Fedora 20 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Tue Apr 29 05:29:58 UTC 2014


The following Fedora 20 Security updates need testing:
 Age  URL
 122  https://admin.fedoraproject.org/updates/FEDORA-2013-24018/varnish-3.0.5-1.fc20
  26  https://admin.fedoraproject.org/updates/FEDORA-2014-4691/a2ps-4.14-23.fc20
  14  https://admin.fedoraproject.org/updates/FEDORA-2014-5018/smb4k-1.1.1-2.fc20
  13  https://admin.fedoraproject.org/updates/FEDORA-2014-5079/cups-1.7.2-1.fc20
  13  https://admin.fedoraproject.org/updates/FEDORA-2014-5198/openstack-glance-2013.2.3-3.fc20
   7  https://admin.fedoraproject.org/updates/FEDORA-2014-5433/bugzilla-4.2.9-1.fc20
   6  https://admin.fedoraproject.org/updates/FEDORA-2014-5471/ndjbdns-1.06-1.fc20
   6  https://admin.fedoraproject.org/updates/FEDORA-2014-5497/openstack-keystone-2013.2.3-3.fc20
   6  https://admin.fedoraproject.org/updates/FEDORA-2014-5503/python-django-1.6.3-1.fc20
   6  https://admin.fedoraproject.org/updates/FEDORA-2014-5475/python-django14-1.4.11-1.fc20
   6  https://admin.fedoraproject.org/updates/FEDORA-2014-5486/python-django15-1.5.6-1.fc20
   6  https://admin.fedoraproject.org/updates/FEDORA-2014-5492/python-pillow-2.2.1-4.fc20
   4  https://admin.fedoraproject.org/updates/FEDORA-2014-5540/zabbix-2.0.11-3.fc20
   4  https://admin.fedoraproject.org/updates/FEDORA-2014-5555/python-keystoneclient-0.7.1-2.fc20
   2  https://admin.fedoraproject.org/updates/FEDORA-2014-5634/qemu-1.6.2-3.fc20
   1  https://admin.fedoraproject.org/updates/FEDORA-2014-5710/qt5-qtbase-5.2.1-8.fc20
   1  https://admin.fedoraproject.org/updates/FEDORA-2014-5695/qt-4.8.6-2.fc20
   1  https://admin.fedoraproject.org/updates/FEDORA-2014-5684/mediawiki-1.21.9-1.fc20
   0  https://admin.fedoraproject.org/updates/FEDORA-2014-5767/mumble-1.2.5-1.fc20
   0  https://admin.fedoraproject.org/updates/FEDORA-2014-5765/cups-filters-1.0.53-1.fc20


The following Fedora 20 Critical Path updates have yet to be approved:
 Age URL
  24  https://admin.fedoraproject.org/updates/FEDORA-2014-4774/gnome-shell-3.10.4-3.fc20
  13  https://admin.fedoraproject.org/updates/FEDORA-2014-5149/iscsi-initiator-utils-6.2.0.873-21.fc20
  13  https://admin.fedoraproject.org/updates/FEDORA-2014-5179/perl-Exporter-5.70-1.fc20
   7  https://admin.fedoraproject.org/updates/FEDORA-2014-5446/ibus-1.5.6-3.fc20
   0  https://admin.fedoraproject.org/updates/FEDORA-2014-5754/zenity-3.8.0-4.fc20


The following builds have been pushed to Fedora 20 updates-testing

    asterisk-11.9.0-1.fc20
    cups-filters-1.0.53-1.fc20
    darktable-1.4.2-1.fc20
    leveldbjni-1.8-1.fc20
    mate-applet-softupd-0.2.11-1.fc20
    mod_wsgi-3.4-13.fc20
    mumble-1.2.5-1.fc20
    perl-Apache-LogFormat-Compiler-0.30-2.fc20
    perl-MooX-late-0.014-3.fc20
    perl-Perl-Critic-Pulp-82-1.fc20
    perl-Test-Harness-3.28-4.fc20
    perl-Text-CSV_XS-1.06-1.fc20
    php-PHP-CSS-Parser-5.1.2-1.fc20
    php-horde-content-2.0.3-2.fc20
    php-tcpdf-6.0.072-1.fc20
    python-flask-script-0.6.7-1.fc20
    python-gstreamer1-1.2.1-1.fc20
    python-urllib3-1.8.2-1.fc20
    qtwebkit-2.3.3-7.fc20
    rubygem-mixlib-cli-1.5.0-1.fc20
    shogun-data-0.8.1-0.8.git20140420.8652c9c.fc20
    xorg-x11-proto-devel-7.7-10.fc20
    zenity-3.8.0-4.fc20

Details about builds:


================================================================================
 asterisk-11.9.0-1.fc20 (FEDORA-2014-5738)
 The Open Source PBX
--------------------------------------------------------------------------------
Update Information:

The Asterisk Development Team has announced the release of Asterisk 11.9.0.
This release is available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk

The release of Asterisk 11.9.0 resolves several issues reported by the
community and would have not been possible without your participation.
Thank you!

The following are the issues resolved in this release:

Bugs fixed in this release:
-----------------------------------
 * ASTERISK-22790 - check_modem_rate() may return incorrect rate
      for V.27 (Reported by Paolo Compagnini)
 * ASTERISK-23034 - [patch] manager Originate doesn't abort on
      failed format_cap allocation (Reported by Corey Farrell)
 * ASTERISK-23061 - [Patch] 'textsupport' setting not mentioned in
      sip.conf.sample (Reported by Eugene)
 * ASTERISK-23028 - [patch] Asterisk man pages contains unquoted
      minus signs (Reported by Jeremy Lainé)
 * ASTERISK-23046 - Custom CDR fields set during a GoSUB called
      from app_queue are not inserted (Reported by Denis Pantsyrev)
 * ASTERISK-23027 - [patch] Spelling typo "transfered" instead of
      "transferred" (Reported by Jeremy Lainé)
 * ASTERISK-23008 - Local channels loose CALLERID name when DAHDI
      channel connects (Reported by Michael Cargile)
 * ASTERISK-23100 - [patch] In chan_mgcp the ident in transmitted
      request and request queue may differ - fix for locking (Reported
      by adomjan)
 * ASTERISK-22988 - [patch]T38 , SIP 488 after Rejecting image
      media offer due to invalid or unsupported syntax (Reported by
      adomjan)
 * ASTERISK-22861 - [patch]Specifying a null time as parameter to
      GotoIfTime or ExecIfTime causes segmentation fault (Reported by
      Sebastian Murray-Roberts)
 * ASTERISK-17837 - extconfig.conf - Maximum Include level (1)
      exceeded (Reported by pz)
 * ASTERISK-22662 - Documentation fix? - queues.conf says
      persistentmembers defaults to yes, it appears to lie (Reported
      by Rusty Newton)
 * ASTERISK-23134 - [patch] res_rtp_asterisk port selection cannot
      handle selinux port restrictions (Reported by Corey Farrell)
 * ASTERISK-23220 - STACK_PEEK function with no arguments causes
      crash/core dump (Reported by James Sharp)
 * ASTERISK-19773 - Asterisk crash on issuing Asterisk-CLI 'reload'
      command multiple times on cli_aliases (Reported by Joel Vandal)
 * ASTERISK-22757 - segfault in res_clialiases.so on reload when
      mapping "module reload" command (Reported by Gareth Blades)
 * ASTERISK-17727 - [patch] TLS doesn't get all certificate chain
      (Reported by LN)
 * ASTERISK-23178 - devicestate.h: device state setting functions
      are documented with the wrong return values (Reported by
      Jonathan Rose)
 * ASTERISK-23232 - LocalBridge AMI Event LocalOptimization value
      is opposite to what's expected (Reported by Leon Roy)
 * ASTERISK-23098 - [patch]possible null pointer dereference in
      format.c (Reported by Marcello Ceschia)
 * ASTERISK-23297 - Asterisk 12, pbx_config.so segfaults if
      res_parking.so is not loaded, or if res_parking.conf has no
      configuration (Reported by CJ Oster)
 * ASTERISK-23069 - Custom CDR variable not recorded when set in
      macro called from app_queue (Reported by Bryan Anderson)
 * ASTERISK-19499 - ConfBridge MOH is not working for transferee
      after attended transfer (Reported by Timo Teräs)
 * ASTERISK-23261 - [patch]Output mixup in
      ${CHANNEL(rtpqos,audio,all)} (Reported by rsw686)
 * ASTERISK-23279 - [patch]Asterisk doesn't support the dynamic
      payload change in rtp mapping in the 200 OK response (Reported
      by NITESH BANSAL)
 * ASTERISK-23255 - UUID included for Redhat, but missing for
      Debian distros in install_prereq script (Reported by Rusty
      Newton)
 * ASTERISK-23260 - [patch]ForkCDR v option does not keep CDR
      variables for subsequent records (Reported by zvision)
 * ASTERISK-23141 - Asterisk crashes on Dial(), in
      pbx_find_extension at pbx.c (Reported by Maxim)
 * ASTERISK-23336 - Asterisk warning "Don't know how to indicate
      condition 33 on ooh323c" on outgoing calls from H323 to SIP peer
      (Reported by Alexander Semych)
 * ASTERISK-23231 - Since 405693 If we have res_fax.conf file set
      to minrate=2400, then res_fax refuse to load (Reported by David
      Brillert)
 * ASTERISK-23135 - Crash - segfault in ast_channel_hangupcause_set
      - probably introduced in 11.7.0 (Reported by OK)
 * ASTERISK-23323 - [patch]chan_sip: missing p->owner checks in
      handle_response_invite (Reported by Walter Doekes)
 * ASTERISK-23406 - [patch]Fix typo in "sip show peer" (Reported by
      ibercom)
 * ASTERISK-23310 - bridged channel crashes in bridge_p2p_rtp_write
      (Reported by Jeremy Lainé)
 * ASTERISK-22911 - [patch]Asterisk fails to resume WebRTC call
      from hold (Reported by Vytis Valentinavičius)
 * ASTERISK-23104 - Specifying the SetVar AMI without a Channel
      cause Asterisk to crash (Reported by Joel Vandal)
 * ASTERISK-21930 - [patch]WebRTC over WSS is not working.
      (Reported by John)
 * ASTERISK-23383 - Wrong sense test on stat return code causes
      unchanged config check to break with include files. (Reported by
      David Woolley)
 * ASTERISK-20149 - Crash when faxing SIP to SIP with strictrtp set
      to yes (Reported by Alexandr Gordeev)
 * ASTERISK-17523 - Qualify for static realtime peers does not work
      (Reported by Maciej Krajewski)
 * ASTERISK-21406 - [patch] chan_sip deadlock on monlock between
      unload_module and do_monitor (Reported by Corey Farrell)
 * ASTERISK-23373 - [patch]Security: Open FD exhaustion with
      chan_sip Session-Timers (Reported by Corey Farrell)
 * ASTERISK-23340 - Security Vulnerability: stack allocation of
      cookie headers in loop allows for unauthenticated remote denial
      of service attack (Reported by Matt Jordan)
 * ASTERISK-23311 - Manager - MoH Stop Event fails to show up when
      leaving Conference (Reported by Benjamin Keith Ford)
 * ASTERISK-23420 - [patch]Memory leak in manager_add_filter
      function in manager.c (Reported by Etienne Lessard)
 * ASTERISK-23488 - Logic error in callerid checksum processing
      (Reported by Russ Meyerriecks)
 * ASTERISK-23461 - Only first user is muted when joining
      confbridge with 'startmuted=yes' (Reported by Chico Manobela)
 * ASTERISK-20841 - fromdomain not honored on outbound INVITE
      request (Reported by Kelly Goedert)
 * ASTERISK-22079 - Segfault: INTERNAL_OBJ (user_data=0x6374652f)
      at astobj2.c:120 (Reported by Jamuel Starkey)
 * ASTERISK-23509 - [patch]SayNumber for Polish language tries to
      play empty files for numbers divisible by 100 (Reported by
      zvision)
 * ASTERISK-23103 - [patch]Crash in ast_format_cmp, in ao2_find
      (Reported by JoshE)
 * ASTERISK-23391 - Audit dialplan function usage of channel
      variable (Reported by Corey Farrell)
 * ASTERISK-23548 - POST to ARI sometimes returns no body on
      success (Reported by Scott Griepentrog)
 * ASTERISK-23460 - ooh323 channel stuck if call is placed directly
      and gatekeeper is not available (Reported by Dmitry Melekhov)

