The following Fedora 28 Security updates need testing:
Age URL
41
https://bodhi.fedoraproject.org/updates/FEDORA-2018-99eed1942f remctl-3.14-1.fc28
38
https://bodhi.fedoraproject.org/updates/FEDORA-2018-d510cfd7eb
jgraphx-3.6.0.0-6.fc28
23
https://bodhi.fedoraproject.org/updates/FEDORA-2018-2c965abb15
dpdk-17.11.2-1.fc28
9
https://bodhi.fedoraproject.org/updates/FEDORA-2018-c75a37ae9b
blktrace-1.2.0-6.fc28
8
https://bodhi.fedoraproject.org/updates/FEDORA-2018-ed74f27aef
ncurses-6.1-5.20180224.fc28
8
https://bodhi.fedoraproject.org/updates/FEDORA-2018-ab62814cee
nodejs-mixin-deep-1.3.1-1.fc28
3
https://bodhi.fedoraproject.org/updates/FEDORA-2018-636f73964f
nodejs-deep-extend-0.5.1-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-25674bb48e
graphviz-2.40.1-22.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-6d91fc0518
ca-certificates-2018.2.24-1.0.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-264d881a62 glibc-2.27-14.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-fa01002d7e curl-7.59.0-3.fc28
The following Fedora 28 Critical Path updates have yet to be approved:
Age URL
12
https://bodhi.fedoraproject.org/updates/FEDORA-2018-35ce81deaf
python-productmd-1.12-1.fc28
9
https://bodhi.fedoraproject.org/updates/FEDORA-2018-93b9a09597
perl-podlators-4.11-1.fc28
8
https://bodhi.fedoraproject.org/updates/FEDORA-2018-ed74f27aef
ncurses-6.1-5.20180224.fc28
7
https://bodhi.fedoraproject.org/updates/FEDORA-2018-6a4441aeff proj-4.9.3-6.fc28
4
https://bodhi.fedoraproject.org/updates/FEDORA-2018-137a0296be sddm-0.17.0-3.fc28
4
https://bodhi.fedoraproject.org/updates/FEDORA-2018-aae2d44488
ghostscript-9.23-4.fc28 libidn-1.34-3.fc28 mcabber-1.1.0-1.fc28.1 pidgin-2.13.0-1.fc28.1
python-slixmpp-1.3.0-5.fc28.1
2
https://bodhi.fedoraproject.org/updates/FEDORA-2018-72866bce5b libldb-1.3.3-1.fc28
samba-4.8.2-1.fc28
2
https://bodhi.fedoraproject.org/updates/FEDORA-2018-6c4322c3d5
libguestfs-1.38.2-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-fa01002d7e curl-7.59.0-3.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-264d881a62 glibc-2.27-14.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-efd392524a
perl-5.26.2-411.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-6d91fc0518
ca-certificates-2018.2.24-1.0.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-90d8f2d6da
libwacom-0.30-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-98f6c89898 lorax-28.11-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-0104c3a5a3
glib2-2.56.1-2.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-a082f0893b gdm-3.28.2-1.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-1d9b4ef945
crypto-policies-20180425-5.git6ad4018.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-d09ad1e0be sssd-1.16.1-8.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-35f4106f77
python2-2.7.15-2.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-538a7a0e36
kernel-4.16.9-300.fc28
0
https://bodhi.fedoraproject.org/updates/FEDORA-2018-7977b3fa1e
cyrus-sasl-2.1.27-0.2rc7.fc28
The following builds have been pushed to Fedora 28 updates-testing
NetworkManager-openvpn-1.8.4-1.fc28
balance-3.57-1.fc28
erlang-20.3.6-1.fc28
fop-2.2-1.fc28
gcompris-qt-0.91-1.fc28
krusader-2.7.0-1.fc28
libmml-2.4-2.20180425git07159b0.fc28
libqalculate-2.0.0-6.fc28
python-tornado-5.0.2-2.fc28
qwtplot3d-qt5-0.3.1a-4.20170803git34d8141.fc28
thunderbird-enigmail-2.0.4-1.fc28
xmlgraphics-commons-2.2-1.fc28
znc-1.7.0-3.fc28
Details about builds:
================================================================================
NetworkManager-openvpn-1.8.4-1.fc28 (FEDORA-2018-3001d38da1)
NetworkManager VPN plugin for OpenVPN
--------------------------------------------------------------------------------
Update Information:
* Update to 1.8.4 release * Ensure openvpn process is terminated on disconect
(rh #1576600)
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 19 2018 Beniamino Galvani <bgalvani(a)redhat.com> - 1:1.8.4-1
- Update to 1.8.4 release
