[SECURITY] Fedora EPEL 4 Update: lighttpd-1.4.26-2.el4
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2694
2010-04-29 15:57:01
--------------------------------------------------------------------------------
Name : lighttpd
Product : Fedora EPEL 4
Version : 1.4.26
Release : 2.el4
URL : http://www.lighttpd.net/
Summary : Lightning fast webserver with light system requirements
Description :
Secure, fast, compliant and very flexible web-server which has been optimized
for high-performance environments. It has a very low memory footprint compared
to other webservers and takes care of cpu-load. Its advanced feature-set
(FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make
it the perfect webserver-software for every server that is suffering load
problems.
Available rpmbuild rebuild options :
--with : gamin webdavprops webdavlocks memcache
--without : ldap gdbm lua (cml)
--------------------------------------------------------------------------------
Update Information:
Update lighttpd to the latest version of the 1.4 branch, with the spawn-fcgi
program split out for the first time on EL. This fixes CVE-2010-0295 and also
includes a fix for upstream bug #2157 where SSL stopped working with RHEL 5.4.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #561340 - CVE-2010-0295 lighttpd: Remote DoS (excessive memory use) by handling specially-crafted HTTP request
https://bugzilla.redhat.com/show_bug.cgi?id=561340
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update lighttpd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
[SECURITY] Fedora EPEL 4 Update: spawn-fcgi-1.6.2-1.el4.1
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2694
2010-04-29 15:57:01
--------------------------------------------------------------------------------
Name : spawn-fcgi
Product : Fedora EPEL 4
Version : 1.6.2
Release : 1.el4.1
URL : http://redmine.lighttpd.net/projects/spawn-fcgi/
Summary : Simple program for spawning FastCGI processes
Description :
This package contains the spawn-fcgi program used for spawning FastCGI
processes, which can be local or remote.
--------------------------------------------------------------------------------
Update Information:
Update lighttpd to the latest version of the 1.4 branch, with the spawn-fcgi
program split out for the first time on EL. This fixes CVE-2010-0295 and also
includes a fix for upstream bug #2157 where SSL stopped working with RHEL 5.4.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #561340 - CVE-2010-0295 lighttpd: Remote DoS (excessive memory use) by handling specially-crafted HTTP request
https://bugzilla.redhat.com/show_bug.cgi?id=561340
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update spawn-fcgi' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
Fedora EPEL 4 Update: bitlbee-1.2.6a-3.el4
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2653
2010-04-26 23:05:22
--------------------------------------------------------------------------------
Name : bitlbee
Product : Fedora EPEL 4
Version : 1.2.6a
Release : 3.el4
URL : http://www.bitlbee.org/
Summary : IRC to other chat networks gateway
Description :
Bitlbee is an IRC to other chat networks gateway. Bitlbee can be used as
an IRC server which forwards everything you say to people on other chat
networks like ICQ/AIM, MSN, XMPP/Jabber (including Google Talk), Yahoo or
Twitter!
--------------------------------------------------------------------------------
Update Information:
- Fixed a typo that renders the Twitter groupchat mode unusable. A last- minute
change that came a few minutes late. - Native (very basic) support for Twitter,
implemented by Geert Mulders. Currently supported are posting tweets, reading
the ones of people you follow, and sending (not yet receiving!) direct messages.
- Fixed format of status messages in /WHOIS to improve IRC client compatibility.
- Show timestamps of offline messages/channel backlogs. - Allow saving MSN
display names locally since sometimes this stuff breaks server-side. (Use the
local_display_name per-account setting.) - Suppress empty "Headline:" messages
for certain new XMPP broadcast messages. - Better handling of XMPP contacts
with multiple resources on-line. Default behaviour now is to write to wherever
the last message came from, or to the bare JID (usually becomes a broadcast) if
there wasn't any recent msg. - Added a switchboard_keepalives setting which
should solve some issues with talking to offline MSN contacts. (Although full
support for offline messages is not ready yet!) - The usual misc. bug fixes.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #584071 - There is now pretty cool version 1.2.6a ... please update
https://bugzilla.redhat.com/show_bug.cgi?id=584071
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update bitlbee' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
Fedora EPEL 5 Update: R-2.11.0-1.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2673
2010-04-26 23:06:19
--------------------------------------------------------------------------------
Name : R
Product : Fedora EPEL 5
Version : 2.11.0
Release : 1.el5
URL : http://www.r-project.org
Summary : A language for data analysis and graphics
Description :
This is a metapackage that provides both core R userspace and
all R development components.
