Fedora 11 Update: rubygem-mixlib-cli-1.1.0-1.fc11
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-5401
2010-03-30 00:36:42
--------------------------------------------------------------------------------
Name : rubygem-mixlib-cli
Product : Fedora 11
Version : 1.1.0
Release : 1.fc11
URL : http://github.com/opscode/mixlib-cli
Summary : Simple ruby mixin for CLI interfaces
Description :
A simple mixin for CLI interfaces, including option parsing.
--------------------------------------------------------------------------------
Update Information:
New upstream version - moves to jeweler for gem creation.
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update rubygem-mixlib-cli' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 11 Update: tinc-1.0.12-1.fc11
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-4649
2010-03-16 23:02:46
--------------------------------------------------------------------------------
Name : tinc
Product : Fedora 11
Version : 1.0.12
Release : 1.fc11
URL : http://www.tinc-vpn.org/
Summary : A virtual private network daemon
Description :
tinc is a Virtual Private Network (VPN) daemon that uses tunnelling
and encryption to create a secure private network between hosts on
the Internet. Because the tunnel appears to the IP level network
code as a normal network device, there is no need to adapt any
existing software. This tunnelling allows VPN sites to share
information with each other over the Internet without exposing any
information to others.
--------------------------------------------------------------------------------
Update Information:
* Mon Mar 15 2010 Fabian Affolter <fabian(a)bernewireless.net> - 1.0.12-1 -
Updated to new upstream version 1.0.12
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update tinc' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: stonevpn-0.4.7-1.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-4587
2010-03-15 23:41:32
--------------------------------------------------------------------------------
Name : stonevpn
Product : Fedora 12
Version : 0.4.7
Release : 1.fc12
URL : http://github.com/lkeijser/stonevpn
Summary : Easy OpenVPN certificate and configuration management
Description :
StoneVPN allows you to manage OpenVPN certificates and create
configurations for Windows and Linux machines based on a
template. It can package everything into a zipfile and mail
it to a user.
--------------------------------------------------------------------------------
Update Information:
Fixed: certificates were generated with an incorrect serial number Fixed: bug
when listing all revoked certificates Fixed: check for existence of crlfile
before trying to parse it. Added: new option to generate an empty CRL file
Added: grouped all options to make --help output look better
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update stonevpn' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: nautilus-python-0.5.2-1.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-3524
2010-03-03 23:01:11
--------------------------------------------------------------------------------
Name : nautilus-python
Product : Fedora 12
Version : 0.5.2
Release : 1.fc12
URL : http://www.gnome.org/
Summary : Python bindings for Nautilus
Description :
Python bindings for Nautilus
--------------------------------------------------------------------------------
Update Information:
Fixes some bugs, including ones on 64-bit systems
--------------------------------------------------------------------------------
ChangeLog:
* Mon Mar 1 2010 Patrick Dignan <dignan.patrick at, gmail.com> - 0.5.2-1
- New upstream release removes need for two patches
* Thu Jan 28 2010 Patrick Dignan <dignan.patrick at, gmail.com>
- Fixed error with location of libpython
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #474428 - not loading 64 bit libpython on 64 bit platform
https://bugzilla.redhat.com/show_bug.cgi?id=474428
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update nautilus-python' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: wallpapoz-0.4.1-20.svn92_trunk.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-4866
2010-03-20 02:19:52
--------------------------------------------------------------------------------
Name : wallpapoz
Product : Fedora 12
Version : 0.4.1
Release : 20.svn92_trunk.fc12
URL : http://wallpapoz.akbarhome.com/
Summary : Gnome Multi Backgrounds and Wallpapers Configuration Tool
Description :
This tool enables your Gnome desktop to have different
wallpapers for different workspaces or virtual desktops.
