The following Fedora 22 Security updates need testing:
Age URL
52
https://admin.fedoraproject.org/updates/FEDORA-2015-4531/quassel-0.11.0-2...
46
https://admin.fedoraproject.org/updates/FEDORA-2015-5279/strongswan-5.3.0...
38
https://admin.fedoraproject.org/updates/FEDORA-2015-5878/echoping-6.1-0.b...
37
https://admin.fedoraproject.org/updates/FEDORA-2015-5948/asterisk-13.3.2-...
32
https://admin.fedoraproject.org/updates/FEDORA-2015-6169/openstack-glance...
16
https://admin.fedoraproject.org/updates/FEDORA-2015-7329/drupal7-views-3....
15
https://admin.fedoraproject.org/updates/FEDORA-2015-7383/python-keystonem...
6
https://admin.fedoraproject.org/updates/FEDORA-2015-7997/libssh-0.7.0-1.fc22
3
https://admin.fedoraproject.org/updates/FEDORA-2015-8226/java-1.8.0-openj...
3
https://admin.fedoraproject.org/updates/FEDORA-2015-8196/rawstudio-2.1-0....
3
https://admin.fedoraproject.org/updates/FEDORA-2015-8187/rawtherapee-4.2-...
3
https://admin.fedoraproject.org/updates/FEDORA-2015-8194/xen-4.5.0-9.fc22
1
https://admin.fedoraproject.org/updates/FEDORA-2015-8316/libinfinity-0.6....
1
https://admin.fedoraproject.org/updates/FEDORA-2015-8303/hostapd-2.4-2.fc22
0
https://admin.fedoraproject.org/updates/FEDORA-2015-8432/LibRaw-0.16.2-1....
0
https://admin.fedoraproject.org/updates/FEDORA-2015-8444/mingw-LibRaw-0.1...
The following Fedora 22 Critical Path updates have yet to be approved:
Age URL
10
https://admin.fedoraproject.org/updates/FEDORA-2015-7322/mash-0.6.16-1.fc22
6
https://admin.fedoraproject.org/updates/FEDORA-2015-7997/libssh-0.7.0-1.fc22
5
https://admin.fedoraproject.org/updates/FEDORA-2015-8118/jack-audio-conne...
5
https://admin.fedoraproject.org/updates/FEDORA-2015-8084/samba-4.2.1-8.fc...
1
https://admin.fedoraproject.org/updates/FEDORA-2015-8326/PackageKit-1.0.6...
0
https://admin.fedoraproject.org/updates/FEDORA-2015-8422/Thunar-1.6.9-1.fc22
0
https://admin.fedoraproject.org/updates/FEDORA-2015-8406/xfdesktop-4.12.2...
0
https://admin.fedoraproject.org/updates/FEDORA-2015-8429/xfwm4-4.12.3-1.fc22
The following builds have been pushed to Fedora 22 updates-testing
GeographicLib-1.42-1.fc22
frama-c-1.10-23.fc22
golang-github-russross-blackfriday-1.2-6.fc22
golang-github-shurcooL-sanitized_anchor_name-0-0.2.git8e87604.fc22
libreoffice-4.4.3.2-4.fc22
mingw-LibRaw-0.16.2-1.fc22
pango-1.36.8-5.fc22
php-mtdowling-jmespath-php-2.1.0-1.fc22
php-mtdowling-transducers-0.3.0-1.fc22
php-whitehat101-apr1-md5-1.0.0-1.fc22
puppet-4.0.0-2.fc22
strace-4.10-2.fc22
why-2.34-19.fc22
why3-0.86-1.fc22
Details about builds:
================================================================================
GeographicLib-1.42-1.fc22 (FEDORA-2015-8445)
Library for geographic coordinate transformations
--------------------------------------------------------------------------------
Update Information:
Update to release 1.42
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 4 2015 Rich Mattes <richmattes(a)gmail.com> - 1.42-1
- Update to release 1.42
- Add octave subpackage
* Sat May 2 2015 Kalev Lember <kalevlember(a)gmail.com> - 1.40-2
- Rebuilt for GCC 5 C++11 ABI change
--------------------------------------------------------------------------------
================================================================================
frama-c-1.10-23.fc22 (FEDORA-2015-8439)
Framework for source code analysis of C software
--------------------------------------------------------------------------------
Update Information:
See
http://lists.gforge.inria.fr/pipermail/why3-club/2015-May/001227.html for the list of
changes in this release of why3. The frama-c and why packages were merely rebuilt against
the new version of why3.
