[SECURITY] Fedora 10 Update: mingw32-libpng-1.2.35-1.fc10
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-2131
2009-02-26 15:02:46
--------------------------------------------------------------------------------
Name : mingw32-libpng
Product : Fedora 10
Version : 1.2.35
Release : 1.fc10
URL : http://www.libpng.org/pub/png/
Summary : MinGW Windows Libpng library
Description :
MinGW Windows Libpng library.
--------------------------------------------------------------------------------
Update Information:
Update to libpng 1.2.35, to fix CVE-2009-0040.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #486355 - CVE-2009-0040 libpng arbitrary free() flaw
https://bugzilla.redhat.com/show_bug.cgi?id=486355
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update mingw32-libpng' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 9 Update: netactview-0.4.1-2.fc9
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-1815
2009-02-17 14:51:49
--------------------------------------------------------------------------------
Name : netactview
Product : Fedora 9
Version : 0.4.1
Release : 2.fc9
URL : http://heanet.dl.sourceforge.net/sourceforge/netactview
Summary : Graphical network connections viewer for Linux
Description :
Netactview is a graphical network connections viewer for Linux, similar in
functionality with Netstat. It includes features like process information,
host name retrieval, automatic refresh and sorting. It has a fully featured
GTK 2 graphical interface.
--------------------------------------------------------------------------------
Update Information:
Netactview is a graphical network connections viewer for Linux, similar in
functionality with Netstat. It includes features like process information, host
name retrieval, automatic refresh and sorting. It has a fully featured GTK 2
graphical interface.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #485580 - Review Request: netactview - Graphical network connections viewer for Linux
https://bugzilla.redhat.com/show_bug.cgi?id=485580
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update netactview' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 9 Update: perl-SystemC-Vregs-1.461-1.fc9
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-2130
2009-02-26 15:02:46
--------------------------------------------------------------------------------
Name : perl-SystemC-Vregs
Product : Fedora 9
Version : 1.461
Release : 1.fc9
URL : http://search.cpan.org/dist/SystemC-Vregs/
Summary : Utility routines used by vregs
Description :
A Vregs object contains a documentation "package" containing enumerations,
definitions, classes, and registers.
--------------------------------------------------------------------------------
Update Information:
new package
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update perl-SystemC-Vregs' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 10 Update: ntfs-3g-2009.2.1-2.fc10
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-1778
2009-02-17 14:51:12
--------------------------------------------------------------------------------
Name : ntfs-3g
Product : Fedora 10
Version : 2009.2.1
Release : 2.fc10
URL : http://www.ntfs-3g.org/
Summary : Linux NTFS userspace driver
Description :
The ntfs-3g driver is an open source, GPL licensed, third generation
Linux NTFS driver. It provides full read-write access to NTFS, excluding
access to encrypted files, writing compressed files, changing file
ownership, access right.
Technically it’s based on and a major improvement to the third
generation Linux NTFS driver, ntfsmount. The improvements include
functionality, quality and performance enhancements.
ntfs-3g features are being merged to ntfsmount. In the meanwhile,
ntfs-3g is currently the only free, as in either speech or beer, NTFS
driver for Linux that supports unlimited file creation and deletion.
--------------------------------------------------------------------------------
Update Information:
Update .fdi file to fix nautilus automounting.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 16 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:2009.2.1-2
- update fdi to fix nautilus mount bug
* Thu Feb 12 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:2009.2.1-1
- update to 2009.2.1
* Fri Jan 30 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:2009.1.1-1
- new release, new versioning scheme from upstream
* Thu Jan 8 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5222-0.2.RC
- move pkgconfig Requires to -devel package where it belongs
* Mon Dec 22 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5222-0.1.RC
- 1.5222-RC
* Tue Dec 2 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5130-1
- update to 1.5130
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #484779 - nautilus Cannot mount volume
https://bugzilla.redhat.com/show_bug.cgi?id=484779
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update ntfs-3g' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 10 Update: eigen2-2.0.0-1.fc10
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-1628
2009-02-13 03:20:53
--------------------------------------------------------------------------------
Name : eigen2
Product : Fedora 10
Version : 2.0.0
Release : 1.fc10
URL : http://eigen.tuxfamily.org/
Summary : A lightweight C++ template library for vector and matrix math
Description :
A lightweight C++ template library for vector and matrix math
--------------------------------------------------------------------------------
Update Information:
Final 2.0.0 release. See also release announcement:
http://listengine.tuxfamily.org/lists.tuxfamily.org/eigen/2009/02/msg0001...
