The following Fedora EPEL 7 Security updates need testing:
Age URL
5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2022-de23d337b0 libopenmpt-0.6.6-1.el7
3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2022-66467c33ea seamonkey-2.53.14-3.el7
2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2022-d8f75949c3 git-lfs-2.10.0-2.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2022-f174e47230 luajit-2.0.5-1.20220913.46e62cd.el7
1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2022-3f600666f9 python3-mod_wsgi-4.7.1-3.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
openbgpd-7.7-1.el7
weechat-3.6-2.el7
Details about builds:
================================================================================
openbgpd-7.7-1.el7 (FEDORA-EPEL-2022-1252f0f76f)
OpenBGPD Routing Daemon
--------------------------------------------------------------------------------
Update Information:
# OpenBGPD 7.7 * Adjust `pathid_assign()` to be much faster for the common
case * Improve performance for generating updates for sessions using add-path
send all * Implement proper routing table sync in the `kroute-linux.c` code
* Enable linux netlink integration by default * Add a `--disable-fib-support`
config option to disable FIB sync on OpenBSD, FreeBSD and Linux systems
--------------------------------------------------------------------------------
ChangeLog:
* Thu Oct 6 2022 Robert Scheck <robert(a)fedoraproject.org> 7.7-1
- Upgrade to 7.7 (#2132808)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2132808 - openbgpd-7.7 is available
https://bugzilla.redhat.com/show_bug.cgi?id=2132808
--------------------------------------------------------------------------------
================================================================================
weechat-3.6-2.el7 (FEDORA-EPEL-2022-e8cd6275b1)
Portable, fast, light and extensible IRC client
--------------------------------------------------------------------------------
Update Information:
Brings EPEL 7 in line with other releases, addressing security issues fixed in
recent versions
--------------------------------------------------------------------------------
ChangeLog:
* Thu Oct 6 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org> 3.6-2
- Restore compatibility with EPEL 7
- use %cmake3 rather than %cmake macros
- conditionally disable tests on EPEL < 8
* Wed Oct 5 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org> 3.6-1
- Update to 3.6
* Sat Jul 23 2022 Fedora Release Engineering <releng(a)fedoraproject.org> 3.5-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Mon Jun 13 2022 Python Maint <python-maint(a)redhat.com> 3.5-4
- Rebuilt for Python 3.11
* Mon May 30 2022 Jitka Plesnikova <jplesnik(a)redhat.com> 3.5-3
- Perl 5.36 rebuild
* Sun May 22 2022 Paul Komkoff <i(a)stingr.net> 3.5-2
- Update to new upstream version 3.5
* Sun May 22 2022 Paul Komkoff <i(a)stingr.net> 3.5-1
- Update to new upstream version 3.5
* Wed Jan 26 2022 Mamoru TASAKA <mtasaka(a)fedoraproject.org> 3.4-9
- F-36: rebuild against ruby31
* Sat Jan 22 2022 Fedora Release Engineering <releng(a)fedoraproject.org> 3.4-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Tue Jan 18 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org> 3.4-7
- Temporarily disable tests on s390x
* Sat Jan 15 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org> 3.4-6
- Fix test compilation
- build tests with -fPIC
- install test dependency on locale data
- disable failing tests
* Fri Jan 14 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org> 3.4-5
- Fix conditional test dependency declaration
* Fri Jan 14 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org>
- Update to 3.4
- use bcond_with{,out} for toggling docs
- prepare for enabling tests
* Sun Nov 7 2021 Paul Komkoff <i(a)stingr.net> - 3.3-1
- update to 3.3
* Fri Jul 23 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 3.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Sun Jul 11 2021 Michel Alexandre Salim <salimma(a)fedoraproject.org> - 3.2-1
- Update to 3.2
- Reenable s390x build for EPEL8 (#1869383)
* Fri Jun 4 2021 Python Maint <python-maint(a)redhat.com> - 3.1-3
- Rebuilt for Python 3.10
* Fri May 21 2021 Jitka Plesnikova <jplesnik(a)redhat.com> - 3.1-2
- Perl 5.34 rebuild
* Sun Mar 7 2021 ��ukasz Patron <priv.luk(a)gmail.com> - 3.1-1
- Update to 3.1
* Fri Feb 12 2021 ��ukasz Patron <priv.luk(a)gmail.com> - 3.0.1-1
- Update to 3.0.1
* Wed Jan 27 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 3.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Mon Jan 18 2021 ��ukasz Patron <priv.luk(a)gmail.com> - 3.0-1
- Update to 3.0
* Wed Jan 6 2021 Mamoru TASAKA <mtasaka(a)fedoraproject.org> - 2.9-3
- F-34: rebuild against ruby 3.0
* Mon Sep 14 2020 Peter Robinson <pbrobinson(a)fedoraproject.org> - 2.9-2
- Use guile 2.2 where possible
* Mon Aug 17 2020 Michel Alexandre Salim <salimma(a)fedoraproject.org> - 2.9-1
- Update to 2.9
* Wed Jul 29 2020 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.8-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Mon Jun 22 2020 Jitka Plesnikova <jplesnik(a)redhat.com> - 2.8-3
- Perl 5.32 rebuild
* Tue May 26 2020 Miro Hron��ok <mhroncok(a)redhat.com> - 2.8-2
- Rebuilt for Python 3.9
* Wed Apr 1 2020 Paul Komkoff <i(a)stingr.net> - 2.8-1
- Update to 2.8
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1286233 - weechat fails to install on RHEL 7.2
https://bugzilla.redhat.com/show_bug.cgi?id=1286233
[ 2 ] Bug #1817391 - CVE-2020-9759 weechat: malformed message 352 (who) can cause a NULL pointer dereference in the callback function which could result in a crash. [epel-7]
https://bugzilla.redhat.com/show_bug.cgi?id=1817391
[ 3 ] Bug #1817400 - CVE-2020-9760 weechat: receiving IRC message 005 with longer nick prefixes could result in buffer overflow and crash [epel-7]
https://bugzilla.redhat.com/show_bug.cgi?id=1817400
[ 4 ] Bug #2063856 - weechat: SSL verification vulnerability [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2063856
[ 5 ] Bug #2072046 - CVE-2022-28352 weechat: allows man-in-the-middle attackers to spoof a TLS chat server [epel-7]
https://bugzilla.redhat.com/show_bug.cgi?id=2072046
[ 6 ] Bug #2128160 - New version of weechat available 3.6
https://bugzilla.redhat.com/show_bug.cgi?id=2128160
--------------------------------------------------------------------------------
When EPEL-8 was launched, it came with some support for modules with the
hope that a module ecosystem could be built from Fedora packages using RHEL
modules as an underlying tool. This has never happened and we have ended up
with a muddle of modular packages which will 'build' but may not install or
even run on an EL-8 system. Attempts to fix this and work within how EPEL
is normally built have been tried for several years by different people but
have not worked.
