The following Fedora EPEL 5 Security updates need testing:
https://admin.fedoraproject.org/updates/rt3-3.6.10-2.el5
https://admin.fedoraproject.org/updates/loggerhead-1.18.1-1.el5
https://admin.fedoraproject.org/updates/python-feedparser-5.0.1-1.el5
The following builds have been pushed to Fedora EPEL 5 updates-testing
389-ds-base-1.2.8.0-1.el5
drupal6-login_destination-2.12-1.el5
drupal7-7.0-4.el5
erlang-mochiweb-1.4.1-5.el5
fpdns-0.9.3-1.el5
imapsync-1.404-3.el5
n2n-2.0.1-3.el5
ngrep-1.45-8.1.el5
perl-NTLM-1.05-3.el5
python-feedparser-5.0.1-1.el5
tinyxml-2.6.1-2.el5
zarafa-6.40.7-1.el5
Details about builds:
================================================================================
389-ds-base-1.2.8.0-1.el5 (FEDORA-EPEL-2011-2999)
389 Directory Server (base)
--------------------------------------------------------------------------------
Update Information:
This is the 389-ds-base-1.2.8.0 release - some bug fixes for winsync
and matching rules and schema
The 389-ds-base-1.2.8.rc5 release - Fix a bug in settting up GSSAPI replication
This is the 1.2.8 release candidate 4 release
This is 389-ds-base-1.2.8 RC 2 - this fixes several bugs found in alpha and RC 1 testing
This is the 389-ds-base-1.2.8 release candidate 1 build
Split off 389-ds-base-libs to solve multilib issues
1.2.8.a3 release - git tag 389-ds-base-1.2.8.a3
see bugs for a list of bugs fixed
This is the 1.2.8 alpha 2 release - many bug fixes
389-ds-base 1.2.8 alpha 1
contains many bug fixes
--------------------------------------------------------------------------------
ChangeLog:
* Tue Apr 5 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8.0-1
- 389-ds-base-1.2.8.0
- Bug 693473 - rhds82 rfe - windows_tot_run to log Sizelimit exceeded instead of LDAP
error - -1
- Bug 692991 - rhds82 - windows_tot_run: failed to obtain data to send to the consumer;
LDAP error - -1
- Bug 693466 - Unable to change schema online
- Bug 693503 - matching rules do not inherit from superior attribute type
- Bug 693455 - nsMatchingRule does not work with multiple values
- Bug 693451 - cannot use localized matching rules
- Bug 692331 - Segfault on index update during full replication push on 1.2.7.5
* Mon Apr 4 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.9.rc5
- 389-ds-base-1.2.8.rc5
- Bug 692469 - Replica install fails after step for "enable GSSAPI for
replication"
* Tue Mar 29 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.8.rc4
- 389-ds-base-1.2.8.rc4
- Bug 668385 - DS pipe log script is executed as many times as the dirsrv serv
ice is restarted
- 389-ds-base-1.2.8.rc3
- Bug 690955 - Mrclone fails due to the replica generation id mismatch
* Tue Mar 22 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.7.rc2
- 389-ds-base-1.2.8 release candidate 2 - git tag 389-ds-base-1.2.8.rc2
- Bug 689537 - (cov#10610) Fix Coverity NULL pointer dereferences
- Bug 689866 - ns-newpwpolicy.pl needs to use the new DN format
- Bug 681015 - RFE: allow fine grained password policy duration attributes
- in days, hours, minutes, as well
- Bug 684996 - Exported tombstone cannot be imported correctly
- Bug 683250 - slapd crashing when traffic replayed
- Bug 668909 - Can't modify replication agreement in some cases
- Bug 504803 - Allow maxlogsize to be set if logmaxdiskspace is -1
- Bug 644784 - Memory leak in "testbind.c" plugin
- Bug 680558 - Winsync plugin fails to restrain itself to the configured subtree
* Wed Mar 2 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.6.rc1
- 389-ds-base-1.2.8 release candidate 1 - git tag 389-ds-base-1.2.8.rc1
- Bug 518890 - setup-ds-admin.pl - improve hostname validation
- Bug 681015 - RFE: allow fine grained password policy duration attributes in
- days, hours, minutes, as well
- Bug 514190 - setup-ds-admin.pl --debug does not log to file
- Bug 680555 - ns-slapd segfaults if I have more than 100 DBs
- Bug 681345 - setup-ds.pl should set SuiteSpotGroup automatically
- Bug 674852 - crash in ldap-agent when using OpenLDAP
- Bug 679978 - modifying attr value crashes the server, which is supposed to
- be indexed as substring type, but has octetstring syntax
- Bug 676655 - winsync stops working after server restart
- Bug 677705 - ds-logpipe.py script is failing to validate "-s" and
- "--serverpid" options with "-t".
