The following Fedora EPEL 7 Security updates need testing:
Age URL
1061 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
824 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
406 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
303 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
135 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
72 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e64eeb6ece nagios-4.3.4-5.el7
36 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8d57a2487b monit-5.25.1-1.el7
22 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-73ee944e65 rootsh-1.5.3-17.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-ce6223e559 GraphicsMagick-1.3.28-1.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-9eb18da891 moodle-3.1.10-1.el7
9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-c0d5d190b0 transmission-2.92-12.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-24ac4ff7df knot-resolver-1.5.3-1.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-dd0bc449d7 konversation-1.5.1-4.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-fb68becde7 w3m-0.5.3-36.git20180125.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-18ea640f19 tomcat-native-1.2.16-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
ReviewBoard-2.5.17-1.el7
ansible-2.4.3.0-1.el7
freshmaker-0.0.11-1.el7
libmfx-1.21-2.el7
pdns-3.4.11-4.el7
php-bartlett-php-compatinfo-db-1.29.0-1.el7
python-click-6.7-6.el7
python-django16-1.6.11.6-16.el7
python-paramiko-2.1.1-0.2.el7
python3-pyusb-1.0.2-2.el7
retrace-server-1.18.0-1.el7
srm-ifce-1.24.3-1.el7
Details about builds:
================================================================================
ReviewBoard-2.5.17-1.el7 (FEDORA-EPEL-2018-87bc21e3b9)
Web-based code review tool
--------------------------------------------------------------------------------
Update Information:
Update to Review Board 2.5.17
https://www.reviewboard.org/docs/releasenotes/reviewboard/2.5.17/
--------------------------------------------------------------------------------
================================================================================
ansible-2.4.3.0-1.el7 (FEDORA-EPEL-2018-d10ccd21f8)
SSH-based configuration management, deployment, and task execution system
--------------------------------------------------------------------------------
Update Information:
Update to 2.4.3.0 bugfix release. See
https://github.com/ansible/ansible/blob/stable-2.4/CHANGELOG.md for full
changes.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1540767 - ansible-2.4.3.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1540767
--------------------------------------------------------------------------------
================================================================================
freshmaker-0.0.11-1.el7 (FEDORA-EPEL-2018-23a941f597)
Freshmaker is a service scheduling rebuilds of artifacts as new content becomes available.
--------------------------------------------------------------------------------
Update Information:
New version 0.0.11.
--------------------------------------------------------------------------------
================================================================================
libmfx-1.21-2.el7 (FEDORA-EPEL-2018-351f76c3b8)
Intel hardware video acceleration dispatcher library
--------------------------------------------------------------------------------
Update Information:
Rebuilt for the rebased libva
--------------------------------------------------------------------------------
================================================================================
pdns-3.4.11-4.el7 (FEDORA-EPEL-2018-f09712d924)
A modern, advanced and high performance authoritative-only nameserver
--------------------------------------------------------------------------------
Update Information:
- CVE-2017-15091
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1540649 - pdns-3.4.11 CVE-2017-15091patch required
https://bugzilla.redhat.com/show_bug.cgi?id=1540649
--------------------------------------------------------------------------------
================================================================================
php-bartlett-php-compatinfo-db-1.29.0-1.el7 (FEDORA-EPEL-2018-54d3ab8a60)
Reference Database to be used with php-compatinfo library
--------------------------------------------------------------------------------
Update Information:
**Version 1.29.0** - 2018-02-01 * **Added** - Support to PHP 7.1.14 *
**Changed** - Xdebug reference updated to version 2.6.0 (stable) *
**Fixed** - issue [GH-241](https://github.com/llaville/php-compat-
info/issues/241) about imagepng (declared in php-compat-info project) -
issue [GH-12](https://github.com/llaville/php-compatinfo-db/issues/12)
$escape_char param of fputcsv() requires PHP = 5.5.4
--------------------------------------------------------------------------------
================================================================================
python-click-6.7-6.el7 (FEDORA-EPEL-2018-a36ba75c3f)
Simple wrapper around optparse for powerful command line utilities
--------------------------------------------------------------------------------
Update Information:
* Ship python34-click * Update: Version 6.7 ------ (bugfix release; released on
January 6th 2017) - Make `click.progressbar` work with `codecs.open` files. See
#637. - Fix bug in bash completion with nested subcommands. See #639. - Fix test
runner not saving caller env correctly. See #644. - Fix handling of SIGPIPE. See
#626 - Deal with broken Windows environments such as Google App Engine's. See
#711. Version 6.6 ----------- (bugfix release; released on April 4th 2016) -
Fix bug in `click.Path` where it would crash when passed a `-`. See #551.
