The following Fedora EPEL 7 Security updates need testing: Age URL 507 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7 269 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7 32 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e0c08a1414 php-PHPMailer-5.2.16-2.el7 18 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-767125139f python34-3.4.3-5.el7 9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-6eebbe7e97 p7zip-16.02-1.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-7913c4c81c breeze-icon-theme-5.24.0-1.el7 extra-cmake-modules-5.24.0-1.el7 kf5-5.24.0-1.el7 kf5-attica-5.24.0-1.el7 kf5-baloo-5.24.0-1.el7 kf5-bluez-qt-5.24.0-1.el7 kf5-frameworkintegration-5.24.0-1.el7 kf5-kactivities-5.24.0-1.el7 kf5-kactivities-stats-5.24.0-1.el7 kf5-kapidox-5.24.0-1.el7 kf5-karchive-5.24.0-1.el7 kf5-kauth-5.24.0-1.el7 kf5-kbookmarks-5.24.0-1.el7 kf5-kcmutils-5.24.0-1.el7 kf5-kcodecs-5.24.0-1.el7 kf5-kcompletion-5.24.0-1.el7 kf5-kconfig-5.24.0-1.el7 kf5-kconfigwidgets-5.24.0-1.el7 kf5-kcoreaddons-5.24.0-1.el7 kf5-kcrash-5.24.0-1.el7 kf5-kdbusaddons-5.24.0-1.el7 kf5-kdeclarative-5.24.0-1.el7 kf5-kded-5.24.0-1.el7 kf5-kdelibs4support-5.24.0-1.el7 kf5-kdesignerplugin-5.24.0-1.el7 kf5-kdesu-5.24.0-1.el7 kf5-kdewebkit-5.24.0-1.el7 kf5-kdnssd-5.24.0-1.el7 kf5-kdoctools-5.24.0-1.el7 kf5-kemoticons-5.24.0-1.el7 kf5-kfilemetadata-5.24.0-1.el7 kf5-kglobalaccel-5.24.0-1.el7 kf5-kguiaddons-5.24.0-1.el7 kf5-khtml -5.24.0-1.el7 kf5-ki18n-5.24.0-1.el7 kf5-kiconthemes-5.24.0-1.el7 kf5-kidletime-5.24.0-1.el7 kf5-kimageformats-5.24.0-1.el7 kf5-kinit-5.24.0-1.el7 kf5-kio-5.24.0-1.el7 kf5-kitemmodels-5.24.0-1.el7 kf5-kitemviews-5.24.0-1.el7 kf5-kjobwidgets-5.24.0-1.el7 kf5-kjs-5.24.0-1.el7 kf5-kjsembed-5.24.0-1.el7 kf5-kmediaplayer-5.24.0-1.el7 kf5-knewstuff-5.24.0-1.el7 kf5-knotifications-5.24.0-1.el7 kf5-knotifyconfig-5.24.0-1.el7 kf5-kpackage-5.24.0-1.el7 kf5-kparts-5.24.0-1.el7 kf5-kpeople-5.24.0-1.el7 kf5-kplotting-5.24.0-1.el7 kf5-kpty-5.24.0-1.el7 kf5-kross-5.24.0-1.el7 kf5-krunner-5.24.0-1.el7 kf5-kservice-5.24.0-1.el7 kf5-ktexteditor-5.24.0-1.el7 kf5-ktextwidgets-5.24.0-1.el7 kf5-kunitconversion-5.24.0-1.el7 kf5-kwallet-5.24.0-1.el7 kf5-kwidgetsaddons-5.24.0-1.el7 kf5-kwindowsystem-5.24.0-1.el7 kf5-kxmlgui-5.24.0-1.el7 kf5-kxmlrpcclient-5.24.0-1.el7 kf5-modemmanager-qt-5.24.0-1.el7 kf5-networkmanager-qt-5.24.0-1.el7 kf5-plasma-5.24.0-1.el7 kf5-solid-5.24.0-1.el7 kf5-sonnet-5.24.0-1.el7 kf5 -threadweaver-5.24.0-1.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-3a667cc289 php-guzzlehttp-guzzle-5.3.1-1.el7 7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-fbf24e04bd drupal7-views-3.14-1.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-76bb0cb040 php-doctrine-common-2.5.3-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-20572dde69 dropbear-2016.74-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-d6a70b113f collectd-5.5.2-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-42ecf5c111 v8-3.14.5.10-25.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-ac6030a9e9 cryptopp-5.6.2-10.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-dbaaa35f43 lighttpd-1.4.40-4.el7 The following builds have been pushed to Fedora EPEL 7 updates-testing SDL2_net-2.0.1-2.el7 collectd-5.5.2-1.el7 collectl-4.0.5-1.el7 cryptopp-5.6.2-10.el7 dpm-dsi-1.9.7-7.el7 dropbear-2016.74-1.el7 duplicity-0.7.09-1.1.el7 duply-1.11.3-1.el7 globus-ftp-control-7.2-1.el7 globus-gridftp-server-11.1-1.el7 glpi-0.90.5-1.el7 golang-github-jessevdk-go-flags-0-0.7.gitf2785f5.el7 golang-googlecode-text-0-0.13.git6fc2e00.el7 kobo-0.5.2-1.el7 lighttpd-1.4.40-4.el7 mcrypt-2.6.8-11.el7 ovirt-guest-agent-1.0.12-4.el7 php-bartlett-php-compatinfo-db-1.11.0-1.el7 php-onelogin-php-saml-2.9.1-3.el7 php-phpunit-PHPUnit-4.8.27-1.el7 php-udan11-sql-parser-3.4.4-1.el7 python-fmn-consumer-1.0.3-1.el7 python-fmn-lib-0.8.2-1.el7 python-fmn-rules-0.9.0-1.el7 v8-3.14.5.10-25.el7 vym-2.5.19-1.el7 zabbix22-2.2.14-1.el7 Details about builds: ================================================================================ SDL2_net-2.0.1-2.el7 (FEDORA-EPEL-2016-46d2a9229b) SDL portable network library -------------------------------------------------------------------------------- Update Information: Initial SDL2_net build for EPEL 7. -------------------------------------------------------------------------------- ================================================================================ collectd-5.5.2-1.el7 (FEDORA-EPEL-2016-d6a70b113f) Statistics collection daemon for filling RRD files -------------------------------------------------------------------------------- Update Information: - Upstream released new version (https://collectd.org/news.shtml#news98) - Contains fix for CVE-2016-6254 - Drop a few patches applied upstream - Use Type=notify in systemd unit now that collectd support it. - Enable zfs_arc plugin (#1359669) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1359669 - RFE: add support for zfs_arc plugin for collectd https://bugzilla.redhat.com/show_bug.cgi?id=1359669 -------------------------------------------------------------------------------- ================================================================================ collectl-4.0.5-1.el7 (FEDORA-EPEL-2016-5fec54170f) A utility to collect various Linux performance data -------------------------------------------------------------------------------- Update Information: updated to 4.0.