The following Fedora EPEL 6 Security updates need testing:
https://admin.fedoraproject.org/updates/bugzilla-3.4.11-1.el6
https://admin.fedoraproject.org/updates/rt3-3.8.10-2.el6.1
https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.4-1.el6
https://admin.fedoraproject.org/updates/mongoose-2.8-7.el6
https://admin.fedoraproject.org/updates/pam_ssh-1.97-7.el6
https://admin.fedoraproject.org/updates/zabbix-1.8.7-1.el6
https://admin.fedoraproject.org/updates/mlmmj-1.2.17.1-1.el6
https://admin.fedoraproject.org/updates/erlang-R14B-03.3.el6
https://admin.fedoraproject.org/updates/bcfg2-1.1.2-2.el6
https://admin.fedoraproject.org/updates/roundcubemail-0.5.4-1.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
bcfg2-1.1.2-2.el6
django-registration-0.7-2.el6
eclipse-ptp-4.0.7-1.el6.1
logcheck-1.3.13-5.el6
mock-1.1.13-1.el6
ntfs-3g-2011.4.12-4.el6
perl-Class-Load-0.10-1.el6
perl-Net-NBName-0.26-2.el6
perl-Package-Stash-0.32-1.el6
perl-Package-Stash-XS-0.25-1.el6
python-turbojson13-1.3.2-1.el6
roundcubemail-0.5.4-1.el6
sysbench-0.4.12-5.el6
xs-0.1-2.git9c19777.el6
Details about builds:
================================================================================
bcfg2-1.1.2-2.el6 (FEDORA-EPEL-2011-4364)
Configuration management system
--------------------------------------------------------------------------------
Update Information:
* Wed Sep 07 2011 Fabian Affolter <fabian(a)bernewireless.net> - 1.1.2-2
- Added patch to fix CVE-2011-3211
* Thu Jun 02 2011 Fabian Affolter <fabian(a)bernewireless.net> - 1.1.2-1
- Updated to new upstream version 1.1.2
- Fixed #683239
* Mon Sep 27 2010 Jeffrey C. Ollie <jeff(a)ocjtech.us> - 1.1.0-2 - Update to final
version
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 7 2011 Fabian Affolter <fabian(a)bernewireless.net> - 1.1.2-2
- Added patch to fix CVE-2011-3211
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #736279 - CVE-2011-3211 bcfg2 (bcfg2-server): Privilege escalation due to
improper escaping of shell command data sent from client, when SSHbase plug-in enabled
https://bugzilla.redhat.com/show_bug.cgi?id=736279
--------------------------------------------------------------------------------
================================================================================
django-registration-0.7-2.el6 (FEDORA-EPEL-2011-4370)
A user-registration application for Django
--------------------------------------------------------------------------------
Update Information:
A user-registration application for Django
--------------------------------------------------------------------------------
================================================================================
eclipse-ptp-4.0.7-1.el6.1 (FEDORA-EPEL-2011-4301)
Eclipse Parallel Tools Platform
--------------------------------------------------------------------------------
Update Information:
Parallel Tools Platform and Photran
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #734821 - Package request for EPEL 6 eclipse-photran
https://bugzilla.redhat.com/show_bug.cgi?id=734821
--------------------------------------------------------------------------------
================================================================================
logcheck-1.3.13-5.el6 (FEDORA-EPEL-2011-4188)
Analyzes log files and sends noticeable events as email
--------------------------------------------------------------------------------
Update Information:
This update should fix problems caused by run-parts missing --list
--------------------------------------------------------------------------------
ChangeLog:
* Fri Aug 26 2011 Matthias Runge <mrunge(a)matthias-runge.de> 1.3.13-5
- even exclude "*~", "*,", "*.swp", und
"*.cfsaved" files
* Wed Aug 17 2011 Matthias Runge <mrunge(a)matthias-runge.de> 1.3.13-4
- fix for bz 705822 (run-parts needs the --list parameter (or logcheck needs a
workaround))
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #705822 - run-parts needs the --list parameter (or logcheck needs a
workaround)
https://bugzilla.redhat.com/show_bug.cgi?id=705822
--------------------------------------------------------------------------------
================================================================================
mock-1.1.13-1.el6 (FEDORA-EPEL-2011-4366)
Builds packages inside chroots
--------------------------------------------------------------------------------
Update Information:
- add custom exception for unshare(2) failures
- change getLog().warn to getLog().warning for consistency
- fix namespace collision with python-mock [BZ# 601725]
- from Kirby Zhou <kirbyzhou(a)sogou-inc.com>
- remove rpmdb files before rebuilding SRPM [BZ# 719008]
- from Marko Myllynen <myllynen(a)redhat.com>
- integrate mock with RHN
- from Giam Teck Choon <choon(a)choon.net>
- add support for passing options to yum-buildep via mock cfg [BZ# 711411]
--------------------------------------------------------------------------------
ChangeLog:
* Thu Sep 8 2011 Clark Williams <williams(a)redhat.com> - 1.1.13-1
- add custom exception for unshare(2) failures
- change getLog().warn to getLog().warning for consistency
- fix namespace collision with python-mock [BZ# 601725]
- from Kirby Zhou <kirbyzhou(a)sogou-inc.com>
- remove rpmdb files before rebuilding SRPM [BZ# 719008]
- from Marko Myllynen <myllynen(a)redhat.com>
- integrate mock with RHN
- from Giam Teck Choon <choon(a)choon.net>
- add support for passing options to yum-buildep via mock cfg
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #711411 - 2.6.32-131.2.1.el6.x86_64 kernel and iDRAC6 serial console
https://bugzilla.redhat.com/show_bug.cgi?id=711411
[ 2 ] Bug #719008 - Cannot do mock rebuild el5 package under RHEL6
https://bugzilla.redhat.com/show_bug.cgi?id=719008
[ 3 ] Bug #601725 - mock has a namespace collision with python-mock
https://bugzilla.redhat.com/show_bug.cgi?id=601725
--------------------------------------------------------------------------------
================================================================================
ntfs-3g-2011.4.12-4.el6 (FEDORA-EPEL-2011-4376)
Linux NTFS userspace driver
--------------------------------------------------------------------------------
Update Information:
* fix issue preventing some volume types from not working properly (bz735862)
* create fsck.ntfs symlink to ntfsck (bz735612).
* apply cleanups from git trunk for ntfsck (bz 706638)
* apply cleanups from git trunk for ntfsfix (bz 711662, 723562)
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 7 2011 Tom Callaway <spot(a)fedoraproject.org> - 2:2011.4.12-4
- fix issue preventing some volume types from not working properly (bz735862)
- create fsck.ntfs symlink to ntfsck (bz735612).
- apply cleanups from git trunk for ntfsck (bz 706638)
- apply cleanups from git trunk for ntfsfix (bz 711662, 723562)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #735862 - ntfs volumes do not work with truecrypt/realcrypt
https://bugzilla.redhat.com/show_bug.cgi?id=735862
[ 2 ] Bug #735612 - ntfsprogs does not provide fsck.ntfs
https://bugzilla.redhat.com/show_bug.cgi?id=735612
[ 3 ] Bug #706638 - [abrt] ntfsprogs-2:2011.4.12-3.fc14: ntfs_boot_sector_parse: Process
/bin/ntfsck was killed by signal 11 (SIGSEGV)
https://bugzilla.redhat.com/show_bug.cgi?id=706638
[ 4 ] Bug #711662 - [abrt] ntfsprogs-2011.4.12-3.fc15: __libc_free: Process /bin/ntfsfix
was killed by signal 11 (SIGSEGV)
https://bugzilla.redhat.com/show_bug.cgi?id=711662
[ 5 ] Bug #723562 - [abrt] ntfsprogs-2011.4.12-3.fc15: __GI_raise: Process /bin/ntfsfix
was killed by signal 6 (SIGABRT)
https://bugzilla.redhat.com/show_bug.cgi?id=723562
--------------------------------------------------------------------------------
================================================================================
perl-Class-Load-0.10-1.el6 (FEDORA-EPEL-2011-4363)
A working (require "Class::Name") and more
--------------------------------------------------------------------------------
Update Information:
This is the latest upstream maintenance release, with internal clean-ups.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 6 2011 Paul Howarth <paul(a)city-fan.org> - 0.10-1
- Update to 0.10:
- Fix is_class_loaded to ignore $ISA (but still look for @ISA) when trying to
determine whether a class is loaded
- Lots of internals cleanup
- BR: perl(Package::Stash) ≥ 0.32 and perl(Try::Tiny)
- Update patches to apply cleanly
* Tue Aug 16 2011 Paul Howarth <paul(a)city-fan.org> - 0.08-1
- Update to 0.08:
- The previous version was missing a prereq declaration for Data::OptList
(CPAN RT#70285)
- This release by DROLSKY -> update source URL
- Package new documentation: LICENSE and README
- Add build requirements for new release tests and run them:
- perl(Pod::Coverage::Moose)
- perl(Test::CPAN::Changes)
- perl(Test::EOL)
- perl(Test::NoTabs)
- perl(Test::Pod)
- perl(Test::Pod::Coverage)
- perl(Test::Requires)
- perl(Test::Spelling) and aspell-en
- Add patch for building with ExtUtils::MakeMaker < 6.30
- Add patch for building with Test::More < 0.88
- Add patch for building without Test::Requires
- Add patch for fixing spell checker word list
- Don't try to run the POD Coverage test if we don't have Pod::Coverage::Moose
* Tue Jun 21 2011 Marcela Mašláňová <mmaslano(a)redhat.com> - 0.06-5
- Perl mass rebuild
* Tue Feb 8 2011 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> -
0.06-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
perl-Net-NBName-0.26-2.el6 (FEDORA-EPEL-2011-4369)
NetBIOS Name Service Requests
--------------------------------------------------------------------------------
Update Information:
Net::NBName is a class that allows you to perform simple NetBIOS Name Service Requests in
your Perl code. It performs these NetBIOS operations over TCP/IP using Perl's built-in
socket support.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #728665 - Please build for EPEL-6
https://bugzilla.redhat.com/show_bug.cgi?id=728665
--------------------------------------------------------------------------------
================================================================================
perl-Package-Stash-0.32-1.el6 (FEDORA-EPEL-2011-4377)
Routines for manipulating stashes
--------------------------------------------------------------------------------
Update Information:
The modules in this update fix a couple of compatibility problems with the add_symbol
method and raise an exception if invalid package or stash entry names are passed to them,
which can usefully be caught in higher-level modules.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 6 2011 Paul Howarth <paul(a)city-fan.org> - 0.32-1
- Update to 0.32
- Bring the behavior of has_symbol for nonexistant scalars into line with the
XS version
- Invalid package names (for instance, Foo:Bar) are not allowed
- Invalid stash entry names (anything containing ::) are not allowed
- Update patches to apply cleanly
- Bump perl(Package::Stash::XS) version requirement to 0.24
* Tue Aug 9 2011 Paul Howarth <paul(a)city-fan.org> - 0.31-1
- Update to 0.31
- Fix ->add_symbol('$foo', qr/sdlfk/) on 5.12+
