[EPEL-devel] Fedora EPEL 6 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Fri May 29 21:49:20 UTC 2015

The following Fedora EPEL 6 Security updates need testing:
 Age  URL
 1133  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2012-5620/bugzilla-3.4.14-2.el6
 197  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-4008/cross-binutils-
  58  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1501/strongswan-5.3.0-1.el6
  49  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5742/asterisk-
  29  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6089/drupal7-views-3.11-1.el6
   9  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6299/zarafa-7.1.12-2.el6
   9  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6361/torque-4.2.10-3.el6
   9  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6294/hostapd-2.0-6.el6
   3  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6400/ntfs-3g-2015.3.14-2.el6
   3  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6421/php-ZendFramework-1.12.13-1.el6
   0  https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-6487/rubygem-activesupport-2.3.18-6.el6

The following builds have been pushed to Fedora EPEL 6 updates-testing


Details about builds:

 Lmod- (FEDORA-EPEL-2015-6340)
 Environmental Modules System in Lua
Update Information:

Update to
- Fix alternatives script handling

* Tue May 26 2015 Orion Poplawski <orion at cora.nwra.com> -
- Fix alternatives script handling
* Tue May 19 2015 Orion Poplawski <orion at cora.nwra.com> -
- Update to
* Wed Apr  8 2015 Orion Poplawski <orion at cora.nwra.com> - 5.9.3-1
- Update to 5.9.3
* Tue Mar 31 2015 Orion Poplawski <orion at cora.nwra.com> - 5.9.2-1.git76a45db
- Update to 5.9.2-1.git76a45db for Lua 5.3 support
* Wed Mar 18 2015 Orion Poplawski <orion at cora.nwra.com> - 5.9-1
- Update to 5.9
* Tue Nov  4 2014 Orion Poplawski <orion at cora.nwra.com> - 5.8-1
- Update to 5.8

 RBTools-0.7.3-1.el6 (FEDORA-EPEL-2015-6448)
 Tools for use with ReviewBoard
Update Information:


* Fri May 29 2015 Stephen Gallagher <sgallagh at redhat.com> 0.7.3-1
- New upstream release 0.7.3
- https://www.reviewboard.org/docs/releasenotes/rbtools/0.7.3/

  [ 1 ] Bug #1225179 - rbt post + git-svn: CRITICAL: object of type 'NoneType' has no len().

 collectl-4.0.2-1.el6 (FEDORA-EPEL-2015-6443)
 A utility to collect various Linux performance data
Update Information:

- update to upstream version 4.0.2
- upstream changelog at http://collectl.sourceforge.net/Releases.html


* Fri May 29 2015 Dan HorĂ¡k <dan[at]danny.cz> - 4.0.2-1
- upgrade to upstream version 4.0.2 (#1225669)

  [ 1 ] Bug #1225669 - collectl-4.0.2.src is available

 createrepo_c-0.9.0-1.el6 (FEDORA-EPEL-2015-6488)
 Creates a common metadata repository
Update Information:

Update to 0.9.0
mergerepo: Do not prepend file:// if protocol is already specified
Update to 0.8.2

