The following Fedora 28 Security updates need testing:
Age URL
38
https://bodhi.fedoraproject.org/updates/FEDORA-2018-99eed1942f remctl-3.14-1.fc28
34
https://bodhi.fedoraproject.org/updates/FEDORA-2018-d510cfd7eb
jgraphx-3.6.0.0-6.fc28
20
https://bodhi.fedoraproject.org/updates/FEDORA-2018-2c965abb15
dpdk-17.11.2-1.fc28
10
https://bodhi.fedoraproject.org/updates/FEDORA-2018-630ecbb116
love-0.10.2-12.fc28
6
https://bodhi.fedoraproject.org/updates/FEDORA-2018-c75a37ae9b
blktrace-1.2.0-6.fc28
5
https://bodhi.fedoraproject.org/updates/FEDORA-2018-54c29139b3 exiv2-0.26-10.fc28
5
https://bodhi.fedoraproject.org/updates/FEDORA-2018-ed74f27aef
ncurses-6.1-5.20180224.fc28
5
https://bodhi.fedoraproject.org/updates/FEDORA-2018-ab62814cee
nodejs-mixin-deep-1.3.1-1.fc28
The following Fedora 28 Critical Path updates have yet to be approved:
Age URL
12
https://bodhi.fedoraproject.org/updates/FEDORA-2018-78baa27bd0
pungi-4.1.24-1.fc28
8
https://bodhi.fedoraproject.org/updates/FEDORA-2018-35ce81deaf
python-productmd-1.12-1.fc28
6
https://bodhi.fedoraproject.org/updates/FEDORA-2018-93b9a09597
perl-podlators-4.11-1.fc28
6
https://bodhi.fedoraproject.org/updates/FEDORA-2018-87bbd4df6e
pulseaudio-11.1-18.fc28.1
5
https://bodhi.fedoraproject.org/updates/FEDORA-2018-ed74f27aef
ncurses-6.1-5.20180224.fc28
3
https://bodhi.fedoraproject.org/updates/FEDORA-2018-6a4441aeff proj-4.9.3-6.fc28
3
https://bodhi.fedoraproject.org/updates/FEDORA-2018-5acb930c9f
breeze-icon-theme-5.46.0-1.fc28 extra-cmake-modules-5.46.0-1.fc28 kf5-5.46.0-1.fc28
kf5-attica-5.46.0-1.fc28 kf5-baloo-5.46.0-1.fc28 kf5-bluez-qt-5.46.0-1.fc28
kf5-frameworkintegration-5.46.0-1.fc28 kf5-kactivities-5.46.0-1.fc28
kf5-kactivities-stats-5.46.0-1.fc28 kf5-kapidox-5.46.0-1.fc28 kf5-karchive-5.46.0-1.fc28
kf5-kauth-5.46.0-1.fc28 kf5-kbookmarks-5.46.0-1.fc28 kf5-kcmutils-5.46.0-1.fc28
kf5-kcodecs-5.46.0-1.fc28 kf5-kcompletion-5.46.0-1.fc28 kf5-kconfig-5.46.0-1.fc28
kf5-kconfigwidgets-5.46.0-1.fc28 kf5-kcoreaddons-5.46.0-1.fc28 kf5-kcrash-5.46.0-1.fc28
kf5-kdbusaddons-5.46.0-1.fc28 kf5-kdeclarative-5.46.0-1.fc28 kf5-kded-5.46.0-1.fc28
kf5-kdelibs4support-5.46.0-1.fc28 kf5-kdesignerplugin-5.46.0-1.fc28
kf5-kdesu-5.46.0-1.fc28 kf5-kdewebkit-5.46.0-1.fc28 kf5-kdnssd-5.46.0-1.fc28
kf5-kdoctools-5.46.0-1.fc28 kf5-kemoticons-5.46.0-1.fc28 kf5-kfilemetadata-5.46.0-1.fc28
kf5-kglobalaccel-5.46.0-1.fc28 kf5-kguiad
dons-5.46.0-1.fc28 kf5-kholidays-5.46.0-1.fc28 kf5-khtml-5.46.0-1.fc28
kf5-ki18n-5.46.0-1.fc28 kf5-kiconthemes-5.46.0-1.fc28 kf5-kidletime-5.46.0-1.fc28
kf5-kimageformats-5.46.0-1.fc28 kf5-kinit-5.46.0-1.fc28 kf5-kio-5.46.0-2.fc28
kf5-kirigami2-5.46.0-1.fc28 kf5-kitemmodels-5.46.0-1.fc28 kf5-kitemviews-5.46.0-1.fc28
kf5-kjobwidgets-5.46.0-1.fc28 kf5-kjs-5.46.0-1.fc28 kf5-kjsembed-5.46.0-1.fc28
kf5-kmediaplayer-5.46.0-1.fc28 kf5-knewstuff-5.46.0-1.fc28
kf5-knotifications-5.46.0-1.fc28 kf5-knotifyconfig-5.46.0-1.fc28
kf5-kpackage-5.46.0-1.fc28 kf5-kparts-5.46.0-1.fc28 kf5-kpeople-5.46.0-1.fc28
kf5-kplotting-5.46.0-1.fc28 kf5-kpty-5.46.0-1.fc28 kf5-kross-5.46.0-1.fc28
kf5-krunner-5.46.0-1.fc28 kf5-kservice-5.46.0-1.fc28 kf5-ktexteditor-5.46.0-1.fc28
kf5-ktextwidgets-5.46.0-1.fc28 kf5-kunitconversion-5.46.0-1.fc28 kf5-kwallet-5.46.0-1.fc28
kf5-kwayland-5.46.0-1.fc28 kf5-kwidgetsaddons-5.46.0-1.fc28
kf5-kwindowsystem-5.46.0-1.fc28 kf5-kxmlgui-5.46.0-1.fc28 kf5-kxmlrpcclient-5.46.0-1.fc28
kf5-modemmanager-qt-5.46.0-1.fc28 kf5-networkmanager-qt-5.46.0-1.fc28
kf5-plasma-5.46.0-1.fc28 kf5-prison-5.46.0-1.fc28 kf5-purpose-5.46.0-1.fc28
kf5-solid-5.46.0-1.fc28 kf5-sonnet-5.46.0-1.fc28 kf5-syntax-highlighting-5.46.0-1.fc28
kf5-threadweaver-5.46.0-1.fc28 oxygen-icon-theme-5.46.0-1.fc28
qqc2-desktop-style-5.46.0-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-707d1a78ea
libdrm-2.4.92-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-e033fe0d35
userspace-rcu-0.10.1-3.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-137a0296be sddm-0.17.0-3.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-aae2d44488
ghostscript-9.23-4.fc28 libidn-1.34-3.fc28 mcabber-1.1.0-1.fc28.1 pidgin-2.13.0-1.fc28.1
python-slixmpp-1.3.0-5.fc28.1
The following builds have been pushed to Fedora 28 updates-testing
cockpit-168-1.fc28
compose-utils-0.1.19-1.fc28
enchant2-2.2.3-3.fc28
freeipa-4.6.90.pre2-3.fc28
gnome-shell-extension-freon-34-1.fc28
javapackages-tools-5.0.0-14.fc28
libu2f-host-1.1.6-1.fc28
libxcrypt-4.0.1-1.fc28
lollypop-0.9.512-1.fc28
microcode_ctl-2.1-23.fc28
mmapper-2.5.0-2.fc28
nodejs-deep-extend-0.5.1-1.fc28
pam-u2f-1.0.7-1.fc28
python-lightblue-0.1.4-1.fc28
python-zmq-17.0.0-1.fc28
vsftpd-3.0.3-23.fc28
Details about builds:
================================================================================
cockpit-168-1.fc28 (FEDORA-2018-5d37a3260d)
A user interface for Linux servers
--------------------------------------------------------------------------------
Update Information:
- Improve checks for root privilege availability
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Martin Pitt <martin(a)piware.de> - 168-1
- Improve checks for root privilege availability
--------------------------------------------------------------------------------
================================================================================
compose-utils-0.1.19-1.fc28 (FEDORA-2018-89d137cae5)
Utilities for working with composes
--------------------------------------------------------------------------------
Update Information:
Fix traceback when generating changelog
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Lubom��r Sedl���� <lsedlar(a)redhat.com> - 0.1.19-1
- Fix changelog generation on Python 3
--------------------------------------------------------------------------------
================================================================================
enchant2-2.2.3-3.fc28 (FEDORA-2018-829a8877da)
An Enchanting Spell Checking Library
--------------------------------------------------------------------------------
Update Information:
This update marks enchant2-voikko as supplementing langpacks-fi.