--------------------------------------------------------------------------------
Update Information:
Some backtrace on daemon_wallpapoz is reported using ABRT. This seems to be
because some race condition occurred during initialization process of
daemon_wallpapoz under compiz. This new rpm will hopefully fix this issue.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 18 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-20.svn92_trunk
- Handle another potentially race condition under compiz (may fix 573642)
* Wed Mar 10 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-19.svn92_trunk
- Kill daemon_wallpapoz in more cases (may fix bug 571827)
* Mon Mar 1 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-18.svn92_trunk
- -compiz-respawn.patch: simplify
- Handle more cases where X is no longer available (bug 569135)
- Handle fork() failure (bug 566594)
* Fri Feb 26 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-17.svn92_trunk
- Another try for race condition on checking compiz status
(bug 567437)
* Wed Feb 10 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-16.svn92_trunk
- Don't update compiz status to fix race (bug 562943)
* Tue Feb 9 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-15.svn92_trunk
- Change the way to fix backtrace with no X resource issue
* Mon Feb 8 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-14.svn92_trunk
- Check if the selected item is really a directory on directory
chooser dialog (bug 549219)
- Avoid backtrace in case no item is selected yet (bug 555181)
- Avoid backtrace when trying to paste when no item is copyed yet
* Thu Feb 4 2010 Mamoru Tasaka <mtasaka(a)ioa.s.u-tokyo.ac.jp> - 0.4.1-12.svn92_trunk
- Some fixes for daemon_wallpapoz under compiz
(bug 531342, 542244)
- Kill daemon_wallpapoz when X resource is no longer avaiable
(bug 531343, 538533, 541434, 556377)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #573642 - [abrt] crash in wallpapoz-0.4.1-18.svn92_trunk.fc12: daemon_wallpapoz:161:<module>:IndexError: list index out of range
https://bugzilla.redhat.com/show_bug.cgi?id=573642
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update wallpapoz' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: libgadu-1.9.0-0.2.rc3.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-4512
2010-03-15 23:39:26
--------------------------------------------------------------------------------
Name : libgadu
Product : Fedora 12
Version : 1.9.0
Release : 0.2.rc3.fc12
URL : http://toxygen.net/libgadu/
Summary : A Gadu-gadu protocol compatible communications library
Description :
libgadu is intended to make it easy to add Gadu-Gadu communication
support to your software.
--------------------------------------------------------------------------------
Update Information:
Update to latest release candidate. Required by recent kadu.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Mar 14 2010 Dominik Mierzejewski <rpm(a)greysector.net> 1.9.0-0.2.rc3
- updated to 1.9.0-rc3
- adds basic support for new GG protocol (UTF-8 and new status messages)
- full upstream changelog (Polish only) http://toxygen.net/libgadu/releases/1.9.0-rc3.html
- disabled OpenSSL support (not used in practice),
fixes license trouble for GPL apps
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update libgadu' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: selinux-policy-3.6.32-106.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-5232
2010-03-24 22:19:02
--------------------------------------------------------------------------------
Name : selinux-policy
Product : Fedora 12
Version : 3.6.32
Release : 106.fc12
URL : http://oss.tresys.com/repos/refpolicy/
Summary : SELinux policy configuration
Description :
SELinux Reference Policy - modular.
Based off of reference policy: Checked out revision 2.20090730
--------------------------------------------------------------------------------
Update Information:
* Tue Mar 23 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-106 - Allow
mysqld_safe setsched, getsched - Allow logrotate to transition to sssd -
Allow snort to read and write generic USB devices - Add label for piranha log
files - Add qpidd policy from rawhide * Fri Mar 19 2010 Miroslav Grepl
<mgrepl(a)redhat.com> 3.6.32-105 - Fixes for nagios * Thu Mar 18 2010
Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-104 - Allow logrotate to transition
to asterisk - Allow xdm to transition to shutdown - Allow shutdown
dac_override - Allow samba sys_chroot
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 23 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-106
- Allow mysqld_safe setsched, getsched
- Allow logrotate to transition to sssd
- Allow snort to read and write generic USB devices
- Add label for piranha log files
- Add qpidd policy from rawhide
* Fri Mar 19 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-105
- Fixes for nagios
* Thu Mar 18 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-104
- Allow logrotate to transition to asterisk
- Allow xdm to transition to shutdown
- Allow shutdown dac_override
- Allow samba sys_chroot
* Mon Mar 15 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-103
- Add sosreport policy
* Mon Mar 15 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-102
- Allow bluetooth sys_admin capability
- Fix label for libADM libraries
- Allow libvirt to set svrit_image_t label on sysfs
- Add shutdown policy from Dan Walsh
* Wed Mar 10 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-101
- Allow nsplugin to manage pulseaudio homedir content
* Tue Mar 9 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-100
- Allow pulseaudio sys_tty_config capability
- Add label for cman_tool
- Fixes for corosync policy
- Allow abrt to get the attributes of all domains
- Allow abrt to read symbolic links on a NFS filesystem
* Fri Mar 5 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-99
- Add back etcfile attribute
* Fri Mar 5 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-98
- Allow modcluster to call getpwnam
- Allow useradd sys_ptrace capability
- Fixes for pulseaudio from Dan Walsh
- Allow swat to signal winbind
- Add label for mssql and allow apache to connect to this database port if boolean set
* Wed Mar 3 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-97
- Fixes for xserver from Dan Walsh
* Mon Mar 1 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-96
- Add cachefilesfd policy
- Update cobbler policy from F13
- Allow hald connect to usbmuxd over a unix domain
- Allow staff_t to read semanage module store
* Fri Feb 26 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-95
- Add fixes from Dan Walsh
* Fri Feb 26 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-94
- Fixes for MLS booting from Dan Walsh
* Thu Feb 25 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-93
- Fix wine dontaudit mmap_zero
- Add vbetool_mmap_zero_ignore boolean
- dontaudit acct using console
* Tue Feb 23 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-92
- Fixes for cluster policy
- Fixes for rgmanager
- Add label for /etc/pki dir in bind-chroot
- Allow system-config-firewall to send system log messages
- Remove label for Directory Server
* Wed Feb 17 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-91
- Add label for /opt/zimbra/log directory
- Add label for /usr/local/centreon/log directory
- Add label for /var/spool/bacula/log directory
- Add nagios_mail_plugin type for nagios mail plugins
- Do not audit attempts to search the network state directory for locate
- Allow ping read and write the console, all ttys and all ptys
- Allow pppd to send audit messages
- Allow modemmanager net_admin capability
- Fixes for cluster policy
* Fri Feb 12 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-90
- Allow dnsmasq to create log file
* Thu Feb 11 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-89
- Allow rpcd to read files with default file type
* Thu Feb 11 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-88
- Fixes for sandbox
- Allow quota to set priority of kernel threads
- Fixes for svirt
* Wed Feb 10 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-87
- Fixes for ipsec policy
- Allow pppd to get attributes of the modem devices
- Add label for /usr/share/e16/misc directory
* Tue Feb 9 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-86
- Allow mysql ipc_lock capability
- Allow passwd sys_nice capability
- Allow plymouth to read network config files
- Fixes for git
- Add label for /usr/sbin/ns-slapd
- Allow munin to list mail queue
- Add label for shorewall compiler
- Fixes for nagios plugin policy
- Allow auditctl to set priority of kernel threads
* Fri Feb 5 2010 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-85
- Cleanup spec file
* Thu Feb 4 2010 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-84
- Fix /var/lib labeling in post install
* Thu Feb 4 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-83
- Fixes for cluster policy
* Wed Feb 3 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-82
- Add label for /root/.Xdefaults
- Allow xauth to read symbolic links on a NFS filesystem
- Add label for /var/run/slim.lock
- Add mcelog policy
* Tue Feb 2 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-81
- Allow policykit-auth to set attributes on fonts cache directory
- Add label for RealPlayer plugins
- Add label for /usr/sbin/xrdp
- Allow chrome-sandbox to read gnome homedir content
- Allow rsyslogd to connect to MySQL using a unix domain stream socket
- Allow apache to list inotifyfs filesystem
- Add label for /dev/pps device
- Fixes for chronyd policy
* Mon Feb 1 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-80
- Allow xdm to execute octave
- Add label for var/run/lxdm.auth
- Allow pppd sys_admin capability
- Allow cups-pdf fowner capability
- Fix path for cluster binaries
- Fixes for pulseaudio
- Add label for /var/webmin directory
- Allow prelink execmod on files in home directory
- Allow cups-config to read process state of all user domains.
- Fixes for vmware policy
- Fixes for lirc policy
- Allow amavis to read utmp
* Fri Jan 29 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-79
- Fix rpm_dontaudit_leaks
- Fix typo in rgmanager.if
- Fixes for nis policy
* Wed Jan 27 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-78
- Allow to openvpn to read utmp
- Allow xdm to read the video4linux devices
- Add label for /etc/openldap/slapd.d directory
- Allow tgtd to manage fixed disk device nodes
- Allow chsh to execute nxserver
- Allow abrt_helper to send system log messages
- Add label for /etc/zabbix/web directory
- Add label for /sbin/mke4fs
* Mon Jan 25 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-77
- Allow xenstored to manage files on on a XENFS filesystem
- Allow cupsd to setattr on a fonts cache directory
- Allot smolt-client to send system log messages
* Fri Jan 22 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-76
- Add labeling for gitweb
- Allow plymouth to read and write the /dev/ptmx
- Fixes for sanbox
- Allow nagios_services_plugin_t to read snmpd libraries
* Thu Jan 21 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-75
- Allow sulogin to talk to console and tty_device_t
* Wed Jan 20 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-74
- Fixes for afs
- Remove transtion from system_cronjob to gpg domain
* Tue Jan 19 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-73
- Add labeling for /var/lib/avahi-autoipd directory
* Tue Jan 19 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-72
- Fixes for memcached from Dan Walsh
- Allow podsleuth to read user tmpfs files
- Allow tftpd to read system state information in proc
- Fixes for sssd from Dan Walsh
- Allow snmpd chown capability
* Fri Jan 15 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-71
- Allow hotplug to transition to brctl domain
- Fixes for sftpd
* Tue Jan 12 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-70
- Move users file to selection by spec file.
- Allow vncserver to run as unconfined_u:unconfined_r:unconfined_t
* Mon Jan 11 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-69
- Fixes for iscsid
- Allow openvpn to bind to http port
- Add wine_mmap_zero_ignore boolean
* Fri Jan 8 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-68
- Fixes for xenconsoled
- Allow xauth to connectto xserver_t unix_stream_socket
- Add textrel_shlib_t fixes
- Add labeling for LXDM
- Allow cupsd_lpd_t to setattr fontconfig directory
- Allow abrt to getattr on all character file device nodes.
- Add labeling for the rest nagios plugins
* Wed Jan 6 2010 Miroslav Grepl <mgrepl(a)redhat.com> 3.6.32-67
- Allow snmbd to send itself signal
- Allow virt_domain to read /dev/random
- Allow apcupsd to send itself signull
- Allow swat to transition to nmbd
- Add textrel_shlib_t label for /usr/local/lib/codecs/
* Mon Jan 4 2010 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-66
- Allow lircd to use tcp_socket and connect/bind to port 8675
* Wed Dec 30 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-65
- Allow traceroute to use all terms
- Fix mgetty use for faxes
- Dontaudit xdm listing fusefs
- Allow xguest to resolve host names
- Allow abrt to read noxattr filesystems (cdrom)
- Allow abrt_helper to send itself signals
- Allow amavis to read certs
- Allow apache to bind to port 3000 (Ruby on rails)
- Asterist uses mysql and snmp
- Allow consolekit to write wtmp file for shutdown
- Allow cups ipc_lock
- Allow hal to transition to ppp
- Fix mailman labels for 64 bit systems
- dontaudit system_mail access to leaked terminals
- Allow mysqld_safe_t to unlink mysqld pid files
- nrpe_t uses getpw calls
- Allow NetworkManager to delete ppp pid files
- Allow pptp_t to sens userdomain signals
- Allow prelude to connect to mysql
- Allow swat to start winbind server
- Fixes for snort
- Allow telnetd to setattr user terminals
- Allow qemu to read fusefs
- Allow domains that have telinit to connectto upstart unix_stream_socket
- Dontaudit ipsec_mgmt sys_tty_config
- Fix labels for postgrestgres test suite
- Other textrel_shlib_t fixes
* Wed Dec 23 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-64
- Update to Rawhide filesystem.if file
- Allow abrt to read nfs
- Allow cups to search fusefs
- Allow dovecot_auth to search var_log
- Fix label on ksmtuned.pid
- Dontaudit policykit looking at mount points
- Allow xdm to manage /var/cache/fontconfig
- Allow xenstored to search xenfs
* Tue Dec 22 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-63
- Allow sendmail setpgid
- Allow dovecot to read nfs homedirs
* Mon Dec 21 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-62
- Add label for /var/ekpd
- Allow portreserve to look at bin files
- Allow gssd to ask the kernel to load modules
- If you can run mount you can run fusermount
* Mon Dec 21 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-61
- Fixes for sandbox_x_server
- Fix ntop policy
- Sandbox fixes
* Fri Dec 18 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-60
- Fixs for cluster policy
- mysql_safe fixes
- Fixes for sssd
- Cgroup access for virtd
- Dontaudit fail2ban leaks
* Tue Dec 15 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-59
- Dontaudit udp_socket leaks for xauth_t
- Dontaudit rules for iceauth_t
- Let locate read symlinks on noxattr file systems
- Remove wine from unconfined domain if unconfined pp removed
- Add labels for vhostmd
- Add port 546 as a dhcpc port
- Add labeled for /dev/dahdi
- Add certmonger policy
- Allow sysadm to communicate with racoon and zebra
- Allow dbus service dbus_chat with unconfined_t
- Fixes for xguest
- Add dontaudits for abrt
- file contexts for mythtv
- Lots of fixes for asterisk
- Fix file context for certmaster
- Add log dir for dovecot
- Policy for ksmtuned
- File labeling and fixes for mysql and mysql_safe
- New plugin infrstructure for nagios
- Allow nut_upsd_t dac_override
- File context fixes for nx
- Allow oddjob_mkhomedir to create homedir
- Add pcscd_pub interfaces to be used by xdm
- Add stream connect from fenced to corosync
- Fixes for swat
- Allow fsdaemon to manage scsi devices
- Policy for tgtd
- Policy for vhostmd
- Allow ipsec to create tmp files
- Change label on fusermount
* Thu Dec 10 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-58
- Dontaudit udp_socket leaks for xauth_t
* Wed Dec 9 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-57
- Allow unconfined_t to send dbus messages to setroubleshoot
- Allow confined screen app to setattr on user ttys
- remove wine_t from unconfined domain when unconfined.pp disabled
- Allow sysadm_t to communicate with racoon
- Allow xauth to be run from all unconfined user types
- Fix labeling on all /var/cache/mod_* apps
- Allow asterisk to communicate with postgresql
- Fix labeling for /var/lib/certmaster
- Add policy for ksmtuned and tgtd
- Fixes fro vhostmd
* Mon Dec 7 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-56
- Dontaudit exec of fusermount from xguest
- Allow licrd to use mouse_device
- Allow sysadm_t to connect to zebra stream socket
- Dontaudit policykit_auth trying to config terminal
- Allow logrotate and asterisk to execute asterisk
- Allow logrotate to read var_lib files (zope) and connect to fail2ban stream
- Allow firewallgui to communicate with unconfined_t
- Allow podsleuth to ask the kernel to load modules
- Fix labeling on vhostmd scripts
- Remove transition from unconfined_t to windbind_helper_t
- Allow abrt_helper to look at inotify
- Fix labels for mythtv
- Allow apache to signal sendmail
- allow asterisk to send mail
- Allow rpcd to get and setcap
- Add tor_bind_all_unreserved_ports boolean
- Add policy for vhostmd
- MOre textrel_shlib_t files
- Add rw_herited_term_perms
* Thu Dec 3 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-55
- Add fprintd_chat(unconfined_t) to fix su timeout problem
- Make xguest follow allow_execstack boolean
- Dontaudit dbus looking at nfs
* Thu Dec 3 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-54
- Require selinux-policy from selinux-policy-TYPE
- Add labeling to /usr/lib/win32 textrel_shlib_t
- dontaudit all leaks for abrt_helper
- Fix labeling for mythtv
- Dontaudit setroubleshoot_fix leaks
- Allow xauth_t to read usr_t
- Allow iptables to use fifo files
- Fix labeling on /var/lib/wifiroamd
* Tue Dec 1 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-53
- Remove transition from dhcpc_t to consoletype_t, just allow exec
- Fixes for prelink cron job
- Fix label on yumex backend
- Allow unconfined_java_t to communicate with iptables
- Allow abrt to read /tmp files
- Fix nut/ups policy
* Tue Dec 1 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-52
- Major fixup of ntop policy
- Fix label on /usr/lib/xorg/modules/extensions/libglx.so.195.22
- Allow xdm to signal session bus
- Allow modemmanager to use generic ptys, and sys_tty_config capability
- Allow abrt_helper chown access, dontaudit leaks
- Allow logwatch to list cifs and nfs file systems
- Allow kismet to read network state
- Allow cupsd_config_t to connecto unconfined unix_stream
- Fix avahi labeling and allow avahi to manage /etc/resolv.conf
- Allow sshd to read usr_t files
- Allow login programs to manage pcscd_var_run_t files
- Allow tor to read usr_t files
* Wed Nov 25 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-51
- Mark google shared libraries as requiring textrel_shlib
- Allow svirt to bind/connect to network ports
- Add label for .libvirt directory.
* Tue Nov 24 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-50
- Allow modemmanager sys_admin
* Mon Nov 23 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-49
- Allow sssd to read all processes domain
* Mon Nov 23 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-48
- Abrt connect to any port
- Dontaudit chrome-sandbox trying to getattr on all processes
- Allow passwd to execute gnome-keyring
- Allow chrome_sandbox_t to read home content inherited from the parent
- Fix eclipse labeling
- Allow mozilla to connect to flash port
- Allow pulseaudio to connect to unix_streams
- Allow sambagui to read secrets file
- Allow mount to mount unlabeled files
- ALlow abrt to use ypbind, send kill signals
- Allow arpwatch to create socket class
- Allow asterisk to read urand
- Allow corosync to communicate with user tmpfs
- Allow devicedisk to read virt images block devices
- Allow gpsd to sys_tty_config
- Fix nagios interfaces
- Policy for nagios plugins
- Fixes for nx
- Allow rtkit_daemon to read locale file
- Allow snort to create socket
- Additional perms for xauth
- lots of textrel_lib_t file context
* Tue Nov 17 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-47
- Make mozilla call in execmem.if optional to fix build of minimum install
- Allow uucpd to execute shells and send mail
- Fix label on libtfmessbsp.so
* Mon Nov 16 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-46
- abrt needs more access to rpm pid files
- Abrt wants to execute its own tmp files
- abrt needs to write sysfs
- abrt needs to search all file system dirs
- logrotate and tmpreaper need to be able to manage abrt cache
- rtkit_daemon needs to be able to setsched on lots of user apps
- networkmanager creates dirs in /var/lib
- plymouth executes lvm tools
* Fri Nov 13 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-45
- Allow mount on dos file systems
- fixes for upsmon and upsd to be able to retrieve pwnam and resolve addresses
* Thu Nov 12 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-44
- Add lighttpd file context to apache.fc
- Allow tmpreaper to read /var/cache/yum
- Allow kdump_t sys_rawio
- Add execmem_exec_t context for /usr/bin/aticonfig
- Allow dovecot-deliver to signull dovecot
- Add textrel_shlib_t to /usr/lib/libADM5avcodec.so
* Tue Nov 10 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-43
- Fix transition so unconfined_exemem_t creates user_tmp_t
- Allow chrome_sandbox_t to write to user_tmp_t when printing
- Allow corosync to connect to port 5404 and to interact with user_tmpfs_t files
- Allow execmem_t to execmod files in mozilla_home_t
- Allow firewallgui to communicate with nscd
* Mon Nov 9 2009 Dan Walsh <dwalsh(a)redhat.com> 3.6.32-42
- Allow kdump to read the kernel core interface
- Dontaudit abrt read all files in home dir
- Allow kismet client to write to .kismet dir in homedir
- Turn on asterisk policy and allow logrotate to communicate with it
- Allow abrt to manage rpm cache files
- Rules to allow sysadm_t to install a kernel
- Allow local_login to read console_device_t to Z series logins
- Allow automount and devicekit_disk to search all filesystem dirs
- Allow corosync to setrlimit
- Allow hal to read modules.dep
- Fix xdm using pcscd
- Dontaudit gssd trying to write user_tmp_t, kerberos libary problem.
- Eliminate transition from unconifned_t to loadkeys_t
- Dontaudit several leaks to xauth_t
- Allow xdm_t to search for man pages
- Allow xdm_dbus to append to xdm log
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #571274 - SELinux is preventing /usr/libexec/nm-openconnect-service "create" access .
https://bugzilla.redhat.com/show_bug.cgi?id=571274
[ 2 ] Bug #572812 - SELinux is preventing /usr/sbin/httpd from using potentially mislabeled files apache_runtime_status.
https://bugzilla.redhat.com/show_bug.cgi?id=572812
[ 3 ] Bug #573414 - SELinux is preventing /usr/sbin/asterisk "write" access on /.
https://bugzilla.redhat.com/show_bug.cgi?id=573414
[ 4 ] Bug #573418 - SELinux is preventing /usr/bin/mono from using potentially mislabeled files file.
https://bugzilla.redhat.com/show_bug.cgi?id=573418
[ 5 ] Bug #573828 - SELinux is preventing /usr/libexec/lxdm-greeter-gtk "remove_name" access on lxdm.conf.8AEG9U.
https://bugzilla.redhat.com/show_bug.cgi?id=573828
[ 6 ] Bug #573884 - SELinux is preventing /usr/sbin/snmpd from binding to port 161.
https://bugzilla.redhat.com/show_bug.cgi?id=573884
[ 7 ] Bug #573885 - SELinux is preventing /usr/sbin/snmptrapd from connecting to port 161.
https://bugzilla.redhat.com/show_bug.cgi?id=573885
[ 8 ] Bug #574237 - SELinux is preventing /usr/libexec/gconfd-2 "append" access on /root/.gconfd/saved_state.
https://bugzilla.redhat.com/show_bug.cgi?id=574237
[ 9 ] Bug #574329 - SELinux is preventing /usr/lib/chromium-browser/chrome-sandbox access to a leaked udp_socket file descriptor.
https://bugzilla.redhat.com/show_bug.cgi?id=574329
[ 10 ] Bug #574523 - SELinux is preventing updatedb "getattr" access on /mnt/s2/SFU/dev/ttyn39.
https://bugzilla.redhat.com/show_bug.cgi?id=574523
[ 11 ] Bug #574581 - SELinux is preventing /opt/altera9.1sp1/quartus/linux/quartus from loading /opt/altera9.1sp1/quartus/linux/libccl_err.so which requires text relocation.
https://bugzilla.redhat.com/show_bug.cgi?id=574581
[ 12 ] Bug #574618 - SELinux is preventing /usr/lib/chromium-browser/chrome-sandbox "getattr" access on /.
https://bugzilla.redhat.com/show_bug.cgi?id=574618
[ 13 ] Bug #574619 - SELinux is preventing /usr/lib/chromium-browser/chromium-browser "read" access on cpuinfo_max_freq.
https://bugzilla.redhat.com/show_bug.cgi?id=574619
[ 14 ] Bug #574652 - SELinux is preventing /usr/sbin/smbd "sys_chroot" access .
https://bugzilla.redhat.com/show_bug.cgi?id=574652
[ 15 ] Bug #574941 - SELinux is preventing /usr/sbin/nagios "write" access on /var/spool/nagios/cmd.
https://bugzilla.redhat.com/show_bug.cgi?id=574941
[ 16 ] Bug #575056 - SELinux is preventing /usr/bin/chsh "open" access on /var/run/utmp.
https://bugzilla.redhat.com/show_bug.cgi?id=575056
[ 17 ] Bug #575179 - sssd requires manage privileges on krb5_host_rcache_t
https://bugzilla.redhat.com/show_bug.cgi?id=575179
[ 18 ] Bug #575319 - SELinux is preventing /sbin/setfiles access to a leaked /var/spool/at/spool/a000030142bc1e file descriptor.
https://bugzilla.redhat.com/show_bug.cgi?id=575319
[ 19 ] Bug #575454 - SELinux is preventing /usr/libexec/nm-openconnect-service "relabelfrom" access .
https://bugzilla.redhat.com/show_bug.cgi?id=575454
[ 20 ] Bug #575561 - SELinux is preventing /bin/nice "setsched" access. (mysqld_safe nice)
https://bugzilla.redhat.com/show_bug.cgi?id=575561
[ 21 ] Bug #575563 - SELinux is preventing /usr/sbin/logrotate "read" access on sssd.
https://bugzilla.redhat.com/show_bug.cgi?id=575563
[ 22 ] Bug #575645 - SELinux is preventing /usr/bin/nautilus "execute" access on linux.bin.
https://bugzilla.redhat.com/show_bug.cgi?id=575645
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update selinux-policy' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 11 Update: rubygem-bunny-0.6.0-1.fc11
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-5398
2010-03-30 00:36:38
--------------------------------------------------------------------------------
Name : rubygem-bunny
Product : Fedora 11
Version : 0.6.0
Release : 1.fc11
URL : http://github.com/celldee/bunny
Summary : Another synchronous Ruby AMQP client
Description :
A synchronous Ruby AMQP client that enables interaction with AMQP-compliant
brokers/servers.
--------------------------------------------------------------------------------
Update Information:
A synchronous Ruby AMQP client that enables interaction with AMQP-compliant
brokers/servers.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #574979 - Review Request: rubygem-bunny - Another synchronous Ruby AMQP client
https://bugzilla.redhat.com/show_bug.cgi?id=574979
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update rubygem-bunny' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: klavaro-1.5.0-1.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-3981
2010-03-09 03:00:25
--------------------------------------------------------------------------------
Name : klavaro
Product : Fedora 12
Version : 1.5.0
Release : 1.fc12
URL : http://klavaro.sourceforge.net/en/
Summary : Typing tutor
Description :
Klavaro is a touch typing tutor that is very flexible and supports
customizable keyboard layouts. Users can edit and save new or unknown
keyboard layouts, as the basic course provided by the program was
designed to not depend on specific layouts.
--------------------------------------------------------------------------------
Update Information:
* Sat Mar 06 2010 Fabian Affolter <fabian(a)bernewireless.net> - 1.5.0-1 -
Removed DSO linking fix - Updated to new upstream version 1.5.0
--------------------------------------------------------------------------------
ChangeLog:
* Sat Mar 6 2010 Fabian Affolter <fabian(a)bernewireless.net> - 1.5.0-1
- Updated to new upstream version 1.5.0
* Tue Jan 5 2010 Fabian Affolter <fabian(a)bernewireless.net> - 1.4.1-1
- Updated to new upstream version 1.4.1
* Fri Dec 18 2009 Fabian Affolter <fabian(a)bernewireless.net> - 1.4.0-1
- BR libsexy-devel removed
- Updated to new upstream version 1.4.0
* Mon Nov 16 2009 Fabian Affolter <fabian(a)bernewireless.net> - 1.3.6-1
- Updated to new upstream version 1.3.6
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update klavaro' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years
Fedora 12 Update: rednotebook-0.9.3-1.fc12
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-5397
2010-03-30 00:36:37
--------------------------------------------------------------------------------
Name : rednotebook
Product : Fedora 12
Version : 0.9.3
Release : 1.fc12
URL : http://rednotebook.sourceforge.net
Summary : A desktop diary
Description :
RedNotebook is a desktop diary that makes it very easy for you
to keep track of the stuff you do and the thoughts you have. This
journal software helps you to write whole passages or just facts,
and does so in style.
--------------------------------------------------------------------------------
Update Information:
* Wed Feb 24 2010 Christoph Wickert <cwickert(a)fedoraproject.org> - 0.9.3-1 -
Update to 0.9.3
--------------------------------------------------------------------------------
ChangeLog:
* Wed Feb 24 2010 Christoph Wickert <cwickert(a)fedoraproject.org> - 0.9.3-1
- Update to 0.9.3
* Mon Feb 1 2010 Christoph Wickert <cwickert(a)fedoraproject.org> - 0.9.2-1
- Update to 0.9.2
* Sun Jan 10 2010 Christoph Wickert <cwickert(a)fedoraproject.org> - 0.9.1-1
- Update to 0.9.1
- Require pywebkitgtk for new print preview
- Use desktop-file-install
* Fri Dec 18 2009 Christoph Wickert <cwickert(a)fedoraproject.org> - 0.9.0-1
- Update to 0.9.0
* Thu Nov 19 2009 Fabian Affolter <fabian(a)bernewireless.net> - 0.8.9-2
- Updated the URL after a request from the upstream maintainer
* Wed Nov 18 2009 Fabian Affolter <fabian(a)bernewireless.net> - 0.8.9-1
- Updated to new upstream version 0.8.9
* Mon Nov 16 2009 Fabian Affolter <fabian(a)bernewireless.net> - 0.8.8-1
- Updated to new upstream version 0.8.8
* Tue Sep 29 2009 Fabian Affolter <fabian(a)bernewireless.net> - 0.8.7-1
- Updated to new upstream version 0.8.7
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #573254 - [abrt] crash in rednotebook-0.9.0-1.fc12: redNotebook.py:392:exit:RuntimeError: called outside of a mainloop
https://bugzilla.redhat.com/show_bug.cgi?id=573254
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update rednotebook' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
14 years