* Thu May 28 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.9.0-1
- mergerepo_c: Prepend protocol (file://) for URLs in pkgorigins (if --koji is used)
- Update bash completion
- doc: Update manpages
- mergerepo: Fix NVR merging method
- mergerepo: Fix behavior of --all param
- createrepo: Add --cut-dirs and --location-prefix options
- misc: Add cr_cut_dirs()
- mergerepo: Use better version comparison algorithm
- utils: Port cr_cmp_version_str() to rpm's algorithm (rpmvercmp)
- misc: Rename elements in cr_Version structure
- mergerepo: Fix version-release comparison for packages when --all is used
- mergerepo: Show warnings if some groupfile cannot be automatically used
- mergerepo: Exit with error code when a groupfile cannot be copied
* Fri May 15 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.8.3-1
- mergerepo: Do not prepend file:// if protocol is already specified
* Thu May 14 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.8.2-1
- doc: Add man pages for sqliterepo and update manpages for other tools
- mergerepo: Work only with noarch packages if --koji is used and
  no archlist is specified
- mergerepo: Use file:// protocol in local baseurl
- mergerepo: Do not include baseurl for first repo if --koji is specified (RhBug: 1220082)
- mergerepo_c: Support multilib arch for --koji repos
- mergerepo_c: Refactoring
- Print debug message with version in each tool when --verbose is used
- modifyrepo: Don't override file with itself (RhBug: 1215229)
* Wed May  6 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.8.1-1
- Fix bash completion for RHEL 6
* Tue May  5 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.8.0-1
- New tool Sqliterepo_c - It generates sqlite databases into repos
  where the sqlite is missing.
- Internal refactoring and code cleanup
* Fri Feb 20 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.7.7-1
- Proper directory for temporary files when --local-sqlite is used (Issue #12)
- Bring bash completion install dir and filenames up to date with current bash-completion
* Thu Jan  8 2015 Tomas Mlcoch <tmlcoch at redhat.com> - 0.7.6-1
- Python: Add __contains__ method to Repomd() class
* Sun Dec 28 2014 Tomas Mlcoch <tmlcoch at redhat.com> - 0.7.5-1
- Python repomd: Support for iteration and indexing by type - e.g. record = repomd['primary']
- Show warning if an XML parser probably parsed a bad type of medata (New XML parser warning type CR_XML_WARNING_BADMDTYPE)
- drpm library: Explicitly try to locate libdrpm.so.0
- deltarpms: Don't show options for delta rpms if support is not available

 drupal7-advanced_help-1.3-1.el6 (FEDORA-EPEL-2015-6469)
 Allows module developers to store their help outside the module system in html
Update Information:

Update to upstream 1.3 release for bug fixes

* Tue May 26 2015 Jared Smith <jsmith at fedoraproject.org> - 1.3-1
- Update to upstream 1.3 release for bug fixes
- Upstream changelog available at https://www.drupal.org/node/2494535

  [ 1 ] Bug #1224827 - drupal7-advanced_help-1.3 is available

 fail2ban-0.9.2-1.el6 (FEDORA-EPEL-2015-6452)
 Ban IPs that make too many password failures
Update Information:

ver. 0.9.2 (2015/04/29) - better-quick-now-than-later

- Fixes:
   * infinite busy loop on _escapedTags match in substituteRecursiveTags gh-907. Thanks TonyThompson
   * port[s] typo in jail.conf/nginx-http-auth gh-913. Thanks Frederik Wagner (fnerdwq)
   * $ typo in jail.conf. Thanks Skibbi. Debian bug #767255
   * grep'ing for IP in *mail-whois-lines.conf should now match also at the beginning and EOL.  Thanks Dean Lee
   * jail.conf
     - php-url-fopen: separate logpath entries by newline
   * failregex declared direct in jail was joined to single line (specifying of multiple expressions was not possible).
   * filters.d/exim.conf - cover different settings of exim logs
     details. Thanks bes.internal
   * filter.d/postfix-sasl.conf - failregex is now case insensitive
   * filters.d/postfix.conf - add 'Client host rejected error message' failregex
   * fail2ban/__init__.py - add strptime thread safety hack-around
   * recidive uses iptables-allports banaction by default now.
     Avoids problems with iptables versions not understanding 'all' for protocols and ports
   * filter.d/dovecot.conf
     - match pam_authenticate line from EL7
     - match unknown user line from EL7
   * Use use_poll=True for Python 2.7 and >=3.4 to overcome "Bad file
     descriptor" msgs issue (gh-161)
   * filter.d/postfix-sasl.conf - tweak failregex and add ignoreregex to ignore system authentication issues
   * fail2ban-regex reads filter file(s) completely, incl. '.local' file etc. (gh-954)
   * firewallcmd-* actions: split output into separate lines for grepping (gh-908)
   * Guard unicode encode/decode issues while storing records in the database.
     Fixes "binding parameter error (unsupported type)" (gh-973), thanks to kot for reporting
   * filter.d/sshd added regex for matching openSUSE ssh authentication failure
   * filter.d/asterisk.conf:
     - Dropped "Sending fake auth rejection" failregex since it incorrectly targets the asterisk server itself
     - match "hacking attempt detected" logs

- New Features:
   - New filters:
     - postfix-rbl  Thanks Lee Clemens
     - apache-fakegooglebot.conf  Thanks Lee Clemens
     - nginx-botsearch  Thanks Frantisek Sumsal
     - drupal-auth  Thanks Lee Clemens
   - New recursive embedded substitution feature added:
     - `<<PREF>HOST>` becomes `<IPV4HOST>` for PREF=`IPV4`;
     - `<<PREF>HOST>` becomes `` for PREF=`IPV4` and IPV4HOST=``;
   - New interpolation feature for config readers - `%(known/parameter)s`. (means last known option with name `parameter`). This interpolation makes possible to extend a stock filter or jail regexp in .local file (opposite to simply set failregex/ignoreregex that overwrites it), see gh-867.
   - Monit config for fail2ban in files/monit/
   - New actions:
     - action.d/firewallcmd-multiport and action.d/firewallcmd-allports Thanks Donald Yandt
     - action.d/sendmail-geoip-lines.conf
     - action.d/nsupdate to update DNSBL. Thanks Andrew St. Jean
   - New status argument for fail2ban-client -- flavor:
     fail2ban-client status <jail> [flavor]
     - empty or "basic" works as-is
     - "cymru" additionally prints (ASN, Country RIR) per banned IP (requires dnspython or dnspython3)
   - Flush log at USR1 signal

- Enhancements:
   * Enable multiport for firewallcmd-new action.  Closes gh-834
   * files/debian-initd migrated from the debian branch and should be suitable for manual installations now (thanks Juan Karlo de Guzman)
   * Define empty ignoreregex in filters which didn't have it to avoid warnings (gh-934)
   * action.d/{sendmail-*,xarf-login-attack}.conf - report local
     timezone not UTC time/zone. Closes gh-911
   * Conditionally log Ignore IP with reason (dns, ip, command). Closes gh-916
   * Absorbed DNSUtils.cidr into addr2bin in filter.py, added unittests
   * Added syslogsocket configuration to fail2ban.conf
   * Note in the jail.conf for the recidive jail to increase dbpurgeage (gh-964)

Update to 0.9.1:

    Refactoring (IMPORTANT -- Please review your setup and configuration):

    iptables-common.conf replaced iptables-blocktype.conf (iptables-blocktype.local should still be read) and now also provides defaults for the chain, port, protocol and name tags


    start of file2ban aborted (on slow hosts, systemd considers the server has been timed out and kills him), see gh-824
    UTF-8 fixes in pure-ftp thanks to Johannes Weberhofer. Closes gh-806.
    systemd backend error on bad utf-8 in python3
    badips.py action error when logging HTTP error raised with badips request
    fail2ban-regex failed to work in python3 due to space/tab mix
    recidive regex samples incorrect log level
    journalmatch for recidive incorrect PRIORITY
    loglevel couldn't be changed in fail2ban.conf
    Handle case when no sqlite library is available for persistent database
    Only reban once per IP from database on fail2ban restart
    Nginx filter to support missing server_name. Closes gh-676
    fail2ban-regex assertion error caused by miscount missed lines with multiline regex
    Fix actions failing to execute for Python 3.4.0. Workaround for http://bugs.python.org/issue21207
    Database now returns persistent bans on restart (bantime < 0)
    Recursive action tags now fully processed. Fixes issue with bsd-ipfw action
    Fixed TypeError with "ipfailures" and "ipjailfailures" action tags. Thanks Serg G. Brester
    Correct times for non-timezone date times formats during DST
    Pass a copy of, not original, aInfo into actions to avoid side-effects
    Per-distribution paths to the exim's main log
    Ignored IPs are no longer banned when being restored from persistent database
    Manually unbanned IPs are now removed from persistent database, such they wont be banned again when Fail2Ban is restarted
    Pass "bantime" parameter to the actions in default jail's action definition(s)
    filters.d/sieve.conf - fixed typo in _daemon. Thanks Jisoo Park
    cyrus-imap -- also catch also failed logins via secured (imaps/pop3s). Regression was introduced while strengthening failregex in 0.8.11 (bd175f) Debian bug #755173
    postfix-sasl - added journalmatch. Thanks Luc Maisonobe
    postfix* - match with a new daemon string (postfix/submission/smtpd). Closes gh-804 . Thanks Paul Traina

    apache - added filter for AH01630 client denied by server configuration.