Improvements made in this release:
-----------------------------------
 * ASTERISK-22980 - [patch]Allow building cdr_radius and cel_radius
      against libfreeradius-client (Reported by Jeremy Lainé)
 * ASTERISK-22661 - Unable to exit ChanSpy if spied channel does
      not have a call in progress (Reported by Chris Hillman)
 * ASTERISK-23099 - [patch] WSS: enable ast_websocket_read()
      function to read the whole available data at first and then wait
      for any fragmented packets (Reported by Thava Iyer)

For a full list of changes in this release, please see the ChangeLog:

http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-11.9.0
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr 23 2014 Jeffrey Ollie <jeff at ocjtech.us> - 11.9.0-1:
- The Asterisk Development Team has announced the release of Asterisk 11.9.0.
- This release is available for immediate download at
- http://downloads.asterisk.org/pub/telephony/asterisk
-
- The release of Asterisk 11.9.0 resolves several issues reported by the
- community and would have not been possible without your participation.
- Thank you!
-
- The following are the issues resolved in this release:
-
- Bugs fixed in this release:
- -----------------------------------
-  * ASTERISK-22790 - check_modem_rate() may return incorrect rate
-       for V.27 (Reported by Paolo Compagnini)
-  * ASTERISK-23034 - [patch] manager Originate doesn't abort on
-       failed format_cap allocation (Reported by Corey Farrell)
-  * ASTERISK-23061 - [Patch] 'textsupport' setting not mentioned in
-       sip.conf.sample (Reported by Eugene)
-  * ASTERISK-23028 - [patch] Asterisk man pages contains unquoted
-       minus signs (Reported by Jeremy Lainé)
-  * ASTERISK-23046 - Custom CDR fields set during a GoSUB called
-       from app_queue are not inserted (Reported by Denis Pantsyrev)
-  * ASTERISK-23027 - [patch] Spelling typo "transfered" instead of
-       "transferred" (Reported by Jeremy Lainé)
-  * ASTERISK-23008 - Local channels loose CALLERID name when DAHDI
-       channel connects (Reported by Michael Cargile)
-  * ASTERISK-23100 - [patch] In chan_mgcp the ident in transmitted
-       request and request queue may differ - fix for locking (Reported
-       by adomjan)
-  * ASTERISK-22988 - [patch]T38 , SIP 488 after Rejecting image
-       media offer due to invalid or unsupported syntax (Reported by
-       adomjan)
-  * ASTERISK-22861 - [patch]Specifying a null time as parameter to
-       GotoIfTime or ExecIfTime causes segmentation fault (Reported by
-       Sebastian Murray-Roberts)
-  * ASTERISK-17837 - extconfig.conf - Maximum Include level (1)
-       exceeded (Reported by pz)
-  * ASTERISK-22662 - Documentation fix? - queues.conf says
-       persistentmembers defaults to yes, it appears to lie (Reported
-       by Rusty Newton)
-  * ASTERISK-23134 - [patch] res_rtp_asterisk port selection cannot
-       handle selinux port restrictions (Reported by Corey Farrell)
-  * ASTERISK-23220 - STACK_PEEK function with no arguments causes
-       crash/core dump (Reported by James Sharp)
-  * ASTERISK-19773 - Asterisk crash on issuing Asterisk-CLI 'reload'
-       command multiple times on cli_aliases (Reported by Joel Vandal)
-  * ASTERISK-22757 - segfault in res_clialiases.so on reload when
-       mapping "module reload" command (Reported by Gareth Blades)
-  * ASTERISK-17727 - [patch] TLS doesn't get all certificate chain
-       (Reported by LN)
-  * ASTERISK-23178 - devicestate.h: device state setting functions
-       are documented with the wrong return values (Reported by
-       Jonathan Rose)
-  * ASTERISK-23232 - LocalBridge AMI Event LocalOptimization value
-       is opposite to what's expected (Reported by Leon Roy)
-  * ASTERISK-23098 - [patch]possible null pointer dereference in
-       format.c (Reported by Marcello Ceschia)
-  * ASTERISK-23297 - Asterisk 12, pbx_config.so segfaults if
-       res_parking.so is not loaded, or if res_parking.conf has no
-       configuration (Reported by CJ Oster)
-  * ASTERISK-23069 - Custom CDR variable not recorded when set in
-       macro called from app_queue (Reported by Bryan Anderson)
-  * ASTERISK-19499 - ConfBridge MOH is not working for transferee
-       after attended transfer (Reported by Timo Teräs)
-  * ASTERISK-23261 - [patch]Output mixup in
-       ${CHANNEL(rtpqos,audio,all)} (Reported by rsw686)
