[SECURITY] Fedora EPEL 6 Update: asterisk-1.8.12.2-1.el6
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-6012
2012-05-31 00:33:18
--------------------------------------------------------------------------------
Name : asterisk
Product : Fedora EPEL 6
Version : 1.8.12.2
Release : 1.el6
URL : http://www.asterisk.org/
Summary : The Open Source PBX
Description :
Asterisk is a complete PBX in software. It runs on Linux and provides
all of the features you would expect from a PBX and more. Asterisk
does voice over IP in three protocols, and can interoperate with
almost all standards-based telephony equipment using relatively
inexpensive hardware.
--------------------------------------------------------------------------------
Update Information:
The Asterisk Development Team has announced the release of Asterisk 1.8.12.2.
This release is available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk
The release of Asterisk 1.8.12.2 resolves an issue reported by the
community and would have not been possible without your participation.
Thank you!
The following is the issue resolved in this release:
* --- Resolve crash in subscribing for MWI notifications
(Closes issue ASTERISK-19827. Reported by B. R)
For a full list of changes in this release, please see the ChangeLog:
http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.8.12.2
The Asterisk Development Team has announced security releases for Certified
Asterisk 1.8.11 and Asterisk 1.8 and 10. The available security releases are
released as versions 1.8.11-cert2, 1.8.12.1, and 10.4.1.
These releases are available for immediate download at
http://downloads.asterisk.org/pub/telephony/asterisk/releases
The release of Asterisk 1.8.11-cert2, 1.8.12.1, and 10.4.1 resolve the following
two issues:
* A remotely exploitable crash vulnerability exists in the IAX2 channel
driver if an established call is placed on hold without a suggested music
class. Asterisk will attempt to use an invalid pointer to the music
on hold class name, potentially causing a crash.
* A remotely exploitable crash vulnerability was found in the Skinny (SCCP)
Channel driver. When an SCCP client closes its connection to the server,
a pointer in a structure is set to NULL. If the client was not in the
on-hook state at the time the connection was closed, this pointer is later
dereferenced. This allows remote authenticated connections the ability to
cause a crash in the server, denying services to legitimate users.
These issues and their resolution are described in the security advisories.
For more information about the details of these vulnerabilities, please read
security advisories AST-2012-007 and AST-2012-008, which were released at the
same time as this announcement.
For a full list of changes in the current releases, please see the ChangeLogs:
http://downloads.asterisk.org/pub/telephony/certified-asterisk/releases/C...
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1...
http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1...
The security advisories are available at:
* http://downloads.asterisk.org/pub/security/AST-2012-007.pdf
* http://downloads.asterisk.org/pub/security/AST-2012-008.pdf
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #826474 - CVE-2012-2947 asterisk: Remote crash in IAX2 channel driver (AST-2012-007)
https://bugzilla.redhat.com/show_bug.cgi?id=826474
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update asterisk' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 5 Update: mcollective-2.0.0-3.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-5950
2012-05-22 15:03:51
--------------------------------------------------------------------------------
Name : mcollective
Product : Fedora EPEL 5
Version : 2.0.0
Release : 3.el5
URL : http://docs.puppetlabs.com/mcollective/
Summary : A framework to build server orchestration or parallel job execution systems
Description :
The Marionette Collective is a framework to build server orchestration
or parallel job execution systems.
--------------------------------------------------------------------------------
Update Information:
Drops lsb requirement from SysV init files.
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update mcollective' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 6 Update: gridsite-1.7.19-1.el6
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-5601
2012-04-17 23:09:32
--------------------------------------------------------------------------------
Name : gridsite
Product : Fedora EPEL 6
Version : 1.7.19
Release : 1.el6
URL : http://www.gridsite.org
Summary : Grid Security for the Web, Web platforms for Grids
Description :
GridSite was originally a web application developed for managing and formatting
the content of the http://www.gridpp.ac.uk/ website. Over the past years it
has grown into a set of extensions to the Apache web server and a toolkit for
Grid credentials, GACL access control lists and HTTP(S) protocol operations.
This package gridsite contains apache httpd modules for enabling
mod_gridsite.