Version 6.4 ----------- (bugfix release; released on March 24th 2016) - Fix
bug in bash completion where click would discard one or more trailing arguments.
See #471.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1433066 - Build for python3 on EPEL
https://bugzilla.redhat.com/show_bug.cgi?id=1433066
--------------------------------------------------------------------------------
================================================================================
python-django16-1.6.11.6-16.el7 (FEDORA-EPEL-2018-87bc21e3b9)
A high-level Python Web framework
--------------------------------------------------------------------------------
Update Information:
Update to Review Board 2.5.17
https://www.reviewboard.org/docs/releasenotes/reviewboard/2.5.17/
--------------------------------------------------------------------------------
================================================================================
python-paramiko-2.1.1-0.2.el7 (FEDORA-EPEL-2018-52c3a303d0)
SSH2 protocol library for python
--------------------------------------------------------------------------------
Update Information:
This update syncs python-paramiko with the version in EL-7 Extras, and is a
limited-arch support package. In addition, python3 support has been enabled, so
there is now support for paramiko with Python 3.4 in EPEL 7.
--------------------------------------------------------------------------------
================================================================================
python3-pyusb-1.0.2-2.el7 (FEDORA-EPEL-2018-44e50f84b2)
Python 3 bindings for libusb
--------------------------------------------------------------------------------
Update Information:
PyUSB provides easy USB access to python. The module contains classes and
methods to support most USB operations. This contains the python 3.4 version of
pyusb.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1540749 - Review Request: python3-pyusb - Python 3 bindings for libusb
https://bugzilla.redhat.com/show_bug.cgi?id=1540749
--------------------------------------------------------------------------------
================================================================================
retrace-server-1.18.0-1.el7 (FEDORA-EPEL-2018-bc35ca9028)
Application for remote coredump analysis
--------------------------------------------------------------------------------
Update Information:
Rebase to new upstream release. Including: - Specfiles improvements
- Update Python 2 dependency declarations to new packaging standards
- Remove duplicate RetraceWorker._fail call when start_vmcore fails
- Add md5sum and kernelver to email notifications, help text to failing
notification - Convert notify_email_success and notify_email_fail to a single
method - Create notify_email_success / notify_email_fail helpers
- Enable packages with epoch
- Update to new mock
- Set kernelver and vmlinux as soon as possible
- reposync: Cleanup is not done by default in createrepo
- Explicitly state python version in shebangs
- Fix unreadable crash subdirectory when tarball is submitted without group read
permissions - Try noarch when checking for package
- Add pylintrc
- Use dnf in mock config on Fedora
- Update mock config for new mock version
- Pylint updates
- Add commandline client
- Add aliases into FAF reposync
- Cleanup tmp FAF repository after failing
- Write coresize for vmcores
- Change error message
- Fix wrong html tag
- Set zero to non-existing type of tasks
- Fix typeo in manager.wsgi which creates a backtrace on non-ftp tasks.
- Bump version of gettext
- Change path for README.md
- Fix problem with missing modules on kernel versions with cached vmlinux files.
- No first retrace time when no existing task
- Make the reposync tool more verbose if required
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1440383 - RFE: Improve email notifications for failed and successful vmcores by giving suggested commands and other organizational info
https://bugzilla.redhat.com/show_bug.cgi?id=1440383
[ 2 ] Bug #1516329 - set_kernelver should be called at the bottom of get_kernel_release upon successful kernelversion detection
https://bugzilla.redhat.com/show_bug.cgi?id=1516329
[ 3 ] Bug #1481433 - retrace-server-interact fails with 'No such file or directory' due to retrace-server creating 'crash' subdirectory without group read permissions
https://bugzilla.redhat.com/show_bug.cgi?id=1481433
[ 4 ] Bug #1535485 - RetraceWorker._fail method called twice for failing vmcores
https://bugzilla.redhat.com/show_bug.cgi?id=1535485
[ 5 ] Bug #1201749 - 'coresize' field of stats sqlite database always NULL
https://bugzilla.redhat.com/show_bug.cgi?id=1201749
--------------------------------------------------------------------------------
================================================================================
srm-ifce-1.24.3-1.el7 (FEDORA-EPEL-2018-8c1d2fd3aa)
SRM client side library
--------------------------------------------------------------------------------
Update Information:
* new upstream release
--------------------------------------------------------------------------------
(This is mostly a duplicate of a post I sent to devel@. I wanted to
alert epel-devel@ but didn't want to crosspost.)
