Dear all,
You are kindly invited to the meeting:
EPEL Steering Committee on 2018-02-21 from 18:00:00 to 19:00:00 GMT
At fedora-meeting(a)irc.freenode.net
The meeting will be about:
The EPEL Steering Committee will have a weekly meeting to cover current tasks and problems needed to keep EPEL going.
Source: https://apps.fedoraproject.org/calendar/meeting/8724/
Openjpeg2 has MANY CVE bugs reported against it and most are fixed with the
current release. I have run abi-compliance-checker on the packages and it
shows 100% binary compatibility so there should not be a problem.
Thanks,
Richard
The following Fedora EPEL 7 Security updates need testing:
Age URL
1078 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
841 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
423 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
320 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
152 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
89 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e64eeb6ece nagios-4.3.4-5.el7
39 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-73ee944e65 rootsh-1.5.3-17.el7
13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-7134fc92a1 jhead-3.00-7.el7
12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-069884a87f p7zip-16.02-10.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-72e5d3ef89 suricata-4.0.4-1.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-276ec6ee2b exim-4.90.1-2.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-e50c94a832 seamonkey-2.49.2-2.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
beecrypt-4.2.1-20.el7
boinc-client-7.9.2-1.el7
cmrt-1.0.6-7.el7
dislocker-0.7.1-6.el7
dist-git-1.6-1.el7
drbdlinks-1.28-3.el7
f2c-20160102-1.el7
fedrepo-req-1.11.1-1.el7
knot-resolver-2.1.0-1.el7
ldapvi-1.7-29.el7
mbedtls-2.7.0-1.el7
perl-Data-Float-0.013-2.el7
pwkickstart-1.0.2-3.el7
python-certbot-dns-digitalocean-0.21.1-1.el7
python-cloudflare-2.0.4-1.el7
spectre-meltdown-checker-0.35-1.el7
ucx-1.2.2-1.el7
Details about builds:
================================================================================
beecrypt-4.2.1-20.el7 (FEDORA-EPEL-2018-2cf57e0262)
An open source cryptography library
--------------------------------------------------------------------------------
Update Information:
Update python 2 dependency declarations to new packaging standards, see
https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3
--------------------------------------------------------------------------------
================================================================================
boinc-client-7.9.2-1.el7 (FEDORA-EPEL-2018-7ed58d7254)
The BOINC client
--------------------------------------------------------------------------------
Update Information:
New upstream release of the BOINC client
--------------------------------------------------------------------------------
================================================================================
cmrt-1.0.6-7.el7 (FEDORA-EPEL-2018-c974ef14ee)
C for Media Runtime
--------------------------------------------------------------------------------
Update Information:
Add missing BR for gcc-c++
--------------------------------------------------------------------------------
================================================================================
dislocker-0.7.1-6.el7 (FEDORA-EPEL-2018-c0d4c9a3a1)
Utility to access BitLocker encrypted volumes
--------------------------------------------------------------------------------
Update Information:
- Rebuilt for mbed TLS 2.7.0
--------------------------------------------------------------------------------
================================================================================
dist-git-1.6-1.el7 (FEDORA-EPEL-2018-50a505e816)
Package source version control system
--------------------------------------------------------------------------------
Update Information:
- add 'fedmsgs', 'old_paths', and 'default_namespace' config options - remove
domain_read_all_domains_state SELinux rule - require dist-git-selinux - give
optional map permission to git_system_t on git_user_content_t - update requires
to work for all environments - make the package completely distribution-agnostic
--------------------------------------------------------------------------------
================================================================================
drbdlinks-1.28-3.el7 (FEDORA-EPEL-2018-aff2d15cc3)
Program for managing links into a DRBD shared partition
--------------------------------------------------------------------------------
Update Information:
- Update python 2 dependency declarations to new packaging standards, see
https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3
--------------------------------------------------------------------------------
================================================================================
f2c-20160102-1.el7 (FEDORA-EPEL-2018-a5d0d7f603)
A Fortran 77 to C/C++ conversion program
--------------------------------------------------------------------------------
Update Information:
Update to 20160102.
