The following Fedora 22 Security updates need testing: Age URL 45 https://admin.fedoraproject.org/updates/FEDORA-2015-4531/quassel-0.11.0-2.fc... 39 https://admin.fedoraproject.org/updates/FEDORA-2015-5279/strongswan-5.3.0-1.... 32 https://admin.fedoraproject.org/updates/FEDORA-2015-5878/echoping-6.1-0.beta... 31 https://admin.fedoraproject.org/updates/FEDORA-2015-5948/asterisk-13.3.2-1.f... 25 https://admin.fedoraproject.org/updates/FEDORA-2015-6169/openstack-glance-20... 10 https://admin.fedoraproject.org/updates/FEDORA-2015-7329/drupal7-views-3.11-... 9 https://admin.fedoraproject.org/updates/FEDORA-2015-7383/python-keystonemidd... 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7725/wordpress-4.2.2-1.f... 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7708/php-ZendFramework2-... 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7730/suricata-2.0.8-1.fc... 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7993/LibRaw-0.16.1-6.fc2... 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7997/libssh-0.7.0-1.fc22
The following Fedora 22 Critical Path updates have yet to be approved: Age URL 3 https://admin.fedoraproject.org/updates/FEDORA-2015-7322/mash-0.6.16-1.fc22 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7981/xorg-x11-xinit-1.3.... 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7997/libssh-0.7.0-1.fc22 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7922/lorax-22.11-1.fc22 0 https://admin.fedoraproject.org/updates/FEDORA-2015-7761/Thunar-1.6.8-1.fc22
The following builds have been pushed to Fedora 22 updates-testing
LibRaw-0.16.1-6.fc22 appstream-data-22-8.fc22 ccache-3.2.2-1.fc22 devassistant-0.11.1-2.fc22 eclipse-rse-3.7.0-1.fc22 gnome-abrt-1.1.2-2.fc22 golang-github-prometheus-client_golang-0.5.0-1.fc22 ibus-libzhuyin-1.7.2-1.fc22 iok-2.1.3-7.fc22 liborigin-20080225-14.fc22 libsidplayfp-1.7.2-1.fc22 libssh-0.7.0-1.fc22 libzhuyin-1.0.1-1.fc22 m17n-db-1.7.0-3.fc22 nodejs-sqlite3-3.0.8-1.fc22 nodejs-srs-0.4.8-1.fc22 opendkim-2.10.2-1.fc22 openstack-trove-2014.2.3-4.fc22 perl-Class-Accessor-Lite-0.08-1.fc22 perl-List-Compare-0.50-1.fc22 perl-Test-Script-1.09-1.fc22 perl-threads-lite-0.034-1.fc22 python-django-rest-framework-3.1.1-3.fc22 spice-gtk-0.28-3.fc22 tangerine-0.19-1.fc22 timedatex-0.3-1.fc22 webkitgtk-2.4.8-4.fc22 xorg-x11-server-1.17.1-11.fc22 xorg-x11-xinit-1.3.4-8.fc22 yast2-devtools-3.1.32-1.fc22
Details about builds:
================================================================================ LibRaw-0.16.1-6.fc22 (FEDORA-2015-7993) Library for reading RAW files obtained from digital photo cameras -------------------------------------------------------------------------------- Update Information:
Fixed dcraw vulnerability in ljpeg_start() -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Jon Ciesla limburgher@gmail.com - 0.16.1-1 - 0.16.1, BZ 1220382. * Sat May 2 2015 Kalev Lember kalevlember@gmail.com - 0.16.0-5 - Rebuilt for GCC 5 C++11 ABI change -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1220382 - LibRaw-0.16.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220382 --------------------------------------------------------------------------------
================================================================================ appstream-data-22-8.fc22 (FEDORA-2015-7990) Fedora AppStream metadata -------------------------------------------------------------------------------- Update Information:
New metadata version, this time with all the webapps. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Richard Hughes richard@hughsie.com 22-8 - New metadata version, this time with all the webapps. --------------------------------------------------------------------------------
================================================================================ ccache-3.2.2-1.fc22 (FEDORA-2015-7998) C/C++ compiler cache -------------------------------------------------------------------------------- Update Information:
Update to 3.2.2.