- Bug 625424 - repl-monitor.pl doesn't work in hub node
* Mon Feb 28 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.5.a3
- Bug 676598 - 389-ds-base multilib: file conflicts
- split off libs into a separate -libs package
* Thu Feb 24 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.4.a3
- do not create /var/run/dirsrv - setup will create it instead
- remove the fedora-ds initscript upgrade stuff - we do not support that anymore
- convert the remaining lua stuff to plain old shell script
* Wed Feb 9 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.3.a3
- 1.2.8.a3 release - git tag 389-ds-base-1.2.8.a3
- Bug 675320 - empty modify operation with repl on or lastmod off will crash server
- Bug 675265 - preventryusn gets added to entries on a failed delete
- Bug 677774 - added support for tmpfiles.d
- Bug 666076 - dirsrv crash (1.2.7.5) with multiple simple paged result search
es
- Bug 672468 - Don't use empty path elements in LD_LIBRARY_PATH
- Bug 671199 - Don't allow other to write to rundir
- Bug 678646 - Ignore tombstone operations in managed entry plug-in
- Bug 676053 - export task followed by import task causes cache assertion
- Bug 677440 - clean up compiler warnings in 389-ds-base 1.2.8
- Bug 675113 - ns-slapd core dump in windows_tot_run if oneway sync is used
- Bug 676689 - crash while adding a new user to be synced to windows
- Bug 604881 - admin server log files have incorrect permissions/ownerships
- Bug 668385 - DS pipe log script is executed as many times as the dirsrv serv
ice is restarted
- Bug 675853 - dirsrv crash segfault in need_new_pw()
* Thu Feb 3 2011 Rich Megginson <rmeggins(a)redhat.com> - 1.2.8-0.2.a2
- 1.2.8.a2 release - git tag 389-ds-base-1.2.8.a2
- Bug 674430 - Improve error messages for attribute uniqueness
- Bug 616213 - insufficient stack size for HP-UX on PA-RISC
- Bug 615052 - intrinsics and 64-bit atomics code fails to compile
- on PA-RISC
- Bug 151705 - Need to update Console Cipher Preferences with new ciphers
- Bug 668862 - init scripts return wrong error code
- Bug 670616 - Allow SSF to be set for local (ldapi) connections
- Bug 667935 - DS pipe log script's logregex.py plugin is not redirecting the
- log output to the text file
- Bug 668619 - slapd stops responding
- Bug 624547 - attrcrypt should query the given slot/token for
- supported ciphers
- Bug 646381 - Faulty password for nsmultiplexorcredentials does not give any
- error message in logs
* Fri Jan 21 2011 Nathan Kinder <nkinder(a)redhat.com> - 1.2.8-0.1.a1
- 1.2.8-0.1.a1 release - git tag 389-ds-base-1.2.8.a1
- many bug fixes
--------------------------------------------------------------------------------
================================================================================
drupal6-login_destination-2.12-1.el5 (FEDORA-EPEL-2011-3004)
Customize login landing page in Drupal 6
--------------------------------------------------------------------------------
================================================================================
drupal7-7.0-4.el5 (FEDORA-EPEL-2011-2982)
An open-source content-management platform
--------------------------------------------------------------------------------
Update Information:
New package, most recent Drupal release, parallel installable with existing drupal and
drupal6 packages.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #679820 - Review Request: drupal7 - An open-source content-management
platform
https://bugzilla.redhat.com/show_bug.cgi?id=679820
--------------------------------------------------------------------------------
================================================================================
erlang-mochiweb-1.4.1-5.el5 (FEDORA-EPEL-2011-2985)
An Erlang library for building lightweight HTTP servers
