Fedora 14 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Sun Oct 31 21:34:02 UTC 2010


The following Fedora 14 Security updates need testing:

    https://admin.fedoraproject.org/updates/mailman-2.1.13-6.fc14
    https://admin.fedoraproject.org/updates/moodle-1.9.10-1.fc14
    https://admin.fedoraproject.org/updates/cvs-1.11.23-11.fc14
    https://admin.fedoraproject.org/updates/monotone-0.48.1-1.fc14
    https://admin.fedoraproject.org/updates/apr-util-1.3.10-1.fc14
    https://admin.fedoraproject.org/updates/horde-3.3.9-1.fc14
    https://admin.fedoraproject.org/updates/tomcat6-6.0.26-14.fc14
    https://admin.fedoraproject.org/updates/gnucash-2.3.15-2.fc14
    https://admin.fedoraproject.org/updates/perl-libwww-perl-5.837-2.fc14
    https://admin.fedoraproject.org/updates/exim-4.72-2.fc14
    https://admin.fedoraproject.org/updates/xpdf-3.02-16.fc14
    https://admin.fedoraproject.org/updates/seamonkey-2.0.9-1.fc14
    https://admin.fedoraproject.org/updates/bristol-0.40.7-7.fc14
    https://admin.fedoraproject.org/updates/sunbird-1.0-0.31.b2pre.fc14,thunderbird-3.1.6-1.fc14
    https://admin.fedoraproject.org/updates/qt-4.7.0-8.fc14
    https://admin.fedoraproject.org/updates/banshee-1.8.0-10.fc14
    https://admin.fedoraproject.org/updates/pootle-2.1.2-1.fc14
    https://admin.fedoraproject.org/updates/libguestfs-1.5.23-1
    https://admin.fedoraproject.org/updates/luci-0.22.4-2.0.b9faf868074git.fc14
    https://admin.fedoraproject.org/updates/gnome-xcf-thumbnailer-1.0-4.fc14


The following Fedora 14 Critical Path updates have yet to be approved:

    https://admin.fedoraproject.org/updates/xdg-utils-1.0.2-21.20101028.fc14
    https://admin.fedoraproject.org/updates/mingetty-1.08-5.fc14
    https://admin.fedoraproject.org/updates/authconfig-6.1.11-1.fc14,sssd-1.4.0-2.fc14,ding-libs-0.1.2-3.fc14


The following builds have been pushed to Fedora 14 updates-testing

    atool-0.37.0-1.fc14
    banshee-1.8.0-10.fc14
    ccd2iso-0.3-6.fc14
    dvdauthor-0.7.0-1.fc14
    erlang-amf-0-0.3.20100908git27329144.fc14
    erlang-gettext-2.1.0-0.2.20101022gitb55cb72.fc14
    erlang-neotoma-1.4-2.fc14
    erlang-xmlrpc-1.13-2.fc14
    ghc-regex-tdfa-1.1.6-1.fc14
    ghc-split-0.1.2.1-1.fc14
    ghc-xmonad-contrib-0.9.1-8.fc14
    gnome-xcf-thumbnailer-1.0-4.fc14
    imagej-1.44-1.i.fc14
    kde-plasma-translatoid-1.30-1.fc14
    libisofs-0.6.38-1.fc14
    libmikey-0.8.0-0.2.20100127svn3750.fc14
    libmsip-0.8.0-0.1.20100629svn3775.fc14
    nzbget-0.7.0-1.fc14
    pootle-2.1.2-1.fc14
    postgresql-plparrot-0.04-2.fc14
    q4wine-0.120-3.fc14
    rubygem-whiskey_disk-0.5.3-1.fc14
    spin-kickstarts-0.14.5-1.fc14
    webkitgtk-1.3.5-1.fc14
    wine-1.3.6-1.fc14
    xfce4-dev-tools-4.7.3-1.fc14
    xsettingsd-0-0.1.20091208git7804894.fc14

Details about builds:


================================================================================
 atool-0.37.0-1.fc14 (FEDORA-2010-17025)
 A perl script for managing file archives of various types
--------------------------------------------------------------------------------