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1356745 - collectl-4.0.5.src is available https://bugzilla.redhat.com/show_bug.cgi?id=1356745 -------------------------------------------------------------------------------- ================================================================================ cryptopp-5.6.2-10.el7 (FEDORA-EPEL-2016-ac6030a9e9) C++ class library of cryptographic schemes -------------------------------------------------------------------------------- Update Information: - CVE-2016-3995 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1325951 - CVE-2016-3995 cryptopp: bogus protection from timing attacks [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1325951 -------------------------------------------------------------------------------- ================================================================================ dpm-dsi-1.9.7-7.el7 (FEDORA-EPEL-2016-53805c3cb3) Disk Pool Manager (DPM) plugin for the Globus GridFTP server -------------------------------------------------------------------------------- Update Information: globus-ftp-control * Add buffering to data ordering mode globus-gridftp-server * Fix forced order issues with restart (11.1) * Add forced ordering option (11.0) * Add Globus task id to transfer log (10.6) * Don't errantly kill a transfer due to timeout while client is still connected (10.5) dpm-dsi * Rebuilt for globus-gridftp-server 11.1 -------------------------------------------------------------------------------- ================================================================================ dropbear-2016.74-1.el7 (FEDORA-EPEL-2016-20572dde69) Lightweight SSH server and client -------------------------------------------------------------------------------- Update Information: new version ---- CVE-2016-3116 dropbear: X11 forwarding input not validated properly -------------------------------------------------------------------------------- References: [ 1 ] Bug #1359635 - dropbear: Multiple security issues fixed in 2016.74 https://bugzilla.redhat.com/show_bug.cgi?id=1359635 -------------------------------------------------------------------------------- ================================================================================ duplicity-0.7.09-1.1.el7 (FEDORA-EPEL-2016-8216bfdf81) Encrypted bandwidth-efficient backup using rsync algorithm -------------------------------------------------------------------------------- Update Information: Latest upstream. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1359548 - duplicity-0.7.09 is available https://bugzilla.redhat.com/show_bug.cgi?id=1359548 -------------------------------------------------------------------------------- ================================================================================ duply-1.11.3-1.el7 (FEDORA-EPEL-2016-8e43691fb4) Wrapper for duplicity -------------------------------------------------------------------------------- Update Information: Latest release, fixes deprecation warning. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1360193 - Duply triggers duplicity deprecation warning when excluding files (since duplicity upgrade) https://bugzilla.redhat.com/show_bug.cgi?id=1360193 -------------------------------------------------------------------------------- ================================================================================ globus-ftp-control-7.2-1.el7 (FEDORA-EPEL-2016-53805c3cb3) Globus Toolkit - GridFTP Control Library -------------------------------------------------------------------------------- Update Information: globus-ftp-control * Add buffering to data ordering mode globus-gridftp-server * Fix forced order issues with restart (11.1) * Add forced ordering option (11.0) * Add Globus task id to transfer log (10.6) * Don't errantly kill a transfer due to timeout while client is still connected (10.5) dpm-dsi * Rebuilt for globus-gridftp-server 11.1 -------------------------------------------------------------------------------- ================================================================================ globus-gridftp-server-11.1-1.el7 (FEDORA-EPEL-2016-53805c3cb3) Globus Toolkit - Globus GridFTP Server -------------------------------------------------------------------------------- Update Information: globus-ftp-control * Add buffering to data ordering mode globus-gridftp-server * Fix forced order issues with restart (11.1) * Add forced ordering option (11.0) * Add Globus task id to transfer