-  * ASTERISK-23279 - [patch]Asterisk doesn't support the dynamic
-       payload change in rtp mapping in the 200 OK response (Reported
-       by NITESH BANSAL)
-  * ASTERISK-23255 - UUID included for Redhat, but missing for
-       Debian distros in install_prereq script (Reported by Rusty
-       Newton)
-  * ASTERISK-23260 - [patch]ForkCDR v option does not keep CDR
-       variables for subsequent records (Reported by zvision)
-  * ASTERISK-23141 - Asterisk crashes on Dial(), in
-       pbx_find_extension at pbx.c (Reported by Maxim)
-  * ASTERISK-23336 - Asterisk warning "Don't know how to indicate
-       condition 33 on ooh323c" on outgoing calls from H323 to SIP peer
-       (Reported by Alexander Semych)
-  * ASTERISK-23231 - Since 405693 If we have res_fax.conf file set
-       to minrate=2400, then res_fax refuse to load (Reported by David
-       Brillert)
-  * ASTERISK-23135 - Crash - segfault in ast_channel_hangupcause_set
-       - probably introduced in 11.7.0 (Reported by OK)
-  * ASTERISK-23323 - [patch]chan_sip: missing p->owner checks in
-       handle_response_invite (Reported by Walter Doekes)
-  * ASTERISK-23406 - [patch]Fix typo in "sip show peer" (Reported by
-       ibercom)
-  * ASTERISK-23310 - bridged channel crashes in bridge_p2p_rtp_write
-       (Reported by Jeremy Lainé)
-  * ASTERISK-22911 - [patch]Asterisk fails to resume WebRTC call
-       from hold (Reported by Vytis Valentinavičius)
-  * ASTERISK-23104 - Specifying the SetVar AMI without a Channel
-       cause Asterisk to crash (Reported by Joel Vandal)
-  * ASTERISK-21930 - [patch]WebRTC over WSS is not working.
-       (Reported by John)
-  * ASTERISK-23383 - Wrong sense test on stat return code causes
-       unchanged config check to break with include files. (Reported by
-       David Woolley)
-  * ASTERISK-20149 - Crash when faxing SIP to SIP with strictrtp set
-       to yes (Reported by Alexandr Gordeev)
-  * ASTERISK-17523 - Qualify for static realtime peers does not work
-       (Reported by Maciej Krajewski)
-  * ASTERISK-21406 - [patch] chan_sip deadlock on monlock between
-       unload_module and do_monitor (Reported by Corey Farrell)
-  * ASTERISK-23373 - [patch]Security: Open FD exhaustion with
-       chan_sip Session-Timers (Reported by Corey Farrell)
-  * ASTERISK-23340 - Security Vulnerability: stack allocation of
-       cookie headers in loop allows for unauthenticated remote denial
-       of service attack (Reported by Matt Jordan)
-  * ASTERISK-23311 - Manager - MoH Stop Event fails to show up when
-       leaving Conference (Reported by Benjamin Keith Ford)
-  * ASTERISK-23420 - [patch]Memory leak in manager_add_filter
-       function in manager.c (Reported by Etienne Lessard)
-  * ASTERISK-23488 - Logic error in callerid checksum processing
-       (Reported by Russ Meyerriecks)
-  * ASTERISK-23461 - Only first user is muted when joining
-       confbridge with 'startmuted=yes' (Reported by Chico Manobela)
-  * ASTERISK-20841 - fromdomain not honored on outbound INVITE
-       request (Reported by Kelly Goedert)
-  * ASTERISK-22079 - Segfault: INTERNAL_OBJ (user_data=0x6374652f)
-       at astobj2.c:120 (Reported by Jamuel Starkey)
-  * ASTERISK-23509 - [patch]SayNumber for Polish language tries to
-       play empty files for numbers divisible by 100 (Reported by
-       zvision)
-  * ASTERISK-23103 - [patch]Crash in ast_format_cmp, in ao2_find
-       (Reported by JoshE)
-  * ASTERISK-23391 - Audit dialplan function usage of channel
-       variable (Reported by Corey Farrell)
-  * ASTERISK-23548 - POST to ARI sometimes returns no body on
-       success (Reported by Scott Griepentrog)
-  * ASTERISK-23460 - ooh323 channel stuck if call is placed directly
-       and gatekeeper is not available (Reported by Dmitry Melekhov)
-
- Improvements made in this release:
- -----------------------------------
-  * ASTERISK-22980 - [patch]Allow building cdr_radius and cel_radius
-       against libfreeradius-client (Reported by Jeremy Lainé)
-  * ASTERISK-22661 - Unable to exit ChanSpy if spied channel does
-       not have a call in progress (Reported by Chris Hillman)
-  * ASTERISK-23099 - [patch] WSS: enable ast_websocket_read()
-       function to read the whole available data at first and then wait
-       for any fragmented packets (Reported by Thava Iyer)
--------------------------------------------------------------------------------