--------------------------------------------------------------------------------
================================================================================
fedrepo-req-1.11.1-1.el7 (FEDORA-EPEL-2018-059175a818)
CLI for Fedora package repo requests
--------------------------------------------------------------------------------
Update Information:
The admin tool now casts the incoming bug IDs as strings (fixes a bug that
occurs when the incoming bug ID is an integer). ---- Adds a deprecation
warning and tells users to use `fedpkg` instead.
--------------------------------------------------------------------------------
================================================================================
knot-resolver-2.1.0-1.el7 (FEDORA-EPEL-2018-cee77fc9b3)
Caching full DNS Resolver
--------------------------------------------------------------------------------
Update Information:
Knot Resolver 2.1.0 (2018-02-16) ================================ Incompatible
changes -------------------- - stats: remove tracking of expiring records
(predict uses another way) - systemd: re-use a single kresd.socket and kresd-
tls.socket - ta_sentinel: implement protocol draft-ietf-dnsop-kskroll-
sentinel-01 (our draft-ietf-dnsop-kskroll-sentinel-00 implementation had
inverted logic) - libknot: require version 2.6.4 or newer to get bugfixes for
DNS-over-TLS Bugfixes -------- - detect_time_jump module: don't clear cache on
suspend-resume (#284) - stats module: fix stats.list() returning nothing,
regressed in 2.0.0 - policy.TLS_FORWARD: refusal when configuring with multiple
IPs (#306) - cache: fix broken refresh of insecure records that were about to
expire - fix the hints module on some systems, e.g. Fedora (came back on 2.0.0)
- build with older gnutls (conditionally disable features) - fix the predict
module to work with insecure records & cleanup code Knot Resolver 2.0.0
(2018-01-31) ================================ Incompatible changes
-------------------- - systemd: change unit files to allow running multiple
instances, deployments with single instance now must use `kresd(a)1.service`
instead of `kresd.service`; see kresd.systemd(7) for details - systemd: the
directory for cache is now /var/cache/knot-resolver - unify default directory
and user to `knot-resolver` - directory with trust anchor file specified by -k
option must be writeable - policy module is now loaded by default to enforce RFC
6761; see documentation for policy.PASS if you use locally-served DNS zones -
drop support for alternative cache backends memcached, redis, and for Lua
bindings for some specific cache operations - REORDER_RR option is not
implemented (temporarily) New features ------------ - aggressive caching of
validated records (RFC 8198) for NSEC zones; thanks to ICANN for sponsoring
this work. - forwarding over TLS, authenticated by SPKI pin or certificate.
policy.TLS_FORWARD pipelines queries out-of-order over shared TLS connection
Beware: Some resolvers do not support out-of-order query processing. TLS
forwarding to such resolvers will lead to slower resolution or failures. - trust
anchors: you may specify a read-only file via -K or --keyfile-ro - trust
anchors: at build-time you may set KEYFILE_DEFAULT (read-only) - ta_sentinel
module implements draft ietf-dnsop-kskroll-sentinel-00, enabled by default -
serve_stale module is prototype, subject to change - extended API for Lua
modules Bugfixes -------- - fix build on osx - regressed in 1.5.3 (different
linker option name) ---- Knot Resolver 1.5.3 (2018-01-23)
================================ Bugfixes -------- - fix the hints module on
some systems, e.g. Fedora. Symptom: `undefined symbol: engine_hint_root_file`
Knot Resolver 1.5.2 (2018-01-22) ================================ Security
-------- - fix CVE-2018-1000002: insufficient DNSSEC validation, allowing
attackers to deny existence of some data by forging packets. Some combinations
pointed out in RFC 6840 sections 4.1 and 4.3 were not taken into account.
