The following Fedora 25 Security updates need testing:
Age URL
143
https://bodhi.fedoraproject.org/updates/FEDORA-2016-d79ba708cb exim-4.87.1-1.fc25
42
https://bodhi.fedoraproject.org/updates/FEDORA-2017-e2d17af41e
python-XStatic-jquery-ui-1.12.0.1-4.fc25
22
https://bodhi.fedoraproject.org/updates/FEDORA-2017-f85c37ae3d
squirrelmail-1.4.22-19.fc25
15
https://bodhi.fedoraproject.org/updates/FEDORA-2017-8d625a8d2b lynis-2.5.0-1.fc25
7
https://bodhi.fedoraproject.org/updates/FEDORA-2017-cc606f1001
chicken-4.12.0-2.fc25
4
https://bodhi.fedoraproject.org/updates/FEDORA-2017-410749716d
FlightGear-2016.3.1-4.fc25
3
https://bodhi.fedoraproject.org/updates/FEDORA-2017-40a6d19c7b
FlightCrew-0.9.1-7.fc25
2
https://bodhi.fedoraproject.org/updates/FEDORA-2017-466d902289
kernel-4.10.16-200.fc25
2
https://bodhi.fedoraproject.org/updates/FEDORA-2017-dc7ce3b314
chromium-58.0.3029.110-2.fc25
chromium-native_client-58.0.3029.81-1.20170421gitc948e9b.fc25
2
https://bodhi.fedoraproject.org/updates/FEDORA-2017-d968f5a95f
wordpress-4.7.5-1.fc25
1
https://bodhi.fedoraproject.org/updates/FEDORA-2017-0e08170fd3
libvncserver-0.9.11-2.fc25.1
1
https://bodhi.fedoraproject.org/updates/FEDORA-2017-4cc8d795e0
moodle-3.1.6-1.fc25
0
https://bodhi.fedoraproject.org/updates/FEDORA-2017-5135c91b36 mupdf-1.10a-7.fc25
The following Fedora 25 Critical Path updates have yet to be approved:
Age URL
14
https://bodhi.fedoraproject.org/updates/FEDORA-2017-9ecf41f097
python-productmd-1.7-1.fc25
11
https://bodhi.fedoraproject.org/updates/FEDORA-2017-6d5aa85fd7
livecd-tools-24.4-1.fc25
7
https://bodhi.fedoraproject.org/updates/FEDORA-2017-e504c7cb8f
nss-3.30.2-1.1.fc25
7
https://bodhi.fedoraproject.org/updates/FEDORA-2017-116fdd792f
pungi-4.1.15-1.fc25
4
https://bodhi.fedoraproject.org/updates/FEDORA-2017-6a5530c175
gtk3-3.22.15-1.fc25
3
https://bodhi.fedoraproject.org/updates/FEDORA-2017-5a57c23040
glusterfs-3.10.2-1.fc25
2
https://bodhi.fedoraproject.org/updates/FEDORA-2017-b8d8e95f8a
tigervnc-1.8.0-1.fc25
2
https://bodhi.fedoraproject.org/updates/FEDORA-2017-f18713a47e
storaged-2.6.2-4.fc25
2
https://bodhi.fedoraproject.org/updates/FEDORA-2017-466d902289
kernel-4.10.16-200.fc25
1
https://bodhi.fedoraproject.org/updates/FEDORA-2017-9e64a52f34
gssproxy-0.7.0-7.fc25
1
https://bodhi.fedoraproject.org/updates/FEDORA-2017-9f5895b99c acl-2.2.52-12.fc25
0
https://bodhi.fedoraproject.org/updates/FEDORA-2017-0dfed2f160 vim-8.0.600-1.fc25
0
https://bodhi.fedoraproject.org/updates/FEDORA-2017-942bb8c05f
mutter-3.22.4-3.fc25
The following builds have been pushed to Fedora 25 updates-testing
NetworkManager-l2tp-1.2.6-1.fc25
container-selinux-2.14-1.fc25
engrampa-1.16.1-1.fc25
keepassxc-2.1.4-1.fc25
mediawriter-4.1.0-1.fc25
metamath-0.144-1.fc25
mupdf-1.10a-7.fc25
mutter-3.22.4-3.fc25
mycli-1.10.0-1.fc25
owncloud-9.1.5-1.fc25
pcp-3.11.10-1.fc25
python-futures-3.1.1-1.fc25
python-pydns-2.3.6-7.fc25
recoll-1.23.2-1.fc25
salt-2016.11.5-3.fc25
snapd-2.26.3-1.fc25
snapd-glib-1.12-1.fc25
storhaug-0.13-6.fc25
urlwatch-2.6-4.fc25
vim-8.0.600-1.fc25
youtube-dl-2017.05.18.1-1.fc25
Details about builds:
================================================================================
NetworkManager-l2tp-1.2.6-1.fc25 (FEDORA-2017-588c07d3a7)
NetworkManager VPN plugin for L2TP and L2TP/IPsec
--------------------------------------------------------------------------------
Update Information:
Updated to 1.2.6 release
--------------------------------------------------------------------------------
================================================================================
container-selinux-2.14-1.fc25 (FEDORA-2017-84b98f1717)
SELinux policies for container runtimes
--------------------------------------------------------------------------------
Update Information:
Add missing features like the ability to execute fusefs files if boolean is set.