================================================================================
 cups-filters-1.0.53-1.fc20 (FEDORA-2014-5765)
 OpenPrinting CUPS filters and backends
--------------------------------------------------------------------------------
Update Information:

This update fixes two flaws and various bugs.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Jiri Popelka <jpopelka at redhat.com> - 1.0.53-1
- 1.0.53
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1091565 - cups-filters: inadequate fix for CVE-2014-2707
        https://bugzilla.redhat.com/show_bug.cgi?id=1091565
  [ 2 ] Bug #1091568 - cups-filters: unsupported BrowseAllow value lets cups-browsed accept from all hosts
        https://bugzilla.redhat.com/show_bug.cgi?id=1091568
--------------------------------------------------------------------------------


================================================================================
 darktable-1.4.2-1.fc20 (FEDORA-2014-5739)
 Utility to organize and develop raw images
--------------------------------------------------------------------------------
Update Information:

upgrade to 1.4.2
--------------------------------------------------------------------------------
ChangeLog:

* Fri Apr 25 2014 Edouard Bourguignon <madko at linuxed.net> - 1.4.2-1
- Upgrade to 1.4.2
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1090878 - darktable-1.4.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1090878
--------------------------------------------------------------------------------


================================================================================
 leveldbjni-1.8-1.fc20 (FEDORA-2014-5748)
 A Java Native Interface to LevelDB
--------------------------------------------------------------------------------
Update Information:

