The following Fedora EPEL 5 Security updates need testing: Age URL 837 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2013-11893 libguestfs-1.20.12-1.el5 601 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2014-1626 puppet-2.7.26-1.el5 451 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2014-3849 sblim-sfcb-1.3.8-2.el5 94 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-edbea40516 mcollective-2.8.4-1.el5 66 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-582c8075e6 thttpd-2.25b-24.el5 47 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-d1309b0eb2 libsndfile-1.0.17-8.el5 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-5a2146a2dd prosody-0.9.10-1.el5 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-2a457c3d5b phpMyAdmin4-4.0.10.14-1.el5 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-991b4f1f7d wordpress-4.4.2-1.el5
The following builds have been pushed to Fedora EPEL 5 updates-testing
pcp-3.11.0-1.el5 wordpress-4.4.2-1.el5
Details about builds:
================================================================================ pcp-3.11.0-1.el5 (FEDORA-EPEL-2016-57b7efb2d7) System-level performance monitoring and performance management -------------------------------------------------------------------------------- Update Information:
* containers: add a pcp-pmwebd container image * pmcd: start PMDAs via pmdaroot, allowing restart on PMDA failure without restarting pmcd itself * pmcd: tenfold speed up of the shutdown process * pmcd: ensure startup before zabbix-agent, with systemd * pmdafreebsd: use getifaddrs() for network interface * pmdalinux: fix /proc/interrupts parsing on s390x platforms * pmdalinux: fix i386 buffer overflow in softnet stats * pmdalinux: support additional vmstat kernel metrics (virt balloon, transparent-huge-page zero page alloc counters) * pmdaxfs: support the per-device XFS metrics * pmdanamed: fix SELinux AVC denials during Install * pmdavmware: updates to work with current VMWare perl API * libpcp: improvements to derived metrics error handling * libpcp: rework interp logic arond <mark> records * libpcp: fix bug in interp mode record caching * libpcp: pthread_mutexattr_destroy, pthread_mutex_destroy calls * libpcp: added a new fetchgroup API * libpcp: fix dup-context-with-attrs memory corruption bug * libpcp: fix derived metric PMNS navigation mem leak * libpcp: unconditional registration of anon (event.*) metrics * pcp-iostat: use py3 and py3 compatible pipe exception handlers * pcp-iostat: improve incorrect counter rate conversion * pcp-iostat: improve BrokenPipeError exception handling * pmmgr: add general monitor-program launching option * pmmgr: resolved a couple of small memory leaks * pmrep: fix first sample reporting, instant/discrete metrics * pmrep: fix string valued metric reporting, with python3 * pmval: improve reporting in the region of <mark> records * pmwebd: add an option to disable service advertising * pmwebd: support for http compression * pmwebd: add units/sem to legend in graphite/png mode * pmwebd: enable graphite image-mode caching via redirection * pmwebd: add an option for alternative name encodings * sar2pcp: support additional mem.util metrics * docs: updates to the system CPU performance tutorial * packaging: add missing dependencies on some perl modules * packaging: drop the pcp-compat subpackage ---- Add -V/--version support to several more commands (BZ 1284411) ---- pcp-3.10.8-1.fc21 - Update pmlogger to log an immediate sample first (BZ 1269921) - Add pmOption host and archive setter python APIs (BZ 1270176) - Replace old pmatop(1) man page with pcp-atop(1) (BZ 1270761) - Update to latest PCP sources. - CHANGELOG : - pmdaslurm: new PMDA exporting HPC scheduler metrics - pmdalinux: correctly report high speed network link speeds - pmdalinux: support for wireless network interfaces - pmdalinux: add support for NVME devices - pmie: fqdn functionality, added %c for action strings - pmlogextract: runtime reducing instance optimizations - pmlogrewrite: metric name lex pattern change - pmlogger: change semantics for first logging operation - rc_pmlogger: shell escape for control file "directory" field - pcp-atop: update with latest atop features (esp. NFS) - pcp-atop: fix