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Parag Nemade <pnemade AT redhat DOT com> - 2.2.3-3
- Make enchant2-voikko installed by langpacks-fi package (#1578352)
--------------------------------------------------------------------------------
================================================================================
freeipa-4.6.90.pre2-3.fc28 (FEDORA-2018-93dfeefc68)
The Identity, Policy and Audit system
--------------------------------------------------------------------------------
Update Information:
Second release candidate for FreeIPA 4.7.0. Includes many improvements and
updates over 4.6.90.pre1.
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Alexander Bokovoy <abokovoy(a)redhat.com> - 4.6.90.pre2-3
- Fine tune packaging of server templates so that it doesn't include
freeipa.template which always go to freeipa-client-common
* Tue May 15 2018 Rob Crittenden <rcritten(a)redhat.com> - 4.6.90.pre2-2
- Exclude /usr/share from client-only builds
* Tue May 15 2018 Rob Crittenden <rcritten(a)redhat.com> - 4.6.90.pre2-1
- Update to upstream 4.6.90.pre2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1573271 - freeipa: Configure SPAKE in install
https://bugzilla.redhat.com/show_bug.cgi?id=1573271
[ 2 ] Bug #1561166 - Enable SPAKE support
https://bugzilla.redhat.com/show_bug.cgi?id=1561166
[ 3 ] Bug #1562606 - validate_selinuxuser does not allow a period in selinux user
identifier
https://bugzilla.redhat.com/show_bug.cgi?id=1562606
--------------------------------------------------------------------------------
================================================================================
gnome-shell-extension-freon-34-1.fc28 (FEDORA-2018-355abe2850)
GNOME Shell extension to display system temperature, voltage, and fan speed
--------------------------------------------------------------------------------
Update Information:
Bump to upstream version 34, which improves the Polish and Spanish translations,
and fixed a bug where it did not check for Nvidia lockfiles.
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Andrew Toskin <andrew(a)tosk.in> - 34-1
- Bump to upstream version 34, which improves the Polish and Spanish
translations, and fixed a bug where it did not check for Nvidia
lockfiles.
--------------------------------------------------------------------------------
================================================================================
javapackages-tools-5.0.0-14.fc28 (FEDORA-2018-2dde2804c8)
Macros and scripts for Java packaging support
--------------------------------------------------------------------------------
Update Information:
Adds javapackages-filesystem provides.
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Mikolaj Izdebski <mizdebsk(a)redhat.com> - 5.0.0-14
- Provide javapackages-filesystem
--------------------------------------------------------------------------------
================================================================================
libu2f-host-1.1.6-1.fc28 (FEDORA-2018-6683593d48)
Yubico Universal 2nd Factor (U2F) Host C Library
--------------------------------------------------------------------------------
Update Information:
Upstream release
--------------------------------------------------------------------------------
ChangeLog:
* Tue May 15 2018 Seth Jennings <sethdjennings(a)gmail.com> - 1.1.6-1
- Upstream release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1578535 - libu2f-host before 1.1.6 unnecessarily delays check-only
authentication
https://bugzilla.redhat.com/show_bug.cgi?id=1578535
--------------------------------------------------------------------------------
================================================================================
libxcrypt-4.0.1-1.fc28 (FEDORA-2018-1f4863d6f3)
Extended crypt library for DES, MD5, Blowfish and others
--------------------------------------------------------------------------------
Update Information:
- New upstream release
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Bj��rn Esser <besser82(a)fedoraproject.org> - 4.0.1-1
- New upstream release
--------------------------------------------------------------------------------
================================================================================
lollypop-0.9.512-1.fc28 (FEDORA-2018-1946deec70)
Music player for GNOME
--------------------------------------------------------------------------------
Update Information:
Update to 0.9.512 ---- Update to 0.9.511 ---- Update to 0.9.510
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Martin Gansser <martinkg(a)fedoraproject.org> - 0.9.512-1
- Update to 0.9.512
* Wed May 16 2018 Martin Gansser <martinkg(a)fedoraproject.org> - 0.9.511-1
- Update to 0.9.511
* Tue May 15 2018 Martin Gansser <martinkg(a)fedoraproject.org> - 0.9.510-1
- Update to 0.9.510
--------------------------------------------------------------------------------
================================================================================