Initial import (#881590)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #881590 - Review Request: leveldbjni - A Java Native Interface to LevelDB
        https://bugzilla.redhat.com/show_bug.cgi?id=881590
--------------------------------------------------------------------------------


================================================================================
 mate-applet-softupd-0.2.11-1.fc20 (FEDORA-2014-5740)
 MATE Software Update Applet
--------------------------------------------------------------------------------
Update Information:

* Mon Apr 28 2014 Patrick Monnerat <pm at datasphere.ch> 0.2.11-1
- New upstream release.
- Stop timers on applet destroy.
  https://bugzilla.redhat.com/show_bug.cgi?id=1086989
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Patrick Monnerat <pm at datasphere.ch> 0.2.11-1
- New upstream release.
- Stop timers on applet destroy.
  https://bugzilla.redhat.com/show_bug.cgi?id=1086989
* Wed Dec 11 2013 Michael Schwendt <mschwendt at fedoraproject.org> - 0.2.10-2
- Add %{?_isa} to PackageKit Requires to avoid arch-independent deps on
  PackageKit causing multiarch conflicts (#972571).
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1086989 - [abrt] mate-applet-softupd: check_dead_bones(): softupd_applet killed by SIGSEGV
        https://bugzilla.redhat.com/show_bug.cgi?id=1086989
--------------------------------------------------------------------------------


================================================================================
 mod_wsgi-3.4-13.fc20 (FEDORA-2014-5756)
 A WSGI interface for Python web applications in Apache
--------------------------------------------------------------------------------
Update Information:

Backport python3-mod_wsgi to f20, do not use conflicts between mod_wsgi packages (rhbz#1087943)
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Matthias Runge <mrunge at redhat.com> - 3.4.13
- do not use conflicts between mod_wsgi packages (rhbz#1087943)
* Thu Jan 23 2014 Joe Orton <jorton at redhat.com> - 3.4-12
- fix _httpd_mmn expansion in absence of httpd-devel
* Fri Jan 10 2014 Matthias Runge <mrunge at redhat.com> - 3.4-11
- added python3 subpackage (thanks to Jakub Dorňák), rhbz#1035876
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1087943 - Do not use Conflicts between mod_wsgi packages -- use conditional in apache conf file instead
        https://bugzilla.redhat.com/show_bug.cgi?id=1087943
  [ 2 ] Bug #1082109 - Backport python3-mod_wsgi to F20
        https://bugzilla.redhat.com/show_bug.cgi?id=1082109
--------------------------------------------------------------------------------


================================================================================
 mumble-1.2.5-1.fc20 (FEDORA-2014-5767)
 Voice chat suite aimed at gamers
--------------------------------------------------------------------------------
Update Information:

New upstream release 1.2.5.

This update fixes:
* CVE-2014-0044
* CVE-2014-0045
--------------------------------------------------------------------------------
ChangeLog:

* Fri Apr 25 2014 Christian Krause <chkr at fedoraproject.org> - 1.2.5-1
- Update 1.2.5 (BZ 1062209)
- Update fixes CVE-2014-0044 (BZ 1061857) and CVE-2014-0045 (BZ 1061858)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1061857 - CVE-2014-0044 mumble: NULL pointer dereference leads to denial of service
        https://bugzilla.redhat.com/show_bug.cgi?id=1061857
  [ 2 ] Bug #1061858 - CVE-2014-0045 mumble: NULL pointer dereference leads to denial of service
        https://bugzilla.redhat.com/show_bug.cgi?id=1061858
--------------------------------------------------------------------------------


================================================================================
 perl-Apache-LogFormat-Compiler-0.30-2.fc20 (FEDORA-2014-5766)
 Compile a log format string to perl-code
--------------------------------------------------------------------------------
Update Information:

 
--------------------------------------------------------------------------------
ChangeLog:

* Fri Apr 25 2014 Petr Pisar <ppisar at redhat.com> - 0.30-2
- Drop unneeded build-time dependencies
* Thu Apr 17 2014 Ralf Corsépius <corsepiu at fedoraproject.org> 0.30-1
- Upstream update.
- Reflect upstream R:/BR: changes.
* Fri Jan 17 2014 Ralf Corsépius <corsepiu at fedoraproject.org> 0.23-1
- Upstream update.
- Reflect upstream R:/BR: changes.
--------------------------------------------------------------------------------


================================================================================
 perl-MooX-late-0.014-3.fc20 (FEDORA-2014-5768)
 Easily translate Moose code to Moo
--------------------------------------------------------------------------------
Update Information:

 
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1079618 - Review Request: perl-MooX-late - Easily translate Moose code to Moo
        https://bugzilla.redhat.com/show_bug.cgi?id=1079618
--------------------------------------------------------------------------------