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1576600 - OpenVPN process is not terminated on disconnection
https://bugzilla.redhat.com/show_bug.cgi?id=1576600
--------------------------------------------------------------------------------
================================================================================
balance-3.57-1.fc28 (FEDORA-2018-43c77a6f80)
TCP load-balancing proxy server with round robin and failover mechanisms
--------------------------------------------------------------------------------
Update Information:
New Upstream version
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 18 2018 Luis Bazan <lbazan(a)fedoraproject.org> - 3.57-1
- New upstream version
* Mon Feb 19 2018 Itamar Reis Peixoto <itamar(a)ispbrasil.com.br> - 3.52-16
- add gcc into buildrequires
--------------------------------------------------------------------------------
================================================================================
erlang-20.3.6-1.fc28 (FEDORA-2018-06873d49a8)
General-purpose programming language and runtime environment
--------------------------------------------------------------------------------
Update Information:
* Erlang ver. 20.3.6
--------------------------------------------------------------------------------
ChangeLog:
* Tue May 15 2018 Peter Lemenkov <lemenkov(a)gmail.com> - 20.3.6-1
- Ver. 20.3.6
--------------------------------------------------------------------------------
================================================================================
fop-2.2-1.fc28 (FEDORA-2018-80980e32d8)
XSL-driven print formatter
--------------------------------------------------------------------------------
Update Information:
* Update to version 2.2 which is compatible with pdfbox/fontbox 2.
--------------------------------------------------------------------------------
ChangeLog:
* Thu May 17 2018 Peter Lemenkov <lemenkov(a)gmail.com> - 2.2-1
- Ver. 2.2
--------------------------------------------------------------------------------
================================================================================
gcompris-qt-0.91-1.fc28 (FEDORA-2018-415bc477ad)
Educational software suite for children aged 2 to 10
--------------------------------------------------------------------------------
Update Information:
GCompris 0.91 is a new bugfix release to correct some issues in previous version
and improve a few things. Here is a list to summarize the changes. Activities:
* fix English text in several activities * fix score position in several
activities * block some buttons and interactions when needed in several places *
lots of fixes for audio in several activities * number_sequence (and others
based on it), fix base layout * update dataset for clickanddraw, drawnumbers and
drawletters * crane, add localized dataset * lightsoff, add keyboard support and
other fixes * algorithm, add keyboard support and other fixes * money, fixes for
locale currency used * ballcatch, improve audio feedback * calendar, several
little fixes * memory-case-association fix icons size Other changes: * re-
enable sound effects on Linux * improved playback of sound effects, no more
delay * add captions to images and OARS tags in the appdata * add Scottish
Gaelic to core, and update some datasets for it * main bar, fix some items size
* remove unused images
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 18 2018 Andrea Musuruane <musuruan(a)gmail.com> - 0.91-1
- Updated to new upstream release
--------------------------------------------------------------------------------
================================================================================
krusader-2.7.0-1.fc28 (FEDORA-2018-1d5f59da16)
An advanced twin-panel (commander-style) file-manager for KDE
--------------------------------------------------------------------------------
Update Information:
Update to upstream version 2.7.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 18 2018 Vitaly Zaitsev <vitaly(a)easycoding.org> - 2.7.0-1
- Updated to version 2.7.0.