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 16 2015 Jerry James <loganjerry(a)gmail.com> - 1.10-23
- Rebuild for why3 0.86
--------------------------------------------------------------------------------
================================================================================
golang-github-russross-blackfriday-1.2-6.fc22 (FEDORA-2015-8449)
Markdown processor implemented in Go
--------------------------------------------------------------------------------
Update Information:
Add license macro for LICENSE
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 17 2015 jchaloup <jchaloup(a)redhat.com> - 1.2-6
- Add license macro for LICENSE
- Remove runtime dependency on golang.
resolves: #1222338
* Mon Mar 2 2015 jchaloup <jchaloup(a)redhat.com> - 1.2-5
- Bump to upstream 77efab57b2f74dd3f9051c79752b2e8995c8b789
Update spec file to used commit tarball
related: #1156176
* Wed Feb 25 2015 jchaloup <jchaloup(a)redhat.com> - 1.2-4
- Add commit and shortcommit global variable
related: #1156176
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222338 - Tracker for golang-github-russross-blackfriday
https://bugzilla.redhat.com/show_bug.cgi?id=1222338
--------------------------------------------------------------------------------
================================================================================
golang-github-shurcooL-sanitized_anchor_name-0-0.2.git8e87604.fc22 (FEDORA-2015-8440)
Package sanitized_anchor_name provides a func to create sanitized anchor names
--------------------------------------------------------------------------------
Update Information:
Add license macro for LICENSE
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 17 2015 jchaloup <jchaloup(a)redhat.com> - 0-0.2.git8e87604
- Add license macro for LICENSE
- Remove runtime dependency on golang.
resolves: #1222336
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222336 - Tracker for golang-github-shurcooL-sanitized_anchor_name
https://bugzilla.redhat.com/show_bug.cgi?id=1222336
--------------------------------------------------------------------------------
================================================================================
libreoffice-4.4.3.2-4.fc22 (FEDORA-2015-8441)
Free Software Productivity Suite
--------------------------------------------------------------------------------
Update Information:
This update adds symbolic app icons.
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 16 2015 Kalev Lember <kalevlember(a)gmail.com> - 1:4.4.3.2-4
- Resolves: rhbz#1215800 install symbolic icons
* Mon May 11 2015 Caolán McNamara <caolanm(a)redhat.com> - 1:4.4.3.2-3
- don't include red spelling underlines on bitmap copy/paste
* Tue May 5 2015 Caolán McNamara <caolanm(a)redhat.com> - 1:4.4.3.2-2
- Use new color selector in the toolbar for area fill
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1215800 - Please install symbolic icons
https://bugzilla.redhat.com/show_bug.cgi?id=1215800
--------------------------------------------------------------------------------
================================================================================
mingw-LibRaw-0.16.2-1.fc22 (FEDORA-2015-8444)
Library for reading RAW files obtained from digital photo cameras
--------------------------------------------------------------------------------
Update Information:
Update to version 0.16.2, see
http://www.libraw.org/download#changelog for details.
Update to version 0.16.1, see
http://www.libraw.org/download#changelog for details.
Security fix for CVE-2015-3885.
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 17 2015 Sandro Mani <manisandro(a)gmail.com> - 0.16.2-1
- Update to 0.16.2
* Mon May 11 2015 Sandro Mani <manisandro(a)gmail.com> - 0.16.1-1
- Update to 0.16.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1221249 - CVE-2015-3885 dcraw: input sanitization flaw leading to buffer
overflow
https://bugzilla.redhat.com/show_bug.cgi?id=1221249
--------------------------------------------------------------------------------
================================================================================
pango-1.36.8-5.fc22 (FEDORA-2015-8442)
System for layout and rendering of internationalized text
--------------------------------------------------------------------------------
Update Information:
Fix pango-view(1) man page
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 14 2015 Matthias Clasen <mclasen(a)redhat.com> - 1.36.8-5
- Regenerate man page for pango-view
* Sat May 2 2015 Kalev Lember <kalevlember(a)gmail.com> - 1.36.8-4
- Rebuilt for GCC 5 C++11 ABI change
* Sat Feb 21 2015 Till Maas <opensource(a)till.name> - 1.36.8-3
- Rebuilt for Fedora 23 Change
https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-...