    New features:

    New filters:
        monit Thanks Jason H Martin
        directadmin Thanks niorg
        apache-shellshock Thanks Eugene Hopkinson (SlowRiot)
    New actions:
        symbiosis-blacklist-allports for Bytemark symbiosis firewall
    fail2ban-client can fetch the running server version

    Added Cloudflare API action


    Start performance of fail2ban-client (and tests) increased, start time and cpu usage rapidly reduced. Introduced a shared storage logic, to bypass reading lots of config files (see gh-824). Thanks to Joost Molenaar for good catch (reported gh-820).
    Fail2ban-regex - add print-all-matched option. Closes gh-652
    Suppress fail2ban-client warnings for non-critical config options
    Match non "Bye Bye" disconnect messages for sshd locked account regex
    courier-smtp filter:
        match lines with user names
        match lines containing "535 Authentication failed" attempts
    Add <chain> tag to iptables-ipsets
    Realign fail2ban log output with white space to improve readability. Does not affect SYSLOG output
    Log unhandled exceptions
    cyrus-imap: catch "user not found" attempts
    Add support for Portsentry

- Fix php-url-fopen logpath

* Wed May 20 2015 Orion Poplawski <orion at cora.nwra.com> - 0.9.2-1
- Update to 0.9.2 (bug #1097720)
- Add requires ipset
- Do not load user paths (bug #1202151)
- Remove non-Linux actions
- Run tests

  [ 1 ] Bug #1097720 - Request for update to 0.9.0

 globus-ftp-client-8.22-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - GridFTP Client Library
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 8.22-1
- GT6 update (test improvements)

 globus-gsi-callback-5.7-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - Globus GSI Callback Library
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 5.7-1
- GT6 update (GT-599: fix race conditions)

 globus-gsi-credential-7.8-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - Globus GSI Credential Library
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 7.8-1
- GT6 update (deprecation of obsolete functions)

 globus-gssapi-gsi-11.16-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - GSSAPI library
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 11.16-1
- GT6-update (SSL cipher configuration)

 globus-io-11.4-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - uniform I/O interface
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 11.4-1
- GT6 update (test improvements)

 globus-simple-ca-4.20-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - Simple CA Utility
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 4.20-1
- GT6 update (increase default key size)

 globus-xio-gsi-driver-3.7-1.el6 (FEDORA-EPEL-2015-6455)
 Globus Toolkit - Globus XIO GSI Driver
Update Information:

Globus Toolkit 6 updates from upstream.

* Fri May 29 2015 Mattias Ellert <mattias.ellert at fysast.uu.se> - 3.7-1
- GT6 update (handle anonymous targets in GSI RFC2818 mode)

 libmediainfo-0.7.74-1.el6 (FEDORA-EPEL-2015-6471)
 Library for supplies technical and tag information about a video or audio file
Update Information:

Update libmediainfo and mediainfo to 0.7.74

* Wed May 27 2015 Vasiliy N. Glazov <vascom2 at gmail.com> 0.7.74-1
- Update to 0.7.74

 lz4-r129-1.el6 (FEDORA-EPEL-2015-6470)
 Extremely fast compression algorithm
Update Information:

- New release - r129.
- New LZ4_compress_fast() API.
- New LZ4 CLI improved performance with multiple files.
- Other bug fix and documentation updates.

