The following Fedora 28 Security updates need testing:
Age URL
302
https://bodhi.fedoraproject.org/updates/FEDORA-2018-d510cfd7eb
jgraphx-3.6.0.0-6.fc28
251
https://bodhi.fedoraproject.org/updates/FEDORA-2018-d7aeaa74da
nodejs-brace-expansion-1.1.11-1.fc28
250
https://bodhi.fedoraproject.org/updates/FEDORA-2018-bc073fdc1a
nodejs-atob-2.1.1-1.fc28
126
https://bodhi.fedoraproject.org/updates/FEDORA-2018-cc4b7af297
xerces-c27-2.7.0-28.fc28
78
https://bodhi.fedoraproject.org/updates/FEDORA-2018-997a9e3e1f xen-4.10.2-4.fc28
78
https://bodhi.fedoraproject.org/updates/FEDORA-2018-aa3752ac3c
nginx-1.14.1-1.fc28
57
https://bodhi.fedoraproject.org/updates/FEDORA-2018-cc86ef9e22 squid-4.4-1.fc28
54
https://bodhi.fedoraproject.org/updates/FEDORA-2018-b18f9dd65b
tomcat-8.5.35-1.fc28
26
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e0eb3d797e
systemd-238-11.gita76ee90.fc28
11
https://bodhi.fedoraproject.org/updates/FEDORA-2019-6cf96757fe
golang-1.10.8-1.fc28
11
https://bodhi.fedoraproject.org/updates/FEDORA-2019-333a7aa511 radvd-2.17-12.fc28
8
https://bodhi.fedoraproject.org/updates/FEDORA-2019-5146cd34e2
rdesktop-1.8.4-2.fc28
6
https://bodhi.fedoraproject.org/updates/FEDORA-2019-7696bb57ca
pdns-recursor-4.1.9-1.fc28
6
https://bodhi.fedoraproject.org/updates/FEDORA-2019-ef5551fcff
perl-Email-Address-List-0.06-1.fc28
6
https://bodhi.fedoraproject.org/updates/FEDORA-2019-f1626b52e9
slurm-17.11.13-2.fc28
5
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e9bc354ee8
libwmf-0.2.12-1.fc28
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-a8f918005c
mingw-libconfuse-3.2.2-1.fc28
The following Fedora 28 Critical Path updates have yet to be approved:
Age URL
78
https://bodhi.fedoraproject.org/updates/FEDORA-2018-997a9e3e1f xen-4.10.2-4.fc28
57
https://bodhi.fedoraproject.org/updates/FEDORA-2018-9f541b469b
nfs-utils-2.3.3-1.rc2.fc28
48
https://bodhi.fedoraproject.org/updates/FEDORA-2018-4dddcb3e5e
highlight-3.48-1.fc28
26
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e0eb3d797e
systemd-238-11.gita76ee90.fc28
21
https://bodhi.fedoraproject.org/updates/FEDORA-2019-78153d357c
totem-pl-parser-3.26.2-1.fc28
17
https://bodhi.fedoraproject.org/updates/FEDORA-2019-ffb6dfc8a9
p11-kit-0.23.15-1.fc28
17
https://bodhi.fedoraproject.org/updates/FEDORA-2019-870e8d8234
osinfo-db-20190120-1.fc28
14
https://bodhi.fedoraproject.org/updates/FEDORA-2019-e9c4843d39
volume_key-0.3.12-2.fc28
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-8a8196e1e1 vim-8.1.818-1.fc28
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-bb30467485
ostree-2019.1-2.fc28 rpm-ostree-2019.1-1.fc28
13
https://bodhi.fedoraproject.org/updates/FEDORA-2019-752f205a3a
python-productmd-1.19-1.fc28
11
https://bodhi.fedoraproject.org/updates/FEDORA-2019-333a7aa511 radvd-2.17-12.fc28
8
https://bodhi.fedoraproject.org/updates/FEDORA-2019-8d89d06043
ibus-1.5.19-10.fc28
7
https://bodhi.fedoraproject.org/updates/FEDORA-2019-2735cb18d8 lorax-28.26-1.fc28
5
https://bodhi.fedoraproject.org/updates/FEDORA-2019-cb4a3023ef
iproute-4.20.0-1.fc28
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-67c405c3d8
hwdata-0.320-1.fc28
3
https://bodhi.fedoraproject.org/updates/FEDORA-2019-856b9ada37
selinux-policy-3.14.1-53.fc28
The following builds have been pushed to Fedora 28 updates-testing
fedmod-0.4.6-1.fc28
firefox-65.0-4.fc28
hplip-3.18.12-4.fc28
ipv6calc-2.0.0-31.fc28
memtest86+-5.01-24.fc28
ndctl-64-1.fc28
paper-icon-theme-1.5.0-2.fc28
perl-Regexp-Trie-0.02-2.fc28
php-theseer-autoload-1.25.2-1.fc28
python-alembic-1.0.7-1.fc28
python-linux-procfs-0.6.1-1.fc28
python-streamlink-1.0.0-1.fc28
rdopkg-0.48.0-1.fc28
spice-0.14.0-5.fc28
syncthing-1.0.1-1.fc28
Details about builds:
================================================================================
fedmod-0.4.6-1.fc28 (FEDORA-2019-aaa19e9de3)
Utilities for generating & maintaining modulemd files
--------------------------------------------------------------------------------
Update Information:
This update fixes buildorder for generated flatpak modulemd files.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Nils Philippsen <nils(a)redhat.com> 0.4.6-1
- Update version metadata for release 0.4.6 (nils(a)redhat.com)
- Fix buildorder for generated flatpak modulemd (otaylor(a)fishsoup.net)
* Thu Jan 31 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.4.5-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