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222289 - man page of pango-view is broken
https://bugzilla.redhat.com/show_bug.cgi?id=1222289
--------------------------------------------------------------------------------
================================================================================
php-mtdowling-jmespath-php-2.1.0-1.fc22 (FEDORA-2015-8450)
Declaratively specify how to extract elements from a JSON document
--------------------------------------------------------------------------------
Update Information:
JMESPath (pronounced "jaymz path") allows you to declaratively specify how to
extract elements from a JSON document. jmespath.php allows you to use JMESPath
in PHP applications with PHP data structures.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222266 - Review Request: php-mtdowling-jmespath-php - Declaratively specify
how to extract elements from a JSON document
https://bugzilla.redhat.com/show_bug.cgi?id=1222266
--------------------------------------------------------------------------------
================================================================================
php-mtdowling-transducers-0.3.0-1.fc22 (FEDORA-2015-8448)
Composable algorithmic transformations
--------------------------------------------------------------------------------
Update Information:
Transducers [1] are composable algorithmic transformations. They are independent
from the context of their input and output sources and specify only the essence
of the transformation in terms of an individual element. Because transducers are
decoupled from input or output sources, they can be used in many different
processes - collections, streams, channels, observables, etc. Transducers
compose directly, without awareness of input or creation of intermediate
aggregates.
[1]
http://clojure.org/transducers
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222267 - Review Request: php-mtdowling-transducers - Composable algorithmic
transformations
https://bugzilla.redhat.com/show_bug.cgi?id=1222267
--------------------------------------------------------------------------------
================================================================================
php-whitehat101-apr1-md5-1.0.0-1.fc22 (FEDORA-2015-8446)
Apache's APR1-MD5 algorithm in pure PHP
--------------------------------------------------------------------------------
Update Information:
A tested, referenced, documented, and packaged implementation of Apache's APR1
MD5 Hashing Algorithm in pure PHP.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222265 - Review Request: php-whitehat101-apr1-md5 - Apache's APR1-MD5
algorithm in pure PHP
https://bugzilla.redhat.com/show_bug.cgi?id=1222265
--------------------------------------------------------------------------------
================================================================================
puppet-4.0.0-2.fc22 (FEDORA-2015-8447)
A network tool for managing many disparate systems
--------------------------------------------------------------------------------
Update Information:
Fix puppet paths and unit files (upstream #12185)
Since Fedora 22 rebased Ruby 2.2 which breaks Puppet 3.7.x and Puppetlabs indicated that
they won't support it, it's been decided to move to 4.0.x (unresponsive
maintainer, so it's been discussed between the people who actually maintains it)
--------------------------------------------------------------------------------
ChangeLog:
* Sun May 17 2015 Haïkel Guémar <hguemar(a)fedoraproject.org> - 4.0.0-2
- Fix puppet paths and unit files (upstream #12185)
* Tue Apr 28 2015 Haïkel Guémar <hguemar(a)fedoraproject.org> - 4.0.0-1
- Upstream 4.0.0
* Mon Apr 27 2015 Haïkel Guémar <hguemar(a)fedoraproject.org> - 4.0.0-0.1rc1
- Upstream 4.0.0
- Fix issue codedir path
- Fix init provider for Fedora (systemd is default on all supported releases now)
* Wed Apr 22 2015 Orion Poplawski <orion(a)cora.nwra.com> - 3.7.5-4
- Do not unbundle puppet's semantic module
* Sun Apr 19 2015 Orion Poplawski <orion(a)cora.nwra.com> - 3.7.5-3
- Require rubygem(pathspec) and rubygem(semantic)
--------------------------------------------------------------------------------
================================================================================
strace-4.10-2.fc22 (FEDORA-2015-8443)
Tracks and displays system calls associated with a running process
--------------------------------------------------------------------------------
Update Information:
Backport set of upstream patches to get it buildable on AArch64
--------------------------------------------------------------------------------
ChangeLog:
* Mon May 11 2015 Marcin Juszkiewicz <mjuszkiewicz(a)redhat.com> - 4.10-2
- Backport set of upstream patches to get it buildable on AArch64
--------------------------------------------------------------------------------
================================================================================
why-2.34-19.fc22 (FEDORA-2015-8439)
Software verification platform
--------------------------------------------------------------------------------
Update Information:
See
http://lists.gforge.inria.fr/pipermail/why3-club/2015-May/001227.html for the list of
changes in this release of why3. The frama-c and why packages were merely rebuilt against
the new version of why3.
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 16 2015 Jerry James <loganjerry(a)gmail.com> - 2.34-19
- Rebuild for why3 0.86
--------------------------------------------------------------------------------
================================================================================
why3-0.86-1.fc22 (FEDORA-2015-8439)
Software verification platform
--------------------------------------------------------------------------------
Update Information:
See
http://lists.gforge.inria.fr/pipermail/why3-club/2015-May/001227.html for the list of
changes in this release of why3. The frama-c and why packages were merely rebuilt against
the new version of why3.
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 16 2015 Jerry James <loganjerry(a)gmail.com> - 0.86-1
- New upstream release
--------------------------------------------------------------------------------