The following Fedora 26 Security updates need testing: Age URL 87 https://bodhi.fedoraproject.org/updates/FEDORA-2017-1bf5a0ce01 python-XStatic-jquery-ui-1.12.0.1-2.fc26 26 https://bodhi.fedoraproject.org/updates/FEDORA-2017-2522df3526 nodejs-brace-expansion-1.1.7-1.fc26 11 https://bodhi.fedoraproject.org/updates/FEDORA-2017-5c6a9b07a3 xen-4.8.1-4.fc26 7 https://bodhi.fedoraproject.org/updates/FEDORA-2017-28387b61fd php-horde-Horde-Image-2.5.1-1.fc26 5 https://bodhi.fedoraproject.org/updates/FEDORA-2017-4e2312892e jetty-9.4.6-1.v20170531.fc26 5 https://bodhi.fedoraproject.org/updates/FEDORA-2017-808dbfe1d3 pius-2.2.4-1.fc26 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-d76189b06d mosquitto-1.4.13-1.fc26 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-bce18ed3f2 mingw-LibRaw-0.18.2-2.fc26 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-39ffa92327 qt5-qtwebkit-5.212.0-0.4.alpha2.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0eea793538 globus-ftp-client-8.36-1.fc26 globus-gass-cache-program-6.7-1.fc26 globus-gass-copy-9.27-1.fc26 globus-gram-client-13.18-1.fc26 globus-gram-job-manager-14.36-1.fc26 globus-gridftp-server-12.2-1.fc26 globus-gssapi-gsi-12.17-1.fc26 globus-io-11.9-1.fc26 globus-net-manager-0.17-1.fc26 globus-xio-5.16-1.fc26 globus-xio-gsi-driver-3.11-1.fc26 globus-xio-pipe-driver-3.10-1.fc26 globus-xio-udt-driver-1.28-1.fc26 myproxy-6.1.28-1.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-156d12fa2f yara-3.6.2-1.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-87f1f8c798 dhcp-4.3.5-7.fc26 bind99-9.9.10-1.P2.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-313712a583 jabberd-2.6.1-1.fc26
The following Fedora 26 Critical Path updates have yet to be approved: Age URL 15 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0dec8a74c5 pungi-4.1.16-3.fc26 11 https://bodhi.fedoraproject.org/updates/FEDORA-2017-5c6a9b07a3 xen-4.8.1-4.fc26 10 https://bodhi.fedoraproject.org/updates/FEDORA-2017-59ca80e001 libguestfs-1.36.5-1.fc26 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-06d188a0fc webkitgtk4-2.16.5-1.fc26 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-dad0fcac5d flatpak-0.9.7-1.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-1bb0d67fc8 gnome-keyring-3.20.1-1.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-96c8b4842a gnutls-3.5.14-1.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-87f1f8c798 dhcp-4.3.5-7.fc26 bind99-9.9.10-1.P2.fc26 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-45a87b7fc4 python-six-1.10.0-9.fc26
The following builds have been pushed to Fedora 26 updates-testing
MUMPS-5.1.1-2.fc26 bind99-9.9.10-1.P2.fc26 cacti-1.1.11-1.fc26 coin-or-Ipopt-3.12.8-2.fc26 dhcp-4.3.5-7.fc26 gitolite3-3.6.7-1.fc26 globus-ftp-client-8.36-1.fc26 globus-gass-cache-program-6.7-1.fc26 globus-gass-copy-9.27-1.fc26 globus-gram-client-13.18-1.fc26 globus-gram-job-manager-14.36-1.fc26 globus-gridftp-server-12.2-1.fc26 globus-gssapi-gsi-12.17-1.fc26 globus-io-11.9-1.fc26 globus-net-manager-0.17-1.fc26 globus-xio-5.16-1.fc26 globus-xio-gsi-driver-3.11-1.fc26 globus-xio-pipe-driver-3.10-1.fc26 globus-xio-udt-driver-1.28-1.fc26 gnome-keyring-3.20.1-1.fc26 gnutls-3.5.14-1.fc26 gst-entrans-1.2.0-1.fc26 jabberd-2.6.1-1.fc26 kanyremote-6.4-1.fc26 libimagequant-2.10.0-1.fc26 libreoffice-5.3.4.2-1.fc26 libtimidity-0.2.4-1.fc26 magic-8.1.175-1.fc26 metamath-0.146-1.fc26 mingw-glibmm24-2.52.0-1.fc26 myproxy-6.1.28-1.fc26 nagios-plugins-2.2.1-2git.fc26 perl-Code-TidyAll-0.60-1.fc26 php-pear-Net-Socket-1.2.2-1.fc26 php-pecl-pq-2.1.2-1.fc26 php-phpunit-PHPUnit-MockObject-3.4.4-1.fc26 phpunit6-6.2.3-1.fc26 pngquant-2.10.0-1.fc26 purple-matrix-0-3.20170530gitbe53d53.fc26 python-six-1.10.0-9.fc26 roundcubemail-1.3.0-2.fc26 scap-security-guide-0.1.34-1.fc26 trustedqsl-2.3.1-1.fc26 yara-3.6.2-1.fc26
Details about builds:
================================================================================ MUMPS-5.1.1-2.fc26 (FEDORA-2017-95ad16b7a5) A MUltifrontal Massively Parallel sparse direct Solver -------------------------------------------------------------------------------- Update Information:
- Update MUMPS and Ipopt to newer versions -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1461038 - coin-or-Ipopt-3.12.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1461038 --------------------------------------------------------------------------------
================================================================================ bind99-9.9.10-1.P2.fc26 (FEDORA-2017-87f1f8c798) The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) libraries -------------------------------------------------------------------------------- Update Information:
Update to new ISC supported version 9.9.10-P2 including security fixes. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1466612 - CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466612 [ 2 ] Bug #1466610 - CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466610 [ 3 ] Bug #1461639 - CVE-2017-3140 bind99: bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1461639 --------------------------------------------------------------------------------
