The following Fedora 29 Security updates need testing:
Age URL
184
https://bodhi.fedoraproject.org/updates/FEDORA-2019-fa5843e0e1
asterisk-16.2.1-1.fc29
170
https://bodhi.fedoraproject.org/updates/FEDORA-2019-c84f291592
WALinuxAgent-2.2.38-1.fc29
165
https://bodhi.fedoraproject.org/updates/FEDORA-2019-7528388823
chicken-5.0.0-2.fc29
124
https://bodhi.fedoraproject.org/updates/FEDORA-2019-9839aded3f
python-gnupg-0.4.4-1.fc29
120
https://bodhi.fedoraproject.org/updates/FEDORA-2019-35cb5a4785
kubernetes-1.13.5-1.fc29
58
https://bodhi.fedoraproject.org/updates/FEDORA-2019-32f7cd9b66
dosbox-0.74.3-2.fc29
50
https://bodhi.fedoraproject.org/updates/FEDORA-2019-3f5c670a8f
thunderbird-60.8.0-1.fc29
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-8eeb8f9d3f
wavpack-5.1.0-16.fc29
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d9a2c03662 cups-2.2.8-12.fc29
7
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d0b1feb995
graphite2-1.3.13-1.fc29
5
https://bodhi.fedoraproject.org/updates/FEDORA-2019-1f17485159
python-mitogen-0.2.8-1.fc29
5
https://bodhi.fedoraproject.org/updates/FEDORA-2019-7a0b45fdc4
nginx-1.16.1-1.fc29
5
https://bodhi.fedoraproject.org/updates/FEDORA-2019-5e4316109b
qt5-qtwebengine-5.12.4-5.fc29
5
https://bodhi.fedoraproject.org/updates/FEDORA-2019-96516ce0ac
community-mysql-8.0.17-2.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-113d27cb80
chromium-76.0.3809.132-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-65db7ad6c7
golang-1.11.13-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e31c2f7d87
seamonkey-2.49.5-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-c1dac1b3b8 lxc-3.0.4-1.fc29
lxcfs-3.0.4-1.fc29 python3-lxc-3.0.4-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-a457303ffc
rdesktop-1.8.6-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d04f66e595 bind-9.11.10-1.fc29
bind-dyndb-ldap-11.1-19.fc29 dhcp-4.3.6-34.fc29 dnsperf-2.3.2-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-80e5e20cf8
pdfresurrect-0.18-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-59d60bd1fa
dovecot-2.3.7.2-1.fc29
2
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e00c65ec6f httpd-2.4.41-1.fc29
mod_md-2.0.8-3.fc29
2
https://bodhi.fedoraproject.org/updates/FEDORA-2019-97380355ae
kernel-5.2.11-100.fc29 kernel-headers-5.2.11-100.fc29 kernel-tools-5.2.11-100.fc29
2
https://bodhi.fedoraproject.org/updates/FEDORA-2019-77d612eab4
grafana-6.3.4-1.fc29
2
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d9c2f1ec70
roundcubemail-1.3.10-1.fc29
2
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e08f78d4a6 SDL-1.2.15-40.fc29
The following Fedora 29 Critical Path updates have yet to be approved:
Age URL
96
https://bodhi.fedoraproject.org/updates/FEDORA-2019-06a2d1c7fb
anaconda-29.24.7-3.fc29
94
https://bodhi.fedoraproject.org/updates/FEDORA-2019-4cefd3161a
nfs-utils-2.3.3-4.rc2.fc29
80
https://bodhi.fedoraproject.org/updates/FEDORA-2019-37faa13746
fontconfig-2.13.1-8.fc29
67
https://bodhi.fedoraproject.org/updates/FEDORA-2019-583d9d5a56
mutter-3.30.2-3.fc29
53
https://bodhi.fedoraproject.org/updates/FEDORA-2019-6f13c38d0d
python-urllib3-1.24.3-2.fc29
51
https://bodhi.fedoraproject.org/updates/FEDORA-2019-62e681b68b ipset-7.2-1.fc29
50
https://bodhi.fedoraproject.org/updates/FEDORA-2019-3f5c670a8f
thunderbird-60.8.0-1.fc29
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d9a2c03662 cups-2.2.8-12.fc29
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-8eeb8f9d3f
wavpack-5.1.0-16.fc29
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-54815c6381
linux-firmware-20190815-101.fc29
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-2a4d354f9b lz4-1.9.1-1.fc29
10
https://bodhi.fedoraproject.org/updates/FEDORA-2019-9de7632b6b bluez-5.50-4.fc29
9
https://bodhi.fedoraproject.org/updates/FEDORA-2019-c85c9971a5
perl-5.28.2-434.fc29
9
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e8002fd7bf
perl-Pod-Perldoc-3.28.01-419.fc29
8
https://bodhi.fedoraproject.org/updates/FEDORA-2019-68005b454d
vim-8.1.1912-1.fc29
7
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d0b1feb995
graphite2-1.3.13-1.fc29
7
https://bodhi.fedoraproject.org/updates/FEDORA-2019-8795529cd2
btrfs-progs-5.2.1-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-c010b35eb6
rpm-4.14.2.1-3.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-d04f66e595 bind-9.11.10-1.fc29
bind-dyndb-ldap-11.1-19.fc29 dhcp-4.3.6-34.fc29 dnsperf-2.3.2-1.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-29435c4ed5
samba-4.9.12-0.fc29
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-f93fcb9fbd
pcre2-10.33-13.fc29
2
https://bodhi.fedoraproject.org/updates/FEDORA-2019-97380355ae
kernel-5.2.11-100.fc29 kernel-headers-5.2.11-100.fc29 kernel-tools-5.2.11-100.fc29