R is a language and environment for statistical computing and graphics.
R is similar to the award-winning S system, which was developed at
Bell Laboratories by John Chambers et al. It provides a wide
variety of statistical and graphical techniques (linear and
nonlinear modelling, statistical tests, time series analysis,
classification, clustering, ...).
R is designed as a true computer language with control-flow
constructions for iteration and alternation, and it allows users to
add additional functionality by defining new functions. For
computationally intensive tasks, C, C++ and Fortran code can be linked
and called at run time.
--------------------------------------------------------------------------------
Update Information:
Update to R 2.11.0. Many bugs fixed, changes made. For full description, see:
http://cran.r-project.org/src/base/NEWS
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update R' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
[SECURITY] Fedora EPEL 5 Update: spawn-fcgi-1.6.2-1.el5.1
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2696
2010-04-29 15:57:08
--------------------------------------------------------------------------------
Name : spawn-fcgi
Product : Fedora EPEL 5
Version : 1.6.2
Release : 1.el5.1
URL : http://redmine.lighttpd.net/projects/spawn-fcgi/
Summary : Simple program for spawning FastCGI processes
Description :
This package contains the spawn-fcgi program used for spawning FastCGI
processes, which can be local or remote.
--------------------------------------------------------------------------------
Update Information:
Update lighttpd to the latest version of the 1.4 branch, with the spawn-fcgi
program split out for the first time on EL. This fixes CVE-2010-0295 and also
includes a fix for upstream bug #2157 where SSL stopped working with RHEL 5.4.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #561340 - CVE-2010-0295 lighttpd: Remote DoS (excessive memory use) by handling specially-crafted HTTP request
https://bugzilla.redhat.com/show_bug.cgi?id=561340
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update spawn-fcgi' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
[SECURITY] Fedora EPEL 5 Update: lighttpd-1.4.26-2.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2696
2010-04-29 15:57:08
--------------------------------------------------------------------------------
Name : lighttpd
Product : Fedora EPEL 5
Version : 1.4.26
Release : 2.el5
URL : http://www.lighttpd.net/
Summary : Lightning fast webserver with light system requirements
Description :
Secure, fast, compliant and very flexible web-server which has been optimized
for high-performance environments. It has a very low memory footprint compared
to other webservers and takes care of cpu-load. Its advanced feature-set
(FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make
it the perfect webserver-software for every server that is suffering load
problems.
Available rpmbuild rebuild options :
--with : gamin webdavprops webdavlocks memcache
--without : ldap gdbm lua (cml)
--------------------------------------------------------------------------------
Update Information:
Update lighttpd to the latest version of the 1.4 branch, with the spawn-fcgi
program split out for the first time on EL. This fixes CVE-2010-0295 and also
includes a fix for upstream bug #2157 where SSL stopped working with RHEL 5.4.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #561340 - CVE-2010-0295 lighttpd: Remote DoS (excessive memory use) by handling specially-crafted HTTP request
https://bugzilla.redhat.com/show_bug.cgi?id=561340
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update lighttpd' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
Fedora EPEL 5 Update: bitlbee-1.2.6a-3.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2664
2010-04-26 23:05:57
--------------------------------------------------------------------------------
Name : bitlbee
Product : Fedora EPEL 5
Version : 1.2.6a
Release : 3.el5
URL : http://www.bitlbee.org/
Summary : IRC to other chat networks gateway
Description :
Bitlbee is an IRC to other chat networks gateway. Bitlbee can be used as
an IRC server which forwards everything you say to people on other chat
networks like ICQ/AIM, MSN, XMPP/Jabber (including Google Talk), Yahoo or
Twitter!