--------------------------------------------------------------------------------
Update Information:
* Don't remove test-file
--------------------------------------------------------------------------------
ChangeLog:
* Wed Apr 6 2011 Peter Lemenkov <lemenkov(a)gmail.com> - 1.4.1-5
- Don't remove test-file (rhbz #675699)
* Tue Feb 8 2011 Fedora Release Engineering <rel-eng(a)lists.fedoraproject.org> -
1.4.1-4
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Mon Nov 22 2010 Peter Lemenkov <lemenkov(a)gmail.com> - 1.4.1-3
- Added erlang-xmerl as BuildRequires
* Mon Nov 22 2010 Peter Lemenkov <lemenkov(a)gmail.com> - 1.4.1-2
- Added accidentally removed dependency required for %check
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #675699 - One or more modules listed in mochiweb.app are not present in
ebin/*.beam
https://bugzilla.redhat.com/show_bug.cgi?id=675699
--------------------------------------------------------------------------------
================================================================================
fpdns-0.9.3-1.el5 (FEDORA-EPEL-2011-2992)
Fingerprint DNS servers
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #672418 - Review Request: fpdns - Fingerprint DNS
https://bugzilla.redhat.com/show_bug.cgi?id=672418
--------------------------------------------------------------------------------
================================================================================
imapsync-1.404-3.el5 (FEDORA-EPEL-2011-2918)
Tool to migrate email between IMAP servers
--------------------------------------------------------------------------------
Update Information:
This module provides methods to use NTLM authentication. It can be used as an
authenticate method with the Mail::IMAPClient module to perform the challenge/response
mechanism for NTLM connections or it can be used on its own for NTLM authentication with
other protocols (eg. HTTP).
--------------------------------------------------------------------------------
ChangeLog:
* Sat Apr 2 2011 Nick Bebout <nb(a)fedoraproject.org> - 1.404-3
- Add dependency on Authen::NTLM
--------------------------------------------------------------------------------
================================================================================
n2n-2.0.1-3.el5 (FEDORA-EPEL-2011-2987)
A layer-two peer-to-peer virtual private network
--------------------------------------------------------------------------------
Update Information:
n2n is a layer-two peer-to-peer virtual private network (VPN) which allows
users to exploit features typical of P2P applications at network instead of
application level.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #691027 - Review Request: n2n - A layer-two peer-to-peer virtual private
network
https://bugzilla.redhat.com/show_bug.cgi?id=691027
--------------------------------------------------------------------------------
================================================================================
ngrep-1.45-8.1.el5 (FEDORA-EPEL-2011-2998)
Network layer grep tool
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #166481 - Review Request: ngrep - network grep
https://bugzilla.redhat.com/show_bug.cgi?id=166481
--------------------------------------------------------------------------------
================================================================================
perl-NTLM-1.05-3.el5 (FEDORA-EPEL-2011-2918)
NTLM Perl module
--------------------------------------------------------------------------------
Update Information:
This module provides methods to use NTLM authentication. It can be used as an
authenticate method with the Mail::IMAPClient module to perform the challenge/response
mechanism for NTLM connections or it can be used on its own for NTLM authentication with
other protocols (eg. HTTP).