firefox-65.0-4.fc28 (FEDORA-2019-4ab744e2bc)
Mozilla Firefox Web browser
--------------------------------------------------------------------------------
Update Information:
- Updated Wayland launcher, don't set GDK_BACKEND
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 4 2019 Martin Stransky <stransky(a)redhat.com> - 65.0-4
- Added fix for mozbz#1522780
* Thu Jan 31 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 65.0-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Thu Jan 31 2019 Jan Grulich <jgrulich(a)redhat.com> - 65.0-2
- Re-enable PipeWire support
--------------------------------------------------------------------------------
================================================================================
hplip-3.18.12-4.fc28 (FEDORA-2019-3d0a38e641)
HP Linux Imaging and Printing Project
--------------------------------------------------------------------------------
Update Information:
1671513 - after 'successful' plugin installation it is not installed ---- hp-
setup crashes when user specifies path to PPD
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Zdenek Dohnal <zdohnal(a)redhat.com> - 3.18.12-4
- 1671513 - after 'successful' plugin installation it is not installed
* Fri Feb 1 2019 Zdenek Dohnal <zdohnal(a)redhat.com> - 3.18.12-3
- m277-m281 printer support got some fixes, so try to do not use our downstream patch
- hpcups-update-ppds can freeze sometimes, add timeout for to be sure
- fixed hp-setup crash when user wants to define path to PPD file
* Fri Feb 1 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 3.18.12-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
ipv6calc-2.0.0-31.fc28 (FEDORA-2019-20b012f60f)
IPv6 address format change and calculation utility
--------------------------------------------------------------------------------
Update Information:
new release 2.0.0
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Peter Bieringer <pb(a)bieringer.de> - 2.0.0-31
- new release 2.0.0
- subpackage ipv6calcweb: remove dependency Perl(Proc::ProcessTable)
- add dependency libmaxminddb-devel
* Sat Jan 26 2019 Peter Bieringer <pb(a)bieringer.de> - 1.1.0-29
- fix bug in lib/libipv6addr.c
--------------------------------------------------------------------------------
================================================================================
memtest86+-5.01-24.fc28 (FEDORA-2019-461428280e)
Stand-alone memory tester for x86 and x86-64 computers
--------------------------------------------------------------------------------
Update Information:
This is an update fixing spontaneous reboots on some machines.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Jaroslav ��karvada <jskarvad(a)redhat.com> - 5.01-24
- Temporally switched to compat-gcc-34
Resolves: rhbz#1598922
* Fri Feb 1 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.01-23
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Fri Jul 20 2018 Jaroslav ��karvada <jskarvad(a)redhat.com> - 5.01-22
- Fixed FTBFS by adding gcc-c++ requirement
Resolves: rhbz#1604814
* Fri Jul 13 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 5.01-21
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1598922 - memtest86+ restarts after a few seconds on some machines (affects
F28 and later)
https://bugzilla.redhat.com/show_bug.cgi?id=1598922
--------------------------------------------------------------------------------
================================================================================
ndctl-64-1.fc28 (FEDORA-2019-8003d9c293)
Manage "libnvdimm" subsystem devices (Non-volatile Memory)
--------------------------------------------------------------------------------
Update Information:
release v64
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 4 2019 Vishal Verma <vishal.l.verma(a)intel.com> - 64-1
- release v64
* Fri Feb 1 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 63-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1671933 - ndctl-64 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1671933
--------------------------------------------------------------------------------
================================================================================
paper-icon-theme-1.5.0-2.fc28 (FEDORA-2019-3338c14d5a)
Modern freedesktop icon theme
--------------------------------------------------------------------------------
Update Information:
Disable icon de-duplication to fix issues with flatpak apps.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Fabio Valentini <decathorpe(a)gmail.com> - 1.5.0-2
- Disable deduplication to fix problems with flatpak apps.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1639717 - symlinks seems to break flatpak apps
https://bugzilla.redhat.com/show_bug.cgi?id=1639717
--------------------------------------------------------------------------------
================================================================================
perl-Regexp-Trie-0.02-2.fc28 (FEDORA-2019-bd6a09ac17)
Build trie-ized regexp
--------------------------------------------------------------------------------
Update Information:
This is the first Fedora/EPEL build of perl-Regexp-Trie.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1672274 - Review Request: perl-Regexp-Trie - Build trie-ized regexp
https://bugzilla.redhat.com/show_bug.cgi?id=1672274
--------------------------------------------------------------------------------
================================================================================
php-theseer-autoload-1.25.2-1.fc28 (FEDORA-2019-713620e438)
A tool and library to generate autoload code
--------------------------------------------------------------------------------
Update Information:
**Release 1.25.2** * Fix Parser to ignore "inline" use of keywords `class`,
`interface` and `trait` ---- **Release 1.25.1** * Merge PR
[#81](https://github.com/theseer/Autoload/pull/81): Fix PHP 7.3 warnings [Remi]
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 4 2019 Remi Collet <remi(a)remirepo.net> - 1.25.2-1
- update to 1.25.2
--------------------------------------------------------------------------------
================================================================================
python-alembic-1.0.7-1.fc28 (FEDORA-2019-d15f544e32)
Database migration tool for SQLAlchemy
--------------------------------------------------------------------------------
Update Information:
Latest upstream.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Alfredo Moralejo <amoralej(a)redhat.com> - 1.0.7-1
- Update to 1.0.7
* Sat Feb 2 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.0.0-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Wed Jul 25 2018 Pierre-Yves Chibon <pingou(a)pingoured.fr> - 1.0.0-1
- Update to 1.0.0
* Fri Jul 13 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.9.7-7
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Tue Jun 19 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 0.9.7-6
- Rebuilt for Python 3.7
* Sun Jun 17 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 0.9.7-5
- Rebuilt for Python 3.7
* Wed Feb 21 2018 Iryna Shcherbina <ishcherb(a)redhat.com> - 0.9.7-4
- Update Python 2 dependency declarations to new packaging standards
(See
https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1669697 - python-alembic-1.0.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1669697
[ 2 ] Bug #1667049 - Update python-alembic to 1.0.6
https://bugzilla.redhat.com/show_bug.cgi?id=1667049
--------------------------------------------------------------------------------
================================================================================
python-linux-procfs-0.6.1-1.fc28 (FEDORA-2019-e28d017ef2)
Linux /proc abstraction classes
--------------------------------------------------------------------------------
Update Information:
update to 0.6.1
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Jiri Kastner <jkastner(a)redhat.com> - 0.6.1-1
- update to 0.6.1
* Sat Feb 2 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.5.1-7
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Sat Jul 14 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.5.1-6
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Tue Jun 19 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 0.5.1-5
- Rebuilt for Python 3.7
--------------------------------------------------------------------------------
================================================================================
python-streamlink-1.0.0-1.fc28 (FEDORA-2019-5ffc33de01)
Python library for extracting streams from various websites
--------------------------------------------------------------------------------
Update Information:
Changes * A ton of plugin updates. Have a look [at this search query](https://g
ithub.com/streamlink/streamlink/pulls?utf8=%E2%9C%93&q=is%3Apr+is%3Ac...