microcode_ctl-2.1-23.fc28 (FEDORA-2018-34f5159e40)
Tool to transform and deploy CPU microcode update for x86
--------------------------------------------------------------------------------
Update Information:
Update to upstream 2.1-17. 20180425
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Anton Arapov <aarapov(a)redhat.com> 2:2.1-23
- Update to upstream 2.1-17. 20180425
--------------------------------------------------------------------------------
================================================================================
mmapper-2.5.0-2.fc28 (FEDORA-2018-7b01cb9110)
Graphical MUME mapper
--------------------------------------------------------------------------------
Update Information:
MMapper 2.5.0 release. - MMapper now encrypts your connection to MUME using
TLS - Holding control and using the mouse wheel navigates layers - Improved
the right click context menu - MMapper's clock can now parse the new MUME time
format - Group manager hosts can opt to not share themselves with clients -
Exposed option to force Software OpenGL on Windows and Linux - Integrated mud
client can now save logs - Integrated mud client will not resize the terminal
on window resize - Remote edit is now be passed through when disabled -
Improved syncing when boarding/leaving the Grey Havens ferry
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Kalev Lember <klember(a)redhat.com> - 2.5.0-2
- Use bundled QtIOCompressor as the packaged one is only for Qt4
* Tue May 15 2018 Kalev Lember <klember(a)redhat.com> - 2.5.0-1
- Update to 2.5.0
- Set cmake build type as "Release"
--------------------------------------------------------------------------------
================================================================================
nodejs-deep-extend-0.5.1-1.fc28 (FEDORA-2018-636f73964f)
Recursive object extending
--------------------------------------------------------------------------------
Update Information:
Security fix for CVE-2018-3750
--------------------------------------------------------------------------------
ChangeLog:
* Tue May 15 2018 Parag Nemade <pnemade AT redhat DOT com> - 0.5.1-1
- Update to 0.5.1 version (#1578248)
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1578246 - CVE-2018-3750 nodejs-deep-extend: Prototype pollution can allow
attackers to modify object properties
https://bugzilla.redhat.com/show_bug.cgi?id=1578246
--------------------------------------------------------------------------------
================================================================================
pam-u2f-1.0.7-1.fc28 (FEDORA-2018-534ecdc9eb)
Implements PAM authentication over U2F
--------------------------------------------------------------------------------
Update Information:
New upstream release
--------------------------------------------------------------------------------
ChangeLog:
--------------------------------------------------------------------------------
================================================================================
python-lightblue-0.1.4-1.fc28 (FEDORA-2018-ef244c14a8)
A Python library to work with Lightblue database
--------------------------------------------------------------------------------
Update Information:
Rebase to 0.1.4
--------------------------------------------------------------------------------
ChangeLog:
* Wed May 16 2018 Ales Raszka <araszka(a)redhat.com> - 0.1.4-1
- Rebase to 0.1.4
* Sun Apr 29 2018 Iryna Shcherbina <shcherbina.iryna(a)gmail.com> - 0.1.3-3
- Update Python 2 dependency declarations to new packaging standards
(See
https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)
--------------------------------------------------------------------------------
================================================================================
python-zmq-17.0.0-1.fc28 (FEDORA-2018-30dc9a799a)
Software library for fast, message-based applications
--------------------------------------------------------------------------------
Update Information:
Update to v17.0.0
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 12 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 17.0.0-1
- Update to 17.0.0 (#1538381)
- Fix shebangs
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1538381 - python-zmq-17.0.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1538381
--------------------------------------------------------------------------------
================================================================================
vsftpd-3.0.3-23.fc28 (FEDORA-2018-b7f6f3fe40)
Very Secure Ftp Daemon
--------------------------------------------------------------------------------
Update Information:
Fix issues found by Coverity Scan
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 10 2018 Ond��ej Lyson��k <olysonek(a)redhat.com> - 3.0.3-23
- Fix issues found by Coverity Scan
--------------------------------------------------------------------------------