--------------------------------------------------------------------------------
================================================================================
python-feedparser-5.0.1-1.el5 (FEDORA-EPEL-2011-3000)
Parse RSS and Atom feeds in Python
--------------------------------------------------------------------------------
Update Information:
Current release: 5.0.1 - February 20, 2011
* Fix issue 91 (invalid text in XML declaration causes sanitizer to crash)
* Fix issue 254 (sanitization can be bypassed by malformed XML comments)
* Fix issue 255 (sanitizer doesn't strip unsafe URI schemes)
Previous release: 5.0 - January 25, 2011
* Improved MathML support
* Support microformats (rel-tag, rel-enclosure, xfn, hcard)
* Support IRIs
* Allow safe CSS through sanitization
* Allow safe HTML5 through sanitization
* Support SVG
* Support inline XML entity declarations
* Support unescaped quotes and angle brackets in attributes
* Support additional date formats
* Added the request_headers argument to parse()
* Added the response_headers argument to parse()
* Support multiple entry, feed, and source authors
* Officially make Python 2.4 the earliest supported version
* Support Python 3
* Bug fixes, bug fixes, bug fixes
--------------------------------------------------------------------------------
ChangeLog:
* Tue Apr 5 2011 Luke Macken <lmacken(a)redhat.com> - 5.0.1-1
- Latest upstream release
- Remove feedparser_utf8_decoding.patch
- Remove democracynow_feedparser_fix.patch
- Run the test suite
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #684877 - CVE-2009-5065 CVE-2011-1156 CVE-2011-1157 CVE-2011-1158
python-feedparser: multiple flaws corrected in version 5.1
https://bugzilla.redhat.com/show_bug.cgi?id=684877
--------------------------------------------------------------------------------
================================================================================
tinyxml-2.6.1-2.el5 (FEDORA-EPEL-2011-2990)
A simple, small, C++ XML parser
--------------------------------------------------------------------------------
Update Information:
A simple, small, C++ XML parser
TinyXML is a simple, small, C++ XML parser that can be easily integrating into other
programs. Have you ever found yourself writing a text file parser every time you needed to
save human readable data or serialize objects?
TinyXML solves the text I/O file once and for all.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #407571 - Review Request: tinyxml - A simple, small, C++ XML parser
https://bugzilla.redhat.com/show_bug.cgi?id=407571
--------------------------------------------------------------------------------
================================================================================
zarafa-6.40.7-1.el5 (FEDORA-EPEL-2011-3003)
Open Source Edition of the Zarafa Collaboration Platform
--------------------------------------------------------------------------------
Update Information:
Changelog 6.40.6 final [26119]
==============================
Backend:
- Feature #6947: Implement a Security-log.
- Feature #7131: Allow search_base to be empty, so AD global catalog is supported.
- Fix #7308: Extend logrotate script with audit logging option.
- Fix #7283: 6.40.7 packages do not install correctly.
- Fix #7224: Rename zarafaexchangeredirector.msi to zarafabesconnector.msi.
- Fix #6503: spooler can deadlock.
- Fix #6771: No error for missing propmap.
- Fix #7128: Zarafa-server segfault after ldap was down.
- Fix #7169: Memory usage is too high.
- Fix #7173: username length check gateway too agressive.
- Fix #7202: Purge softdelete still fails at some customers after 6.40.5 update.
- Fix #7215: Archiver will stop completely when an specific user doesn't have a
store.
- Fix #7221: zarafa-admin gives error: Unable to list users, object not found.
- Fix #7236: Cannot create a user with umlauts.
Webaccess:
- Fix #5999: Save draft in outlook with a incorrect email address. open draft in
WebAccess will give error.
- Fix #7247: An emailaddress with & is not allowed by webaccess.
- Fix #6837: ReplyAll to mail with attachments, will include original attachments again.
- Fix #7087: Make column order in WebAccess addressbook different, so it's more user
friendly.
- Fix #7256: Adding groups in multi user calendar doesn't work at all.
--------------------------------------------------------------------------------
ChangeLog:
* Wed Apr 6 2011 Robert Scheck <robert(a)fedoraproject.org> 6.40.7-1
- Upgrade to 6.40.7
* Thu Mar 24 2011 Robert Scheck <robert(a)fedoraproject.org> 6.40.6-2
- Rebuilt for mysql 5.5.10 (soname bump in libmysqlclient)
--------------------------------------------------------------------------------