================================================================================
 banshee-1.8.0-10.fc14 (FEDORA-2010-17021)
 Easily import, manage, and play selections from your music collection
--------------------------------------------------------------------------------
ChangeLog:

* Mon Oct 25 2010 Nathaniel McCallum <nathaniel at natemccallum.com> - 1.8.0-10
- Add a patch to fix CVE-2010-3998
* Tue Oct 19 2010 Dan Horák <dan[at]danny.cz> - 1.8.0-9
- Update the Requires to match BR on s390(x)
* Tue Oct 19 2010 Nathaniel McCallum <nathaniel at natemccallum.com> - 1.8.0-8
- Added gnome-doc-utils BR
* Mon Oct 18 2010 Dan Horák <dan[at]danny.cz> - 1.8.0-7
- Fix BRs and configure options on s390(x)
- Be verbose during build
* Mon Oct 11 2010 Nathaniel McCallum <nathaniel at natemccallum.com> - 1.8.0-6
- Fix download URL
* Fri Oct  8 2010 Nathaniel McCallum <nathaniel at natemccallum.com> - 1.8.0-5
- Add upstream patch to fix sync screen
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #644554 - CVE-2010-3998 banshee: insecure library loading vulnerability
        https://bugzilla.redhat.com/show_bug.cgi?id=644554
--------------------------------------------------------------------------------


================================================================================
 ccd2iso-0.3-6.fc14 (FEDORA-2010-17032)
 CloneCD image to ISO image file converter
--------------------------------------------------------------------------------
Update Information:

The ccd2iso project converts CD backup files created using the non-free CloneCD
program to a format understood by most Free Software CD writing programs.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #562585 - Review Request: ccd2iso - CloneCD image to ISO image file converter
        https://bugzilla.redhat.com/show_bug.cgi?id=562585
--------------------------------------------------------------------------------


================================================================================
 dvdauthor-0.7.0-1.fc14 (FEDORA-2010-16991)
 Command line DVD authoring tool
--------------------------------------------------------------------------------
Update Information:

Update to version 0.7.0.
http://github.com/ldo/dvdauthor/blob/master/ChangeLog
--------------------------------------------------------------------------------
ChangeLog:

* Wed Oct 27 2010 Ville Skyttä <ville.skytta at iki.fi> - 0.7.0-1
- Update to 0.7.0, all patches applied upstream.
- Improve %description.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #595543 - [abrt] crash in dvdauthor-0.6.18-1.fc13: dump_dvd: Process /usr/bin/dvdunauthor was killed by signal 11 (SIGSEGV)
        https://bugzilla.redhat.com/show_bug.cgi?id=595543
  [ 2 ] Bug #595830 - [abrt] crash in dvdauthor-0.6.18-1.fc12: MarkChapters: Process /usr/bin/dvdauthor was killed by signal 11 (SIGSEGV)
        https://bugzilla.redhat.com/show_bug.cgi?id=595830
  [ 3 ] Bug #646938 - dvdauthor-0.7.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=646938
--------------------------------------------------------------------------------


================================================================================
 erlang-amf-0-0.3.20100908git27329144.fc14 (FEDORA-2010-17010)
 Erlang Action Message Format Library
--------------------------------------------------------------------------------
Update Information:

* Added missing exported function
* Added workaround for missing BIFs in Erlang/OTP R12B
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 31 2010 Peter Lemenkov <lemenkov at gmail.com> - 0-0.3.20100908git27329144
- Fixed missing BIFs in Erlang/OTP R12B
- Exported one more function
--------------------------------------------------------------------------------


================================================================================
 erlang-gettext-2.1.0-0.2.20101022gitb55cb72.fc14 (FEDORA-2010-17020)
 Erlang internationalization library
--------------------------------------------------------------------------------
Update Information:

Initial build
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #645801 - Review Request: erlang-gettext - Erlang internationalization library
        https://bugzilla.redhat.com/show_bug.cgi?id=645801
--------------------------------------------------------------------------------


================================================================================
 erlang-neotoma-1.4-2.fc14 (FEDORA-2010-17042)
 Erlang library and packrat parser-generator for parsing expression grammars
--------------------------------------------------------------------------------
Update Information:

Initial build
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #639284 - Review Request: erlang-neotoma - Erlang library and packrat parser-generator for parsing expression grammars
        https://bugzilla.redhat.com/show_bug.cgi?id=639284
--------------------------------------------------------------------------------


================================================================================
 erlang-xmlrpc-1.13-2.fc14 (FEDORA-2010-17005)
 HTTP 1.1 compliant XML-RPC library for Erlang
--------------------------------------------------------------------------------
Update Information:

Initial build
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #645288 - Review Request: erlang-xmlrpc - HTTP 1.1 compliant XML-RPC library for Erlang
        https://bugzilla.redhat.com/show_bug.cgi?id=645288
--------------------------------------------------------------------------------


================================================================================
 ghc-regex-tdfa-1.1.6-1.fc14 (FEDORA-2010-17024)
 Haskell regular expression library
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #595697 - Review Request: ghc-regex-tdfa - Haskell "tagged" DFA regex engine
        https://bugzilla.redhat.com/show_bug.cgi?id=595697
--------------------------------------------------------------------------------


================================================================================
 ghc-split-0.1.2.1-1.fc14 (FEDORA-2010-17036)
 Combinator library for splitting lists
--------------------------------------------------------------------------------
Update Information:

Combinator library for splitting lists.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #630509 - Review Request: ghc-split - Combinator library for splitting lists
        https://bugzilla.redhat.com/show_bug.cgi?id=630509
--------------------------------------------------------------------------------


================================================================================
 ghc-xmonad-contrib-0.9.1-8.fc14 (FEDORA-2010-17029)
 Third party extensions for xmonad
--------------------------------------------------------------------------------
Update Information:

Fix broken dependencies when using xmonad --recompile. See RHBZ #648134.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 31 2010 Ben Boeckel <mathstuf at gmail.com> - 0.9.1-8
- Rebuild for broken xmonad deps (RHBZ#648134)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #648134 - broken deps for ghc-xmonad-contrib
        https://bugzilla.redhat.com/show_bug.cgi?id=648134
--------------------------------------------------------------------------------


================================================================================
 gnome-xcf-thumbnailer-1.0-4.fc14 (FEDORA-2010-17035)
 Thumbnailer for XCF files
--------------------------------------------------------------------------------
Update Information:

This update fixes potential stack-based buffer overflows that can
allow remote attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a crafted image that causes a
conversion to a location "above or to the left of the canvas."
--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct 29 2010 ELMORABITY Mohamed <melmorabity at fedoraproject.org> 1.0-4
- Fix RHBZ #64797 (CVE-2009-2175)
- Update GConf scriptlets to latest specifications
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #647907 - CVE-2009-2175 xcftools: stack-based buffer overflow in flatten.c
        https://bugzilla.redhat.com/show_bug.cgi?id=647907
--------------------------------------------------------------------------------


================================================================================
 imagej-1.44-1.i.fc14 (FEDORA-2010-17006)
 Image Processing and Analysis in Java
--------------------------------------------------------------------------------
Update Information:

update to 1.44i
--------------------------------------------------------------------------------
ChangeLog:

* Sat Oct 30 2010 Georget Fabien <fabien.georget at gmail.com> 1.44-1.i
- update to 1.44i
- create imagej.jar link
* Tue Sep 28 2010 Georget Fabien <fabien.georget at gmail.com> 1.44-1.h
- version 1.44h
--------------------------------------------------------------------------------


================================================================================
 kde-plasma-translatoid-1.30-1.fc14 (FEDORA-2010-17038)
 Translator Using Google Translator
--------------------------------------------------------------------------------
Update Information:

- Version upgrade
- Correct Json parser with new Google Api.
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #483730 - Review Request: kde-plasma-translatoid - A Google Translation Plasmoid
        https://bugzilla.redhat.com/show_bug.cgi?id=483730
  [ 2 ] Bug #633712 - translatoid widget does not translate
        https://bugzilla.redhat.com/show_bug.cgi?id=633712
--------------------------------------------------------------------------------


================================================================================
 libisofs-0.6.38-1.fc14 (FEDORA-2010-17030)
 Library to create ISO 9660 disk images
--------------------------------------------------------------------------------
Update Information:

This release mainly provides a new feature for ISO 9660 images on USB sticks.