log (10.6) * Don't errantly kill a transfer due to timeout while client is still connected (10.5) dpm-dsi * Rebuilt for globus-gridftp-server 11.1 -------------------------------------------------------------------------------- ================================================================================ glpi-0.90.5-1.el7 (FEDORA-EPEL-2016-6a963cbce0) Free IT asset management software -------------------------------------------------------------------------------- Update Information: Upgrade from old version 0.84 to latest upstream maintained version 0.90. **Notice:** this version drops the support for OCS Inventory NG, if needed, you have to install the [ocsinventoryng](http://plugins.glpi- project.org/#/plugin/ocsinventoryng) plugin. -------------------------------------------------------------------------------- ================================================================================ golang-github-jessevdk-go-flags-0-0.7.gitf2785f5.el7 (FEDORA-EPEL-2016-df23b8d98f) Go command line option parser -------------------------------------------------------------------------------- Update Information: Bump to upstream f2785f5820ec967043de79c8be97edfc464ca745 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1250487 - Tracker for golang-github-jessevdk-go-flags https://bugzilla.redhat.com/show_bug.cgi?id=1250487 -------------------------------------------------------------------------------- ================================================================================ golang-googlecode-text-0-0.13.git6fc2e00.el7 (FEDORA-EPEL-2016-d4f9bf2d32) Supplementary Go text libraries -------------------------------------------------------------------------------- Update Information: Enable devel and unit-test ---- Polishing the spec file -------------------------------------------------------------------------------- References: [ 1 ] Bug #1254601 - Tracker for golang-googlecode-text https://bugzilla.redhat.com/show_bug.cgi?id=1254601 -------------------------------------------------------------------------------- ================================================================================ kobo-0.5.2-1.el7 (FEDORA-EPEL-2016-929a79e528) Python modules for tools development -------------------------------------------------------------------------------- Update Information: Update to latest upstream. -------------------------------------------------------------------------------- ================================================================================ lighttpd-1.4.40-4.el7 (FEDORA-EPEL-2016-dbaaa35f43) Lightning fast webserver with light system requirements -------------------------------------------------------------------------------- Update Information: Patch for CVE-2016-1000212. ---- Connection state patch. ---- Patch for ipv6 blocking bug. ---- 1.4.40 https://www.lighttpd.net/2016/7/16/1.4.40/ -------------------------------------------------------------------------------- References: [ 1 ] Bug #1360641 - CVE-2016-1000212 lighttpd: sets environmental variable based on user supplied Proxy request header [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1360641 [ 2 ] Bug #1360640 - CVE-2016-1000212 lighttpd: sets environmental variable based on user supplied Proxy request header [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1360640 [ 3 ] Bug #1357238 - lighttpd-1.4.40 is available https://bugzilla.redhat.com/show_bug.cgi?id=1357238 -------------------------------------------------------------------------------- ================================================================================ mcrypt-2.6.8-11.el7 (FEDORA-EPEL-2016-f6c714ab8e) Replacement for crypt() -------------------------------------------------------------------------------- Update Information: New package for EL7 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1357685 - None https://bugzilla.redhat.com/show_bug.cgi?id=1357685 -------------------------------------------------------------------------------- ================================================================================ ovirt-guest-agent-1.0.12-4.el7 (FEDORA-EPEL-2016-4f7f85fe25) The oVirt Guest Agent -------------------------------------------------------------------------------- Update Information: Bump to upstream version 1.0.12.2 and dependency fix on F24 -------------------------------------------------------------------------------- ================================================================================ php-bartlett-php-compatinfo-db-1.11.0-1.el7 (FEDORA-EPEL-2016-97860fac75) Reference Database to be used with php-compatinfo library -------------------------------------------------------------------------------- Update Information: **Version 1.11.0** - 2016-07-25 - Support to PHP 7.0.9 - Support to PHP 5.6.24 - Support to PHP 5.5.38 -------------------------------------------------------------------------------- ================================================================================ php-onelogin-php-saml-2.9.1-3.el7 (FEDORA-EPEL-2016-81dff2c066) SAML support for PHP -------------------------------------------------------------------------------- Update Information: New package used for PHP interfaces to SAML authentication services -------------------------------------------------------------------------------- References: [ 1 ] Bug #1356552 - Review Request: php-onelogin-php-saml - SAML support for PHP softwares https://bugzilla.redhat.com/show_bug.cgi?id=1356552 -------------------------------------------------------------------------------- ================================================================================ php-phpunit-PHPUnit-4.8.27-1.el7 (FEDORA-EPEL-2016-cf8d6058c7) The PHP Unit Testing framework -------------------------------------------------------------------------------- Update Information: **Version 4.8.27** - 2016-07-21 * Fixed [#1968](https://github.com/sebastianbergmann/phpunit/issues/1968): Invalid data sets are not handled correctly for `@testWith` annotation -------------------------------------------------------------------------------- ================================================================================ php-udan11-sql-parser-3.4.4-1.el7 (FEDORA-EPEL-2016-2671f99a1a) A validating SQL lexer and parser with a focus on MySQL dialect -------------------------------------------------------------------------------- Update Information: - update to 3.4.4 - switch from udan11/sql-parser to phpmyadmin/sql-parser - add sql-parser-highlight-query and sql-parser-lint-query commands -------------------------------------------------------------------------------- References: [ 1 ] Bug #1342512 - Outdated dependency on sql-parser https://bugzilla.redhat.com/show_bug.cgi?id=1342512 -------------------------------------------------------------------------------- ================================================================================ python-fmn-consumer-1.0.3-1.el7 (FEDORA-EPEL-2016-360d4ef294) Backend worker daemon for Fedora Notifications -------------------------------------------------------------------------------- Update Information: Bugfix to fmn-lib and fmn-rules and new architecture to fmn-consumer -------------------------------------------------------------------------------- ================================================================================ python-fmn-lib-0.8.2-1.el7 (FEDORA-EPEL-2016-360d4ef294) Internal API components and model for Fedora Notifications -------------------------------------------------------------------------------- Update Information: Bugfix to fmn-lib and fmn-rules and new architecture to fmn-consumer -------------------------------------------------------------------------------- ================================================================================ python-fmn-rules-0.9.0-1.el7 (FEDORA-EPEL-2016-360d4ef294) Message processing rules for Fedora Notifications -------------------------------------------------------------------------------- Update Information: Bugfix to fmn-lib and fmn-rules and new architecture to fmn-consumer -------------------------------------------------------------------------------- ================================================================================ v8-3.14.5.10-25.el7 (FEDORA-EPEL-2016-42ecf5c111) JavaScript Engine -------------------------------------------------------------------------------- Update Information: fix for CVE-2016-1669, fix for builtin reporting, add provides for v8-314 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1353623 - CVE-2016-1669 v8: chromium-browser,v8,nodejs: buffer overflow in v8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1353623 [ 2 ] Bug #1353620 - CVE-2016-1669 v8: chromium-browser,v8,nodejs: buffer overflow in v8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1353620 -------------------------------------------------------------------------------- ================================================================================ vym-2.5.19-1.el7 (FEDORA-EPEL-2016-75d0cae8b7) View your mind -------------------------------------------------------------------------------- Update Information: Latest upstream. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1359465 - vym-2.5.19-1.21 is available https://bugzilla.redhat.com/show_bug.cgi?id=1359465 -------------------------------------------------------------------------------- ================================================================================ zabbix22-2.2.14-1.el7 (FEDORA-EPEL-2016-cf904307bf) Open-source monitoring solution for your IT infrastructure -------------------------------------------------------------------------------- Update Information: http://www.zabbix.com/rn2.2.14.php -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list epel-devel@xxxxxxxxxxxxxxxxxxxxxxx https://lists.fedoraproject.org/admin/lists/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx