The following Fedora EPEL 7 Security updates need testing:
Age URL
420
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d
condor-8.6.11-1.el7
162
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-c499781e80
python-gnupg-0.4.4-1.el7
160
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-bc0182548b
bubblewrap-0.3.3-2.el7
96
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-12067fc897
dosbox-0.74.3-2.el7
13
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-1c8bc2bf57
mosquitto-1.6.7-1.el7
11
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-600b4ad49c
yara-3.10.0-3.el7
10
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-8b6b5df244
mbedtls-2.7.12-1.el7
7
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-180a83b5fc
suricata-4.1.5-3.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-6ca75fc39a
nginx-1.16.1-1.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-b69e8f60ca
libapreq2-2.13-13.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-40a9ceccd5
radare2-3.9.0-1.el7.1
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-3bcbd2f338
opendmarc-1.3.2-1.el7
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-4e8faaa263
python34-3.4.10-4.el7
3
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-301b621e07
golang-1.13.1-1.el7
2
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-86a4692b13
scapy-2.4.3-2.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
NetworkManager-l2tp-1.2.14-1.el7
koji-1.18.1-1.el7
mkvtoolnix-38.0.0-1.el7
nodejs-rhea-1.0.10-1.el7
python-dns-lexicon-3.3.4-2.el7
python-ecdsa-0.13.3-1.el7
python-ldap3-2.6.1-1.el7
python-paho-mqtt-1.4.0-1.el7
python-pluginlib-0.6.2-1.el7
python3-numpy-1.12.1-3.el7
qpid-dispatch-1.9.0-1.el7
qpid-proton-0.29.0-1.el7
rubygem-qpid_proton-0.29.0-1.el7
xxhash-0.7.2-1.el7
Details about builds:
================================================================================
NetworkManager-l2tp-1.2.14-1.el7 (FEDORA-EPEL-2019-66c2d5f794)
NetworkManager VPN plugin for L2TP and L2TP/IPsec
--------------------------------------------------------------------------------
Update Information:
Updated to 1.2.14 release
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Douglas Kosovic <doug(a)uq.edu.au> - 1.2.14-1
- Updated to 1.2.14 release
* Wed Jul 24 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 1.2.12-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
koji-1.18.1-1.el7 (FEDORA-EPEL-2019-35adef43f8)
Build system tools
--------------------------------------------------------------------------------
Update Information:
Rebase to Koji 1.18.1 for CVE-2019-17109
--------------------------------------------------------------------------------
ChangeLog:
* Wed Oct 9 2019 Patrick Uiterwijk <patrick(a)puiterwijk.org> - 1.18.1-1
- Rebase to 1.18.1 for CVE-2019-17109
--------------------------------------------------------------------------------
================================================================================
mkvtoolnix-38.0.0-1.el7 (FEDORA-EPEL-2019-8fcc4fc363)
Matroska container manipulation utilities
--------------------------------------------------------------------------------
Update Information:
# Version 38.0.0 "The Silent Type" 2019-10-06 ## New features and enhancements
* mkvextract: chapters, tags & cue sheets will now be written to standard
output if no file name is given, same as if `-` is given as the file name. *
MKVToolNix GUI: job queue: added a new setting in the preferences' "job queue
&
job status" section that, when enabled, will cause the GUI to remove all output
files created by jobs that are either aborted by the user or that end in an
error. Implements #2614. ## Bug fixes * mkvmerge: when splitting by chapters
the user can now split by chapters coming from one of the appended files, too.
Fixes #2625. * mkvmerge: AAC reader: fixed reading codec parameters (channels,
sample rate) if a file starts with garbage that includes valid-but-bogus AAC
headers. Fixes #2622. * MKVToolNix GUI: Hebrew was added to the list of often-
used languages so that it can be selected by default again. Fixes #2610. *
MKVToolNix GUI: when updating the GUI's settings from v37.0.0 or older, the GUI
checks if the list of often-used languages equals the built-in list from
v36.0.0. If it does, it will be updated to the built-in list changed in v37.0.0.
Fixes #2611.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Dominik Mierzejewski <rpm(a)greysector.net> - 38.0.0-1
- update to 38.0.0 (#1758875)
- use gpgverify macro
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1758875 - mkvtoolnix-38.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1758875
--------------------------------------------------------------------------------
================================================================================
nodejs-rhea-1.0.10-1.el7 (FEDORA-EPEL-2019-5e7d46191e)
A reactive messaging library based on the AMQP protocol
--------------------------------------------------------------------------------
Update Information:
Rebased to 1.0.10.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Oct 2 2019 Irina Boverman <iboverma(a)redhat.com> - 1.0.10-1
- Rebased to 1.0.10
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1724785 - nodejs-rhea-1.0.10 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1724785
--------------------------------------------------------------------------------
================================================================================
python-dns-lexicon-3.3.4-2.el7 (FEDORA-EPEL-2019-c14316eb72)
Manipulate DNS records on various DNS providers in a standardized/agnostic way
--------------------------------------------------------------------------------
Update Information:
Update to 3.3.4.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Eli Young <elyscape(a)gmail.com> - 3.3.4-2
- Rebuild due to Koji issues
* Mon Oct 7 2019 Eli Young <elyscape(a)gmail.com> - 3.3.4-1
- Update to 3.3.4 (#1725208)
- Support EPEL8 builds
* Thu Oct 3 2019 Miro Hron��ok <mhroncok(a)redhat.com> - 3.2.8-4
- Rebuilt for Python 3.8.0rc1 (#1748018)
* Mon Aug 19 2019 Miro Hron��ok <mhroncok(a)redhat.com> - 3.2.8-3
- Rebuilt for Python 3.8
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 3.2.8-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1725208 - python-dns-lexicon-3.3.4 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1725208
--------------------------------------------------------------------------------
================================================================================
python-ecdsa-0.13.3-1.el7 (FEDORA-EPEL-2019-ef109e65c0)
ECDSA cryptographic signature library
--------------------------------------------------------------------------------
Update Information:
Update to 0.13.3 - CVE-2019-14853
--------------------------------------------------------------------------------
ChangeLog:
* Mon Oct 7 2019 Orion Poplawski <orion(a)nwra.com> - 0.13.3-1
- Update to 0.13.3 - CVE-2019-14853 (bugz #1758704)
- Update Python 2 dependency declarations to new packaging standards
(See
https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1758704 - CVE-2019-14853 python-ecdsa: Unexpected and undocumented
exceptions during signature decoding
https://bugzilla.redhat.com/show_bug.cgi?id=1758704
--------------------------------------------------------------------------------
================================================================================
python-ldap3-2.6.1-1.el7 (FEDORA-EPEL-2019-42b3f06efb)
Strictly RFC 4511 conforming LDAP V3 pure Python client
--------------------------------------------------------------------------------
Update Information:
Update to 2.6.1
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Avram Lubkin <aviso(a)rockhopper.net> - 2.6.1-1
- Update to 2.6.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1698339 - python36-ldap3 is not functional. And error is thrown during
import.