--------------------------------------------------------------------------------
Update Information:
Gridsite update 1.7.19.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #803062 - Missing Requires: httpd-mmn
https://bugzilla.redhat.com/show_bug.cgi?id=803062
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update gridsite' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 5 Update: lcg-infosites-3.1.0-3.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-5876
2012-05-15 01:31:54
--------------------------------------------------------------------------------
Name : lcg-infosites
Product : Fedora EPEL 5
Version : 3.1.0
Release : 3.el5
URL : http://svnweb.cern.ch/trac/gridinfo/wiki
Summary : Command line tool for the WLCG information system
Description :
lcg-infosites is a simple command line tool in Perl for
the WLCG information system
--------------------------------------------------------------------------------
Update Information:
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #814719 - Review Request: lcg-infosites - Command line tool in Perl for the LCG information system
https://bugzilla.redhat.com/show_bug.cgi?id=814719
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update lcg-infosites' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 6 Update: lcg-infosites-3.1.0-3.el6
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-5869
2012-05-15 01:31:36
--------------------------------------------------------------------------------
Name : lcg-infosites
Product : Fedora EPEL 6
Version : 3.1.0
Release : 3.el6
URL : http://svnweb.cern.ch/trac/gridinfo/wiki
Summary : Command line tool for the WLCG information system
Description :
lcg-infosites is a simple command line tool in Perl for
the WLCG information system
--------------------------------------------------------------------------------
Update Information:
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
Command line tool in Perl for the WLCG information system
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #814719 - Review Request: lcg-infosites - Command line tool in Perl for the LCG information system
https://bugzilla.redhat.com/show_bug.cgi?id=814719
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update lcg-infosites' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 5 Update: gridsite-1.7.19-1.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-5595
2012-04-17 23:09:16
--------------------------------------------------------------------------------
Name : gridsite
Product : Fedora EPEL 5
Version : 1.7.19
Release : 1.el5
URL : http://www.gridsite.org
Summary : Grid Security for the Web, Web platforms for Grids
Description :
GridSite was originally a web application developed for managing and formatting
the content of the http://www.gridpp.ac.uk/ website. Over the past years it
has grown into a set of extensions to the Apache web server and a toolkit for
Grid credentials, GACL access control lists and HTTP(S) protocol operations.
This package gridsite contains apache httpd modules for enabling
mod_gridsite.
--------------------------------------------------------------------------------
Update Information:
Gridsite update 1.7.19.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #803062 - Missing Requires: httpd-mmn
https://bugzilla.redhat.com/show_bug.cgi?id=803062
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update gridsite' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 6 Update: mcollective-2.0.0-3.el6
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-5948
2012-05-22 15:03:45
--------------------------------------------------------------------------------
Name : mcollective
Product : Fedora EPEL 6
Version : 2.0.0
Release : 3.el6
URL : http://docs.puppetlabs.com/mcollective/
Summary : A framework to build server orchestration or parallel job execution systems
Description :
The Marionette Collective is a framework to build server orchestration
or parallel job execution systems.
--------------------------------------------------------------------------------
Update Information:
Drops lsb requirement from SysV init files.
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update mcollective' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 6 Update: Pound-2.6-2.el6
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-6001
2012-05-31 00:32:47
--------------------------------------------------------------------------------
Name : Pound
Product : Fedora EPEL 6
Version : 2.6
Release : 2.el6
URL : http://www.apsis.ch/pound
Summary : Reverse proxy and load balancer
Description :
The Pound program is a reverse proxy, load balancer and
HTTPS front-end for Web server(s). Pound was developed
to enable distributing the load among several Web-servers
and to allow for a convenient SSL wrapper for those Web
servers that do not offer it natively. Pound is distributed
under the GPL - no warranty, it's free to use, copy and
give away
--------------------------------------------------------------------------------
Update Information:
rebuild with new gperftools.
fixes https://bugzilla.redhat.com/show_bug.cgi?id=795501
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #795501 - Pound package has broken dependencies
https://bugzilla.redhat.com/show_bug.cgi?id=795501
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update Pound' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 5 Update: Django-south-0.7.5-1.el5
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-6030
2012-06-02 01:51:32
--------------------------------------------------------------------------------
Name : Django-south
Product : Fedora EPEL 5
Version : 0.7.5
Release : 1.el5
URL : http://south.aeracode.org
Summary : Intelligent schema migrations for Django apps
Description :
South brings migrations to Django applications. Its main objectives are to
provide a simple, stable and database-independent migration layer to prevent
all the hassle schema changes over time bring to your Django applications.
--------------------------------------------------------------------------------
Update Information:
Update to new upstream
version.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #826802 - New Upstream Version fixes Django 1.4 issues
https://bugzilla.redhat.com/show_bug.cgi?id=826802
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update Django-south' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months
Fedora EPEL 6 Update: irclog2html-2.10.0-4.el6
by updates@fedoraproject.org
--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-6000
2012-05-31 00:32:44
--------------------------------------------------------------------------------
Name : irclog2html
Product : Fedora EPEL 6
Version : 2.10.0
Release : 4.el6
URL : http://mg.pov.lt/irclog2html/
Summary : Script to convert IRC logs to HTML and other formats
Description :
irclog2html is a nice IRC log parser and colorizer that will do the most common
things necessary to make an IRC log readable in a web browser. It can export to
many different HTML formats, and can export MediaWiki pipe-table syntax.
--------------------------------------------------------------------------------
Update Information:
* Mon May 28 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-4
- Missing build added (#821438)
* Mon May 14 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-3 - BR updated
* Mon May 14 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-2 - Install section fixed
* Mon May 14 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-3 - BR updated
* Mon May 14 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-2 - Install section fixed
* Mon May 14 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-3 - BR updated
* Mon May 14 2012 Fabian Affolter <mail(a)fabian-affolter.ch> - 2.10.0-2 - Install section fixed
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #821438 - irclog2html 2.10.0 is completely non-functional
https://bugzilla.redhat.com/show_bug.cgi?id=821438
--------------------------------------------------------------------------------
This update can be installed with the "yum" update programs. Use
su -c 'yum update irclog2html' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora EPEL GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
11 years, 11 months