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 2 2009 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-1
- eigen-2.0.0 (final)
* Wed Jan 28 2009 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-0.10.rc1
- eigen-2.0-rc1
* Thu Jan 22 2009 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-0.9.beta6
- eigen-2.0-beta6
* Fri Jan 9 2009 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-0.8.20090109svn
- eigen2-20090109svn snapshot
* Tue Jan 6 2009 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-0.7.beta5
- eigen-2.0-beta5
* Sun Jan 4 2009 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-0.6.beta4
- eigen-2.0-beta4
* Mon Dec 8 2008 Rex Dieter <rdieter(a)fedoraproject.org> 2.0-0.5.beta2
- eigen-2.0-beta2
- (re)enable buildtime test
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update eigen2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
[SECURITY] Fedora 9 Update: libpng-1.2.35-1.fc9
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-2128
2009-02-26 15:02:45
--------------------------------------------------------------------------------
Name : libpng
Product : Fedora 9
Version : 1.2.35
Release : 1.fc9
URL : http://www.libpng.org/pub/png/
Summary : A library of functions for manipulating PNG image format files
Description :
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format. PNG was
created to replace the GIF format, since GIF uses a patented data
compression algorithm.
Libpng should be installed if you need to manipulate PNG format image
files.
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2009-0040
--------------------------------------------------------------------------------
ChangeLog:
* Wed Feb 25 2009 Tom Lane <tgl(a)redhat.com> 2:1.2.35-1
- Update to libpng 1.2.35, to fix CVE-2009-0040
* Fri Jan 9 2009 Tom Lane <tgl(a)redhat.com> 2:1.2.34-1
- Update to libpng 1.2.34
* Sun Nov 2 2008 Tom Lane <tgl(a)redhat.com> 2:1.2.33-1
- Update to libpng 1.2.33
* Sat May 31 2008 Tom Lane <tgl(a)redhat.com> 2:1.2.29-1
- Update to libpng 1.2.29 (fixes low-priority security issue CVE-2008-1382)
Related: #441839
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #486355 - CVE-2009-0040 libpng arbitrary free() flaw
https://bugzilla.redhat.com/show_bug.cgi?id=486355
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libpng' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 9 Update: eigen2-2.0.0-1.fc9
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-1533
2009-02-12 23:39:51
--------------------------------------------------------------------------------
Name : eigen2
Product : Fedora 9
Version : 2.0.0
Release : 1.fc9
URL : http://eigen.tuxfamily.org/
Summary : A lightweight C++ template library for vector and matrix math
Description :
A lightweight C++ template library for vector and matrix math
--------------------------------------------------------------------------------
Update Information:
Final 2.0.0 release. See also release announcement:
http://listengine.tuxfamily.org/lists.tuxfamily.org/eigen/2009/02/msg0001...
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update eigen2' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
[SECURITY] Fedora 10 Update: mldonkey-2.9.7-3.fc10
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-2122
2009-02-26 15:02:36
--------------------------------------------------------------------------------
Name : mldonkey
Product : Fedora 10
Version : 2.9.7
Release : 3.fc10
URL : http://mldonkey.sourceforge.net
Summary : Client for several P2P networks
Description :
MLDonkey is a door to the 'donkey' network, a decentralized network used to
exchange big files on the Internet. It is written in a wonderful language,
called Objective-Caml, and present most features of the basic Windows donkey
client, plus some more:
- It should work on most UNIX-compatible platforms.
- You can remotely command your client, either by telnet (port 4000),
by a WEB browser (http://localhost:4080), or with a classical client
interface (see http://www.nongnu.org/mldonkey)
- You can connect to several servers, and each search will query all the
connected servers.
- You can select mp3s by bitrates in queries (useful ?).
- You can select the name of a downloaded file before moving it to your
incoming directory.
- You can have several queries in the graphical user interface at the same
time.
- You can remember your old queries results in the command-line interface.
- You can search in the history of all files you have seen on the network.
It can also access other peer-to-peer networks:
- BitTorrent
- Fasttrack
- FileTP (wget-clone)
- DC++
--------------------------------------------------------------------------------
Update Information:
Fix remote arbitrary file disclosure via a GET request with more than one
leading / (slash) character in the filename. Ver. 2.9.7
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #487132 - MLDonkey: remote arbitrary file disclosure via a GET request with more than one leading / (slash) character in the filename.
https://bugzilla.redhat.com/show_bug.cgi?id=487132
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update mldonkey' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 10 Update: setup-2.7.4-4.fc10
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-2121
2009-02-26 15:02:36
--------------------------------------------------------------------------------
Name : setup
Product : Fedora 10
Version : 2.7.4
Release : 4.fc10
URL : https://fedorahosted.org/setup/
Summary : A set of system configuration and setup files
Description :
The setup package contains a set of important system configuration and
setup files, such as passwd, group, and profile.