https://ccache.samba.org/releasenotes.html#_ccache_3_2_2 -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Ville Skyttä ville.skytta@iki.fi - 3.2.2-1 - Update to 3.2.2 - Add bunch of missing cross-gcc and c++ symlink triggers (#1205187) - Fix cross-gcc symlink ownerships -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1205187 - ccache not enabled for aarch64 C++ cross compiler https://bugzilla.redhat.com/show_bug.cgi?id=1205187 [ 2 ] Bug #1190507 - Fix breakage of -fplugin=libcc1plugin https://bugzilla.redhat.com/show_bug.cgi?id=1190507 [ 3 ] Bug #1220187 - ccache-3.2.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220187 --------------------------------------------------------------------------------
================================================================================ devassistant-0.11.1-2.fc22 (FEDORA-2015-8001) DevAssistant - Making life easier for developers -------------------------------------------------------------------------------- Update Information:
Make the GNOME 3 icon work -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Miro Hrončok mhroncok@redhat.com - 0.11.1-2 - Add upstream patch to make the GNOME 3 icon work --------------------------------------------------------------------------------
================================================================================ eclipse-rse-3.7.0-1.fc22 (FEDORA-2015-7978) Eclipse Remote System Explorer -------------------------------------------------------------------------------- Update Information:
- Update to upstream 3.7.0 release. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Alexander Kurtakov akurtako@redhat.com 3.7.0-1 - Update to upstream 3.7.0 release. --------------------------------------------------------------------------------
================================================================================ gnome-abrt-1.1.2-2.fc22 (FEDORA-2015-7742) A utility for viewing problems that have occurred with the system -------------------------------------------------------------------------------- Update Information:
- Add symbolic icon - Use own window header also in GNOME Classic - Let the theme handle the colour in the problems list - Remove border's custom style in the problems list -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Matej Habrnal mhabrnal@redhat.com - 1.1.2-2 - Translations update * Tue May 5 2015 Matej Habrnal mhabrnal@redhat.com - 1.1.2-1 - Add symbolic icon - Use own window header also in GNOME Classic - Let the theme handle the colour in the problems list - Remove border's custom style in the problems list --------------------------------------------------------------------------------
================================================================================ golang-github-prometheus-client_golang-0.5.0-1.fc22 (FEDORA-2015-7992) Prometheus instrumentation library for Go applications -------------------------------------------------------------------------------- Update Information:
Bump to upstream b0bd7e1be33327b85cb4853e7011156e3cedd657 -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 jchaloup jchaloup@redhat.com - 0.5.0-1 - Bump to upstream b0bd7e1be33327b85cb4853e7011156e3cedd657 related: #1214784 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1214784 - Tracker for golang-github-prometheus-client_golang https://bugzilla.redhat.com/show_bug.cgi?id=1214784 --------------------------------------------------------------------------------
================================================================================ ibus-libzhuyin-1.7.2-1.fc22 (FEDORA-2015-7989) New Zhuyin engine based on libzhuyin for IBus -------------------------------------------------------------------------------- Update Information:
new upstream release. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Peng Wu pwu@redhat.com - 1.7.2-1 - Update to 1.7.2 * Sat May 2 2015 Kalev Lember kalevlember@gmail.com - 1.7.1-2 - Rebuilt for GCC 5 C++11 ABI change --------------------------------------------------------------------------------
================================================================================ iok-2.1.3-7.fc22 (FEDORA-2015-7979) Indic Onscreen Virtual Keyboard -------------------------------------------------------------------------------- Update Information:
Add appdata file -------------------------------------------------------------------------------- ChangeLog:
* Thu May 7 2015 Parag Nemade <pnemade AT redhat DOT com>- 2.1.3-7 - Add appdata file --------------------------------------------------------------------------------
================================================================================ liborigin-20080225-14.fc22 (FEDORA-2015-7994) Library for reading OriginLab OPJ project files -------------------------------------------------------------------------------- Update Information:
This update ensures that the version/release of the package in Fedora 22 and Rawhide is higher than in Fedora 21. It also fixes failing rebuilds. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Nils Philippsen nils@redhat.com 2008525-14 - remove bad conditional, use %_lib instead of testing %__isa_bits * Sun Aug 17 2014 Fedora Release Engineering rel-eng@lists.fedoraproject.org - 20080225-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ libsidplayfp-1.7.2-1.fc22 (FEDORA-2015-7975) SID chip music module playing library -------------------------------------------------------------------------------- Update Information:
- New 1.7.2 upstream bugfix release -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Hans de Goede hdegoede@redhat.com - 1.7.2-1 - New upstream release 1.7.2 (rhbz#1220146) * Sat May 2 2015 Kalev Lember kalevlember@gmail.com - 1.7.1-2 - Rebuilt for GCC 5 C++11 ABI change -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1220146 - libsidplayfp-1.7.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220146 --------------------------------------------------------------------------------
================================================================================ libssh-0.7.0-1.fc22 (FEDORA-2015-7997) A library implementing the SSH protocol -------------------------------------------------------------------------------- Update Information:
Update to version 0.7.0 Security fix for CVE-2015-3146 -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Andreas Schneider asn@redhat.com - 0.7.0-1 - Update to version 0.7.0 * Added support for ed25519 keys * Added SHA2 algorithms for HMAC * Added improved and more secure buffer handling code * Added callback for auth_none_function * Added support for ECDSA private key signing * Added more tests * Fixed a lot of bugs * Improved API documentation * Thu Apr 30 2015 Andreas Schneider asn@redhat.com - 0.6.5-1 - resolves: #1213775 - Security fix for CVE-2015-3146 - resolves: #1218076 - Security fix for CVE-2015-3146 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1213775 - CVE-2015-3146 libssh: null pointer dereference due to a logical error in the handling of a SSH_MSG_NEWKEYS and KEXDH_REPLY packets https://bugzilla.redhat.com/show_bug.cgi?id=1213775 --------------------------------------------------------------------------------
================================================================================ libzhuyin-1.0.1-1.fc22 (FEDORA-2015-7989) Library to deal with zhuyin -------------------------------------------------------------------------------- Update Information:
new upstream release. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Peng Wu pwu@redhat.com - 1.0.1-1 - Update to 1.0.1 * Sat May 2 2015 Kalev Lember kalevlember@gmail.com - 1.0.0-2 - Rebuilt for GCC 5 C++11 ABI change --------------------------------------------------------------------------------
================================================================================ m17n-db-1.7.0-3.fc22 (FEDORA-2015-7985) Multilingualization datafiles for m17n-lib -------------------------------------------------------------------------------- Update Information:
Fixed e. mappings for Gujarati and Marathi itrans (rh#1129917) -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Parag Nemade <pnemade AT redhat DOT com> - 1.7.0-3 - Fixed e. mappings for Gujarati and Marathi itrans (rh#1129917) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1129917 - [gu_IN] Gujarati and Hindi itrans method misprints characters. https://bugzilla.redhat.com/show_bug.cgi?id=1129917 --------------------------------------------------------------------------------
================================================================================ nodejs-sqlite3-3.0.8-1.fc22 (FEDORA-2015-7976) Asynchronous, non-blocking SQLite3 bindings for Node.js -------------------------------------------------------------------------------- Update Information:
Updates to new upstream releases -------------------------------------------------------------------------------- ChangeLog:
* Sat May 9 2015 Tom Hughes tom@compton.nu - 3.0.8-1 - Update to 3.0.8 upstream release * Wed May 6 2015 Tom Hughes tom@compton.nu - 3.0.7-1 - Update to 3.0.7 upstream release * Tue May 5 2015 Tom Hughes tom@compton.nu - 3.0.6-1 - Update to 3.0.6 upstream release * Sat May 2 2015 Kalev Lember kalevlember@gmail.com - 3.0.5-2 - Rebuilt for GCC 5 C++11 ABI change -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1213036 - nodejs-srs-0.4.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1213036 [ 2 ] Bug #1218463 - nodejs-sqlite3-3.0.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1218463 --------------------------------------------------------------------------------
================================================================================ nodejs-srs-0.4.8-1.fc22 (FEDORA-2015-7976) Spatial reference library for Node.js -------------------------------------------------------------------------------- Update Information:
Updates to new upstream releases -------------------------------------------------------------------------------- ChangeLog:
* Fri May 8 2015 Tom Hughes tom@compton.nu - 0.4.8-1 - Update to 0.4.8 upstream release * Sat Apr 18 2015 Tom Hughes tom@compton.nu - 0.4.7-1 - Update to 0.4.7 upstream release -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1213036 - nodejs-srs-0.4.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1213036 [ 2 ] Bug #1218463 - nodejs-sqlite3-3.0.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1218463 --------------------------------------------------------------------------------