Bugfixes -------- - memcached: fix fallout from module rename in 1.5.1 Knot
Resolver 1.5.1 (2017-12-12) ================================ Incompatible
changes -------------------- - script supervisor.py was removed, please migrate
to a real process manager - module ketcd was renamed to etcd for consistency -
module kmemcached was renamed to memcached for consistency Bugfixes -------- -
fix SIGPIPE crashes (#271) - tests: work around out-of-space for platforms with
larger memory pages - lua: fix mistakes in bindings affecting 1.4.0 and 1.5.0
(and 1.99.1-alpha), potentially causing problems in dns64 and workarounds
modules - predict module: various fixes (!399) Improvements ------------ - add
priming module to implement RFC 8109, enabled by default (#220) - add modules
helping with system time problems, enabled by default; for details see
documentation of detect_time_skew and detect_time_jump
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1537462 - CVE-2018-1000002 knot-resolver: Insufficient DNSSEC validation
https://bugzilla.redhat.com/show_bug.cgi?id=1537462
--------------------------------------------------------------------------------
================================================================================
ldapvi-1.7-29.el7 (FEDORA-EPEL-2018-6a0e112717)
An interactive LDAP client
--------------------------------------------------------------------------------
Update Information:
First build for EPEL7
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1236778 - Ldapvi is not yet packaged or available for EL7
https://bugzilla.redhat.com/show_bug.cgi?id=1236778
--------------------------------------------------------------------------------
================================================================================
mbedtls-2.7.0-1.el7 (FEDORA-EPEL-2018-525417d3d4)
Light-weight cryptographic and SSL/TLS library
--------------------------------------------------------------------------------
Update Information:
- Update to 2.7.0 Release notes: https://tls.mbed.org/tech-
updates/releases/mbedtls-2.7.0-2.1.10-and-1.3.22-released Security Advisory:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-
advisory-2018-01
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1544730 - CVE-2017-18187 CVE-2018-0487 CVE-2018-0488 mbedtls: various flaws [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1544730
--------------------------------------------------------------------------------
================================================================================
perl-Data-Float-0.013-2.el7 (FEDORA-EPEL-2018-c1d675a7fe)
Details of the floating point data type
--------------------------------------------------------------------------------
Update Information:
This package provides details of the Perl floating point data type.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #919110 - Review Request: perl-Data-Float - Details of the floating point data type
https://bugzilla.redhat.com/show_bug.cgi?id=919110
--------------------------------------------------------------------------------
================================================================================
pwkickstart-1.0.2-3.el7 (FEDORA-EPEL-2018-3053770bc1)
Helps to generate kickstart passwords
--------------------------------------------------------------------------------
Update Information:
Password kickstart generator
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1543813 - Review Request: pwkickstart - generate kickstart passwords
https://bugzilla.redhat.com/show_bug.cgi?id=1543813
--------------------------------------------------------------------------------
================================================================================
python-certbot-dns-digitalocean-0.21.1-1.el7 (FEDORA-EPEL-2018-a0cef0c53f)
DigitalOcean DNS Authenticator plugin for Certbot
--------------------------------------------------------------------------------
Update Information:
Initial package of python-certbot-dns-digitalocean
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1545969 - Review Request: python-certbot-dns-digitalocean - DigitalOcean DNS Authenticator plugin for Certbot
https://bugzilla.redhat.com/show_bug.cgi?id=1545969
--------------------------------------------------------------------------------
================================================================================
python-cloudflare-2.0.4-1.el7 (FEDORA-EPEL-2018-234443e846)
Python wrapper for the Cloudflare Client API v4
--------------------------------------------------------------------------------
Update Information:
Initial package of python-cloudflare
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1546297 - Review Request: python-cloudflare - Python wrapper for the Cloudflare Client API v4
https://bugzilla.redhat.com/show_bug.cgi?id=1546297
--------------------------------------------------------------------------------
================================================================================
spectre-meltdown-checker-0.35-1.el7 (FEDORA-EPEL-2018-96f5413796)
Spectre & Meltdown vulnerability/mitigation checker for Linux
--------------------------------------------------------------------------------
Update Information:
Update to 0.35 - Feature: correctly detect specific Red Hat/Ubuntu patch for
Spectre Variant 1 - Update: new list of blacklisted microcodes (from Intel
document) - Enhancement: detect disrepancy between found kernel image and
running kernel - Enhancement: speed up execution by not decompressing kernel in
--sysfs-only mode - Enhancement: find images installed by systemd kernel-install
- Enhancement: better explanation when kernel supports IBRS but CPU doesn't -
Misc: other minor changes and bugfixes
--------------------------------------------------------------------------------