--------------------------------------------------------------------------------
Update Information:
fix non-portable redirect (&>) used in /etc/profile and /etc/bashrc which causes
spurious ksh login output
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 26 2009 Ondrej Vasik <ovasik(a)redhat.com> 2.7.4-4
- make output redirection work under ksh(#487419)
* Fri Jan 30 2009 Ondrej Vasik <ovasik(a)redhat.com> 2.7.4-3
- add gid 87 reservation for polkituser, add gid reservation
for group cdrom(:11), dialout(:18), tape(:33) , kvm (:36) ,
uidgid pair for pkiuser(17:17), uid for vdsm user (36:),
make uidgid file better parseable
- do not export INPUTRC(to respect just created ~/.inputrc)
- update procols to later IANA list(2008-04-18)
- update services to later IANA list(2008-11-17)
- add URL, few spec files fixes, mark /etc/protocols and
/etc/inputrc %config(noreplace)
- add support for ctrl+arrow keys in rxvt(#474110)
* Tue Nov 18 2008 Ondrej Vasik <ovasik(a)redhat.com> 2.7.4-2
- again process profile.d scripts in noninteractive shells,
but do not display stderr/stdout messages(#457243)
- fix wrong prompt for csh/tcsh (#443854)
- don't show error message about missing hostname in profile
(#301481)
- reserve rquotad port 875 in /etc/services (#455859)
- export PATH after processing profile.d scripts (#449286)
- assign gid's for audio (:63) and video (:39) group(#458843),
assign uidgid pair (52:52) for puppet (#471918)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #487419 - non-portable redirect (&>) used in /etc/profile causes spurious ksh login output
https://bugzilla.redhat.com/show_bug.cgi?id=487419
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update setup' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month
Fedora 9 Update: ntfs-3g-2009.2.1-2.fc9
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-1800
2009-02-17 14:51:34
--------------------------------------------------------------------------------
Name : ntfs-3g
Product : Fedora 9
Version : 2009.2.1
Release : 2.fc9
URL : http://www.ntfs-3g.org/
Summary : Linux NTFS userspace driver
Description :
The ntfs-3g driver is an open source, GPL licensed, third generation
Linux NTFS driver. It provides full read-write access to NTFS, excluding
access to encrypted files, writing compressed files, changing file
ownership, access right.
Technically it’s based on and a major improvement to the third
generation Linux NTFS driver, ntfsmount. The improvements include
functionality, quality and performance enhancements.
ntfs-3g features are being merged to ntfsmount. In the meanwhile,
ntfs-3g is currently the only free, as in either speech or beer, NTFS
driver for Linux that supports unlimited file creation and deletion.
--------------------------------------------------------------------------------
Update Information:
Update .fdi file to fix nautilus automounting.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 16 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:2009.2.1-2
- update fdi to fix nautilus mount bug
* Thu Feb 12 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:2009.2.1-1
- update to 2009.2.1
* Fri Jan 30 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:2009.1.1-1
- new release, new versioning scheme from upstream
* Thu Jan 8 2009 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5222-0.2.RC
- move pkgconfig Requires to -devel package where it belongs
* Mon Dec 22 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5222-0.1.RC
- 1.5222-RC
* Tue Dec 2 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5130-1
- update to 1.5130
* Wed Oct 29 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5012-4
- fix hal file to properly ignore internal recovery partitions
* Wed Oct 29 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5012-3
- fix hal file to cover all mount cases (thanks to Richard Hughes)
* Mon Oct 20 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5012-2
- add fdi file to enable hal automounting
* Wed Oct 15 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.5012-1
- update to 1.5012 (same code as 1.2926-RC)
* Mon Sep 22 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.2926-0.1.RC
- update to 1.2926-RC (rawhide, F10)
* Fri Aug 22 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.2812-1
- update to 1.2812
* Sat Jul 12 2008 Tom "spot" Callaway <tcallawa(a)redhat.com> - 2:1.2712-1
- update to 1.2712
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #484779 - nautilus Cannot mount volume
https://bugzilla.redhat.com/show_bug.cgi?id=484779
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update ntfs-3g' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
15 years, 1 month