The following Fedora EPEL 7 Security updates need testing: Age URL 653 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-1087 dokuwiki-0-0.24.20140929c.el7 415 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-dac7ed832f mcollective-2.8.4-1.el7 134 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-23fa04bf1c redis-3.2.3-1.el7 118 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e8f4ff76b3 chicken-4.11.0-3.el7 60 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-ee3cc4d1b6 compat-guile18-1.8.8-14.el7 8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-090cbd0a83 botan-1.10.14-3.el7 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-73b4fc1c78 chromium-55.0.2883.87-1.el7.1 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-d21e337184 hdf5-1.8.12-8.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-0899019edf game-music-emu-0.6.1-1.el7 2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-911ea9b639 fedfind-3.2.3-1.el7 python-wikitcms-2.1.9-1.el7 2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-17165c490b nagios-plugins-2.1.4-2.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-403020225c tor-0.2.8.12-1.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-a189d9c701 js-jquery1-1.12.4-2.el7 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-11ee6fcfdf js-jquery-2.2.4-1.el7 The following builds have been pushed to Fedora EPEL 7 updates-testing jabberd-2.4.0-6.el7 js-jquery-2.2.4-1.el7 js-jquery1-1.12.4-2.el7 libspf2-1.2.10-12.20150405gitd57d79fd.el7 opendkim-2.11.0-0.1.el7 python-egenix-mx-base-3.2.9-1.el7 python3-zope-interface-4.3.3-1.el7 tor-0.2.8.12-1.el7 uwsgi-2.0.14-3.el7 webalizer-2.23_08-5.el7 wine-1.8.6-1.el7 Details about builds: ================================================================================ jabberd-2.4.0-6.el7 (FEDORA-EPEL-2016-8ba4818a55) OpenSource server implementation of the Jabber protocols -------------------------------------------------------------------------------- Update Information: Added patches to fix "segfaut in 'sm' component when blocking users" (#1406062) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406062 - segfaut in 'sm' component when blocking users https://bugzilla.redhat.com/show_bug.cgi?id=1406062 -------------------------------------------------------------------------------- ================================================================================ js-jquery-2.2.4-1.el7 (FEDORA-EPEL-2016-11ee6fcfdf) JavaScript DOM manipulation, event handling, and AJAX library -------------------------------------------------------------------------------- Update Information: Update to 2.2.4 with backport for XSS vulnerability. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1307666 - js-jquery: FTBFS in F24 https://bugzilla.redhat.com/show_bug.cgi?id=1307666 [ 2 ] Bug #1399550 - js-jquery: Cross-site scripting via cross-domain ajax requests [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1399550 [ 3 ] Bug #1399549 - js-jquery: Cross-site scripting via cross-domain ajax requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1399549 -------------------------------------------------------------------------------- ================================================================================ js-jquery1-1.12.4-2.el7 (FEDORA-EPEL-2016-a189d9c701) JavaScript DOM manipulation, event handling, and AJAX library -------------------------------------------------------------------------------- Update Information: Update to latest jquery1 stable, with backport fix for XSS vulnerability.) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1307668 - js-jquery1: FTBFS in F24 https://bugzilla.redhat.com/show_bug.cgi?id=1307668 [ 2 ] Bug #1257589 - Upgrade js-jquery1 to 1.11.3 https://bugzilla.redhat.com/show_bug.cgi?id=1257589 [ 3 ] Bug #1399548 - js-jquery1: js-jquery: Cross-site scripting via cross-domain ajax requests [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1399548 [ 4 ] Bug #1399547 - js-jquery1: js-jquery: Cross-site scripting via cross-domain ajax requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1399547 -------------------------------------------------------------------------------- ================================================================================ libspf2-1.2.10-12.20150405gitd57d79fd.el7 (FEDORA-EPEL-2016-55b3f94e04) An implementation of the SPF specification -------------------------------------------------------------------------------- Update Information: Simplify release numbers (same for both library and perl module) -------------------------------------------------------------------------------- ================================================================================ opendkim-2.11.0-0.1.el7 (FEDORA-EPEL-2016-b701e2ad15) A DomainKeys Identified Mail (DKIM) milter to sign and/or verify mail -------------------------------------------------------------------------------- Update Information: Updating to the 2.11.Alpha0 upstream source @ https://sourceforge.net/projects/opendkim/, which has been stable since 2015. