Fedora 14 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Thu Jun 30 18:59:20 UTC 2011


The following Fedora 14 Security updates need testing:

    https://admin.fedoraproject.org/updates/feh-1.14.1-1.fc14
    https://admin.fedoraproject.org/updates/subversion-1.6.17-1.fc14
    https://admin.fedoraproject.org/updates/drupal7-7.4-1.fc14
    https://admin.fedoraproject.org/updates/wordpress-3.1.4-1.fc14
    https://admin.fedoraproject.org/updates/dokuwiki-0-0.8.20110525.a.fc14
    https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-2.git20110622.fc14
    https://admin.fedoraproject.org/updates/mingw32-libpng-1.4.3-2.fc14
    https://admin.fedoraproject.org/updates/libpng10-1.0.54-3.fc14
    https://admin.fedoraproject.org/updates/asterisk-1.6.2.19-1.fc14
    https://admin.fedoraproject.org/updates/tomcat6-6.0.26-21.fc14
    https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14
    https://admin.fedoraproject.org/updates/oprofile-0.9.6-21.fc14
    https://admin.fedoraproject.org/updates/blender-2.49b-14.fc14
    https://admin.fedoraproject.org/updates/curl-7.21.0-8.fc14
    https://admin.fedoraproject.org/updates/weechat-0.3.5-1.fc14
    https://admin.fedoraproject.org/updates/libxml-1.8.17-27.fc14
    https://admin.fedoraproject.org/updates/xulrunner-1.9.2.18-1.fc14,firefox-3.6.18-1.fc14,mozvoikko-1.0-22.fc14.1,perl-Gtk2-MozEmbed-0.08-6.fc14.27,gnome-web-photo-0.9-21.fc14.1,galeon-2.0.7-41.fc14.1,gnome-python2-extras-2.25.3-31.fc14.1,thunderbird-3.1.11-1.fc14
    https://admin.fedoraproject.org/updates/gdk-pixbuf2-2.22.0-2.fc14


The following Fedora 14 Critical Path updates have yet to be approved:

    https://admin.fedoraproject.org/updates/cronie-1.4.8-2.fc14
    https://admin.fedoraproject.org/updates/mash-0.5.22-1.fc14
    https://admin.fedoraproject.org/updates/tzdata-2011h-1.fc14
    https://admin.fedoraproject.org/updates/python-slip-0.2.17-1.fc14
    https://admin.fedoraproject.org/updates/gdk-pixbuf2-2.22.0-2.fc14
    https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-2.git20110622.fc14
    https://admin.fedoraproject.org/updates/bash-4.1.7-4.fc14
    https://admin.fedoraproject.org/updates/perl-5.12.4-146.fc14
    https://admin.fedoraproject.org/updates/policycoreutils-2.0.85-30.1.fc14
    https://admin.fedoraproject.org/updates/system-config-keyboard-1.3.1-5.fc14
    https://admin.fedoraproject.org/updates/fedora-logos-14.0.2-1.fc14
    https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-8.fc14.2
    https://admin.fedoraproject.org/updates/pygobject2-2.21.5-4.fc14
    https://admin.fedoraproject.org/updates/pcre-8.10-2.fc14
    https://admin.fedoraproject.org/updates/libpcap-1.1.1-3.fc14
    https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-3.fc14
    https://admin.fedoraproject.org/updates/evolution-exchange-2.32.3-1.fc14,evolution-data-server-2.32.3-1.fc14,evolution-2.32.3-1.fc14
    https://admin.fedoraproject.org/updates/xorg-x11-drv-nouveau-0.0.16-14.20101010git8c8f15c.fc14
    https://admin.fedoraproject.org/updates/libconcord-0.23-5.fc14,udev-161-9.fc14,concordance-0.23-2.fc14
    https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14