The following builds have been pushed to Fedora 29 updates-testing
R-3.6.1-2.fc29
anki-2.1.15-1.fc29
dino-0.0-0.10.20190830.git.016ab2c.fc29
fuse3-3.6.2-1.fc29
libxcrypt-4.4.8-1.fc29
pcsc-cyberjack-3.99.5final.SP13-1.fc29
pdfbox-2.0.16-1.fc29
python-injector-0.17.0-1.fc29
rkward-0.7.0-9.fc29
rpy-2.9.5-4.fc29
Details about builds:
================================================================================
R-3.6.1-2.fc29 (FEDORA-2019-32499f9021)
A language for data analysis and graphics
--------------------------------------------------------------------------------
Update Information:
Update R to 3.6.1. ---- Update R to 3.6.0. Rebuild lapack with --no-optimize-
sibling-calls to work around gfortran issues (Fedora 30+ only).
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 30 2019 Tom Callaway <spot(a)fedoraproject.org> - 3.6.1-2
- conditionalize macro usage so that it only happens on Fedora 31+ and EPEL-8
* Fri Aug 16 2019 Tom Callaway <spot(a)fedoraproject.org> - 3.6.1-1
- update to 3.6.1
* Sun Aug 11 2019 Elliott Sales de Andrade <quantum.analyst(a)gmail.com> - 3.6.0-5
- Remove unused and nonfunctional macros and helper script
* Wed Jul 24 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 3.6.0-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Sun Jul 21 2019 Elliott Sales de Andrade <quantum.analyst(a)gmail.com> - 3.6.0-3
- Add automated dependency generator to R-devel
- Add standard Provides for bundled libraries
* Thu Jun 13 2019 Tom Callaway <spot(a)fedoraproject.org> - 3.6.0-2
- use devtoolset toolchain to compile on el6/el7 for C++11 support
* Wed May 29 2019 Tom Callaway <spot(a)fedoraproject.org> - 3.6.0-1
- update to 3.6.0
- use --no-optimize-sibling-calls for gfortran to work around issues
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1744723 - R-devel requires R-rpm-macros
https://bugzilla.redhat.com/show_bug.cgi?id=1744723
[ 2 ] Bug #1727281 - R-3.6.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1727281
[ 3 ] Bug #1703495 - R-3.6.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1703495
--------------------------------------------------------------------------------
================================================================================
anki-2.1.15-1.fc29 (FEDORA-2019-5cf60b7cad)
Flashcard program for using space repetition learning
--------------------------------------------------------------------------------
Update Information:
Update to new upstream release 2.1.15. Please see
https://apps.ankiweb.net/docs/changes.html for details.
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 23 2019 Christian Krause <chkr(a)fedoraproject.org> - 2.1.15-1
- Update to new upstream version 2.1.15 (BZ 1744359)
- Remove obsolete requirement python3-qt5-webkit
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1744359 - anki-2.1.15 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1744359
--------------------------------------------------------------------------------
================================================================================
dino-0.0-0.10.20190830.git.016ab2c.fc29 (FEDORA-2019-309d5af288)
Modern XMPP ("Jabber") Chat Client using GTK+/Vala
--------------------------------------------------------------------------------
Update Information:
Update dino to
[
016ab2c1](https://github.com/dino/dino/compare/8120203d...016ab2c1).
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 31 2019 Randy Barlow <bowlofeggs(a)fedoraproject.org> -
0.0-0.12.20190830.git.016ab2c1
- Update to 016ab2c1.
-
https://github.com/dino/dino/compare/8120203d...016ab2c1
--------------------------------------------------------------------------------
================================================================================
fuse3-3.6.2-1.fc29 (FEDORA-2019-8f885c1dc8)
File System in Userspace (FUSE) v3 utilities
--------------------------------------------------------------------------------
Update Information:
* fuse3 ver. 3.6.2
--------------------------------------------------------------------------------
ChangeLog:
* Sun Sep 1 2019 Peter Lemenkov <lemenkov(a)gmail.com> - 3.6.2-1
- Update to 3.6.2
* Thu Jul 25 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 3.6.1-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1728264 - fuse3-3.6.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1728264
--------------------------------------------------------------------------------
================================================================================
libxcrypt-4.4.8-1.fc29 (FEDORA-2019-ee93f54081)
Extended crypt library for descrypt, md5crypt, bcrypt, and others
--------------------------------------------------------------------------------
Update Information:
- New upstream release.