Fix labeling for CRI-O Projects. Fix issues found in RHEL testing.
--------------------------------------------------------------------------------
================================================================================
engrampa-1.16.1-1.fc25 (FEDORA-2017-112c5e9c28)
MATE Desktop file archiver
--------------------------------------------------------------------------------
Update Information:
- fix rhbz (#1422004)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1422004 - Wrong behavior of Skip button in Replace file dialog
https://bugzilla.redhat.com/show_bug.cgi?id=1422004
--------------------------------------------------------------------------------
================================================================================
keepassxc-2.1.4-1.fc25 (FEDORA-2017-4cfaf64698)
Cross-platform password manager
--------------------------------------------------------------------------------
Update Information:
First release
--------------------------------------------------------------------------------
================================================================================
mediawriter-4.1.0-1.fc25 (FEDORA-2017-dade9f0f49)
Fedora Media Writer
--------------------------------------------------------------------------------
Update Information:
Update to 4.1.0 ---- Update to 4.0.95
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1418898 - The Fedora Media Writer program for Windows (primary download) does
not work on Windows 7 nor 8.1 by default
https://bugzilla.redhat.com/show_bug.cgi?id=1418898
[ 2 ] Bug #1394611 - the latest mediawriter asks for password twice when write the
server media to usb disk
https://bugzilla.redhat.com/show_bug.cgi?id=1394611
[ 3 ] Bug #1413796 - USB stick restore feature uses incorrect type code, macOS wants to
initialize the stick
https://bugzilla.redhat.com/show_bug.cgi?id=1413796
--------------------------------------------------------------------------------
================================================================================
metamath-0.144-1.fc25 (FEDORA-2017-f2cfb21fcc)
Construct mathematics from basic axioms
--------------------------------------------------------------------------------
Update Information:
Changes in version 0.142: - added "#define DATE_BELOW_PROOF" in mmdata.h that
if uncommented, will enable use of the (soon-to-be obsolete) date below the
proof - fixed memory leaks and warnings found by valgrind. - added xxChanged
flags to statement structure so that any part of the source can be changed -
removed /CLEAN qualifier of WRITE SOURCE - automatically put "(Contributed by
?who?..." during SAVE NEW_PROOF or SAVE PROOF when it is missing - more VERIFY
MARKUP checking. Changes in version 0.143: - added SET CONTRIBUTOR - for
missing "(Contributed by..." use date below proof if it exists, otherwise use
today's date, in order to update old .mm files. - fix memory leaks in ERASE
Changes in version 0.144: - Add "(Revised by..." tag for conversion of legacy
.mm's if there is a 2nd date under the proof
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1450652 - metamath-0.143 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1450652
--------------------------------------------------------------------------------
================================================================================
mupdf-1.10a-7.fc25 (FEDORA-2017-5135c91b36)
A lightweight PDF viewer and toolkit
--------------------------------------------------------------------------------
Update Information:
Fix for CVE-2016-8728 CVE-2016-8729 ---- Rebuild with new jbig2dec
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1452545 - CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities
[fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1452545
[ 2 ] Bug #1443933 - CVE-2017-7885 CVE-2017-7975 CVE-2017-7976 mupdf: various flaws
[fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1443933
--------------------------------------------------------------------------------
================================================================================
mutter-3.22.4-3.fc25 (FEDORA-2017-942bb8c05f)
Window and compositing manager based on Clutter
--------------------------------------------------------------------------------
Update Information:
Fix copy+paste of UTF8 strings between X11 and wayland clients
--------------------------------------------------------------------------------
================================================================================
mycli-1.10.0-1.fc25 (FEDORA-2017-c106f3ff7c)
Interactive CLI for MySQL Database with auto-completion and syntax highlighting
--------------------------------------------------------------------------------
Update Information:
Update to latest upstream release mycli 1.10.0.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1433707 - mycli-1.10.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1433707
--------------------------------------------------------------------------------
================================================================================
owncloud-9.1.5-1.fc25 (FEDORA-2017-c062c639a4)
Private file sync and share server
--------------------------------------------------------------------------------
Update Information:
update to 9.1.5
--------------------------------------------------------------------------------
================================================================================
