[SECURITY] Fedora 16 Update: python-paste-script-1.7.5-4.fc16
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-2418
2012-02-25 07:55:25
--------------------------------------------------------------------------------
Name : python-paste-script
Product : Fedora 16
Version : 1.7.5
Release : 4.fc16
URL : http://pythonpaste.org/script
Summary : A pluggable command-line frontend
Description :
Paster is pluggable command-line frontend, including commands to setup package
file layouts
Built-in features:
* Creating file layouts for packages.
For instance a setuptools-ready file layout.
* Serving up web applications, with configuration based on paste.deploy
--------------------------------------------------------------------------------
Update Information:
This update fixes a security flaw with Paster that prevents it from properly dropping privileges when run as root.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 27 2012 Luke Macken <lmacken(a)redhat.com> - 1.7.5-4
- Remove the conflicting tests module (#797813)
* Thu Feb 23 2012 Luke Macken <lmacken(a)redhat.com> - 1.7.5-3
- Apply a patch from upstream to fix a security issue when running Paster as
root (#796790)
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> - 1.7.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Tue Nov 8 2011 Luke Macken <lmacken(a)redhat.com> - 1.7.5-1
- Update to 1.7.5
* Fri Oct 28 2011 Luke Macken <lmacken(a)redhat.com> - 1.7.4.2-1
- Update to 1.7.4.2
- Update the unbundle patch
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #796790 - CVE-2012-0878 python-paste-script: Supplementary groups not dropped when started an application with "paster serve" as root
https://bugzilla.redhat.com/show_bug.cgi?id=796790
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update python-paste-script' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 1 month
Fedora 16 Update: paraview-3.14.0-3.fc16
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5007
2012-03-31 02:13:40
--------------------------------------------------------------------------------
Name : paraview
Product : Fedora 16
Version : 3.14.0
Release : 3.fc16
URL : http://www.paraview.org/
Summary : Parallel visualization application
Description :
ParaView is an application designed with the need to visualize large data
sets in mind. The goals of the ParaView project include the following:
* Develop an open-source, multi-platform visualization application.
* Support distributed computation models to process large data sets.
* Create an open, flexible, and intuitive user interface.
* Develop an extensible architecture based on open standards.
ParaView runs on distributed and shared memory parallel as well as single
processor systems and has been successfully tested on Windows, Linux and
various Unix workstations and clusters. Under the hood, ParaView uses the
Visualization Toolkit as the data processing and rendering engine and has a
user interface written using a unique blend of Tcl/Tk and C++.
NOTE: The version in this package has NOT been compiled with MPI support.
Install the paraview-openmpi package to get a version compiled with openmpi.
Install the paraview-mpich2 package to get a version compiled with mpich2.
--------------------------------------------------------------------------------
Update Information:
Only remove vtk conflicting binaries
--------------------------------------------------------------------------------
ChangeLog:
* Thu Mar 29 2012 Orion Poplawski <orion(a)cora.nwra.com> - 3.14.0-3
- Only remove vtk conflicting binaries (bug #807756)
* Wed Feb 29 2012 Orion Poplawski <orion(a)cora.nwra.com> - 3.14.0-2
- Add patch to make vtk use system libraries
* Wed Feb 29 2012 Orion Poplawski <orion(a)cora.nwra.com> - 3.14.0-1
- Update to 3.14.0
- Rebase gcc47 patch
- Try to handle python install problems manually
* Tue Feb 28 2012 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> - 3.12.0-8
- Rebuilt for c++ ABI breakage
* Fri Jan 27 2012 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-7
- Build with gcc 4.7
- Add patch to support gcc 4.7
- Build with new libOSMesa
* Tue Dec 27 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-6
- vtkPV*Python.so needs to go into the paraview python dir
- Drop chrpath
* Fri Dec 16 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-5
- Oops, install vtk*Python.so, not libvtk*Python.so
* Mon Dec 12 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-4
- Install more libvtk libraries by hand and manually remove rpath
* Fri Dec 9 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-3
- Add patch from Petr Machata to build with boost 1.48.0
* Thu Dec 1 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-2
- Enable PARAVIEW_INSTALL_DEVELOPMENT and re-add -devel sub-package
- Install libvtk*Python.so by hand for now
* Thu Nov 10 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.12.0-1
- Update to 3.12.0
* Fri Oct 28 2011 Orion Poplawski <orion(a)cora.nwra.com> - 3.10.1-6
- Fixup forward paths for mpi versions (bug #748221)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #807756 - vtkWrapClientServer missing from paraview-devel package
https://bugzilla.redhat.com/show_bug.cgi?id=807756
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update paraview' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 1 month
[SECURITY] Fedora 15 Update: python-paste-script-1.7.5-4.fc15
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-2413
2012-02-25 07:55:12
--------------------------------------------------------------------------------
Name : python-paste-script
Product : Fedora 15
Version : 1.7.5
Release : 4.fc15
URL : http://pythonpaste.org/script
Summary : A pluggable command-line frontend
Description :
Paster is pluggable command-line frontend, including commands to setup package
file layouts
Built-in features:
* Creating file layouts for packages.
For instance a setuptools-ready file layout.