--------------------------------------------------------------------------------
ChangeLog:
* Sun Sep 1 2019 Bj��rn Esser <besser82(a)fedoraproject.org> - 4.4.8-1
- New upstream release
* Sat Aug 24 2019 Bj��rn Esser <besser82(a)fedoraproject.org> - 4.4.7-1
- New upstream release
* Thu Jul 25 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.4.6-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1747795 - libxcrypt-4.4.8 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1747795
--------------------------------------------------------------------------------
================================================================================
pcsc-cyberjack-3.99.5final.SP13-1.fc29 (FEDORA-2019-3d29392dd7)
PC/SC driver for REINER SCT cyberjack USB chip card reader
--------------------------------------------------------------------------------
Update Information:
* Update to new upstream version SP13 (rev cyberJack@1374)
--------------------------------------------------------------------------------
ChangeLog:
* Sun Sep 1 2019 Robert Scheck <robert(a)fedoraproject.org> - 3.99.5final.SP13-1
- Update to new upstream version SP13 (#1554806)
- Drop requirements for 'initscripts' from specfile (#1592381)
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> -
3.99.5final.SP12-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri Feb 1 2019 Fedora Release Engineering <releng(a)fedoraproject.org> -
3.99.5final.SP12-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1592381 - [pcsc-cyberjack] Drop requirements for 'initscripts' from
specfile
https://bugzilla.redhat.com/show_bug.cgi?id=1592381
[ 2 ] Bug #1554806 - pcsc-cyberjack-3.99.5final.SP13 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1554806
--------------------------------------------------------------------------------
================================================================================
pdfbox-2.0.16-1.fc29 (FEDORA-2019-6fa01d12b4)
Apache PDFBox library for working with PDF documents
--------------------------------------------------------------------------------
Update Information:
Update to 2.0.16
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 31 2019 Orion Poplawski <orion(a)nwra.com> - 2.0.16-1
- Update to 2.0.16 (CVE-2018-8036, CVE-2018-11797, CVE-2019-0228)
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.0.9-6
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri Feb 1 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.0.9-5
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1699742 - CVE-2019-0228 pdfbox: XML External Entity (XXE) attacks via a
crafted XFDF [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1699742
[ 2 ] Bug #1637494 - CVE-2018-11797 pdfbox: unbounded computation in parser resulting in
a denial of service [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1637494
[ 3 ] Bug #1597491 - CVE-2018-8036 pdfbox: Infinite loop in AFMParser.java allows for
out of memory erros via crafted PDF [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1597491
--------------------------------------------------------------------------------
================================================================================
python-injector-0.17.0-1.fc29 (FEDORA-2019-72c2965488)
Python dependency injection framework inspired by Guice
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Sun Sep 1 2019 Artem Polishchuk <ego.cordatus(a)gmail.com> - 0.17.0-1
- Update to 0.17.0
* Mon Aug 19 2019 Miro Hron��ok <mhroncok(a)redhat.com> - 0.16.1-3
- Rebuilt for Python 3.8
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.16.1-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
rkward-0.7.0-9.fc29 (FEDORA-2019-32499f9021)
Graphical frontend for R language
--------------------------------------------------------------------------------
Update Information:
Update R to 3.6.1. ---- Update R to 3.6.0. Rebuild lapack with --no-optimize-
sibling-calls to work around gfortran issues (Fedora 30+ only).
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 16 2019 Tom Callaway <spot(a)fedoraproject.org> - 0.7.0-9
- rebuild for R 3.6.1
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.7.0-8
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Thu May 30 2019 Tom Callaway <spot(a)fedoraproject.org> - 0.7.0-7
- rebuild for R 3.6.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1744723 - R-devel requires R-rpm-macros
https://bugzilla.redhat.com/show_bug.cgi?id=1744723
[ 2 ] Bug #1727281 - R-3.6.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1727281
[ 3 ] Bug #1703495 - R-3.6.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1703495
--------------------------------------------------------------------------------
================================================================================
rpy-2.9.5-4.fc29 (FEDORA-2019-32499f9021)
Python interface to the R language
--------------------------------------------------------------------------------
Update Information:
Update R to 3.6.1. ---- Update R to 3.6.0. Rebuild lapack with --no-optimize-
sibling-calls to work around gfortran issues (Fedora 30+ only).
--------------------------------------------------------------------------------
ChangeLog:
* Sat Aug 17 2019 Tom Callaway <spot(a)fedoraproject.org> - 2.9.5-4
- R 3.6.1
* Fri May 31 2019 Tom Callaway <spot(a)fedoraproject.org> - 2.9.5-3
- R 3.6.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1744723 - R-devel requires R-rpm-macros
https://bugzilla.redhat.com/show_bug.cgi?id=1744723
[ 2 ] Bug #1727281 - R-3.6.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1727281
[ 3 ] Bug #1703495 - R-3.6.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1703495
--------------------------------------------------------------------------------