The following Fedora EPEL 7 Security updates need testing:
Age URL
150
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3835d39d1a
unrtf-0.21.9-8.el7
101
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-f9d6ff695a
bibutils-6.6-1.el7 ghc-hs-bibutils-6.6.0.0-1.el7 pandoc-citeproc-0.3.0.1-4.el7
84
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3c9292b62d
condor-8.6.11-1.el7
56
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3492a96896
myrepos-1.20180726-1.el7
6
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-bdb21ebc3f
drupal7-7.60-2.el7
6
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-29716ed12f
php-pear-CAS-1.3.6-1.el7
6
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-8876f503ce
libgit2-0.26.8-1.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-9091f95cd5
zchunk-0.9.14-1.el7
4
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-dea9ade8c1
icecast-2.4.4-1.el7
2
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-cbfa290941
mkvtoolnix-28.2.0-1.el7
The following builds have been pushed to Fedora EPEL 7 updates-testing
SDL2_image-2.0.4-1.el7
SDL2_mixer-2.0.4-1.el7
mingw-SDL2-2.0.9-1.el7
mingw-SDL2_image-2.0.4-1.el7
mingw-SDL2_mixer-2.0.4-1.el7
perl-Mojolicious-7.94-1.el7
python-mock-1.0.1-10.el7
python3-mock-2.0.0-1.el7
twa-1.6.2-1.el7
Details about builds:
================================================================================
SDL2_image-2.0.4-1.el7 (FEDORA-EPEL-2018-be918c58c6)
Image loading library for SDL
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2018-3977
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 6 2018 Pete Walter <pwalter(a)fedoraproject.org> - 2.0.4-1
- Update to 2.0.4
* Thu Jul 12 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.0.3-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1646575 - CVE-2018-3977 SDL2_image: code execution in the XCF image rendering
functionality
https://bugzilla.redhat.com/show_bug.cgi?id=1646575
--------------------------------------------------------------------------------
================================================================================
SDL2_mixer-2.0.4-1.el7 (FEDORA-EPEL-2018-7311575631)
Simple DirectMedia Layer - Sample Mixer Library
--------------------------------------------------------------------------------
Update Information:
Update to 2.0.4
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 6 2018 Pete Walter <pwalter(a)fedoraproject.org> - 2.0.4-1
- Update to 2.0.4
* Thu Jul 12 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.0.2-5
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Wed Feb 7 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.0.2-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Wed Jan 31 2018 Igor Gnatenko <ignatenkobrain(a)fedoraproject.org> - 2.0.2-3
- Switch to %ldconfig_scriptlets
--------------------------------------------------------------------------------
================================================================================
mingw-SDL2-2.0.9-1.el7 (FEDORA-EPEL-2018-df2d5af2fe)
MinGW Windows port of SDL2 cross-platform multimedia library
--------------------------------------------------------------------------------
Update Information:
mingw-SDL2 refresh for EPEL 7: update to latest upstream releases, fixing a
number of security issues.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1500450 - CVE-2017-2887 SDL_image: Incorrect XCF property handling
https://bugzilla.redhat.com/show_bug.cgi?id=1500450
--------------------------------------------------------------------------------
================================================================================
mingw-SDL2_image-2.0.4-1.el7 (FEDORA-EPEL-2018-df2d5af2fe)
MinGW Windows port of the Image loading library for SDL2
--------------------------------------------------------------------------------
Update Information:
mingw-SDL2 refresh for EPEL 7: update to latest upstream releases, fixing a
number of security issues.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1500450 - CVE-2017-2887 SDL_image: Incorrect XCF property handling
https://bugzilla.redhat.com/show_bug.cgi?id=1500450
--------------------------------------------------------------------------------
================================================================================
mingw-SDL2_mixer-2.0.4-1.el7 (FEDORA-EPEL-2018-df2d5af2fe)
MinGW Windows port of Simple DirectMedia Layer's Sample Mixer Library
--------------------------------------------------------------------------------
Update Information:
mingw-SDL2 refresh for EPEL 7: update to latest upstream releases, fixing a
number of security issues.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1500450 - CVE-2017-2887 SDL_image: Incorrect XCF property handling
https://bugzilla.redhat.com/show_bug.cgi?id=1500450
--------------------------------------------------------------------------------
================================================================================
perl-Mojolicious-7.94-1.el7 (FEDORA-EPEL-2018-32e0cee0bb)
A next generation web framework for Perl
--------------------------------------------------------------------------------
Update Information:
Mojolicious 7.94 is the last Mojolicious 7.x release and fixes a number of bugs
that were in the previous versions. As an example, Mojo::UserAgent was not
checking peer SSL certificates by default.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 6 2018 Emmanuel Seyman <emmanuel(a)seyman.fr> - 7.94-1
- Update to 7.94
--------------------------------------------------------------------------------
================================================================================
python-mock-1.0.1-10.el7 (FEDORA-EPEL-2018-51facbfbbb)
A Python Mocking and Patching Library for Testing
--------------------------------------------------------------------------------
Update Information:
- Update python34-mock to 2.0.0 - Ship python36-mock
--------------------------------------------------------------------------------
ChangeLog:
* Mon Nov 5 2018 Orion Poplawski <orion(a)nwra.com> - 1.0.1-10
- Move Python 3 package to python3-mock
--------------------------------------------------------------------------------
================================================================================
python3-mock-2.0.0-1.el7 (FEDORA-EPEL-2018-51facbfbbb)
A Python Mocking and Patching Library for Testing
--------------------------------------------------------------------------------
Update Information:
- Update python34-mock to 2.0.0 - Ship python36-mock
--------------------------------------------------------------------------------
================================================================================
twa-1.6.2-1.el7 (FEDORA-EPEL-2018-3f8001658e)
Tiny web auditor with strong opinions
--------------------------------------------------------------------------------
Update Information:
Update to latest upstream version
--------------------------------------------------------------------------------
ChangeLog:
* Tue Nov 6 2018 Artur Iwicki <fedora(a)svgames.pl> - 1.6.2-1
- Update to latest upstream version
* Sat Oct 20 2018 Artur Iwicki <fedora(a)svgames.pl> - 1.6.0-1
- Update to latest upstream version
- Update upstream URL (repo owner change)
--------------------------------------------------------------------------------