- New release
- New -static sub package
- Fixed missing debuginfo for liblz4
- New release
- New -static sub package
- Fixed missing debuginfo for liblz4
- New release
- New -static sub package
- Fixed missing debuginfo for liblz4

* Wed May 27 2015 pjp <pjp at fedoraproject.org> - r129-1
- New LZ4_compress_fast() API.
- New LZ4 CLI improved performance with multiple files.
- Other bug fix and documentation updates.
* Mon Apr  6 2015 pjp <pjp at fedoraproject.org> - r128-2
- Update files section to install unlz4 & its manual
* Wed Apr  1 2015 pjp <pjp at fedoraproject.org> - r128-1
- lz4cli sparse file support
- Restored lz4hc compression ratio
- lz4 cli supports long commands
- Introduced lz4-static sub package BZ#1208203
* Thu Jan  8 2015 pjp <pjp at fedoraproject.org> - r127-2
- Bump dist to override an earlier build.

  [ 1 ] Bug #1220384 - lz4-r129 is available
  [ 2 ] Bug #1204611 - liblz4 missing valid debuginfo
  [ 3 ] Bug #1207664 - lz4-r128 is available
  [ 4 ] Bug #1208203 - RFE: Add lz4-static subpackage build to 'Everything' to allow for zlib-static migration

 mediainfo-0.7.74-1.el6 (FEDORA-EPEL-2015-6471)
 Supplies technical and tag information about a video or audio file (CLI)
Update Information:

Update libmediainfo and mediainfo to 0.7.74

* Wed May 27 2015 Vasiliy N. Glazov <vascom2 at gmail.com> 0.7.74-1
- Update to 0.7.74

 osbs-0.10-1.el6 (FEDORA-EPEL-2015-6457)
 Python command line client for OpenShift Build Service
Update Information:

new upstream release: 0.10
new upstream release: 0.9
new upstream release: 0.5

* Thu May 28 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.10-1
- new upstream release: 0.10
* Thu May 28 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.9-1
- new upstream release: 0.9
* Tue May 26 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.8-1.1.git.c83fd0d
- test release 0.8-1.1
* Mon May 25 2015 Jiri Popelka <jpopelka at redhat.com> - 0.8-1
- new upstream release: 0.8
* Sat May 23 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.7-1.1.git.9c50ab0
- test release 0.7-1.1.git.9c50ab0
* Fri May 22 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.7-1
- new upstream release: 0.7
* Thu May 21 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.6-2.1
- testing release
* Thu May 21 2015 Jiri Popelka <jpopelka at redhat.com> - 0.6-2
- fix %license handling
* Thu May 21 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.6-1
- new upstream release: 0.6
* Tue May 19 2015 Tomas Tomecek <ttomecek at redhat.com> - 0.5-1
- new upstream release: 0.5
* Tue May 12 2015 Slavek Kabrda <bkabrda at redhat.com> - 0.4-2
- Introduce python-osbs subpackage
- move /usr/bin/osbs to /usr/bin/osbs2, /usr/bin/osbs is now a symlink
- depend on python[3]-setuptools because of entrypoints usage

 python-regex-2015.05.28-1.el6 (FEDORA-EPEL-2015-6464)
 Alternative regular expression module, to replace re
Update Information:

Update to the latest stable version 2015.05.28.

* Fri May 29 2015 Thomas Moschny <thomas.moschny at gmx.de> - 2015.05.28-1
- Update to 2015.05.28.
* Sat May 23 2015 Thomas Moschny <thomas.moschny at gmx.de> - 2015.05.10-1
- Update to 2015.05.10.

 python-rosdistro-0.4.2-1.el6 (FEDORA-EPEL-2015-6476)
 File format for managing ROS Distributions
Update Information:

Update to release 0.4.2 (#1207455)

* Wed May 27 2015 Rich Mattes <richmattes at gmail.com> - 0.4.2-1
- Update to release 0.4.2 (#1207455)

  [ 1 ] Bug #1207455 - python-rosdistro-0.4.2 is available

 qpid-dispatch-0.4-2.el6 (FEDORA-EPEL-2015-6444)
 Dispatch router for Qpid
Update Information:

Create the local state directory explicity on SysVInit systems.
Rebased on Dispatch 0.4.
Changed SysVInit script to properly name qdrouterd as the service to start.
Update inter-package dependencies to include release as well as version.
Disabled building documentation due to missing pandoc-pdf on EL6.