The following builds have been pushed to Fedora 14 updates-testing

    R-AnnotationDbi-1.14.1-1.fc14
    R-Biobase-2.12.1-1.fc14
    R-BufferedMatrix-1.16.0-1.fc14
    R-DynDoc-1.30.0-1.fc14
    R-GeneR-2.22.0-1.fc14
    R-IRanges-1.10.4-1.fc14
    R-RUnit-0.4.26-2.fc14
    R-affy-1.30.0-1.fc14
    R-affyio-1.20.0-1.fc14
    R-caTools-1.12-1.fc14
    R-multtest-2.8.0-1.fc14
    R-preprocessCore-1.14.0-1.fc14
    R-qvalue-1.26.0-1.fc14
    R-tkWidgets-1.30.0-1.fc14
    R-widgetTools-1.30.0-1.fc14
    asterisk-1.6.2.19-1.fc14
    bullet-2.78-1.fc14
    cppunit-1.12.1-5.fc14
    cups-1.4.7-2.fc14
    drupal7-7.4-1.fc14
    imgtarget-0.1.4-7.fc14
    kde-plasma-networkmanagement-0.9-0.41.1.20110616git.fc14
    libphidget-2.1.8.20110615-1.fc14
    python-msgpack-0.1.9-2.fc14
    python-taboot-0.3.0-1.fc14
    rubygem-gem2rpm-0.7.1-1.fc14
    scap-workbench-0.4.0-1.fc14
    tgif-4.2.5-1.fc14
    wordpress-3.1.4-1.fc14

Details about builds:


================================================================================
 R-AnnotationDbi-1.14.1-1.fc14 (FEDORA-2011-8883)
 Annotation Database Interface
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.14.1-1
- Update to version 1.14.1
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.12.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.12.0-1
- Update to version 1.12.0
--------------------------------------------------------------------------------


================================================================================
 R-Biobase-2.12.1-1.fc14 (FEDORA-2011-8883)
 Base functions for Bioconductor
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 2.12.1-1
- Update to version 2.12.1
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 2.10.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 2.10.0-1
- Update to version 2.10.0
--------------------------------------------------------------------------------


================================================================================
 R-BufferedMatrix-1.16.0-1.fc14 (FEDORA-2011-8883)
 A matrix data storage object method from bioconductor
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.16.0-1
- Update to version 1.16.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.14.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.14.0-1
- Update to version 1.14.0
--------------------------------------------------------------------------------


================================================================================
 R-DynDoc-1.30.0-1.fc14 (FEDORA-2011-8883)
 Functions for dynamic documents
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.30.0-1
- Update to version 1.30.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.28.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.28.0-1
- Update to version 1.28.0
--------------------------------------------------------------------------------


================================================================================
 R-GeneR-2.22.0-1.fc14 (FEDORA-2011-8883)
 R for genes and sequences analysis
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 2.22.0-1
- Update to version 2.22.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 2.20.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 2.20.0-1
- Update to version 2.20.0
--------------------------------------------------------------------------------


================================================================================
 R-IRanges-1.10.4-1.fc14 (FEDORA-2011-8883)
 Low-level containers for storing sets of integer ranges
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.10.4-1
- Update to version 1.10.4
* Tue Mar 15 2011 pingou <pingou at pingoured.fr> 1.8.9-1
- Update to version 1.8.9
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.8.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Jan 18 2011 pingou <pingou at pingoured.fr> 1.8.8-1
- Update to version 1.8.8
* Mon Dec 13 2010 pingou <pingou at pingoured.fr> 1.8.7-1
- Update to version 1.8.7
* Thu Nov 25 2010 pingou <pingou at pingoured.fr> 1.8.3-1
- Update to version 1.8.3
* Sun Nov  7 2010 pingou <pingou at pingoured.fr> 1.8.2-1
- Update to version 1.8.2
- Change requires from R to R-core
* Thu Oct 14 2010 pingou <pingou at pingoured.fr> 1.6.17-1
- Update to version 1.6.17
--------------------------------------------------------------------------------


================================================================================
 R-RUnit-0.4.26-2.fc14 (FEDORA-2011-8883)
 R Unit test framework
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 0.4.26-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 0.4.26-1
- Update to version 0.4.26
* Thu Oct 14 2010 pingou <pingou at pingoured.fr> 0.4.26-1
- Update to version 0.4.26
--------------------------------------------------------------------------------


================================================================================
 R-affy-1.30.0-1.fc14 (FEDORA-2011-8883)
 Methods for Affymetrix Oligonucleotide Arrays
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.30.0-1
- Update to version 1.30.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.28.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.28.0-1
- Update to version 1.28.0
--------------------------------------------------------------------------------


================================================================================
 R-affyio-1.20.0-1.fc14 (FEDORA-2011-8883)
 Tools for parsing Affymetrix data files
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.20.0-1
- Update to version 1.20.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.18.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.18.0-1
- Update to version 1.18.0
--------------------------------------------------------------------------------