* Serving up web applications, with configuration based on paste.deploy
--------------------------------------------------------------------------------
Update Information:
This update fixes a security flaw with Paster that prevents it from properly dropping privileges when run as root.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 27 2012 Luke Macken <lmacken(a)redhat.com> - 1.7.5-4
- Remove the conflicting tests module (#797813)
* Thu Feb 23 2012 Luke Macken <lmacken(a)redhat.com> - 1.7.5-3
- Apply a patch from upstream to fix a security issue when running Paster as
root (#796790)
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> - 1.7.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Tue Nov 8 2011 Luke Macken <lmacken(a)redhat.com> - 1.7.5-1
- Update to 1.7.5
* Fri Oct 28 2011 Luke Macken <lmacken(a)redhat.com> - 1.7.4.2-1
- Update to 1.7.4.2
- Update the unbundle patch
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #796790 - CVE-2012-0878 python-paste-script: Supplementary groups not dropped when started an application with "paster serve" as root
https://bugzilla.redhat.com/show_bug.cgi?id=796790
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update python-paste-script' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 1 month
Fedora 17 Update: anaconda-17.18-1.fc17
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5323
2012-04-05 00:47:34.085061
--------------------------------------------------------------------------------
Name : anaconda
Product : Fedora 17
Version : 17.18
Release : 1.fc17
URL : http://fedoraproject.org/wiki/Anaconda
Summary : Graphical system installer
Description :
The anaconda package contains the program which was used to install your
system.
--------------------------------------------------------------------------------
Update Information:
Fix missing import, revert patch preventing updates=http from working
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update anaconda' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 2 months
Fedora 17 Update: mesa-8.0.2-2.fc17
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5322
2012-04-05 00:47:34
--------------------------------------------------------------------------------
Name : mesa
Product : Fedora 17
Version : 8.0.2
Release : 2.fc17
URL : http://www.mesa3d.org
Summary : Mesa graphics libraries
Description :
Mesa
--------------------------------------------------------------------------------
Update Information:
Default cirrus driver to 16bpp, and fix llvmpipe in Mesa for 16bpp.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #809052 - Gnome - Corrupted windows displaying
https://bugzilla.redhat.com/show_bug.cgi?id=809052
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update mesa' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 2 months
Fedora 17 Update: xorg-x11-drv-cirrus-1.3.2-19.fc17
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-5322
2012-04-05 00:47:34
--------------------------------------------------------------------------------
Name : xorg-x11-drv-cirrus
Product : Fedora 17
Version : 1.3.2
Release : 19.fc17
URL : http://www.x.org
Summary : Xorg X11 cirrus video driver
Description :
X.Org X11 cirrus video driver.
--------------------------------------------------------------------------------
Update Information:
Default cirrus driver to 16bpp, and fix llvmpipe in Mesa for 16bpp.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #809052 - Gnome - Corrupted windows displaying
https://bugzilla.redhat.com/show_bug.cgi?id=809052
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update xorg-x11-drv-cirrus' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 2 months
Fedora 17 Update: lorax-17.13-1.fc17
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-4838
2012-03-28 19:33:53
--------------------------------------------------------------------------------
Name : lorax
Product : Fedora 17
Version : 17.13
Release : 1.fc17
URL : http://git.fedorahosted.org/git/?p=lorax.git
Summary : Tool for creating the anaconda install images
Description :
Lorax is a tool for creating the anaconda install images.
It also includes livemedia-creator which is used to create bootable livemedia,
including live isos and disk images. It can use libvirtd for the install, or
Anaconda's image install feature.
--------------------------------------------------------------------------------
Update Information:
Add iscsi utils
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #804522 - anaconda failed to install using a software RAID device
https://bugzilla.redhat.com/show_bug.cgi?id=804522
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update lorax' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 2 months
Fedora 16 Update: python-pycallgraph-0.5.1-2.fc16
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-4711
2012-03-26 03:28:28
--------------------------------------------------------------------------------
Name : python-pycallgraph
Product : Fedora 16
Version : 0.5.1
Release : 2.fc16
URL : http://pycallgraph.slowchop.com
Summary : A module that creates call graphs for Python programs
Description :
Python Call Graph uses GraphViz to generate call graphs from one execution of
your Python code. It's very easy to use and can point out possible problems
with your code execution.
--------------------------------------------------------------------------------
Update Information:
Initial release of pycallgraph for Fedora and EPEL
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #803148 - Review Request: python-pycallgraph - A module that creates call graphs for Python programs
https://bugzilla.redhat.com/show_bug.cgi?id=803148
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update python-pycallgraph' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 2 months
Fedora 16 Update: python-meliae-0.4.0-2.fc16
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2012-4123
2012-03-17 23:03:11
--------------------------------------------------------------------------------
Name : python-meliae
Product : Fedora 16
Version : 0.4.0
Release : 2.fc16
URL : https://launchpad.net/meliae
Summary : Python memory usage statistics
Description :
"meliae" provides a way to dump python memory usage information to a JSON disk
format, which can then be parsed into useful things like graph representations.
The name is simply a fun word (means Ash-wood Nymph).
--------------------------------------------------------------------------------
Update Information:
A fairly major update of meliae
--------------------------------------------------------------------------------
ChangeLog:
* Tue Mar 13 2012 Luke Macken <lmacken(a)redhat.com> - 0.4.0-2
- Add python-simplejson to the BuildRequires to fix a couple of unit tests
* Tue Jan 24 2012 David Malcolm <dmalcolm(a)redhat.com> - 0.4.0-1
- 0.4.0
- drop upstream patch 1 (meliae-0.2.0-fix-builtintype-heap-assertion.patch)
- add a %check section, running the upstream test suite
* Sat Jan 14 2012 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> - 0.2.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update python-meliae' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
12 years, 2 months