initial fetch time offset for the globals - pcp-atop: fix -b/-e options to match man page description - docs: update Quick Ref Guide with pcp-atop/pcp-atopsar - docs: remove outdated pmatop man page, see pcp-atop(1) - python api: fix local-context mode type error - python api: improve handling of non-ascii instance names - python api: simple debugging interface to access pmDebug - python api: ensure an interruptible sleep is used - python api: add single host/archive pmOption setter methods - libpcp: add $PCP_DEBUG to initialize pmDebug - libpcp: extend __pmAF* family with __pmAFsetup - libpcp: resolve false-context- sharing corner cases - pcp2graphite: provide a local-context mode option - pmmgr: add the subtarget-containers option - pmmgr: add pmlogreduce support - rc_pmcd: be more careful with auto-install/-remove - pmcd: allow dynamic switching of monitored containers - pmdapmcd: add pmcd.client.container diagnostic metric - pmdaroot: new metric mapping containers to their cgroups - pmdaroot: add cgroup heuristics for non- systemd setups - pmdaroot: fix timeliness of creation of socket connection - pmdads389: add normalized dn cache metrics - pmdads389: instantaneous vs discrete metric corrections - pmdads389: send correct error codes when not connected - pmdamounts: correct a number of 32-bit unsafe calculations - pmdanfsclient: improve PMDA error handling - pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference clock cycles for NHM and WSM - docs: added upgrade instructions to pmdaperfevent man page - containers: bindmount /dev/log for syslog messages - build: fix FreeBSD 10.2 with dtrace probes auto-enabled pcp-3.10.8-1.fc22 - Update pmlogger to log an immediate sample first (BZ 1269921) - Add pmOption host and archive setter python APIs (BZ 1270176) - Replace old pmatop(1) man page with pcp-atop(1) (BZ 1270761) - Update to latest PCP sources. - CHANGELOG - pmdaslurm: new PMDA exporting HPC scheduler metrics - pmdalinux: correctly report high speed network link speeds - pmdalinux: support for wireless network interfaces - pmdalinux: add support for NVME devices - pmie: fqdn functionality, added %c for action strings - pmlogextract: runtime reducing instance optimizations - pmlogrewrite: metric name lex pattern change - pmlogger: change semantics for first logging operation - rc_pmlogger: shell escape for control file "directory" field - pcp-atop: update with latest atop features (esp. NFS) - pcp-atop: fix initial fetch time offset for the globals - pcp-atop: fix -b/-e options to match man page description - docs: update Quick Ref Guide with pcp-atop/pcp-atopsar - docs: remove outdated pmatop man page, see pcp- atop(1) - python api: fix local-context mode type error - python api: improve handling of non-ascii instance names - python api: simple debugging interface to access pmDebug - python api: ensure an interruptible sleep is used - python api: add single host/archive pmOption setter methods - libpcp: add $PCP_DEBUG to initialize pmDebug - libpcp: extend __pmAF* family with __pmAFsetup - libpcp: resolve false-context-sharing corner cases - pcp2graphite: provide a local-context mode option - pmmgr: add the subtarget-containers option - pmmgr: add pmlogreduce support - rc_pmcd: be more careful with auto-install/-remove - pmcd: allow dynamic switching of monitored containers - pmdapmcd: add pmcd.client.container diagnostic metric - pmdaroot: new metric mapping containers to their cgroups - pmdaroot: add cgroup heuristics for non-systemd setups - pmdaroot: fix timeliness of creation of socket connection - pmdads389: add normalized dn cache metrics - pmdads389: instantaneous vs discrete metric corrections - pmdads389: send correct error codes when not connected - pmdamounts: correct a number of 32-bit unsafe calculations - pmdanfsclient: improve PMDA error handling - pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference clock cycles for NHM and WSM - docs: added upgrade instructions to pmdaperfevent man page - containers: bindmount /dev/log for syslog messages - build: fix FreeBSD 10.2 with dtrace probes auto-enabled pcp-3.10.8-1.el5 - Update pmlogger to log an immediate sample first (BZ 1269921) - Add pmOption host and archive setter python APIs (BZ 