At this point we are saying that this experiment with modules in EPEL has
not worked and we will focus our resources on what does work.
Schedule of EPEL 8 Module Retirement:
Next Week:
- epel-release will be updated.
-- epel-modular will set enabled = 0
-- epel-modular full name will have "Deprecated" in it
October 31 2022:
- The EPEL 8 modules will be archived and removed.
-- The mirror manager will be pointed to the archive.
- Packagers will no longer be able to build EPEL 8 modules.
After October 31st (Actual date to be determined):
- epel-release will be updated again.
-- epel-modular repo configs will be removed.
Question: Will I still be able to access the modules after October 31st?
Answer: It is not recommended, because the modules will not get any
security or bug fixes, but yes. They will be in the Fedora archives,
and the mirror managers will point at them.
EPEL Steering Committee
[1] - https://pagure.io/epel/issue/198
Hi all,
We should probably retire weechat from EPEL 7 - it has multiple CVEs
that can only be fixed by updating to versions >= 3.5, but the spec no
longer works on EPEL 7 thanks to macros like `%cmake_build` not being
available.
https://bugz.fedoraproject.org/weechat
I'm not sure either Paul or myself really care enough about EL7 to
maintain a divergent spec. If someone does still care, PR appreciated to
fix this, otherwise consider this the first notice that I'll retire this
branch in a few days.
Best regards,
--
Michel Alexandre Salim
identities: https://keyoxide.org/5dce2e7e9c3b1cffd335c1d78b229d2f7ccc04f2
The following Fedora EPEL 9 Security updates need testing:
Age URL
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2022-1ee1fe2c17 libopenmpt-0.6.6-1.el9
The following builds have been pushed to Fedora EPEL 9 updates-testing
gnome-shell-extension-appindicator-46-1.el9
ioping-1.3-1.el9
weechat-3.6-1.el9
Details about builds:
================================================================================
gnome-shell-extension-appindicator-46-1.el9 (FEDORA-EPEL-2022-2531c94250)
AppIndicator/KStatusNotifierItem support for GNOME Shell
--------------------------------------------------------------------------------
Update Information:
Update to latest version
--------------------------------------------------------------------------------
ChangeLog:
* Fri Sep 30 2022 Artem Polishchuk <ego.cordatus(a)gmail.com> 46-1
- chore(update): 46
* Thu Sep 29 2022 Artem Polishchuk <ego.cordatus(a)gmail.com> 45-1
- chore(update): 45
--------------------------------------------------------------------------------
================================================================================
ioping-1.3-1.el9 (FEDORA-EPEL-2022-43ac9fb3fb)
Simple disk I/O latency monitoring tool
--------------------------------------------------------------------------------
Update Information:
ioping lets you monitor I/O latency in real time. It shows disk latency in the
same way as ping shows network latency
--------------------------------------------------------------------------------
ChangeLog:
* Thu Oct 6 2022 Robin Lee <cheeselee(a)fedoraproject.org> 1.3-1
- Update to 1.3
* Thu Jul 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.1-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jan 20 2022 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.1-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Thu Jul 22 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.1-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jan 26 2021 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2132428 - Please branch and build ioping in epel9
https://bugzilla.redhat.com/show_bug.cgi?id=2132428
--------------------------------------------------------------------------------
================================================================================
weechat-3.6-1.el9 (FEDORA-EPEL-2022-1c6c522b07)
Portable, fast, light and extensible IRC client
--------------------------------------------------------------------------------
Update Information:
- add command "/item" to create custom bar items - add bar item "spacer" - add
case conversion in evaluation of expressions with "lower:string" and
"upper:string" - move detailed list of hooks from command "/plugin listfull" to
"/debug hooks " - allow to remove multiple filters at once with command "/filter
del" - allow to catch multiple signals in functions hook_signal and hook_hsignal
- rename option "save" to "apply" in IRC command "/autojoin" - add support of
RPL_HELPSTART, RPL_HELPTXT and RPL_ENDOFHELP (IRC messages 524, 704, 705, 706) -
add support of PHP 8.2 - many bugs fixed.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Oct 5 2022 Michel Alexandre Salim <salimma(a)fedoraproject.org> 3.6-1
- Update to 3.6
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2063856 - weechat: SSL verification vulnerability [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2063856
[ 2 ] Bug #2128160 - New version of weechat available 3.6
https://bugzilla.redhat.com/show_bug.cgi?id=2128160
--------------------------------------------------------------------------------