pcp-3.11.10-1.fc25 (FEDORA-2017-6992355779)
System-level performance monitoring and performance management
--------------------------------------------------------------------------------
Update Information:
Update to latest PCP Sources
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1289912 - Python PMAPI command line parsing
https://bugzilla.redhat.com/show_bug.cgi?id=1289912
--------------------------------------------------------------------------------
================================================================================
python-futures-3.1.1-1.fc25 (FEDORA-2017-72193a52c6)
Backport of the concurrent.futures package from Python 3.2
--------------------------------------------------------------------------------
Update Information:
Update to latest upstream release futures 3.1.1.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1442589 - python-futures-3.1.1 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1442589
--------------------------------------------------------------------------------
================================================================================
python-pydns-2.3.6-7.fc25 (FEDORA-2017-95d01e9022)
Python module for DNS (Domain Name Service)
--------------------------------------------------------------------------------
Update Information:
Fix failure to resolve DNS queries (rhbz#1305746)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1305746 - Failure to resolve DNS queries
https://bugzilla.redhat.com/show_bug.cgi?id=1305746
--------------------------------------------------------------------------------
================================================================================
recoll-1.23.2-1.fc25 (FEDORA-2017-d00ced5940)
Desktop full text search tool with Qt GUI
--------------------------------------------------------------------------------
Update Information:
Update latest upstream release recoll 1.23.2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1450929 - recoll-1.23.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1450929
--------------------------------------------------------------------------------
================================================================================
salt-2016.11.5-3.fc25 (FEDORA-2017-e9ffd8c477)
A parallel remote execution system
--------------------------------------------------------------------------------
Update Information:
Add patch for Fix ipv6 nameserver grains #41244 ---- Commented out check for
pycryptodomex on Fedora ---- Use python-crypto on fedora platforms till
pycryptodomex becomes available
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #41244 - None
https://bugzilla.redhat.com/show_bug.cgi?id=41244
--------------------------------------------------------------------------------
================================================================================
snapd-2.26.3-1.fc25 (FEDORA-2017-2e4459fa03)
A transactional software package manager
--------------------------------------------------------------------------------
Update Information:
Update to snapd v2.26.3 and snapd-glib v1.12. Some of the upstream snapd
v2.26.3 software highlights (from the Snappy team): * support tab-completion in
snaps, i.e a snap can ship a bash completion script and it will get exported to
the users shell * new `snap whoami` command * new `snap refresh --time` option
that displays information about refresh settings * new `snap tasks
--last={refresh,install,remove,connect,disconnect,configure,try}` option *
Improve `snap info` output * Improve tab completion for interfaces * Mediate
netlink sockets via seccomp * Go 1.8 fixes * Interface API improvements * new
interfaces: `random`, `network-status`, `online-account-service`, `storage-
framework` * Interface improvements: `browser-support`, `locale-control`, `dbus`
From snapd 2.25: * Improved aliases implementation, details in
https://forum.snapcraft.io/t/improving-the-aliases-implementation/18 * Improved
channels support (tracks), see
https://forum.snapcraft.io/t/channels-2-0-implementation/156 * Per-revision
snapshots of the snap configuration refresh schedule support, see
https://forum.snapcraft.io/t/refresh-schedule-via-core-config/434 * Cross distro
improvements (Xauthority handling, etc.) * Test improvements (more spread tests)
* More fine-grained seccomp support for ioctl and quotactl * Download robustness
improvements (auto retry on hashsum and RST issues) * New `snap tasks` command *
Speedup for device key generation on Pi 2 and Pi 3 * New interfaces: `media-
hub`, `kubernetes-support` * Interface improvements Highlights for snapd-glib
v1.12 since v1.10: * New API: - `snapd_client_install2_async` -
`snapd_client_install2_finish` - `snapd_client_install2_sync` -
`snapd_system_information_get_binaries_directory` -
`snapd_system_information_get_kernel_version` -
`snapd_system_information_get_mount_directory` * Fix calls not working inside
threads. * Fix reference counting error when calling
`snapd_client_get_interfaces` and `snapd_client_create_user`. * Deprecated
API: - `snapd_client_install_async` - `snapd_client_install_finish`
- `snapd_client_install_sync` Packaging specific improvements: * Final
removal of `snapd` will trigger removal of all Snappy content
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1444422 - /var/lib/snapd not removed when removing snapd
https://bugzilla.redhat.com/show_bug.cgi?id=1444422