* Wed Feb 7 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 2.6.0-2
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1556011 - krusader: FTBFS in F28
https://bugzilla.redhat.com/show_bug.cgi?id=1556011
--------------------------------------------------------------------------------
================================================================================
libmml-2.4-2.20180425git07159b0.fc28 (FEDORA-2018-61efbc5eb0)
MML Widget
--------------------------------------------------------------------------------
Update Information:
- New libmml packages
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1575412 - Review Request: libmml - MML Widget
https://bugzilla.redhat.com/show_bug.cgi?id=1575412
--------------------------------------------------------------------------------
================================================================================
libqalculate-2.0.0-6.fc28 (FEDORA-2018-4167f9ffee)
Multi-purpose calculator library
--------------------------------------------------------------------------------
Update Information:
patched to fix segfaults
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 18 2018 Mukundan Ragavan <nonamedotc(a)fedoraproject.org> - 2.0.0-6
- Apply patch to fix segfault
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1567599 - Please update this package on Fedora 27 and 28
https://bugzilla.redhat.com/show_bug.cgi?id=1567599
[ 2 ] Bug #1575280 - [abrt] qalculate-gtk: std::__replacement_assert(): qalculate-gtk
killed by SIGABRT
https://bugzilla.redhat.com/show_bug.cgi?id=1575280
--------------------------------------------------------------------------------
================================================================================
python-tornado-5.0.2-2.fc28 (FEDORA-2018-e5567c62cb)
Scalable, non-blocking web server and tools
--------------------------------------------------------------------------------
Update Information:
Update to 5.0.2
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 19 2018 Miro Hron��ok <mhroncok(a)redhat.com> - 5.0.2-2
- Require python2-futures
* Fri May 18 2018 Charalampos Stratakis <cstratak(a)redhat.com> - 5.0.2-1
- Update to 5.0.2
* Thu Apr 26 2018 Lum��r Balhar <lbalhar(a)redhat.com> - 4.5.2-5
- New conditionals for Python 2
- Drop Python 3 conditional
* Mon Feb 12 2018 Iryna Shcherbina <ishcherb(a)redhat.com> - 4.5.2-4
- Update Python 2 dependency declarations to new packaging standards
(See
https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3)
* Fri Feb 9 2018 Fedora Release Engineering <releng(a)fedoraproject.org> - 4.5.2-3
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1556277 - python-tornado: FTBFS in F28
https://bugzilla.redhat.com/show_bug.cgi?id=1556277
[ 2 ] Bug #1529414 - python-tornado-5.0.2 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1529414
--------------------------------------------------------------------------------
================================================================================
qwtplot3d-qt5-0.3.1a-4.20170803git34d8141.fc28 (FEDORA-2018-617c9bafac)
Extended version of the original QwtPlot3D library
--------------------------------------------------------------------------------
Update Information:
- Update to the commit from project for COPASI
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 5 2018 Antonio Trande <sagitter(a)fedoraproject.org> -
0.3.1a-4.20170803git34d8141
- Build new commit from COPASI repository
- Use CMake method
--------------------------------------------------------------------------------
================================================================================
thunderbird-enigmail-2.0.4-1.fc28 (FEDORA-2018-77fe2e20ad)
Authentication and encryption extension for Mozilla Thunderbird
--------------------------------------------------------------------------------
Update Information:
Enigmail update to version 2.0.4, introduces fixes for the efail attack. Please
check and modify your Thunderbird settings if required:
https://enigmail.net/index.php/en/home/news/66-2018-05-16-efail-vulnerabi...
affects-encrypted-mails
--------------------------------------------------------------------------------
ChangeLog:
* Sat May 19 2018 Christian Dersch <lupinix(a)fedoraproject.org> - 2.0.4-1
- new version fixing efail vulnerability
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1577912 - CVE-2017-17688 CVE-2017-17689 thunderbird-enigmail: various flaws
[fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1577912
--------------------------------------------------------------------------------
================================================================================
xmlgraphics-commons-2.2-1.fc28 (FEDORA-2018-80980e32d8)
XML Graphics Commons
--------------------------------------------------------------------------------
Update Information:
* Update to version 2.2 which is compatible with pdfbox/fontbox 2.
--------------------------------------------------------------------------------
ChangeLog:
* Thu Apr 26 2018 Mat Booth <mat.booth(a)redhat.com> - 0:2.2-1
- Update to latest release
- Switch to maven-based build
- Add OSGi metadata
--------------------------------------------------------------------------------
================================================================================
znc-1.7.0-3.fc28 (FEDORA-2018-4400d7249a)
An advanced IRC bouncer
--------------------------------------------------------------------------------
Update Information:
Update to 1.7.0
--------------------------------------------------------------------------------
ChangeLog:
* Fri May 18 2018 Nick Bebout <nb(a)usi.edu> - 1.7.0-3
- Fix %files to not use wildcard
* Tue May 15 2018 Pete Walter <pwalter(a)fedoraproject.org> - 1.7.0-2
- Rebuild for ICU 61.1
* Wed May 2 2018 Nick Bebout <nb(a)usi.edu> - 1.7.0-1
- Update to 1.7.0
* Mon Apr 30 2018 Pete Walter <pwalter(a)fedoraproject.org> - 1.6.6-2
- Rebuild for ICU 61.1
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1574119 - znc-1.7.0 is available
https://bugzilla.redhat.com/show_bug.cgi?id=1574119
--------------------------------------------------------------------------------