--------------------------------------------------------------------------------
Update Information:
- Fixed a typo that renders the Twitter groupchat mode unusable. A last- minute
change that came a few minutes late. - Native (very basic) support for Twitter,
implemented by Geert Mulders. Currently supported are posting tweets, reading
the ones of people you follow, and sending (not yet receiving!) direct messages.
- Fixed format of status messages in /WHOIS to improve IRC client compatibility.
- Show timestamps of offline messages/channel backlogs. - Allow saving MSN
display names locally since sometimes this stuff breaks server-side. (Use the
local_display_name per-account setting.) - Suppress empty "Headline:" messages
for certain new XMPP broadcast messages. - Better handling of XMPP contacts
with multiple resources on-line. Default behaviour now is to write to wherever
the last message came from, or to the bare JID (usually becomes a broadcast) if
there wasn't any recent msg. - Added a switchboard_keepalives setting which
should solve some issues with talking to offline MSN contacts. (Although full
support for offline messages is not ready yet!) - The usual misc. bug fixes.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #584071 - There is now pretty cool version 1.2.6a ... please update
https://bugzilla.redhat.com/show_bug.cgi?id=584071
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update bitlbee' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 11 months
Fedora EPEL 4 Update: mktorrent-1.0-4.el4
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2670
2010-04-26 23:06:11
--------------------------------------------------------------------------------
Name : mktorrent
Product : Fedora EPEL 4
Version : 1.0
Release : 4.el4
URL : http://mktorrent.sourceforge.net/
Summary : Command line utility to create BitTorrent metainfo files
Description :
Command line utility to create BitTorrent metainfo files.
See --help option for mktorrent command for details on usage.
--------------------------------------------------------------------------------
Update Information:
Command line utility to create BitTorrent metainfo files
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #580849 - Review Request: mktorrent - Command line utility to create BitTorrent metainfo files
https://bugzilla.redhat.com/show_bug.cgi?id=580849
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update mktorrent' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 12 months
[SECURITY] Fedora EPEL 5 Update: couchdb-0.10.2-1.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2771
2010-05-10 19:20:50
--------------------------------------------------------------------------------
Name : couchdb
Product : Fedora EPEL 5
Version : 0.10.2
Release : 1.el5
URL : http://couchdb.apache.org/
Summary : A document database server, accessible via a RESTful JSON API
Description :
Apache CouchDB is a distributed, fault-tolerant and schema-free
document-oriented database accessible via a RESTful HTTP/JSON API.
Among other features, it provides robust, incremental replication
with bi-directional conflict detection and resolution, and is
queryable and indexable using a table-oriented view engine with
JavaScript acting as the default view definition language.
--------------------------------------------------------------------------------
Update Information:
Ver. 0.10.2 (bugfix release).
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #578572 - CVE-2010-0009 Apache CouchDB v0.10.0 prone to timing attacks vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=578572
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update couchdb' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 12 months
Fedora EPEL 5 Update: python-tw-jquery-0.9.9-1.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2010-2655
2010-04-26 23:05:26
--------------------------------------------------------------------------------
Name : python-tw-jquery
Product : Fedora EPEL 5
Version : 0.9.9
Release : 1.el5
URL : http://toscawidgets.org
Summary : ToscaWidgets wrapping for jQuery
Description :
ToscaWidgets wrapping for jQuery
--------------------------------------------------------------------------------
Update Information:
This is the latest upstream release of the tw.jquery modules. Changes include:
* jQuery 1.4.2 (http://blog.jquery.com/2010/02/19/jquery-142-released) * jQuery
UI 1.8 (http://blog.jqueryui.com/2010/03/jquery-ui-18) * Flot 0.6
(http://flot.googlecode.com/svn/trunk/NEWS.txt)
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update python-tw-jquery' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
13 years, 12 months