================================================================================
 R-caTools-1.12-1.fc14 (FEDORA-2011-8883)
 Tools: moving window statistics, gif, base64, roc auc...
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.12-1
- Update to version 1.12
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.11-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Sat Jan 29 2011 pingou <pingou at pingoured.fr> 1.11-2
- Fix URL
- Fix source0 which fix the build...
* Mon Dec 20 2010 pingou <pingou at pingoured.fr> 1.11-1
- Update to version 1.11
--------------------------------------------------------------------------------


================================================================================
 R-multtest-2.8.0-1.fc14 (FEDORA-2011-8883)
 Multiple hypothesis testing library from Bioconductor
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 2.8.0-1
- Update to version 2.8.0
* Thu Feb 10 2011 pingou <pingou at pingoured.fr> 2.6.0-3
- Remove the check section to test build
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 2.6.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Sat Jan 29 2011 pingou <pingou at pingoured.fr> 2.6.0-1
- Update to version 2.6.0
--------------------------------------------------------------------------------


================================================================================
 R-preprocessCore-1.14.0-1.fc14 (FEDORA-2011-8883)
 A collection of pre-processing functions
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.14.0-1
- Update to version 1.14.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.12.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.12.0-1
- Update to version 1.12.0
--------------------------------------------------------------------------------


================================================================================
 R-qvalue-1.26.0-1.fc14 (FEDORA-2011-8883)
 Q-value estimation for false discovery rate control
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.26.0-1
- Update to version 1.26.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.24.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Nov 25 2010 pingou <pingou at pingoured.fr> 1.24.0-1
- Update to version 1.24.0
--------------------------------------------------------------------------------


================================================================================
 R-tkWidgets-1.30.0-1.fc14 (FEDORA-2011-8883)
 Widgets to provide user interfaces from bioconductor
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.30.0-1
- Update to version 1.30.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.28.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.28.0-1
- Update to version 1.28.0
--------------------------------------------------------------------------------


================================================================================
 R-widgetTools-1.30.0-1.fc14 (FEDORA-2011-8883)
 Bioconductor tools to support tcltk widgets
--------------------------------------------------------------------------------
Update Information:

Update to new Bioconductor
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 22 2011 pingou <pingou at pingoured.fr> 1.30.0-1
- Update to version 1.30.0
* Mon Feb  7 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.28.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Tue Oct 26 2010 pingou <pingou at pingoured.fr> 1.28.0-1
- Update to version 1.28.0
--------------------------------------------------------------------------------


================================================================================
 asterisk-1.6.2.19-1.fc14 (FEDORA-2011-8914)
 The Open Source PBX
--------------------------------------------------------------------------------
Update Information:

The Asterisk Development Team has announced the final maintenance release of
Asterisk, version 1.6.2.19. This release is available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/

Please note that Asterisk 1.6.2.19 is the final maintenance release from the
1.6.2 branch. Support for security related issues will continue until April 21,
2012. For more information about support of the various Asterisk branches, see
https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions

The release of Asterisk 1.6.2.19 resolves several issues reported by the
community and would have not been possible without your participation.
Thank you!

The following is a sample of the issues resolved in this release:

* Don't broadcast FullyBooted to every AMI connection
 The FullyBooted event should not be sent to every AMI connection
 every time someone connects via AMI. It should only be sent to
 the user who just connected.
 (Closes issue #18168. Reported, patched by FeyFre)
* Fix thread blocking issue in the sip TCP/TLS implementation.
 (Closes issue #18497. Reported by vois. Tested by vois, rossbeer, kowalma,
 Freddi_Fonet. Patched by dvossel)
* Don't delay DTMF in core bridge while listening for DTMF features.
 (Closes issue #15642, #16625. Reported by jasonshugart, sharvanek. Tested by
 globalnetinc, jde. Patched by oej, twilson)
* Fix chan_local crashs in local_fixup()
 Thanks OEJ for tracking down the issue and submitting the patch.
 (Closes issue #19053. Reported, patched by oej)
* Don't offer video to directmedia callee unless caller offered it as well
 (Closes issue #19195. Reported, patched by one47)

Additionally security announcements AST-2011-008, AST-2011-010, and
AST-2011-011 have been resolved in this release.

For a full list of changes in this release, please see the ChangeLog:

http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.19
The Asterisk Development Team has announced the release of Asterisk versions
1.4.41.1, 1.6.2.18.1, and 1.8.4.3, which are security releases.