================================================================================
ucx-1.2.2-1.el7 (FEDORA-EPEL-2018-b1a3ad29aa)
A communication library implementing high-performance messaging
--------------------------------------------------------------------------------
Update Information:
Initial submit
--------------------------------------------------------------------------------
The following Fedora EPEL 7 Security updates need testing:
Age URL
1076 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
839 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
421 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
319 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
150 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
88 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e64eeb6ece nagios-4.3.4-5.el7
37 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-73ee944e65 rootsh-1.5.3-17.el7
23 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-24ac4ff7df knot-resolver-1.5.3-1.el7
11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-7134fc92a1 jhead-3.00-7.el7
10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-069884a87f p7zip-16.02-10.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-72e5d3ef89 suricata-4.0.4-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
OpenStego-0.7.2-1.el7
exim-4.90.1-2.el7
koji-1.15.0-4.el7
llvm5.0-5.0.1-5.el7
python-pyside-1.2.4-1.el7
rust-1.24.0-1.el7
shiboken-1.2.4-9.el7
vim-vimoutliner-0.4.0-8.el7
Details about builds:
================================================================================
OpenStego-0.7.2-1.el7 (FEDORA-EPEL-2018-9a37b84d40)
Free Steganography solution
--------------------------------------------------------------------------------
Update Information:
New package - Free Steganography solution OpenStego is a tool implemented in
Java for generic steganography, with support for password-based encryption of
the data. It supports plugins for various steganographic algorithms.
--------------------------------------------------------------------------------
================================================================================
exim-4.90.1-2.el7 (FEDORA-EPEL-2018-276ec6ee2b)
The exim mail transfer agent
--------------------------------------------------------------------------------
Update Information:
This is an update fixing undefined symbols in mysql module. ---- This is new
version fixing CVE-2018-6789.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1543268 - CVE-2018-6789 exim: buffer overflow in b64decode() function, possibly leading to remote code execution
https://bugzilla.redhat.com/show_bug.cgi?id=1543268
--------------------------------------------------------------------------------
================================================================================
koji-1.15.0-4.el7 (FEDORA-EPEL-2018-748be86dfe)
Build system tools
--------------------------------------------------------------------------------
Update Information:
Rebase to koji 1.15. Backports included for PR#735 and PR#794. Changelog: -
Display license Info - Keytabs for GSSAPI authentication - Add krb_canon_host
option - Watch-task return code - New runroot options - New watch-logs options
--------------------------------------------------------------------------------
================================================================================
llvm5.0-5.0.1-5.el7 (FEDORA-EPEL-2018-592dd11f3d)
The Low Level Virtual Machine
--------------------------------------------------------------------------------
Update Information:
New version of Rust -- see the release notes for [1.24](https://blog.rust-
lang.org/2018/02/15/Rust-1.24.html)
--------------------------------------------------------------------------------
================================================================================
python-pyside-1.2.4-1.el7 (FEDORA-EPEL-2018-2341acd2bd)
Python bindings for Qt4
--------------------------------------------------------------------------------
Update Information:
- Update to 1.2.4 - Ship python3 version (bug #1320653) - Fix scriptlet
packages - Drop deprecated provides filter
--------------------------------------------------------------------------------
================================================================================
rust-1.24.0-1.el7 (FEDORA-EPEL-2018-592dd11f3d)
The Rust Programming Language
--------------------------------------------------------------------------------
Update Information:
New version of Rust -- see the release notes for [1.24](https://blog.rust-
lang.org/2018/02/15/Rust-1.24.html)
--------------------------------------------------------------------------------
================================================================================
shiboken-1.2.4-9.el7 (FEDORA-EPEL-2018-3bb0a88e7f)
CPython bindings generator for C++ libraries
--------------------------------------------------------------------------------
Update Information:
- Build for python 3 - Add BR for libxslt to enable support for doc
strings
--------------------------------------------------------------------------------
================================================================================
vim-vimoutliner-0.4.0-8.el7 (FEDORA-EPEL-2018-3c27a78d2b)
Script for building an outline editor on top of Vim
--------------------------------------------------------------------------------
Update Information:
Taking over the package and adding AppStream metadata. ---- Just rebuild upon
clean-up and taking over the maintenance of the package.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1128821 - Add Addon metadata for GNOME Software
https://bugzilla.redhat.com/show_bug.cgi?id=1128821
--------------------------------------------------------------------------------