================================================================================ cacti-1.1.11-1.fc26 (FEDORA-2017-7ab0179693) An rrd based graphing tool -------------------------------------------------------------------------------- Update Information:
- Update to 1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1467460 - None https://bugzilla.redhat.com/show_bug.cgi?id=1467460 [ 2 ] Bug #1463471 - None https://bugzilla.redhat.com/show_bug.cgi?id=1463471 --------------------------------------------------------------------------------
================================================================================ coin-or-Ipopt-3.12.8-2.fc26 (FEDORA-2017-95ad16b7a5) Interior Point OPTimizer -------------------------------------------------------------------------------- Update Information:
- Update MUMPS and Ipopt to newer versions -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1461038 - coin-or-Ipopt-3.12.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1461038 --------------------------------------------------------------------------------
================================================================================ dhcp-4.3.5-7.fc26 (FEDORA-2017-87f1f8c798) Dynamic host configuration protocol software -------------------------------------------------------------------------------- Update Information:
Update to new ISC supported version 9.9.10-P2 including security fixes. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1466612 - CVE-2017-3142 bind99: bind: An error in TSIG authentication can permit unauthorized zone transfers [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466612 [ 2 ] Bug #1466610 - CVE-2017-3143 bind99: bind: An error in TSIG authentication can permit unauthorized dynamic updates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1466610 [ 3 ] Bug #1461639 - CVE-2017-3140 bind99: bind: Error processing RPZ rules leads to endless loop while handling query [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1461639 --------------------------------------------------------------------------------
================================================================================ gitolite3-3.6.7-1.fc26 (FEDORA-2017-a66c4ed872) Highly flexible server for git directory version tracker -------------------------------------------------------------------------------- Update Information:
subdirectories, and allow the multi-hook driver to be placed in some other location of your choice allow simple test code to be embedded within the gitolite.conf file; see contrib/utils/testconf for how. (This goes on the client side, not on the server) allow syslog "facility" to be changed, from the default of 'local0' allow @group names in config values to be expanded; it is replaced with a space separated list of members --------------------------------------------------------------------------------
================================================================================ globus-ftp-client-8.36-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - GridFTP Client Library -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-gass-cache-program-6.7-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Tools to manipulate local and remote GASS caches -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-gass-copy-9.27-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Globus Gass Copy -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-gram-client-13.18-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - GRAM Client Library -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-gram-job-manager-14.36-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - GRAM Jobmanager -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-gridftp-server-12.2-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Globus GridFTP Server -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-gssapi-gsi-12.17-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - GSSAPI library -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-io-11.9-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - uniform I/O interface -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-net-manager-0.17-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Network Manager -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-xio-5.16-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Globus XIO Framework -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-xio-gsi-driver-3.11-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Globus XIO GSI Driver -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-xio-pipe-driver-3.10-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Globus Pipe Driver -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ globus-xio-udt-driver-1.28-1.fc26 (FEDORA-2017-0eea793538) Globus Toolkit - Globus XIO UDT Driver -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ gnome-keyring-3.20.1-1.fc26 (FEDORA-2017-1bb0d67fc8) Framework for managing passwords and other secrets -------------------------------------------------------------------------------- Update Information:
* Fix boolean logic error in ssh-agent * Pass the correct argc to gkr_pam_client_run_operation [#766222] * Look for both dlopen and dlsym when configuring [#766221] * Fix .so link in gnome-keyring-3 man page [#767095] * Die if the XDG session we were started under goes away [#768943] * Shorten unlock keyring dialog title [#770170] * Updated translations --------------------------------------------------------------------------------