Changes towards previous version 0.6.34:

 * New API function iso_write_opts_set_part_offset() controls creation of an MBR with a first partiton table entry that bears non-zero start address. A second set of volume descriptors and directory tree+tables gets created which can be used to mount the image at the partition start.
 * Hiding all non-API symbols from the linker by use of --version-script
 * Automatic C++ detection in libisofs.h by using macro __cplusplus
 * Corrected several memory leaks and potential NULL pointer evaluations in case of memory shortage.


This release can use libjte to produce jigdo files along with the ISO image.  Further filesystem images may be appended as MBR partitions 1 to 4. The capability was added to produce boot blocks for computers with MIPS CPU.

Changes towards previous version 0.6.36:

 * New API calls iso_write_opts_attach_jte() and iso_write_opts_detach_jte() allow to use libjte for jigdo production.
 * New API call iso_write_opts_set_tail_blocks() for tail padding inside ISO image.
 * New API call iso_image_generator_is_running() to learn when the write thread is done.
 * New API calls iso_image_add_mips_boot_file(), iso_image_get_mips_boot_files(), iso_image_give_up_mips_boot().
 * New API call iso_write_opts_set_partition_img() for appending e.g. a small empty FAT12 filesystem which may be used on USB stick.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 31 2010 Robert Scheck <robert at fedoraproject.org> 0.6.38-1
- Upgrade to 0.6.38
--------------------------------------------------------------------------------


================================================================================
 libmikey-0.8.0-0.2.20100127svn3750.fc14 (FEDORA-2010-17017)
 A C++ library implementing the Multimedia Internet KEYing protocol
--------------------------------------------------------------------------------
Update Information:

Initial build
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #626701 - Review Request: libmikey - A C++ library implementing the Multimedia Internet KEYing protocol
        https://bugzilla.redhat.com/show_bug.cgi?id=626701
--------------------------------------------------------------------------------


================================================================================
 libmsip-0.8.0-0.1.20100629svn3775.fc14 (FEDORA-2010-17028)
 A C++ library implementing the SIP protocol
--------------------------------------------------------------------------------
Update Information:

Initial build
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #626726 - Review Request: libmsip - A C++ library implementing the SIP protocol
        https://bugzilla.redhat.com/show_bug.cgi?id=626726
--------------------------------------------------------------------------------


================================================================================
 nzbget-0.7.0-1.fc14 (FEDORA-2010-17011)
 Command-line based binary newsgrabber for nzb files
--------------------------------------------------------------------------------


================================================================================
 pootle-2.1.2-1.fc14 (FEDORA-2010-17000)
 Localization and translation management web application
--------------------------------------------------------------------------------
Update Information:

Update to 2.1.2
- Fix XSS on translate page
- Improved monolingual support
- Improved GNU style project support
- New translations: Zulu, Greek, Danish, Acoli and Fulah
- Completed translations: Uighur, Chinese (China), Catalan, Asturian, Akan and Ganda
- Various bug fixes
--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct 29 2010 Dwayne Bailey <dwayne at translate.org.za> - 2.1.2-1
- Update to 2.1.2
   - Fix XSS on translate page
   - Improved monolingual support
   - Improved GNU style project support
   - New translations: Zulu, Greek, Danish, Acoli and Fulah
   - Completed translations: Uighur, Chinese (China), Catalan, Asturian, Akan
     and Ganda
   - Various bug fixes
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #647832 - pootle: XSS via 'match_names' parameter on translate.html page
        https://bugzilla.redhat.com/show_bug.cgi?id=647832
--------------------------------------------------------------------------------


================================================================================
 postgresql-plparrot-0.04-2.fc14 (FEDORA-2010-17026)
 A PostgreSQL procedural language for the Parrot virtual machine
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #634091 - Review Request: postgresql-plparrot - A PostgreSQL procedural language for the Parrot virtual machine
        https://bugzilla.redhat.com/show_bug.cgi?id=634091
--------------------------------------------------------------------------------


================================================================================
 q4wine-0.120-3.fc14 (FEDORA-2010-17034)
 Qt4 GUI for wine
--------------------------------------------------------------------------------
Update Information:

Q4Wine is a qt4 GUI for W.I.N.E. It will help                                   
you manage wine prefixes and installed applications.                            