These releases are available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/releases

The release of Asterisk 1.4.41.1, 1.6.2.18, and 1.8.4.3 resolves several issues
as outlined below:

* AST-2011-008: If a remote user sends a SIP packet containing a null,
 Asterisk assumes available data extends past the null to the
 end of the packet when the buffer is actually truncated when
 copied.  This causes SIP header parsing to modify data past
 the end of the buffer altering unrelated memory structures.
 This vulnerability does not affect TCP/TLS connections.
 -- Resolved in 1.6.2.18.1 and 1.8.4.3

* AST-2011-009: A remote user sending a SIP packet containing a Contact header
 with a missing left angle bracket (<) causes Asterisk to
 access a null pointer.
 -- Resolved in 1.8.4.3

* AST-2011-010: A memory address was inadvertently transmitted over the
 network via IAX2 via an option control frame and the remote party would try
 to access it.
 -- Resolved in 1.4.41.1, 1.6.2.18.1, and 1.8.4.3


The issues and resolutions are described in the AST-2011-008, AST-2011-009, and
AST-2011-010 security advisories.

For more information about the details of these vulnerabilities, please read
the security advisories AST-2011-008, AST-2011-009, and AST-2011-010, which were
released at the same time as this announcement.

For a full list of changes in the current releases, please see the ChangeLog:

http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.4.41.1
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.18.1
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.4.3

Security advisories AST-2011-008, AST-2011-009, and AST-2011-010 are available
at:

http://downloads.asterisk.org/pub/security/AST-2011-008.pdf
http://downloads.asterisk.org/pub/security/AST-2011-009.pdf
http://downloads.asterisk.org/pub/security/AST-2011-010.pdf
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 29 2011 Jeffrey C. Ollie <jeff at ocjtech.us> - 1.6.2.19-1:
- The Asterisk Development Team has announced the final maintenance release of
- Asterisk, version 1.6.2.19. This release is available for immediate download at
- http://downloads.asterisk.org/pub/telephony/asterisk/
-
- Please note that Asterisk 1.6.2.19 is the final maintenance release from the
- 1.6.2 branch. Support for security related issues will continue until April 21,
- 2012. For more information about support of the various Asterisk branches, see
- https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions
-
- The release of Asterisk 1.6.2.19 resolves several issues reported by the
- community and would have not been possible without your participation.
- Thank you!
-
- The following is a sample of the issues resolved in this release:
-
- * Don't broadcast FullyBooted to every AMI connection
-  The FullyBooted event should not be sent to every AMI connection
-  every time someone connects via AMI. It should only be sent to
-  the user who just connected.
-  (Closes issue #18168. Reported, patched by FeyFre)
- * Fix thread blocking issue in the sip TCP/TLS implementation.
-  (Closes issue #18497. Reported by vois. Tested by vois, rossbeer, kowalma,
-  Freddi_Fonet. Patched by dvossel)
- * Don't delay DTMF in core bridge while listening for DTMF features.
-  (Closes issue #15642, #16625. Reported by jasonshugart, sharvanek. Tested by
-  globalnetinc, jde. Patched by oej, twilson)
- * Fix chan_local crashs in local_fixup()
-  Thanks OEJ for tracking down the issue and submitting the patch.
-  (Closes issue #19053. Reported, patched by oej)
- * Don't offer video to directmedia callee unless caller offered it as well
-  (Closes issue #19195. Reported, patched by one47)
-
- Additionally security announcements AST-2011-008, AST-2011-010, and
- AST-2011-011 have been resolved in this release.
-
- For a full list of changes in this release, please see the ChangeLog:
-
- http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.19
* Tue Jun 28 2011 Jeffrey C. Ollie <jeff at ocjtech.us> - 1.6.2.19-0.1:
- The Asterisk Development Team has announced the first release
- candidate of Asterisk 1.6.2.19. This release candidate is available
- for immediate download at
- http://downloads.asterisk.org/pub/telephony/asterisk/
-
- Please note that Asterisk 1.6.2.19 will be the final maintenance
- release from the 1.6.2 branch. Support for security related issues
- will continue for one additional year. For more information about
- support of the various Asterisk branches, see
- https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions
-
- The release of Asterisk 1.6.2.19-rc1 resolves several issues reported
- by the community and would have not been possible without your
- participation.  Thank you!
-
- The following is a sample of the issues resolved in this release candidate:
-
- * Don't broadcast FullyBooted to every AMI connection The FullyBooted
-  event should not be sent to every AMI connection every time someone
-  connects via AMI. It should only be sent to the user who just
-  connected.  (Closes issue #18168. Reported, patched by FeyFre)
-
- * Fix thread blocking issue in the sip TCP/TLS implementation.
-  (Closes issue #18497. Reported by vois. Tested by vois, rossbeer,
-  kowalma, Freddi_Fonet. Patched by dvossel)
-
- * Don't delay DTMF in core bridge while listening for DTMF features.
-  (Closes issue #15642, #16625. Reported by jasonshugart,
-  sharvanek. Tested by globalnetinc, jde. Patched by oej, twilson)
-
- * Fix chan_local crashs in local_fixup() Thanks OEJ for tracking down
-  the issue and submitting the patch.  (Closes issue #19053. Reported,
-  patched by oej)
-
- * Don't offer video to directmedia callee unless caller offered it as
-  well (Closes issue #19195. Reported, patched by one47)
-
- For a full list of changes in this release candidate, please see the
- ChangeLog:
-
- http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.19-rc1
* Sat Jun 25 2011 Jeffrey C. Ollie <jeff at ocjtech.us> - 1.6.2.18.1-1
- The Asterisk Development Team has announced the release of Asterisk versions
- 1.4.41.1, 1.6.2.18.1, and 1.8.4.3, which are security releases.
-
- These releases are available for immediate download at
- http://downloads.asterisk.org/pub/telephony/asterisk/releases
-
- The release of Asterisk 1.4.41.1, 1.6.2.18, and 1.8.4.3 resolves several issues
- as outlined below:
-
- * AST-2011-008: If a remote user sends a SIP packet containing a null,
-  Asterisk assumes available data extends past the null to the
-  end of the packet when the buffer is actually truncated when
-  copied.  This causes SIP header parsing to modify data past
-  the end of the buffer altering unrelated memory structures.
-  This vulnerability does not affect TCP/TLS connections.
-  -- Resolved in 1.6.2.18.1 and 1.8.4.3
-
- * AST-2011-009: A remote user sending a SIP packet containing a Contact header
-  with a missing left angle bracket (<) causes Asterisk to
-  access a null pointer.
-  -- Resolved in 1.8.4.3
-
- * AST-2011-010: A memory address was inadvertently transmitted over the
-  network via IAX2 via an option control frame and the remote party would try
-  to access it.
-  -- Resolved in 1.4.41.1, 1.6.2.18.1, and 1.8.4.3
-
-
- The issues and resolutions are described in the AST-2011-008, AST-2011-009, and
- AST-2011-010 security advisories.
-
- For more information about the details of these vulnerabilities, please read
- the security advisories AST-2011-008, AST-2011-009, and AST-2011-010, which were
- released at the same time as this announcement.
-
- For a full list of changes in the current releases, please see the ChangeLog:
-
- http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.4.41.1
- http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.18.1
- http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.4.3
-
- Security advisories AST-2011-008, AST-2011-009, and AST-2011-010 are available
- at:
-
- http://downloads.asterisk.org/pub/security/AST-2011-008.pdf
- http://downloads.asterisk.org/pub/security/AST-2011-009.pdf
- http://downloads.asterisk.org/pub/security/AST-2011-010.pdf
--------------------------------------------------------------------------------


================================================================================
 bullet-2.78-1.fc14 (FEDORA-2011-8900)
 3D Collision Detection and Rigid Body Dynamics Library
--------------------------------------------------------------------------------
Update Information:

Update to bullet-2.78
--------------------------------------------------------------------------------
ChangeLog:

* Wed May 11 2011 Rich Mattes <richmattes at gmail.com> - 2.78-1
- Update to version 2.78
- Remove upstreamed patches
--------------------------------------------------------------------------------


================================================================================
 cppunit-1.12.1-5.fc14 (FEDORA-2011-8898)
 C++ unit testing framework
--------------------------------------------------------------------------------
Update Information:

Bug 641350 - implicit destructor of CppUnit::Message causes segfault when test is built with debug.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jun 28 2011 Steven M. Parrish <smparrish at gmail.com> - 1.12.1-5
- Fix for bug 452340
* Tue Feb  8 2011 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> - 1.12.1-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #641350 - implicit destructor of CppUnit::Message causes segfault when test is built with debug. STL
        https://bugzilla.redhat.com/show_bug.cgi?id=641350
--------------------------------------------------------------------------------


================================================================================
 cups-1.4.7-2.fc14 (FEDORA-2011-8916)
 Common Unix Printing System
--------------------------------------------------------------------------------
Update Information:

The new upstream release fixes a number of scheduler, driver, and backend issues.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 29 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.7-2
- Tag localization files correctly (bug #716421).
* Tue Jun 28 2011 Jiri Popelka <jpopelka at redhat.com> 1:1.4.7-1
- 1.4.7.
* Thu Mar 10 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-7
- LSPP: only warn when unable to get printer context.
* Fri Feb 25 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-6
- Fixed build failure due to php_zend_api macro type.
* Fri Feb 25 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-5
- Fixed dbus notifier support for job-state-changed.
* Thu Feb 10 2011 Jiri Popelka <jpopelka at redhat.com> 1:1.4.6-4
- Remove testing cups-usb-buffer-size.patch (bug #661814).
* Tue Jan 18 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-3
- Don't use --enable-pie configure option as it has been removed and
  is now assumed.  See STR #3691.
* Mon Jan 10 2011 Tim Waugh <twaugh at redhat.com> 1:1.4.6-2
- Use a smaller buffer when writing to USB devices (bug #661814).
- Handle EAI_NONAME when resolving hostnames (bug #617208).
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #716421 - cups package doesn't tag localization files correctly
        https://bugzilla.redhat.com/show_bug.cgi?id=716421
--------------------------------------------------------------------------------


================================================================================
 drupal7-7.4-1.fc14 (FEDORA-2011-8879)
 An open-source content-management platform
--------------------------------------------------------------------------------
Update Information:

Remember to log in as user 1 prior to the RPM update, to perform the DB upgrade via http://yoursite/update.php.

  * Advisory ID: DRUPAL-SA-CORE-2011-002
  * Project: Drupal core [1]
  * Version: 7.x
  * Date: 2011-JUNE-29
  * Security risk: Highly critical [2]
  * Exploitable from: Remote
  * Vulnerability: Access bypass

-------- DESCRIPTION  
---------------------------------------------------------

.... Access bypass in node listings

Listings showing nodes but not JOINing the node table show all nodes
regardless of restrictions imposed by the node_access system. In core, this
affects the taxonomy and the forum subsystem.

Note that fixing this issue in contributed modules requires a
backwards-compatible API change for modules listing nodes. See
http://drupal.org/node/1204572 [3] for more details.

This issue affects Drupal 7.x only.

-------- VERSIONS AFFECTED  
---------------------------------------------------

  * Drupal 7.0, 7.1 and 7.2.

-------- SOLUTION  
------------------------------------------------------------

Install the latest version:

  * If you are running Drupal 7.x then upgrade to Drupal 7.3 or 7.4.

The Security Team has released both a pure security update without other bug
fixes and a security update combined with other bug fixes and improvements.
You can choose to either only include the security update for an immediate
fix (which might require less quality assurance and testing) or more fixes
and improvements alongside the security fixes by choosing between Drupal 7.3
and Drupal 7.4. Read the announcement [4] for more information.

See also the Drupal core [5] project page.

-------- REPORTED BY  
---------------------------------------------------------

  * The access bypass was reported independently by numerous people, including
    Sascha Grossenbacher [6], Khaled Alhourani [7], and Ben Ford [8].

-------- FIXED BY  
------------------------------------------------------------

  * The access bypass was fixed by Károly Négyesi [9], member of the Drupal
    security team

-------- CONTACT AND MORE INFORMATION  
----------------------------------------

The Drupal security team can be reached at security at drupal.org or via the
contact form at http://drupal.org/contact [10].

Learn more about the Drupal Security team and their policies [11], writing
secure code for Drupal [12], and securing your site [13].


[1] http://drupal.org/project/drupal
[2] http://drupal.org/security-team/risk-levels
[3] http://drupal.org/node/1204572
[4] http://drupal.org/drupal-7.4
[5] http://drupal.org/project/drupal
[6] http://drupal.org/user/214652
[7] http://drupal.org/user/265439
[8] http://drupal.org/user/12534
[9] http://drupal.org/user/9446
[10] http://drupal.org/contact
[11] http://drupal.org/security-team
[12] http://drupal.org/writing-secure-code
[13] http://drupal.org/security/secure-configuration