================================================================================ gnutls-3.5.14-1.fc26 (FEDORA-2017-96c8b4842a) A TLS protocol implementation -------------------------------------------------------------------------------- Update Information:
- Update to upstream 3.5.14 release --------------------------------------------------------------------------------
================================================================================ gst-entrans-1.2.0-1.fc26 (FEDORA-2017-2b6b3bc915) Plug-ins and tools for transcoding and recording with GStreamer -------------------------------------------------------------------------------- Update Information:
1.2.0 --------------------------------------------------------------------------------
================================================================================ jabberd-2.6.1-1.fc26 (FEDORA-2017-313712a583) OpenSource server implementation of the Jabber protocols -------------------------------------------------------------------------------- Update Information:
updated to 2.6.1 (security bugfix release) --------------------------------------------------------------------------------
================================================================================ kanyremote-6.4-1.fc26 (FEDORA-2017-b42897a5dc) KDE frontend for anyRemote -------------------------------------------------------------------------------- Update Information:
v6.4 --------------------------------------------------------------------------------
================================================================================ libimagequant-2.10.0-1.fc26 (FEDORA-2017-d52ef5c617) Palette quantization library -------------------------------------------------------------------------------- Update Information:
Update to 2.10.0, see https://github.com/ImageOptim/libimagequant/compare/2.9.1...2.10.0 for details. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1467117 - libimagequant-2.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467117 [ 2 ] Bug #1467125 - pngquant-2.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467125 --------------------------------------------------------------------------------
================================================================================ libreoffice-5.3.4.2-1.fc26 (FEDORA-2017-34fa770c4d) Free Software Productivity Suite -------------------------------------------------------------------------------- Update Information:
update to 5.3.4 rc2 --------------------------------------------------------------------------------
================================================================================ libtimidity-0.2.4-1.fc26 (FEDORA-2017-c7207d6039) MIDI to WAVE converter library -------------------------------------------------------------------------------- Update Information:
Update to 0.2.4 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1466119 - libtimidity-0.2.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1466119 [ 2 ] Bug #1426676 - bogus libdir in libtimidity.pc https://bugzilla.redhat.com/show_bug.cgi?id=1426676 --------------------------------------------------------------------------------
================================================================================ magic-8.1.175-1.fc26 (FEDORA-2017-7a3cccb65c) A very capable VLSI layout tool -------------------------------------------------------------------------------- Update Information:
New version 8.1.175 is released. --------------------------------------------------------------------------------
================================================================================ metamath-0.146-1.fc26 (FEDORA-2017-89117fbe26) Construct mathematics from basic axioms -------------------------------------------------------------------------------- Update Information:
Changes in version 0.145: - fix bug 1741 during MINIMIZE_WITH - make duplicate bug numbers unique - adjust to prevent lcc compiler "Function too big for the optimizer" - take out extraneous <HTML>...</HTML> markup tags in HTML output so w3c validator will pass Changes in version 0.146: - fix handling of local labels in 'show proof.../tex' (bug 2341 reported by Eric Parfitt) -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1462574 - metamath-0.145 is available https://bugzilla.redhat.com/show_bug.cgi?id=1462574 [ 2 ] Bug #1467070 - metamath-0.146 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467070 --------------------------------------------------------------------------------
================================================================================ mingw-glibmm24-2.52.0-1.fc26 (FEDORA-2017-1806cd922b) MinGW Windows C++ interface for GTK2 (a GUI library for X) -------------------------------------------------------------------------------- Update Information:
* update to 2.52.0 --------------------------------------------------------------------------------
================================================================================ myproxy-6.1.28-1.fc26 (FEDORA-2017-0eea793538) Manage X.509 Public Key Infrastructure (PKI) security credentials -------------------------------------------------------------------------------- Update Information:
globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus- gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex- unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager- pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------
================================================================================ nagios-plugins-2.2.1-2git.fc26 (FEDORA-2017-4337b54215) Host/service/network monitoring program plugins for Nagios -------------------------------------------------------------------------------- Update Information:
Update to git for 20170703 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1204683 - None https://bugzilla.redhat.com/show_bug.cgi?id=1204683 [ 2 ] Bug #1423008 - None https://bugzilla.redhat.com/show_bug.cgi?id=1423008 --------------------------------------------------------------------------------
================================================================================ perl-Code-TidyAll-0.60-1.fc26 (FEDORA-2017-edb9f72c83) Engine for tidyall, your all-in-one code tidier and validator -------------------------------------------------------------------------------- Update Information:
Updated to the latest version -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1467459 - perl-Code-TidyAll-0.60 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467459 --------------------------------------------------------------------------------
================================================================================ php-pear-Net-Socket-1.2.2-1.fc26 (FEDORA-2017-c7be78296f) Network Socket Interface -------------------------------------------------------------------------------- Update Information:
**Version 1.2.2** * Bug #21178: $php_errormsg is deprecated in PHP 7.2 ---- **Version 1.2.1** * Fix BSD-2 licensing ---- **Version 1.2.0** * Change license to BSD-2 Clause --------------------------------------------------------------------------------
================================================================================ php-pecl-pq-2.1.2-1.fc26 (FEDORA-2017-e569a2916d) PostgreSQL client library (libpq) binding -------------------------------------------------------------------------------- Update Information:
**Version 2.1.2** * Fix gh-issue #32: JSON compatibility with PHP-7.1 * Fix pq\DateTime::createFromFormat() prototype with PHP-7.2 * Update static pq\Types with PostgreSQL-9.6 types --------------------------------------------------------------------------------
================================================================================ php-phpunit-PHPUnit-MockObject-3.4.4-1.fc26 (FEDORA-2017-b5faaebfbf) Mock Object library for PHPUnit -------------------------------------------------------------------------------- Update Information:
From git history: **Version 3.4.4** * Generate mock's class name using mt_rand() instead of microtime() --------------------------------------------------------------------------------
================================================================================ phpunit6-6.2.3-1.fc26 (FEDORA-2017-eca62d31e4) The PHP Unit Testing framework -------------------------------------------------------------------------------- Update Information:
**Version 6.2.3** - 2017-07-03 * Fixed [#2705](https://github.com/sebastianbergmann/phpunit/issues/2705): `stderr` parameter in `phpunit.xml` always considered `true` --------------------------------------------------------------------------------
================================================================================ pngquant-2.10.0-1.fc26 (FEDORA-2017-d52ef5c617) PNG quantization tool for reducing image file size -------------------------------------------------------------------------------- Update Information:
Update to 2.10.0, see https://github.com/ImageOptim/libimagequant/compare/2.9.1...2.10.0 for details. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1467117 - libimagequant-2.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467117 [ 2 ] Bug #1467125 - pngquant-2.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467125 --------------------------------------------------------------------------------
================================================================================ purple-matrix-0-3.20170530gitbe53d53.fc26 (FEDORA-2017-cdf0c11cc2) Matrix plugin for libpurple -------------------------------------------------------------------------------- Update Information:
Initial release. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1464225 - Review Request: purple-matrix - Matrix plugin for libpurple https://bugzilla.redhat.com/show_bug.cgi?id=1464225 --------------------------------------------------------------------------------
================================================================================ python-six-1.10.0-9.fc26 (FEDORA-2017-45a87b7fc4) Python 2 and 3 compatibility utilities -------------------------------------------------------------------------------- Update Information:
Fix unversioned Python BuildRequires --------------------------------------------------------------------------------
