[SECURITY] Fedora 12 Update: puppet-0.25.4-1.fc12

updates at fedoraproject.org updates at fedoraproject.org
Tue Mar 2 01:09:48 UTC 2010


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-1372
2010-02-21 20:07:12
--------------------------------------------------------------------------------

Name        : puppet
Product     : Fedora 12
Version     : 0.25.4
Release     : 1.fc12
URL         : http://puppet.reductivelabs.com/
Summary     : A network tool for managing many disparate systems
Description :
Puppet lets you centrally manage every important aspect of your system using a
cross-platform specification language that manages all the separate elements
normally aggregated in different files, like users, cron jobs, and hosts,
along with obviously discrete elements like packages, services, and files.

--------------------------------------------------------------------------------
Update Information:

The update from 0.24.x to 0.25.x brings many, many changes and improvements to
puppet. The upstream release notes cover them in detail:
http://reductivelabs.com/trac/puppet/wiki/ReleaseNotes    Of note is that 0.25.x
clients do not work with 0.24.x masters, so it is important to update the master
before or at the same time as clients.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan 29 2010 Todd Zullinger <tmz at pobox.com> - 0.25.4-1
- Update to 0.25.4
* Tue Jan 19 2010 Todd Zullinger <tmz at pobox.com> - 0.25.3-2
- Apply upstream patch to fix cron resources (upstream #2845)
* Mon Jan 11 2010 Todd Zullinger <tmz at pobox.com> - 0.25.3-1
- Update to 0.25.3
* Tue Jan  5 2010 Todd Zullinger <tmz at pobox.com> - 0.25.2-1.1
- Replace %define with %global for macros
* Tue Jan  5 2010 Todd Zullinger <tmz at pobox.com> - 0.25.2-1
- Update to 0.25.2
- Fixes CVE-2010-0156, tmpfile security issue (#502881)
- Install auth.conf, puppetqd manpage, and queuing examples/docs
* Wed Nov 25 2009 Jeroen van Meeuwen <j.van.meeuwen at ogd.nl> - 0.25.1-1
- New upstream version
* Tue Oct 27 2009 Todd Zullinger <tmz at pobox.com> - 0.25.1-0.3
- Update to 0.25.1
- Include the pi program and man page (R.I.Pienaar)
* Sat Oct 17 2009 Todd Zullinger <tmz at pobox.com> - 0.25.1-0.2.rc2
- Update to 0.25.1rc2
* Tue Sep 22 2009 Todd Zullinger <tmz at pobox.com> - 0.25.1-0.1.rc1
- Update to 0.25.1rc1
- Move puppetca to puppet package, it has uses on client systems
- Drop redundant %doc from manpage %file listings
* Fri Sep  4 2009 Todd Zullinger <tmz at pobox.com> - 0.25.0-1
- Update to 0.25.0
- Fix permissions on /var/log/puppet (#495096)
- Install emacs mode and vim syntax files (#491437)
- Install ext/ directory in %{_datadir}/puppet (/usr/share/puppet)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #502881 - CVE-2010-0156 puppet: several insecure tempfile creation issues
        https://bugzilla.redhat.com/show_bug.cgi?id=502881
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update puppet' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list