================================================================================
 perl-Perl-Critic-Pulp-82-1.fc20 (FEDORA-2014-5753)
 Some add-on perlcritic policies
--------------------------------------------------------------------------------
Update Information:

This release fixes handling =begin POD blocks.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Petr Pisar <ppisar at redhat.com> - 82-1
- 82 version bump
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1091918 - perl-Perl-Critic-Pulp-82 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1091918
--------------------------------------------------------------------------------


================================================================================
 perl-Test-Harness-3.28-4.fc20 (FEDORA-2014-5734)
 Run Perl standard test scripts with statistics
--------------------------------------------------------------------------------
Update Information:

This release silents a warning when running tests under tainted mode if PERL5LIB environment variable does not exist.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Petr Pisar <ppisar at redhat.com> - 3.28-4
- Do not warn on tainted test without PERL5LIB environment variable
  (bug #1091916)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1091916 - Warning in TAP::Parser::SourceHandler::Perl
        https://bugzilla.redhat.com/show_bug.cgi?id=1091916
--------------------------------------------------------------------------------


================================================================================
 perl-Text-CSV_XS-1.06-1.fc20 (FEDORA-2014-5745)
 Comma-separated values manipulation routines
--------------------------------------------------------------------------------
Update Information:

Close filehandles in csv() only on real files.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Petr Šabata <contyk at redhat.com> - 1.06-1
- 1.06 bump
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1091737 - perl-Text-CSV_XS-1.06 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1091737
--------------------------------------------------------------------------------


================================================================================
 php-PHP-CSS-Parser-5.1.2-1.fc20 (FEDORA-2014-5749)
 A Parser for CSS Files
--------------------------------------------------------------------------------
Update Information:

* Add fr relative size unit
* Fix some issues with HHVM
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Remi Collet <remi at fedoraproject.org> - 5.1.2-1
- update to 5.1.2
--------------------------------------------------------------------------------


================================================================================
 php-horde-content-2.0.3-2.fc20 (FEDORA-2014-5758)
 Tagging application
--------------------------------------------------------------------------------
Update Information:

This application provides tagging support for the other Horde applications.

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1087046 - Review Request: php-horde-content - Tagging application
        https://bugzilla.redhat.com/show_bug.cgi?id=1087046
--------------------------------------------------------------------------------


================================================================================
 php-tcpdf-6.0.072-1.fc20 (FEDORA-2014-5747)
 PHP class for generating PDF documents
--------------------------------------------------------------------------------
Update Information:

Upstream Changelog:

6.0.072 (2014-04-27)
* Deprecated curly braces substring syntax was replaced with square braces.

6.0.071 (2014-04-25)
* Bug #911 "error with buffered png pics" was fixed.

6.0.070 (2014-04-24)
* Bug #910 "An SVG image is being cut off (with clipping mask) when you use align options" was fixed.

6.0.069 (2014-04-24)
* Datamatrix Base256 encoding was fixed.

6.0.068 (2014-04-22)
* Some Datamatrix barcode bugs were fixed.

6.0.067 (2014-04-21)
* startLayer() method signature was changed to include a new "lock" parameter.

6.0.066 (2014-04-20)
* Bug #908 "Linebreak is not considered when getting length of the next string" was fixed.

6.0.065 (2014-04-10)
* Bug #905 "RGB percentage color bug in convertHTMLColorToDec()" was fixed.

--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Remi Collet <remi at fedoraproject.org> - 6.0.072-1
- update to 6.0.072
--------------------------------------------------------------------------------


================================================================================
 python-flask-script-0.6.7-1.fc20 (FEDORA-2014-5762)
 Scripting support for Flask
--------------------------------------------------------------------------------
Update Information:

Update to v0.6.7
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Robert Kuska <rkuska at redhat.com> - 0.6.7-1
- Update to 0.6.7
--------------------------------------------------------------------------------


================================================================================
 python-gstreamer1-1.2.1-1.fc20 (FEDORA-2014-5764)
 Python bindings for GStreamer
--------------------------------------------------------------------------------
Update Information:

Upstream release gstreamer-python-1.2.1, fixing Python 3 support
--------------------------------------------------------------------------------
ChangeLog:

* Sun Apr 27 2014 Simon Farnsworth <simon.farnsworth at onelan.co.uk> - 1.2.1-1
- Upstream release gstreamer-python-1.2.1, fixing Python 3 support
* Mon Mar 17 2014 Simon Farnsworth <simon.farnsworth at onelan.co.uk> - 1.2.0-2
- Disable Python 3 support - it's too buggy to ship
- Correct faulty macro setting in Python 3 block - it broke Python 2 build
* Sun Mar 16 2014 Simon Farnsworth <simon.farnsworth at onelan.co.uk> - 1.2.0-1
- Upstream release gstreamer-python-1.2.0
- Python 3 support
--------------------------------------------------------------------------------