https://bugzilla.redhat.com/show_bug.cgi?id=1698339
--------------------------------------------------------------------------------
================================================================================
python-paho-mqtt-1.4.0-1.el7 (FEDORA-EPEL-2019-3481e02394)
A Python MQTT version 3.1/3.1.1 client class
--------------------------------------------------------------------------------
Update Information:
Update to new upstream version 1.4.0 (rhbz#1695729)
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Fabian Affolter <mail(a)fabian-affolter.ch> - 1.4.0-1
- Update to new upstream version 1.4.0 (rhbz#1695729)
* Thu Feb 5 2015 Fabian Affolter <mail(a)fabian-affolter.ch> - 1.1-1
- Update to new upstream version 1.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1695729 - [REBASE] can python-paho-mqtt be updated to version 1.4.0
https://bugzilla.redhat.com/show_bug.cgi?id=1695729
--------------------------------------------------------------------------------
================================================================================
python-pluginlib-0.6.2-1.el7 (FEDORA-EPEL-2019-7fb455885f)
A framework for creating and importing plugins in Python
--------------------------------------------------------------------------------
Update Information:
0.6.2 Release
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Avram Lubkin <aviso(a)rockhopper.net> - 0.6.2-1
- 0.6.2 Release
* Thu Oct 3 2019 Miro Hron��ok <mhroncok(a)redhat.com> - 0.6.1-5
- Rebuilt for Python 3.8.0rc1 (#1748018)
* Mon Aug 19 2019 Miro Hron��ok <mhroncok(a)redhat.com> - 0.6.1-4
- Rebuilt for Python 3.8
* Fri Jul 26 2019 Fedora Release Engineering <releng(a)fedoraproject.org> - 0.6.1-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
--------------------------------------------------------------------------------
================================================================================
python3-numpy-1.12.1-3.el7 (FEDORA-EPEL-2019-cbae15145d)
A fast multidimensional array facility for Python 3
--------------------------------------------------------------------------------
Update Information:
Provide python3-numpy Provide f2py3 and f2py3.6
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 8 2019 Orion Poplawski <orion(a)nwra.com> - 1.12.1-3
- Provide both f2py3 and f2py3.X
* Fri Oct 4 2019 Orion Poplawski <orion(a)nwra.com> - 1.12.1-2
- Provide python3-numpy (bugz#1758151)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1758151 - python3-numpy is not available for CentOS 7 with EPEL
https://bugzilla.redhat.com/show_bug.cgi?id=1758151
--------------------------------------------------------------------------------
================================================================================
qpid-dispatch-1.9.0-1.el7 (FEDORA-EPEL-2019-5a437f2196)
Dispatch router for Qpid
--------------------------------------------------------------------------------
Update Information:
Rebased to 1.9.0.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Oct 2 2019 Irina Boverman <iboverma(a)redhat.com> - 1.9.0-1
- Rebased to 1.9.0
--------------------------------------------------------------------------------
================================================================================
qpid-proton-0.29.0-1.el7 (FEDORA-EPEL-2019-2408fbd638)
A high performance, lightweight messaging library
--------------------------------------------------------------------------------
Update Information:
Rebased to 0.29.0.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Oct 1 2019 Irina Boverman <iboverma(a)redhat.com> - 0.29.0-1
- Rebased to 0.29.0
--------------------------------------------------------------------------------
================================================================================
rubygem-qpid_proton-0.29.0-1.el7 (FEDORA-EPEL-2019-72c7800c16)
Ruby language bindings for the Qpid Proton messaging framework
--------------------------------------------------------------------------------
Update Information:
Rebased to 0.29.0.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Oct 2 2019 Irina Boverman <iboverma(a)redhat.com> - 0.29.0-1
- Rebased to 0.29.0
--------------------------------------------------------------------------------
================================================================================
xxhash-0.7.2-1.el7 (FEDORA-EPEL-2019-533014b6b6)
Extremely fast hash algorithm
--------------------------------------------------------------------------------
Update Information:
xxhash 0.7.2
--------------------------------------------------------------------------------
ChangeLog:
* Wed Oct 9 2019 Mattias Ellert <mattias.ellert(a)physics.uu.se> - 0.7.2-1
- Update to version 0.7.2
--------------------------------------------------------------------------------