1270176) - Replace old pmatop(1) man page with pcp-atop(1) (BZ 1270761) - Update to latest PCP sources. - CHANGELOG - pmdaslurm: new PMDA exporting HPC scheduler metrics - pmdalinux: correctly report high speed network link speeds - pmdalinux: support for wireless network interfaces - pmdalinux: add support for NVME devices - pmie: fqdn functionality, added %c for action strings - pmlogextract: runtime reducing instance optimizations - pmlogrewrite: metric name lex pattern change - pmlogger: change semantics for first logging operation - rc_pmlogger: shell escape for control file "directory" field - pcp-atop: update with latest atop features (esp. NFS) - pcp-atop: fix initial fetch time offset for the globals - pcp-atop: fix -b/-e options to match man page description - docs: update Quick Ref Guide with pcp-atop/pcp-atopsar - docs: remove outdated pmatop man page, see pcp-atop(1) - python api: fix local-context mode type error - python api: improve handling of non-ascii instance names - python api: simple debugging interface to access pmDebug - python api: ensure an interruptible sleep is used - python api: add single host/archive pmOption setter methods - libpcp: add $PCP_DEBUG to initialize pmDebug - libpcp: extend __pmAF* family with __pmAFsetup - libpcp: resolve false-context-sharing corner cases - pcp2graphite: provide a local- context mode option - pmmgr: add the subtarget-containers option - pmmgr: add pmlogreduce support - rc_pmcd: be more careful with auto- install/-remove - pmcd: allow dynamic switching of monitored containers - pmdapmcd: add pmcd.client.container diagnostic metric - pmdaroot: new metric mapping containers to their cgroups - pmdaroot: add cgroup heuristics for non-systemd setups - pmdaroot: fix timeliness of creation of socket connection - pmdads389: add normalized dn cache metrics - pmdads389: instantaneous vs discrete metric corrections - pmdads389: send correct error codes when not connected - pmdamounts: correct a number of 32-bit unsafe calculations - pmdanfsclient: improve PMDA error handling - pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference clock cycles for NHM and WSM - docs: added upgrade instructions to pmdaperfevent man page - containers: bindmount /dev/log for syslog messages - build: fix FreeBSD 10.2 with dtrace probes auto-enabled pcp-3.10.8-1.fc23.1 - Update pmlogger to log an immediate sample first (BZ 1269921) - Add pmOption host and archive setter python APIs (BZ 1270176) - Replace old pmatop(1) man page with pcp-atop(1) (BZ 1270761) - Update to latest PCP sources. - CHANGELOG - pmdaslurm: new PMDA exporting HPC scheduler metrics - pmdalinux: correctly report high speed network link speeds - pmdalinux: support for wireless network interfaces - pmdalinux: add support for NVME devices - pmie: fqdn functionality, added %c for action strings - pmlogextract: runtime reducing instance optimizations - pmlogrewrite: metric name lex pattern change - pmlogger: change semantics for first logging operation - rc_pmlogger: shell escape for control file "directory" field - pcp-atop: update with latest atop features (esp. NFS) - pcp-atop: fix initial fetch time offset for the globals - pcp-atop: fix -b/-e options to match man page description - docs: update Quick Ref Guide with pcp-atop/pcp-atopsar - docs: remove outdated pmatop man page, see pcp-atop(1) - python api: fix local-context mode type error - python api: improve handling of non-ascii instance names - python api: simple debugging interface to access pmDebug - python api: ensure an interruptible sleep is used - python api: add single host/archive pmOption setter methods - libpcp: add $PCP_DEBUG to initialize pmDebug - libpcp: extend __pmAF* family with __pmAFsetup - libpcp: resolve false-context-sharing corner cases - pcp2graphite: provide a local- context mode option - pmmgr: add the subtarget-containers option - pmmgr: add pmlogreduce support - rc_pmcd: be more careful with auto- install/-remove - pmcd: allow dynamic switching of monitored containers - pmdapmcd: add pmcd.client.container diagnostic metric - pmdaroot: new metric mapping containers to their cgroups - pmdaroot: add cgroup heuristics for non-systemd setups - pmdaroot: fix timeliness of creation of socket connection - pmdads389: add normalized dn cache metrics - pmdads389: instantaneous vs discrete metric corrections - pmdads389: send correct error codes when not connected - pmdamounts: correct a number of 32-bit unsafe calculations - pmdanfsclient: improve PMDA error handling - pmdaperfevent: fix invalid metric names - pmdaperfevent: add reference clock cycles for NHM and WSM - docs: added upgrade instructions to pmdaperfevent man page - containers: bindmount /dev/log for syslog messages - build: fix FreeBSD 10.2 with dtrace probes auto-enabled ---- Update to latest PCP and Vector sources. pcp-3.10.7-1.el5 - Resolved pmchart sigsegv opening view without context (BZ 1256708) - Fixed pmchart memory corruption restoring Saved Hosts (BZ 1257009) - Fix perl PMDA API double-free on socket error path (BZ 1258862) - Fix python API pmGetOption(3) alignment interface (BZ 1262722) - Added missing RPM dependencies to several PMDA sub-packages. - Update to latest stable Vector release for pcp-vector-webapp. - Update to latest PCP sources. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1284411 - RFE: Add pcp -V https://bugzilla.redhat.com/show_bug.cgi?id=1284411 [ 2 ] Bug #1249572 - pcp-iostat exception at the end of an archive https://bugzilla.redhat.com/show_bug.cgi?id=1249572 [ 3 ] Bug #1163413 - RFE: pmdapipe https://bugzilla.redhat.com/show_bug.cgi?id=1163413 [ 4 ] Bug #1284417 - Python PMAPI pmSetMode does not allow None timeval https://bugzilla.redhat.com/show_bug.cgi?id=1284417 [ 5 ] Bug #1285371 - Python PMAPI pmiPutValue does not accept singular metrics https://bugzilla.redhat.com/show_bug.cgi?id=1285371 [ 6 ] Bug #1286733 - Invalid Python PMAPI pmRegisterDerived call crashes libpcp https://bugzilla.redhat.com/show_bug.cgi?id=1286733 [ 7 ] Bug #1287678 - pmstat -g SEGV https://bugzilla.redhat.com/show_bug.cgi?id=1287678 [ 8 ] Bug #1287778 - Python PMAPI pmNonOptionsFromList cryptic error message https://bugzilla.redhat.com/show_bug.cgi?id=1287778 [ 9 ] Bug #1289909 - pmdumptext -g / -p not working https://bugzilla.redhat.com/show_bug.cgi?id=1289909 [ 10 ] Bug #1256125 - SELinux is preventing /usr/bin/pmlogger from 'open' accesses on the file /var/lib/pcp/config/pmlogger/config.default. https://bugzilla.redhat.com/show_bug.cgi?id=1256125 [ 11 ] Bug #1270761 - pmatop -h does not work https://bugzilla.redhat.com/show_bug.cgi?id=1270761 [ 12 ] Bug #1270176 - Python PMAPI pmSetOptionHostList no workie https://bugzilla.redhat.com/show_bug.cgi?id=1270176 [ 13 ] Bug #1269921 - pmRecordControl misses the first sample https://bugzilla.redhat.com/show_bug.cgi?id=1269921 [ 14 ] Bug #1262722 - PCP Python PMAPI pmGetOptionAlignment fails https://bugzilla.redhat.com/show_bug.cgi?id=1262722 [ 15 ] Bug #1258862 - local_sock() double free error https://bugzilla.redhat.com/show_bug.cgi?id=1258862 [ 16 ] Bug #1257009 - pmchart connect incorrect host with savedHosts entry in .config/PCP/pmchart.conf https://bugzilla.redhat.com/show_bug.cgi?id=1257009 [ 17 ] Bug #1256708 - [abrt] pcp-gui: context(): pmchart killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1256708 --------------------------------------------------------------------------------
================================================================================ wordpress-4.4.2-1.el5 (FEDORA-EPEL-2016-991b4f1f7d) Blog tool and publishing platform -------------------------------------------------------------------------------- Update Information:
**WordPress 4.4.2 Security and Maintenance Release** WordPress 4.4.2 is now available. This is a security release for all previous versions and we strongly encourage you to update your sites immediately. WordPress versions 4.4.1 and earlier are affected by two security issues: a possible SSRF for certain local URIs, reported by Ronni Skansing; and an open redirection attack, reported by Shailesh Suthar. Thank you to both reporters for practicing responsible disclosure. In addition to the security issues above, WordPress 4.4.2 fixes 17 bugs from 4.4 and 4.4.1. For more information, see the [release notes](https://codex.wordpress.org/Version_4.4.2) or consult the [list of changes](https://core.trac.wordpress.org/query?milestone=4.4.2). --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org