ns.+) for all the recent updates * You can now provide a custom key URI to
override HLS streams
([#2139](https://github.com/streamlink/streamlink/pull/2139)). For example:
`--hls-segment-key-uri <URI>` * User agents for API communication have been
updated ([#2194](https://github.com/streamlink/streamlink/pull/2194)) * Special
synonyms have been added to sort "best" and "worst" streams
([#2127](https://github.com/streamlink/streamlink/pull/2127)). For example:
`streamlink --stream-sorting-excludes '>=480p' URL best,best-unfiltered` *
Process output will no longer show if tty is unavailable
([#2090](https://github.com/streamlink/streamlink/pull/2090)) * Improved
terminal progress display for wide characters
([#2032](https://github.com/streamlink/streamlink/pull/2032)) * Fixed a bug with
dynamic playlists on playback
([#2096](https://github.com/streamlink/streamlink/pull/2096)) * Old Livestreamer
deprecations and API references were removed
([#1987](https://github.com/streamlink/streamlink/pull/1987)) * Newer and more
common User-Agents are now used
([#1974](https://github.com/streamlink/streamlink/pull/1974)) * DASH stream
bitrates now round-up to the nearest 10, 100, 1000, etc.
([#1995](https://github.com/streamlink/streamlink/pull/1995)) * URL have been
added for better processing of HTML tags
([#1675](https://github.com/streamlink/streamlink/pull/1675)) * Fixed sort and
prog issue ([#1964](https://github.com/streamlink/streamlink/pull/1964)) * Fixed
crashing bug with player-continuous-http option
([#2234](https://github.com/streamlink/streamlink/pull/2234)) * -r parameter has
been replaced for --rtmp-rtmpdump
([#2152](https://github.com/streamlink/streamlink/pull/2152)) Breaking changes
A large number of unmaintained or NSFW plugins have been removed. You can find
the PR that implemented that change here:
[#2003](https://github.com/streamlink/streamlink/pull/2003) . See our [CONTRIBUT
ING.md](https://github.com/streamlink/streamlink/blob/master/CONTRIBUTING...
documentation for plugin policy.
--------------------------------------------------------------------------------
ChangeLog:
* Mon Feb 4 2019 Mohamed El Morabity <melmorabity(a)fedoraproject.org> - 1.0.0-1
- Update to 1.0.0
--------------------------------------------------------------------------------
================================================================================
rdopkg-0.48.0-1.fc28 (FEDORA-2019-398b39a4eb)
RPM packaging automation tool CLI
--------------------------------------------------------------------------------
Update Information:
Ensure `python-distroinfo >= 0.2.0` that works with new `rdoinfo` after reorg.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Jakub Ru��i��ka <jruzicka(a)redhat.com> 0.48.0-1
- Update to 0.48.0
- Require python-distroinfo >= 0.2.0
--------------------------------------------------------------------------------
================================================================================
spice-0.14.0-5.fc28 (FEDORA-2019-afade40f3d)
Implements the SPICE protocol
--------------------------------------------------------------------------------
Update Information:
Fixes CVE-2019-3813
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Christophe Fergeau <cfergeau(a)redhat.com> - 0.14.0-5
- Fix off-by-one error during guest-to-host memory address conversion
Resolves: CVE-2019-3813
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1670158 - CVE-2019-3813 spice: Off-by-one error in array access in
spice/server/memslot.c [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1670158
--------------------------------------------------------------------------------
================================================================================
syncthing-1.0.1-1.fc28 (FEDORA-2019-71a3c815ed)
Continuous File Synchronization
--------------------------------------------------------------------------------
Update Information:
Update to version 1.0.1. Release notes:
https://github.com/syncthing/syncthing/releases/tag/v1.0.1
--------------------------------------------------------------------------------
ChangeLog:
* Tue Feb 5 2019 Fabio Valentini <decathorpe(a)gmail.com> - 1.0.1-1
- Update to version 1.0.1.
--------------------------------------------------------------------------------