The following Fedora EPEL 7 Security updates need testing: Age URL 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2014-3989 cross-binutils-2.23.88.0.1-2.el7.1 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-6813 chicken-4.9.0.1-4.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7613 zabbix20-2.0.15-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7800 python-django-1.6.11-3.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7845 php-guzzle-Guzzle-3.9.3-5.el7 php-ZendFramework2-2.4.7-2.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7874 onionshare-0.7.1-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7909 pdns-3.4.6-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7960 php-doctrine-cache-1.4.2-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7962 php-doctrine-annotations-1.2.7-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7964 php-doctrine-doctrine-bundle-1.5.2-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
carbon-c-relay-0.44-3.el7 cgit-0.11.2-3.el7 ipv6calc-0.99.1-13.el7 libnetfilter_log-1.0.1-7.el7 mozilla-https-everywhere-5.1.1-1.el7 nodejs-ast-types-0.4.5-2.el7 nrpe-2.15-6.el7 php-aws-sdk-2.8.20-1.el7 php-doctrine-annotations-1.2.7-1.el7 php-doctrine-cache-1.4.2-1.el7 php-doctrine-doctrine-bundle-1.5.2-1.el7 php-icewind-streams-0.2.0-1.el7 php-jeremeamia-superclosure-2.1.0-1.el7 php-php-gettext-1.0.11-12.el7 xfoil-6.99-1.el7
Details about builds:
================================================================================ carbon-c-relay-0.44-3.el7 (FEDORA-EPEL-2015-7955) Enhanced C implementation of Carbon relay, aggregator and rewriter -------------------------------------------------------------------------------- Update Information:
Exclude 32 bit arches --------------------------------------------------------------------------------
================================================================================ cgit-0.11.2-3.el7 (FEDORA-EPEL-2015-7948) A fast web interface for git -------------------------------------------------------------------------------- Update Information:
Fix up logic around webserver and httpd. ---- Update to 0.11.2 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1258552 - EPEL6 build of cgit-0.11.2 https://bugzilla.redhat.com/show_bug.cgi?id=1258552 --------------------------------------------------------------------------------
================================================================================ ipv6calc-0.99.1-13.el7 (FEDORA-EPEL-2015-7945) IPv6 address format change and calculation utility -------------------------------------------------------------------------------- Update Information:
new release 0.99.1 (introduces new subpackage mod_ipv6calc) --------------------------------------------------------------------------------
================================================================================ libnetfilter_log-1.0.1-7.el7 (FEDORA-EPEL-2015-7944) Netfilter logging userspace library -------------------------------------------------------------------------------- Update Information:
libnetfilter_log-1.0.1-7.el6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild libnetfilter_log-1.0.1-7.el7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ mozilla-https-everywhere-5.1.1-1.el7 (FEDORA-EPEL-2015-7952) HTTPS/HSTS enforcement extension for Mozilla Firefox and SeaMonkey -------------------------------------------------------------------------------- Update Information:
- Ruleset fixes - Remove the AMO signature - Fix the "not appearing" problem ---- mozilla-https-everywhere-5.1.0-1.el5 - Ruleset fixes - AMO signature mozilla-https-everywhere-5.1.0-1.el6 - Ruleset fixes - AMO signature mozilla- https-everywhere-5.1.0-1.el7 - Ruleset fixes - AMO signature --------------------------------------------------------------------------------
================================================================================ nodejs-ast-types-0.4.5-2.el7 (FEDORA-EPEL-2015-7947) Esprima-compatible implementation of the Mozilla JS Parser API -------------------------------------------------------------------------------- Update Information:
package missing def dir -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1260268 - def directory not packaged https://bugzilla.redhat.com/show_bug.cgi?id=1260268 --------------------------------------------------------------------------------
================================================================================ nrpe-2.15-6.el7 (FEDORA-EPEL-2015-7939) Host/service/network monitoring agent for Nagios -------------------------------------------------------------------------------- Update Information:
nrpe-2.15-6.el7 - Fix spec file for missing /usr/share/libtool/config/config.guess nrpe-2.15-6.el6 - Fix spec file for missing /usr/share/libtool/config/config.guess nrpe-2.15-6.fc23 - Fix spec file for missing /usr/share/libtool/config/config.guess nrpe-2.15-6.fc22 - Fix spec file for missing /usr/share/libtool/config/config.guess nrpe-2.15-6.fc21 - Fix spec file for missing /usr/share/libtool/config/config.guess -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1089880 - CVE-2014-2913 nrpe: remote command execution when command arguments are enabled [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1089880 [ 2 ] Bug #1239738 - nrpe: FTBFS in rawhide https://bugzilla.redhat.com/show_bug.cgi?id=1239738 --------------------------------------------------------------------------------
================================================================================ php-aws-sdk-2.8.20-1.el7 (FEDORA-EPEL-2015-7958) Amazon Web Services framework for PHP -------------------------------------------------------------------------------- Update Information:
## 2.8.20 - 2015-09-03 * `Aws\CodePipeline` - Added support for using encryption keys with artifact stores. * `Aws\ConfigService` - Added support for the `ListDiscoveredResources` operation and new resource types. * `Aws\Ec2` - Added support for using instance weights with the `RequestSpotFleet` API. * `Aws\Sns` - Added support for configurable SigningCertURL host patterns. * `Aws\StorageGateway` - Added support for tagging and untagging resources. * Fixed issue with loading the phar from opcache. ## 2.8.19 - 2015-08-20 * `Aws\S3` - Added support for event notification filters. ## 2.8.18 - 2015-08-12 * `Aws\ElasticBeanstalk` - Added support for enhanced health reporting. * `Aws\Glacier` - Fixed an issue where content bodies that equaled false (e.g., '0') would not be uploaded. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1253094 - php-aws-sdk-2.8.20 is available https://bugzilla.redhat.com/show_bug.cgi?id=1253094 --------------------------------------------------------------------------------
================================================================================ php-doctrine-annotations-1.2.7-1.el7 (FEDORA-EPEL-2015-7962) PHP docblock annotations parser library -------------------------------------------------------------------------------- Update Information:
CVE-2015-5723 http://www.doctrine-project.org/2015/08/31/security_misconfigurat ion_vulnerability_in_various_doctrine_projects.html -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1258669 - php-doctrine-annotations-v1.2.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1258669 --------------------------------------------------------------------------------
================================================================================ php-doctrine-cache-1.4.2-1.el7 (FEDORA-EPEL-2015-7960) Doctrine Cache -------------------------------------------------------------------------------- Update Information:
CVE-2015-5723 http://www.doctrine-project.org/2015/08/31/security_misconfigurat ion_vulnerability_in_various_doctrine_projects.html -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1258670 - php-doctrine-cache-v1.4.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1258670 --------------------------------------------------------------------------------
================================================================================ php-doctrine-doctrine-bundle-1.5.2-1.el7 (FEDORA-EPEL-2015-7964) Symfony Bundle for Doctrine -------------------------------------------------------------------------------- Update Information:
## 1.5.2 (2015-08-31) ### Security: * Fix Security Misconfiguration Vulnerability, allowing potential local arbitrary code execution * CVE-2015-5723 * http://www.doctrine-project.org/2015/08/31/security_misconfi guration_vulnerability_in_various_doctrine_projects.html ## 1.5.1 (2015-08-12) ### Bugfix: * Fixed the JS expanding all queries in the profiler in case of multiple connections * Fixed the retrieval of the namespace in DisconnectedMetadataFactory * Changed the composer constraint to allow Symfony 3.0 for people wanting to do early testing -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1253092 - php-doctrine-doctrine-bundle-v1.5.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1253092 --------------------------------------------------------------------------------
================================================================================ php-icewind-streams-0.2.0-1.el7 (FEDORA-EPEL-2015-7942) A set of generic stream wrappers -------------------------------------------------------------------------------- Update Information:
Generic stream wrappers for php. To use this library, you just have to add, in your project: require-once '/usr/share/php/Icewind/Streams/autoload.php'; -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1258955 - Review Request: php-icewind-streams - A set of generic stream wrappers https://bugzilla.redhat.com/show_bug.cgi?id=1258955 --------------------------------------------------------------------------------
================================================================================ php-jeremeamia-superclosure-2.1.0-1.el7 (FEDORA-EPEL-2015-7941) Serialize Closure objects, including their context and binding -------------------------------------------------------------------------------- Update Information:
Even though serializing closures is "not allowed" by PHP, the SuperClosure library makes it possible To use this library, you just have to add, in your project: require-once '/usr/share/php/SuperClosure/autoload.php'; -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1258899 - Review Request: php-jeremeamia-superclosure - Serialize Closure objects, including their context and binding https://bugzilla.redhat.com/show_bug.cgi?id=1258899 --------------------------------------------------------------------------------
================================================================================ php-php-gettext-1.0.11-12.el7 (FEDORA-EPEL-2015-7935) Gettext emulation in PHP -------------------------------------------------------------------------------- Update Information:
Added a patch for compatibility with PHP 7 --------------------------------------------------------------------------------
================================================================================ xfoil-6.99-1.el7 (FEDORA-EPEL-2015-7953) Subsonic Airfoil Development System -------------------------------------------------------------------------------- Update Information:
Update to version 6.99, see http://web.mit.edu/drela/Public/web/xfoil/version_notes.txt for details. --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org