General features:                                                               
* Can export QT color theme into wine colors settings.
* Can easy work with different wine versions at same time;
* Easy creating, deleting and managing prefixes (WINEPREFIX);
* Easy controlling for wine process;
* Autostart icons support;
* Easy cd-image use;
* You can extract icons from PE files (.exe .dll);
* Easy backup and restore for managed prefixes.
* Winetriks support.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #640889 - Review Request: q4wine - Qt4 GUI for wine
        https://bugzilla.redhat.com/show_bug.cgi?id=640889
--------------------------------------------------------------------------------


================================================================================
 rubygem-whiskey_disk-0.5.3-1.fc14 (FEDORA-2010-17015)
 Ruby tool for embarrassingly fast deployments
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #646573 - Review Request: rubygem-whiskey_disk - Ruby tool for embarrassingly fast deployments
        https://bugzilla.redhat.com/show_bug.cgi?id=646573
--------------------------------------------------------------------------------


================================================================================
 spin-kickstarts-0.14.5-1.fc14 (FEDORA-2010-16995)
 Kickstart files and templates for creating your own Fedora Spins
--------------------------------------------------------------------------------
Update Information:

Includes one fix for LXDE that didn't make gold, otherwise just a new upstream incorporating patches that were included with package instead of upstream.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 31 2010 Bruno Wolff III <bruno at wolff.to> - 0.14.5-1
- Patches are upstream now and there is one lxde change.
--------------------------------------------------------------------------------


================================================================================
 webkitgtk-1.3.5-1.fc14 (FEDORA-2010-17027)
 GTK+ Web content engine library
--------------------------------------------------------------------------------
Update Information:

Fixes various bugs, including issue with new fedoraproject.org site.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Oct 28 2010 Kevin Fenzi <kevin at tummy.com> - 1.3.5-1
- Update to 1.3.5-1
* Wed Oct 13 2010 Dan Horák <dan[at]danny.cz> - 1.3.4-4
- Add back updated s390(x) patch
- Do not generate debug information to prevent linker memory exhaustion on s390
  with its 2 GB address space
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #643300 - [abrt] epiphany-1:2.30.6-1.fc14: glyphDataForCharacter: Process /usr/bin/epiphany was killed by signal 11 (SIGSEGV)
        https://bugzilla.redhat.com/show_bug.cgi?id=643300
--------------------------------------------------------------------------------


================================================================================
 wine-1.3.6-1.fc14 (FEDORA-2010-17031)
 A Windows 16/32/64 bit emulator
--------------------------------------------------------------------------------
Update Information:

 * Support for GStreamer filters.
 * Mapping of standard cursors to native desktop cursors.
 * Improved support for installers with services.
 * Many MSXML improvements.
 * Decoder for TGA-format images.
 * Translation updates.
 * Various bug fixes.

--------------------------------------------------------------------------------
ChangeLog:

* Fri Oct 29 2010 Andreas Bierfert <andreas.bierfert[AT]lowlatency.de>
- 1.3.6-1
- version upgrade
- rebase winepulse configure patch
- add gstreamer BR for new gstreamer support
- add libtiff BR for new tiff support
--------------------------------------------------------------------------------


================================================================================
 xfce4-dev-tools-4.7.3-1.fc14 (FEDORA-2010-17018)
 Xfce developer tools
--------------------------------------------------------------------------------
Update Information:

New upstream version that fixes some bugs, mainly sanity checks. This update is targeted at the release of Xfce 4.8.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Oct 31 2010 Christoph Wickert <cwickert at fedoraproject.org> - 4.7.3-1
- Update to 4.7.3
--------------------------------------------------------------------------------


================================================================================
 xsettingsd-0-0.1.20091208git7804894.fc14 (FEDORA-2010-17033)
 Provides settings to X11 clients via the XSETTINGS specification
--------------------------------------------------------------------------------



More information about the test mailing list