--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 30 2011 Jon Ciesla <limb at jcomserv.net> - 7.4-1
- New upstream, SA-CORE-2011-002, BZ 717874.
- Dropped unused dirs in /etc/drupal7/, BZ 703736.
* Fri Jun 17 2011 Jon Ciesla <limb at jcomserv.net> - 7.2-2
- Bump and rebuild for BZ 712251.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #717874 - Remote access bypass vulnerability in Drupal 7
        https://bugzilla.redhat.com/show_bug.cgi?id=717874
  [ 2 ] Bug #706736 - Put modules and themes directories under /etc/drupal7/all/
        https://bugzilla.redhat.com/show_bug.cgi?id=706736
--------------------------------------------------------------------------------


================================================================================
 imgtarget-0.1.4-7.fc14 (FEDORA-2011-8891)
 Front-end to functionality provided by ArgyllCMS
--------------------------------------------------------------------------------
Update Information:

F14FTBFS, F16FTBFS
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 30 2011 Ralf Corsépius <corsepiu at fedoraproject.org> - 0.1.4-7
- Fix up broken spec-changelog entry.
* Thu Jun 30 2011 Ralf Corsépius <corsepiu at fedoraproject.org> - 0.1.4-6
- Append INCLUDES="-I/usr/include/netpbm" and LIBS="-lX11" to %configure
  (Fix FTBFS BZ#599895, BZ#715981).
--------------------------------------------------------------------------------


================================================================================
 kde-plasma-networkmanagement-0.9-0.41.1.20110616git.fc14 (FEDORA-2011-8910)
 NetworkManager KDE 4 integration
--------------------------------------------------------------------------------
Update Information:

An update of the Network Management Plasma widget to a more recent
snapshot, which fixes many bugs and adds support for system
connections.

(This matches what is now in Fedora 15, except that this is the
version for NetworkManager 0.8, from upstream's git master branch,
as opposed to the nm09 branch used in Fedora 15.)
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jun 17 2011 Kevin Kofler <Kevin at tigcc.ticalc.org> 1:0.9-0.41.1.20110616git
- 20110616 snapshot (from git master)
- drop NULL checks patch (fixed upstream)
--------------------------------------------------------------------------------


================================================================================
 libphidget-2.1.8.20110615-1.fc14 (FEDORA-2011-8896)
 Drivers and API for Phidget devices
--------------------------------------------------------------------------------
Update Information:

Update to version 2.1.8.20110615
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 29 2011 Rich Mattes <richmattes at gmail.com> - 2.1.8.20110615-1
- Update to 2.1.8.20110615
* Wed May 11 2011 Rich Mattes <richmattes at gmail.com> - 2.1.8.20110322-1
- Update to 2.1.8.20110322
--------------------------------------------------------------------------------


================================================================================
 python-msgpack-0.1.9-2.fc14 (FEDORA-2011-8901)
 A Python MessagePack (de)serializer
--------------------------------------------------------------------------------
Update Information:

MessagePack is a binary-based efficient data interchange format that is
focused on high performance. It is like JSON, but very fast and small.
This is a Python (de)serializer for MessagePack.

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #691114 - Review Request: python-msgpack - A MessagePack (de)serializer
        https://bugzilla.redhat.com/show_bug.cgi?id=691114
--------------------------------------------------------------------------------


================================================================================
 python-taboot-0.3.0-1.fc14 (FEDORA-2011-8888)
 Client utility for scripted multi-system administration over Func
--------------------------------------------------------------------------------
Update Information:

Fixed #13 - Generate HTML versions of the man pages

Fixed #6, #7, #11, #12 - Updated the Nagios task completely to use the native Func Nagios module

Fixed #17 - sleep.Minutes not printing correct status message

Fixed #20 - Be more helpful when YAML fails to load

Fixed #22 - Taboots not processing YAML files with multiple documents inside

Fixed #15 - Die gracefully when processing bad CLI options
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 23 2011 Tim Bielawa <tbielawa at redhat.com> 0.3.0-1
- Update version. 0.3.0. If Linux can do it -- so can we. (tbielawa at redhat.com)
- Now included in EPEL and Fedora. Fixes #9 (tbielawa at redhat.com)
- Correct a lot of spelling errors. Fixes #23 (Taboot maintainer has atrocious
  spelling) (tbielawa at redhat.com)
- Correctly handle YAML files with multiple YAML documents inside. Fixes #22
  (tbielawa at redhat.com)
- Better YAML loading debugging. Fixes #20 (tbielawa at redhat.com)
- Handle bad CLI options gracefully. Fixes #15 (tbielawa at redhat.com)
- Modify patch from jdetiber. Fixes #17 - sleep.Minutes not printing correct
  status message (tbielawa at redhat.com)
- Updated output for sleep.Minutes (jason.detiberus at redhat.com)
- Update man page (tbielawa at redhat.com)
- Update taboot-tasks manpage (tbielawa at redhat.com)
- Make HOST the default for downtime scheduling again (tbielawa at redhat.com)
- Updating Nagios task docs (tbielawa at redhat.com)
- Rewrite the Nagios task to use the new Func Nagios module instead of CURL.
  Fixes #6, #7, #11, #12 (tbielawa at redhat.com)
- Adding HTML versions of the man pages to the HTML docs. Fixes #13
  (tbielawa at redhat.com)
--------------------------------------------------------------------------------