Following my proposal in
https://fedoraproject.org/wiki/User:Tibbs/EPELPythonStubPackages which
met with favor from a number of folks here, I went ahead and set up four
dummy packages:
python2-setuptools (in EPEL6)
python2-sphinx (EPEL7)
python2-pytest (EPEL7)
python2-six (EPEL7)
I'll do EPEL6 versions of the latter tomorrow. (I forgot that I can
only request one branch with the initial repo request. Oops. In my
defense, that's a really odd restriction.)
These should, once actually pushed to stable, allow you to avoid having
to add conditionals to depend on setuptools/sphinx/pytest/six in EPEL.
If this works out for folks, I (or anyone else) can potentially add
similar dummy packages for every package which needs one. Anything to
cut down on those conditionals.
Please check my work, test and give karma as appropriate. They seem to
work fine for me when I set up a local repo and do some mock builds, but
I only have access to Centos so I guess anything is possible.
- J<
The following Fedora EPEL 7 Security updates need testing:
Age URL
1060 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7
823 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7
405 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-04bc9dd81d libbsd-0.8.3-1.el7
302 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d241156dfe mod_cluster-1.3.3-10.el7
134 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e27758bd23 libmspack-0.6-0.1.alpha.el7
71 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e64eeb6ece nagios-4.3.4-5.el7
35 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8d57a2487b monit-5.25.1-1.el7
21 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-73ee944e65 rootsh-1.5.3-17.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-ce6223e559 GraphicsMagick-1.3.28-1.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-9eb18da891 moodle-3.1.10-1.el7
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-c0d5d190b0 transmission-2.92-12.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-24ac4ff7df knot-resolver-1.5.3-1.el7
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-dd0bc449d7 konversation-1.5.1-4.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-fb68becde7 w3m-0.5.3-36.git20180125.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
clamav-0.99.3-3.el7
composer-1.6.3-1.el7
fcitx-4.2.9.5-1.el7
fcitx-configtool-0.4.10-1.el7
fcitx-qt5-1.2.2-1.el7
libabigail-1.1-1.el7
php-composer-spdx-licenses-1.3.0-1.el7
proftpd-1.3.5e-4.el7
python-fedora-0.10.0-1.el7
tomcat-native-1.2.16-1.el7
Details about builds:
================================================================================
clamav-0.99.3-3.el7 (FEDORA-EPEL-2018-a19bc46b6c)
End-user tools for the Clam Antivirus scanner
--------------------------------------------------------------------------------
Update Information:
- add systemctl daemon-reload (temporally) - Fix and organize systemd
scriptlets, clamd@.service missed systemd_preun_macro and had a wrong
systemd_postun_with_restart - Remove triggerin macros that aren't need it
anymore - Fix scriplet - Organize startup scriptlets - Exclude one file listed
twice
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1540100 - clamav-milter fails to restart after update
https://bugzilla.redhat.com/show_bug.cgi?id=1540100
--------------------------------------------------------------------------------
================================================================================
composer-1.6.3-1.el7 (FEDORA-EPEL-2018-9c09111eb9)
Dependency Manager for PHP
--------------------------------------------------------------------------------
Update Information:
**composer/spdx-licenses 1.3.0**- 2018-01-31 * Added:
`SpdxLicenses::getLicenses` to get the whole list of methods. * Changed:
license identifiers are now case insensitive. ---- **composer 1.6.3** -
2018-01-31 * Fixed GitLab downloads failing in some edge cases * Fixed
ctrl-C handling during create-project * Fixed GitHub VCS repositories not
prompting for a token in some conditions * Fixed SPDX license identifiers
being case sensitive * Fixed and clarified a few dependency resolution error
reporting strings * Fixed SVN commit log fetching in verbose mode when using
private repositories
--------------------------------------------------------------------------------
================================================================================
fcitx-4.2.9.5-1.el7 (FEDORA-EPEL-2018-b44163c20b)
An input method framework
--------------------------------------------------------------------------------
Update Information:
Minor upstream update of Fcitx. Fcitx-configtool is included since it requires
4.2.9 version of Fcitx.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1473715 - fcitx-configtool requires a graphical configuration tool
https://bugzilla.redhat.com/show_bug.cgi?id=1473715