================================================================================ opendkim-2.10.2-1.fc22 (FEDORA-2015-7987) A DomainKeys Identified Mail (DKIM) milter to sign and/or verify mail -------------------------------------------------------------------------------- Update Information:
- Updated to use newer upstream 2.10.2 source code - Removed patches for bugs fixed in upstream source - Included support for systemd macros - Added deprecated options notice to default configuration file - Added new options to default configuration file - Updated README.fedora with additional SQL useage info -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Steve Jenkins steve@stevejenkins.com - 2.10.2-1 - Updated to use newer upstream 2.10.2 source code - Removed patches for bugs fixed in upstream source - Included support for systemd macros - Added deprecated options notice to default configuration file - Added new options to default configuration file - Updated README.fedora with additional SQL useage info -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1220390 - opendkim-2.10.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220390 --------------------------------------------------------------------------------
================================================================================ openstack-trove-2014.2.3-4.fc22 (FEDORA-2015-7977) OpenStack DBaaS (trove) -------------------------------------------------------------------------------- Update Information:
Fix mysql configuration paths in the guestmanager -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Victoria Martinez de la Cruz vkmc@fedoraproject.org - 2014.2.3-4 - Fix mysql configuration paths in the guestmanager * Wed May 6 2015 Victoria Martinez de la Cruz vkmc@fedoraproject.org - 2014.2.3-3 - Remove deps to mariadb service to openstack-trove-{api,conductor,taskmanager} and adds restarts on failure * Thu Apr 16 2015 Haïkel Guémar hguemar@fedoraproject.org - 2014.2.3-2 - Add deps to mariadb service to openstack-trove-{api,conductor,taskmanager} * Wed Apr 15 2015 Haikel Guemar hguemar@fedoraproject.org - 2014.2.3-1 - Update to upstream 2014.2.3 - Add missing requirements to python-netifaces (RHBZ#1205950) - Add dep to mariadb.service to openstack-trove-guestagent (RHBZ#1209584) --------------------------------------------------------------------------------
================================================================================ perl-Class-Accessor-Lite-0.08-1.fc22 (FEDORA-2015-7996) Minimalistic variant of Class::Accessor -------------------------------------------------------------------------------- Update Information:
-------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Ralf Corsépius corsepiu@fedoraproject.org - 0.08-1 - Upstream update. --------------------------------------------------------------------------------
================================================================================ perl-List-Compare-0.50-1.fc22 (FEDORA-2015-7980) Compare elements of two or more lists -------------------------------------------------------------------------------- Update Information:
Improve performance of is_LsubsetR. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Petr Šabata contyk@redhat.com - 0.50-1 - 0.50 bump, performance improvements * Thu Mar 12 2015 Petr Šabata contyk@redhat.com - 0.49-1 - 0.49 bump, metadata updates -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1220089 - perl-List-Compare-0.50 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220089 --------------------------------------------------------------------------------
================================================================================ perl-Test-Script-1.09-1.fc22 (FEDORA-2015-7995) Cross-platform basic tests for scripts -------------------------------------------------------------------------------- Update Information:
-------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Ralf Corsépius corsepiu@fedoraproject.org - 1.09-1 - Upstream update. - Reflect upstream Source0: having changed. - Reflect upstream BR-changes. - Modernize spec. --------------------------------------------------------------------------------
================================================================================ perl-threads-lite-0.034-1.fc22 (FEDORA-2015-7984) Actor model threading for Perl -------------------------------------------------------------------------------- Update Information:
This release fixes unquoted curly brackets in regular expression and importing symbols in a test. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Petr Pisar ppisar@redhat.com - 0.034-1 - 0.034 bump -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1220001 - perl-threads-lite-0.034 is available https://bugzilla.redhat.com/show_bug.cgi?id=1220001 --------------------------------------------------------------------------------
================================================================================ python-django-rest-framework-3.1.1-3.fc22 (FEDORA-2015-8000) Web APIs for Django, made easy -------------------------------------------------------------------------------- Update Information:
initial packaging (rhbz#1197605) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1197605 - Review Request: python-django-rest-framework - Web APIs for Django, made easy https://bugzilla.redhat.com/show_bug.cgi?id=1197605 --------------------------------------------------------------------------------
================================================================================ spice-gtk-0.28-3.fc22 (FEDORA-2015-7983) A GTK+ widget for SPICE clients -------------------------------------------------------------------------------- Update Information:
Fix audio and usb channels with GNOME Boxes. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Marc-Andre Lureau marcandre.lureau@redhat.com 0.28-3 - Fix audio and usb channels with GNOME Boxes. Resolves: rhbz#1220026 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1220026 - [gnome-boxes] sound is not working https://bugzilla.redhat.com/show_bug.cgi?id=1220026 --------------------------------------------------------------------------------
================================================================================ tangerine-0.19-1.fc22 (FEDORA-2015-7991) Perl dependency metadata tool -------------------------------------------------------------------------------- Update Information:
This release fixes archive diff handling. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 4 2015 Petr Šabata contyk@redhat.com - 0.19-1 - 0.19 bugfix bump * Mon May 4 2015 Petr Šabata contyk@redhat.com - 0.18-1 - 0.18 bugfix bump -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1217355 - diff mode with tarballs does not seem to work https://bugzilla.redhat.com/show_bug.cgi?id=1217355 [ 2 ] Bug #1217453 - tangerine-0.18 is available https://bugzilla.redhat.com/show_bug.cgi?id=1217453 --------------------------------------------------------------------------------
================================================================================ timedatex-0.3-1.fc22 (FEDORA-2015-7988) D-Bus service for system clock and RTC settings -------------------------------------------------------------------------------- Update Information:
This update fixes SELinux context setting on /etc/localtime when changing timezone after installation from live image. -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Miroslav Lichvar mlichvar@redhat.com 0.3-1 - update to 0.3 (#1190377) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1190377 - SELinux is preventing polkitd from 'read' accesses on the lnk_file localtime. https://bugzilla.redhat.com/show_bug.cgi?id=1190377 --------------------------------------------------------------------------------
================================================================================ webkitgtk-2.4.8-4.fc22 (FEDORA-2015-7999) GTK+ Web content engine library -------------------------------------------------------------------------------- Update Information:
Add Fedora branding to the user agent -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Tomas Popela tpopela@redhat.com - 2.4.8-4 - Add Fedora branding to the user agent --------------------------------------------------------------------------------
================================================================================ xorg-x11-server-1.17.1-11.fc22 (FEDORA-2015-7981) X.Org X11 X server -------------------------------------------------------------------------------- Update Information:
- Fix explicitly specifying a vt on which to start x not working, e.g. "startx -- vt7" -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Hans de Goede hdegoede@redhat.com - 1.17.1-11 - Fix "start -- vt7" not working (#1203780) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1203780 - startx stopped to work for me as user https://bugzilla.redhat.com/show_bug.cgi?id=1203780 --------------------------------------------------------------------------------
================================================================================ xorg-x11-xinit-1.3.4-8.fc22 (FEDORA-2015-7981) X.Org X11 X Window System xinit startup scripts -------------------------------------------------------------------------------- Update Information:
- Fix explicitly specifying a vt on which to start x not working, e.g. "startx -- vt7" -------------------------------------------------------------------------------- ChangeLog:
* Thu Apr 30 2015 Hans de Goede hdegoede@redhat.com - 1.3.4-8 - Only set XORG_RUN_AS_USER_OK when no vt is specified (#1203780) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1203780 - startx stopped to work for me as user https://bugzilla.redhat.com/show_bug.cgi?id=1203780 --------------------------------------------------------------------------------
================================================================================ yast2-devtools-3.1.32-1.fc22 (FEDORA-2015-7986) YaST Development Tools -------------------------------------------------------------------------------- Update Information:
new upstream release -------------------------------------------------------------------------------- ChangeLog:
* Mon May 11 2015 Björn Esser bjoern.esser@gmail.com - 3.1.32-1 - new upstream release - add `-Wobsolete`-flag to autoreconf - remove Patch0 and Patch1, since they are merged into upstream - use conditional and more elaborate test-invocation --------------------------------------------------------------------------------