================================================================================
 rubygem-gem2rpm-0.7.1-1.fc14 (FEDORA-2011-8899)
 Generate rpm specfiles from gems
--------------------------------------------------------------------------------
Update Information:

Updated to the 0.7.1 version.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 30 2011 Vít Ondruch <vondruch at redhat.com> - 0.7.1-1
- Updated to the 0.7.1 version.
* Tue Sep 28 2010 Michael Stahnke <stahnma at fedoraproject.org> - 0.6.0-5
- Breaking into a main and doc package
--------------------------------------------------------------------------------


================================================================================
 scap-workbench-0.4.0-1.fc14 (FEDORA-2011-8880)
 Scanning, tailoring, editing and validation tool for SCAP content
--------------------------------------------------------------------------------
Update Information:

New release
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 30 2011 Maros Barabas <xbarry at gmail.com> 0.4.0-1
- Redesign of abstract classes in editor
- New dialog module
- New preview dialog
- UI improvements
- Added documentation
- Fixed bugs
--------------------------------------------------------------------------------


================================================================================
 tgif-4.2.5-1.fc14 (FEDORA-2011-8894)
 2-D drawing tool
--------------------------------------------------------------------------------
Update Information:

New version 4.2.5 is released.




New version 4.2.4 is released.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Jun 30 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 4.2.5-1
- 4.2.5
* Sun Jun 26 2011 Mamoru Tasaka <mtasaka at fedoraproject.org> - 4.2.4-1
- 4.2.4
--------------------------------------------------------------------------------


================================================================================
 wordpress-3.1.4-1.fc14 (FEDORA-2011-8908)
 Blog tool and publishing platform
--------------------------------------------------------------------------------
Update Information:

Upstream security release. Details at
http://wordpress.org/news/2011/06/wordpress-3-1-4/
Fix old FSF address and Summary to make rpmlint happy.
Make wp-content directory owned by apache:apache.
Correctly Provides/Obsoletes (with versions).
Upgrade to the latest upstream version (security fixes and enhancements, BZ 707772).
Move wp-content directory to /var/www/wordpress/ (BZ 522897).
Simplify overly detailed files list.
Actually, we just don't need gettext.php at all, it is provided by
php itself. Just remove the file, don't make a symlink.
Revert back to wp-content in /usr/share/wordpress, I am not able to make it
work. Not fixing BZ 522897.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Jun 29 2011 Matěj Cepl <mcepl at redhat.com> - 3.1.4-1
- New upstream security release.
* Thu Jun  2 2011 Matěj Cepl <mcepl at redhat.com> - 3.1.3-3
- Actually, we just don't need gettext.php at all, it is provided by
  php itself. Just remove the file, don't make a symlink.
- revert back to wp-content in /usr/share/wordpress, I am not able to make it
  work. Not fixing BZ 522897.
* Wed Jun  1 2011 Matěj Cepl <mcepl at redhat.com> - 3.1.3-2
- Fix old FSF address and Summary to make rpmlint happy.
- Make wp-content directory owned by apache:apache
- Correctly Provides/Obsoletes (with versions)
* Wed May 25 2011 Matěj Cepl <mcepl at redhat.com> - 3.1.3-1
- Upgrade to the latest upstream version (security fixes and enhancements, BZ 707772)
- Move wp-content directory to /var/www/wordpress/ (BZ 522897)
- Simplify overly detailed %files
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #707772 - New upstream version 3.1.3 has been released
        https://bugzilla.redhat.com/show_bug.cgi?id=707772
  [ 2 ] Bug #522897 - Unable To Upload Images To /usr/share/wordpress/wp-content/uploads/
        https://bugzilla.redhat.com/show_bug.cgi?id=522897
--------------------------------------------------------------------------------



More information about the test mailing list