--------------------------------------------------------------------------------
================================================================================
fcitx-configtool-0.4.10-1.el7 (FEDORA-EPEL-2018-b44163c20b)
Gtk+-based configuring tools for Fcitx
--------------------------------------------------------------------------------
Update Information:
Minor upstream update of Fcitx. Fcitx-configtool is included since it requires
4.2.9 version of Fcitx.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1473715 - fcitx-configtool requires a graphical configuration tool
https://bugzilla.redhat.com/show_bug.cgi?id=1473715
--------------------------------------------------------------------------------
================================================================================
fcitx-qt5-1.2.2-1.el7 (FEDORA-EPEL-2018-b44163c20b)
Fcitx IM module for Qt5
--------------------------------------------------------------------------------
Update Information:
Minor upstream update of Fcitx. Fcitx-configtool is included since it requires
4.2.9 version of Fcitx.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1473715 - fcitx-configtool requires a graphical configuration tool
https://bugzilla.redhat.com/show_bug.cgi?id=1473715
--------------------------------------------------------------------------------
================================================================================
libabigail-1.1-1.el7 (FEDORA-EPEL-2018-7ea892fb14)
Set of ABI analysis tools
--------------------------------------------------------------------------------
Update Information:
Update to upstream 1.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1532670 - in compare_dies at: abg-dwarf-reader.cc:11423
https://bugzilla.redhat.com/show_bug.cgi?id=1532670
--------------------------------------------------------------------------------
================================================================================
php-composer-spdx-licenses-1.3.0-1.el7 (FEDORA-EPEL-2018-9c09111eb9)
SPDX licenses list and validation library
--------------------------------------------------------------------------------
Update Information:
**composer/spdx-licenses 1.3.0**- 2018-01-31 * Added:
`SpdxLicenses::getLicenses` to get the whole list of methods. * Changed:
license identifiers are now case insensitive. ---- **composer 1.6.3** -
2018-01-31 * Fixed GitLab downloads failing in some edge cases * Fixed
ctrl-C handling during create-project * Fixed GitHub VCS repositories not
prompting for a token in some conditions * Fixed SPDX license identifiers
being case sensitive * Fixed and clarified a few dependency resolution error
reporting strings * Fixed SVN commit log fetching in verbose mode when using
private repositories
--------------------------------------------------------------------------------
================================================================================
proftpd-1.3.5e-4.el7 (FEDORA-EPEL-2018-cbd4882644)
Flexible, stable and highly-configurable FTP server
--------------------------------------------------------------------------------
Update Information:
This update includes a backport of the `InsecureHostKeyPerms` `SFTPOption` from
upstream version 1.3.6, which allows ProFTPD's `mod_sftp` to share group-
readable host keys with `sshd`. To use this feature, add `SFTPOptions
InsecureHostKeyPerms` to the ProFTPD configuration file before any `SFTPHostKey`
lines.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1522998 - proftpd is overly strict about SFTPHostKey permisions
https://bugzilla.redhat.com/show_bug.cgi?id=1522998
--------------------------------------------------------------------------------
================================================================================
python-fedora-0.10.0-1.el7 (FEDORA-EPEL-2018-f0ad30b79f)
Python modules for talking to Fedora Infrastructure Services
--------------------------------------------------------------------------------
Update Information:
Rebase to upstream 0.10.0
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1481210 - spec file points to URL: https://fedorahosted.org/python-fedora/https://bugzilla.redhat.com/show_bug.cgi?id=1481210
[ 2 ] Bug #1540970 - python-fedora-0.10.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1540970
--------------------------------------------------------------------------------
================================================================================
tomcat-native-1.2.16-1.el7 (FEDORA-EPEL-2018-18ea640f19)
Tomcat native library
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2017-15698
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1540824 - CVE-2017-15698 tomcat-native: Mishandling of client certificates can allow for OCSP check bypass
https://bugzilla.redhat.com/show_bug.cgi?id=1540824
--------------------------------------------------------------------------------