_PY2REMOVAL)
Target Milestone: ---
Classification: Fedora
Python 2.7 will reach end-of-life in January 2020, over 9 years after it was
released. This falls within the Fedora 31 lifetime.
Packages that depend on Python 2 are being switched to Python 3 or removed from
Fedora:
https://fedoraproject.org/wiki/Changes/F31_Mass_Python_2_Package_Removal#In…
Python 2 will be retired in Fedora 32:
https://fedoraproject.org/wiki/Changes/RetirePython2
To help planning, we'd like to know the plans for tomoe-gtk's future.
Specifically:
- What is the reason for the Python2 dependency? (Is it software written in
Python, or does it just provide Python bindings, or use Python in the build
system or test runner?)
- What are the upstream/community plans/timelines regarding Python 3?
- What is the guidance for porting to Python 3? (Assuming that there is someone
who generally knows how to port to Python 3, but doesn't know anything about
the particular package, what are the next steps to take?)
This bug is filed semi-automatically, and might not have all the context
specific to tomoe-gtk.
If you need anything from us, or something is unclear, please mention it here.
Thank you.
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1698500
[Bug 1698500] F31 Mass Python 2 Package Removal
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1748187
Bug ID: 1748187
Summary: cannot install the best update candidate for package
liberation-fonts-1:2.00.5-3.fc30.noarch
Product: Fedora
Version: 30
Hardware: x86_64
OS: Linux
Status: NEW
Component: liberation-narrow-fonts
Severity: high
Assignee: vishalvijayraghavan(a)gmail.com
Reporter: sascha(a)peilicke.de
QA Contact: extras-qa(a)fedoraproject.org
CC: i18n-bugs(a)lists.fedoraproject.org,
psatpute(a)redhat.com, vishalvijayraghavan(a)gmail.com
Target Milestone: ---
Classification: Fedora
Description of problem:
$ sudo dnf upgrade --best --allowerasing --skip-broken
Last metadata expiration check: 0:01:01 ago on Di 03 Sep 2019 08:17:06 CEST.
Error:
Problem: cannot install the best update candidate for package
liberation-fonts-1:2.00.5-3.fc30.noarch
- cannot install both liberation-fonts-1:2.00.5-1.fc30.noarch and
liberation-fonts-1:2.00.5-3.fc30.noarch
- problem with installed package liberation-narrow-fonts-1.07.6-1.fc30.noarch
- cannot install the best update candidate for package
liberation-narrow-fonts-1.07.6-1.fc30.noarch
$ dnf list installed | grep liberation
liberation-fonts.noarch 1:2.00.5-3.fc30 @updates
liberation-fonts-common.noarch 1:2.00.5-3.fc30 @updates
liberation-mono-fonts.noarch 1:2.00.5-3.fc30 @updates
liberation-narrow-fonts.noarch 1.07.6-1.fc30 @fedora
liberation-sans-fonts.noarch 1:2.00.5-3.fc30 @updates
liberation-serif-fonts.noarch 1:2.00.5-3.fc30 @updates
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1761089
Bug ID: 1761089
Summary: Request to package fcitx and other fcitx libraries on
EPEL 8
Product: Fedora EPEL
Version: epel8
Status: NEW
Component: fcitx
Assignee: liangsuilong(a)gmail.com
Reporter: jatin1812(a)protonmail.com
QA Contact: extras-qa(a)fedoraproject.org
CC: i18n-bugs(a)lists.fedoraproject.org, i(a)cicku.me,
liangsuilong(a)gmail.com, pwu(a)redhat.com,
robinlee.sysu(a)gmail.com
Target Milestone: ---
Classification: Fedora
We do have fcitx in EPEL 7 repos, RHEL 8/ CentOS 8 need fcitx in EPEL 8
repositories :)
--
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=1762523
Bug ID: 1762523
Summary: Please build scim in normal EPEL8
Product: Fedora EPEL
Version: epel7
Status: NEW
Component: scim
Assignee: pwu(a)redhat.com
Reporter: tdawson(a)redhat.com
QA Contact: extras-qa(a)fedoraproject.org
CC: i18n-bugs(a)lists.fedoraproject.org,
petersen(a)redhat.com, pwu(a)redhat.com,
shawn.p.huang(a)gmail.com
Target Milestone: ---
Classification: Fedora
Please build scim in EPEL8
--
You are receiving this mail because:
You are on the CC list for the bug.