* Wed May 27 2015 Darryl L. Pierce <dpierce at redhat.com> - 0.4-2
- Create the local state directory explicity on SysVInit systems.
* Tue Apr 21 2015 Darryl L. Pierce <dpierce at rehdat.com> - 0.4-1
- Rebased on Dispatch 0.4.
- Changed username for qdrouterd to be qdrouterd.
* Tue Feb 24 2015 Darryl L. Pierce <dpierce at redhat.com> - 0.3-4
- Changed SysVInit script to properly name qdrouterd as the service to start.
* Fri Feb 20 2015 Darryl L. Pierce <dpierce at redhat.com> - 0.3-3
- Update inter-package dependencies to include release as well as version.
* Wed Feb 11 2015 Darryl L. Pierce <dpierce at redhat.com> - 0.3-2
- Disabled building documentation due to missing pandoc-pdf on EL6.
- Disabled daemon setgid.
- Fixes to accomodate Python 2.6 on EL6.
- Removed implicit dependency on python-qpid-proton in qpid-dispatch-router.
* Tue Jan 27 2015 Darryl L. Pierce <dpierce at redhat.com> - 0.3-1
- Rebased on Dispatch 0.3.
- Increased the minimum Proton version needed to 0.8.
- Moved all tests to the -devel package.
- Ensure executable bit turned off on systemd file.
- Set the location of installed documentation.

 rubygem-activesupport-2.3.18-6.el6 (FEDORA-EPEL-2015-6487)
 Support and utility classes used by the Rails framework
Update Information:

Update to newer version of rubygem-activesupport for CVE-2013-0333

* Thu May 28 2015 Jared K. Smith <jsmith at fedoraproject.org> - 2.3.18-6
- Fix up some minor issues in the changelog
* Tue Apr 21 2015 Jared K. Smith <jsmith at fedoraproject.org> - 2.3.18-5
- Update from EL5 branch to bring up to 2.3.18 version for CVE-2013-0333
* Tue Oct 21 2014 Michael Stahnke <stahnma at fedoraproject.org> - -2.3.18-1
- Update to 2.3.18
- Obsolete patch for CVE-2009-3009 fixed in 2.3.4
- Bug 905373 - CVE-2013-0333 fixed in 2.3.16
- Bug 731435 - CVE-2011-2932
- Bug 731435, 731450 - CVE-2011-2932 fixed in 2.3.8

  [ 1 ] Bug #905374 - CVE-2013-0333 rubygem-activesupport: json to yaml parsing [epel-6]

 salt-2015.5.1-1.el6 (FEDORA-EPEL-2015-6460)
 A parallel remote execution system
Update Information:

Update to bugfix release 2015.5.1

* Wed May 27 2015 Erik Johnson <erik at saltstack.com> - 2015.5.1-1
- Update to bugfix release 2015.5.1

 torsocks-2.1.0-1.el6 (FEDORA-EPEL-2015-6449)
 Use SOCKS-friendly applications with Tor
Update Information:

update to upstream release 2.1.0

* Thu May 28 2015 Jamie Nguyen <jamielinux at fedoraproject.org> - 2.1.0-1
- update to upstream release 2.1.0
- run test suite
* Wed Apr 29 2015 Jon Ciesla <limburgher at gmail.com> - 2.0.0-3
- Updated to latest to fix syscall errors.

 xforms-1.2.4-5.el6 (FEDORA-EPEL-2015-6478)
 XForms toolkit library
Update Information:

Provide -doc subpkg as requested on xforms mailing list.

* Thu May 28 2015 Rex Dieter <rdieter at fedoraproject.org> 1.2.4-5
- tweak pkgdocdir to work on el6 too, fix %preun doc scriptlet
* Thu May 28 2015 Rex Dieter <rdieter at fedoraproject.org> 1.2.4-4
- -doc: include demos/ too
* Tue May 26 2015 Rex Dieter <rdieter at fedoraproject.org> 1.2.4-3
- -doc subpkg
- trim %changelog

More information about the epel-devel mailing list