================================================================================ roundcubemail-1.3.0-2.fc26 (FEDORA-2017-b69431b8e3) Round Cube Webmail is a browser-based multilingual IMAP client -------------------------------------------------------------------------------- Update Information:
Upstream announcement: **Roundcube Webmail 1.3.0 released** 26 June 2017 We proudly announce the stable version 1.3.0 of Roundcube Webmail which is now available for download. With this milestone we introduce new features since the 1.2 version: * Widescreen layout aka Three Column View * Possibility to display QR code for contacts data * New identicon plugin * Attach contact vCards to composed message * Support WEBP images and MathML preview * Preview, download and rename attachments when composing a message * Message/rfc822 attachment preview * Various Enigma (PGP) and Managesieve plugin improvements * ���Flattened��� the Larry theme giving it a fresher look **Plus security and deployment improvements:** * Improve randomness of password salts and random hashes * Fixed redundancy in sql caching system and compatibility with Galera Cluster **And finally some code-cleanup:** * Dropped support for legacy browsers (IE < 10; removed legacy_browser plugin) * Require PHP >= 5.4 * Removed PHP mail() support * Removed 3rd party javascript libraries from repo * Require jQuery 3.x which has breaking changes to older versions **IMPORTANT:** The code-cleanup part brings major changes and possibly incompatibilities to your existing Roundcube installations. So please read the [Changelog](https://github.com/roundcube/roundcubemail/wiki/Changelog) carefully and thoroughly test your upgrade scenario. **Please note that Roundcube 1.3** * no longer runs on PHP 5.3 * no longer supports IE < 10 and old versions of Firefox, Chrome and Safari * requires an SMTP server connection to send mails * uses jQuery 3.2 and will not work with current jQuery mobile plugin With the release of Roundcube 1.3.0, the previous stable release branches 1.2.x and 1.1.x will switch in to LTS low maintenance mode which means they will only receive important security updates but no longer any regular improvement updates. --------------------------------------------------------------------------------
================================================================================ scap-security-guide-0.1.34-1.fc26 (FEDORA-2017-ec765db39a) Security guidance and baselines in SCAP formats -------------------------------------------------------------------------------- Update Information:
updated to latest upstream release 0.1.34 --------------------------------------------------------------------------------
================================================================================ trustedqsl-2.3.1-1.fc26 (FEDORA-2017-3780c22109) TrustedQSL ham-radio applications -------------------------------------------------------------------------------- Update Information:
Defects Corrected: = * Added 'Saving QSOs' to the messages to be translated. * When renewing a callsign certificate and backing up to earlier pages in the wizard, TQSL could display an unexpected page for selecting the certificate type, which is not needed for renewals. TQSL will no longer display the unexpected page. * When editing an ADIF file that has an invalid mode setting, TQSL now notifies the user that the mode is being ignored. * For Unix systems, fix a defect that could cause the password prompt to not appear when the system has built the wxWidgets system with debug assertions enabled. Correct the invocation of the Windows Installer when an update is available. * Correct the counts reported when duplicate QSOs are found along with QSOs with other errors. * Fix formatting of the messages that appear when QSOs change values in the station location for duplicate QSOs. * Correct improperly formatted frequencies from ADIF files (values like '7.010.20') to remove the extra periods. * Revert the change that stripped spaces in the TQSL configuration file as that caused newlines to be removed in places like the station_data file. * Fix "OpenSSL error - bad end line" by ensuring that there's always a newline starting a new certificate. Feature Additions: = * Add Finnish translation from Juhani, OH8MXL. * Add the ADIF satellite name to the pulldown menu in the ADIF editor to allow satellites to be more easily looked up. * Allow 'LIGHT' in a Cabrillo file to represent 300 GHz and above. * Allow TQSL to build against OpenSSL 1.1.0. * Add the ability to pull DXCC Entity valid date ranges from the TQSL configuration file. --------------------------------------------------------------------------------
================================================================================ yara-3.6.2-1.fc26 (FEDORA-2017-156d12fa2f) Pattern matching Swiss knife for malware researchers -------------------------------------------------------------------------------- Update Information:
Security fix for CVE-2017-9304, CVE-2017-9465 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1459490 - CVE-2017-9465 yara: Buffer over-read in yr_arena_write_data function https://bugzilla.redhat.com/show_bug.cgi?id=1459490 --------------------------------------------------------------------------------