================================================================================
 python-urllib3-1.8.2-1.fc20 (FEDORA-2014-5743)
 Python HTTP library with thread-safe connection pooling and file post
--------------------------------------------------------------------------------
Update Information:

Update to latest upstream version
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 21 2014 Arun S A G <sagarun at gmail.com> - 1.8.2-1
- Update to latest upstream version
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1089626 - urllib3 1.8.2 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1089626
--------------------------------------------------------------------------------


================================================================================
 qtwebkit-2.3.3-7.fc20 (FEDORA-2014-5763)
 Qt WebKit bindings
--------------------------------------------------------------------------------
Update Information:

backport some upstream fixes
--------------------------------------------------------------------------------
ChangeLog:

* Thu Feb 13 2014 Rex Dieter <rdieter at fedoraproject.org> 2.3.3-7
- backport more upstream fixes
* Thu Feb 13 2014 Rex Dieter <rdieter at fedoraproject.org> 2.3.3-6
- ftbfs using bison3
* Wed Feb 12 2014 Rex Dieter <rdieter at fedoraproject.org> 2.3.3-5
- rebuild (libicu)
* Wed Jan  1 2014 Rex Dieter <rdieter at fedoraproject.org> 2.3.3-4
- rebuild (libwebp)
--------------------------------------------------------------------------------


================================================================================
 rubygem-mixlib-cli-1.5.0-1.fc20 (FEDORA-2014-5737)
 Simple Ruby mix-in for CLI interfaces
--------------------------------------------------------------------------------
Update Information:

Update to 1.5.0 (bz#1091745)
--------------------------------------------------------------------------------
ChangeLog:

* Sun Apr 27 2014 Julian C. Dunn <jdunn at aquezada.com> - 1.5.0-1
- Update to 1.5.0 (bz#1091745)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1091745 - rubygem-mixlib-cli-1.5.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1091745
--------------------------------------------------------------------------------


================================================================================
 shogun-data-0.8.1-0.8.git20140420.8652c9c.fc20 (FEDORA-2014-5757)
 Data-files for the SHOGUN machine learning toolbox
--------------------------------------------------------------------------------
Update Information:

updated to new snapshot git20140420.8652c9c8f81742a80ee9b999ea182fd9624dd4f2
--------------------------------------------------------------------------------
ChangeLog:

* Thu Apr 24 2014 Björn Esser <bjoern.esser at gmail.com> - 0.8.1-0.8.git20140420.8652c9c
- updated to new snapshot git20140420.8652c9c8f81742a80ee9b999ea182fd9624dd4f2
* Mon Apr 14 2014 Björn Esser <bjoern.esser at gmail.com> - 0.8.1-0.7.git20140414.9a8b634
- updated to new snapshot git20140414.9a8b634ebdbc013ae020191bf1f5fe9846168087
* Mon Apr 14 2014 Björn Esser <bjoern.esser at gmail.com> - 0.8.1-0.6.git20140408.1e5eb17
- updated to new snapshot git20140408.1e5eb17040965b5ffe7f6c13ab3d7eae41fd7a25
- removed %config from macro-files
* Tue Mar 18 2014 Björn Esser <bjoern.esser at gmail.com> - 0.8.1-0.5.git20140317.082eeb5
- updated to new snapshot git20140317.082eeb56ea20fc55085950e6114ef4e7849d438d
--------------------------------------------------------------------------------


================================================================================
 xorg-x11-proto-devel-7.7-10.fc20 (FEDORA-2014-5744)
 X.Org X11 Protocol headers
--------------------------------------------------------------------------------
Update Information:

fontsproto-2.1.3, videoproto 2.3.2, xextproto 7.3.0, xproto 7.0.26, misc bugfixes
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr 16 2014 Hans de Goede <hdegoede at redhat.com> - 7.7-10
- fontsproto-2.1.3
- videoproto-2.3.2
- xextproto-7.3.0
- xproto-7.0.26
- Cherry pick some unreleased fixes from upstream git
--------------------------------------------------------------------------------


================================================================================
 zenity-3.8.0-4.fc20 (FEDORA-2014-5754)
 Display dialog boxes from shell scripts
--------------------------------------------------------------------------------
Update Information:

This update makes list boxes expand to fill the window, again.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Apr 28 2014 Matthias Clasen <mclasen at redhat.com> - 3.8.0-4
- Fix nonexpanding list boxes (#1022949)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1022949 - zenity --list --height does not stretch list widget to window height
        https://bugzilla.redhat.com/show_bug.cgi?id=1022949
--------------------------------------------------------------------------------



More information about the test mailing list