- Fix ->add_symbol('$foo', \v1.2.3) on 5.10+
- Update patch for old Test::More versions
- Update patch for no Test::Requires
--------------------------------------------------------------------------------
================================================================================
perl-Package-Stash-XS-0.25-1.el6 (FEDORA-EPEL-2011-4377)
Faster and more correct implementation of the Package::Stash API
--------------------------------------------------------------------------------
Update Information:
The modules in this update fix a couple of compatibility problems with the add_symbol
method and raise an exception if invalid package or stash entry names are passed to them,
which can usefully be caught in higher-level modules.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 6 2011 Paul Howarth <paul(a)city-fan.org> - 0.25-1
- Update to 0.25
- Invalid package names (for instance, Foo:Bar) are not allowed
- Invalid stash entry names (anything containing ::) are not allowed
- Update patches to apply cleanly
* Tue Aug 9 2011 Paul Howarth <paul(a)city-fan.org> - 0.23-1
- Update to 0.23
- Fix the test for scalar values, again
- Disallow assigning globrefs to scalar glob slots (this doesn't actually
make any sense)
- Update patches for old ExtUtils::MakeMaker and Test::More versions
- perl(Pod::Coverage::TrustPod) now available in EPEL-4 too
- Don't use macros for commands
* Tue Jul 19 2011 Petr Sabata <contyk(a)redhat.com> - 0.22-2
- Perl mass rebuild
--------------------------------------------------------------------------------
================================================================================
python-turbojson13-1.3.2-1.el6 (FEDORA-EPEL-2011-4378)
Python template plugin that supports json
--------------------------------------------------------------------------------
Update Information:
* Update that increases the speed by re-requiring python-simplejson and using it in
preference to the json stdlib module.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Sep 7 2011 Toshio Kuratomi <toshio(a)fedoraproject.org> - 1.3.2-1
- New upstream. Once again require simplejson because the speed is so much better
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #728898 - python-turbojson-1.3.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=728898
--------------------------------------------------------------------------------
================================================================================
roundcubemail-0.5.4-1.el6 (FEDORA-EPEL-2011-4368)
Round Cube Webmail is a browser-based multilingual IMAP client
--------------------------------------------------------------------------------
Update Information:
Corrects XSS flaw in UI messages.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 6 2011 Jon Ciesla <limb(a)jcomserv.net> = 0.5.4-1
- New upstream, fixes multiple security issues.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #731786 - CVE-2011-2937 roundcubemail: XSS flaw in UI messages
https://bugzilla.redhat.com/show_bug.cgi?id=731786
--------------------------------------------------------------------------------
================================================================================
sysbench-0.4.12-5.el6 (FEDORA-EPEL-2011-4380)
System performance benchmark
--------------------------------------------------------------------------------
Update Information:
Add support for libaio.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Sep 6 2011 Xavier Bachelot <xavier(a)bachelot.org> 0.4.12-5
- Add BR: libaio-devel (rhbz#735882).
* Wed Mar 23 2011 Dan Horák <dan(a)danny.cz> - 0.4.12-4
- rebuilt for mysql 5.5.10 (soname bump in libmysqlclient)
* Wed Feb 9 2011 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> -
0.4.12-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Fri Dec 24 2010 Xavier Bachelot <xavier(a)bachelot.org> 0.4.12-2
- Rebuild against new mysql.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #735882 - sysbench not compiled with libaio-devel installed
https://bugzilla.redhat.com/show_bug.cgi?id=735882
--------------------------------------------------------------------------------
================================================================================
xs-0.1-2.git9c19777.el6 (FEDORA-EPEL-2011-4379)
Shell supporting functional programming
--------------------------------------------------------------------------------
Update Information:
XS is a shell supporting functional programming, based on es.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #735705 - Review Request: xs - Shell supporting functional programming
https://bugzilla.redhat.com/show_bug.cgi?id=735705
--------------------------------------------------------------------------------