[ 2 ] Bug #1446605 - snapd-2.25 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1446605
[ 3 ] Bug #1448027 - snapd-glib-1.12 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1448027
[ 4 ] Bug #1450242 - snapd-2.26.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1450242
--------------------------------------------------------------------------------
================================================================================
snapd-glib-1.12-1.fc25 (FEDORA-2017-2e4459fa03)
Library providing a GLib interface to snapd
--------------------------------------------------------------------------------
Update Information:
Update to snapd v2.26.3 and snapd-glib v1.12. Some of the upstream snapd
v2.26.3 software highlights (from the Snappy team): * support tab-completion in
snaps, i.e a snap can ship a bash completion script and it will get exported to
the users shell * new `snap whoami` command * new `snap refresh --time` option
that displays information about refresh settings * new `snap tasks
--last={refresh,install,remove,connect,disconnect,configure,try}` option *
Improve `snap info` output * Improve tab completion for interfaces * Mediate
netlink sockets via seccomp * Go 1.8 fixes * Interface API improvements * new
interfaces: `random`, `network-status`, `online-account-service`, `storage-
framework` * Interface improvements: `browser-support`, `locale-control`, `dbus`
From snapd 2.25: * Improved aliases implementation, details in
https://forum.snapcraft.io/t/improving-the-aliases-implementation/18 * Improved
channels support (tracks), see
https://forum.snapcraft.io/t/channels-2-0-implementation/156 * Per-revision
snapshots of the snap configuration refresh schedule support, see
https://forum.snapcraft.io/t/refresh-schedule-via-core-config/434 * Cross distro
improvements (Xauthority handling, etc.) * Test improvements (more spread tests)
* More fine-grained seccomp support for ioctl and quotactl * Download robustness
improvements (auto retry on hashsum and RST issues) * New `snap tasks` command *
Speedup for device key generation on Pi 2 and Pi 3 * New interfaces: `media-
hub`, `kubernetes-support` * Interface improvements Highlights for snapd-glib
v1.12 since v1.10: * New API: - `snapd_client_install2_async` -
`snapd_client_install2_finish` - `snapd_client_install2_sync` -
`snapd_system_information_get_binaries_directory` -
`snapd_system_information_get_kernel_version` -
`snapd_system_information_get_mount_directory` * Fix calls not working inside
threads. * Fix reference counting error when calling
`snapd_client_get_interfaces` and `snapd_client_create_user`. * Deprecated
API: - `snapd_client_install_async` - `snapd_client_install_finish`
- `snapd_client_install_sync` Packaging specific improvements: * Final
removal of `snapd` will trigger removal of all Snappy content
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1444422 - /var/lib/snapd not removed when removing snapd
https://bugzilla.redhat.com/show_bug.cgi?id=1444422
[ 2 ] Bug #1446605 - snapd-2.25 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1446605
[ 3 ] Bug #1448027 - snapd-glib-1.12 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1448027
[ 4 ] Bug #1450242 - snapd-2.26.3 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1450242
--------------------------------------------------------------------------------
================================================================================
storhaug-0.13-6.fc25 (FEDORA-2017-1b6d719e22)
High-Availability Add-on for NFS-Ganesha and Samba
--------------------------------------------------------------------------------
Update Information:
Requires storhaug.noarch, not storhaug.(x86-64), samba too
--------------------------------------------------------------------------------
================================================================================
urlwatch-2.6-4.fc25 (FEDORA-2017-d20834bda7)
A tool for monitoring webpages for updates
--------------------------------------------------------------------------------
Update Information:
Fix rhbz#1445286
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1445286 - Urlwatch requires python3-minidb, but nothing provides it
https://bugzilla.redhat.com/show_bug.cgi?id=1445286
--------------------------------------------------------------------------------
================================================================================
vim-8.0.600-1.fc25 (FEDORA-2017-0dfed2f160)
The VIM editor
--------------------------------------------------------------------------------
Update Information:
The newest upstream commit.
--------------------------------------------------------------------------------
================================================================================
youtube-dl-2017.05.18.1-1.fc25 (FEDORA-2017-fa2479e084)
A small command-line program to download online videos
--------------------------------------------------------------------------------
Update Information:
Finally fixing
https://github.com/rg3/youtube-dl/issues/13123 which broke
YouTube. ---- 2017.05.14
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1449434 - youtube-dl-2017.05.14 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1449434
[ 2 ] Bug #1441014 - youtube-dl-2017.04.17 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1441014
--------------------------------------------------------------------------------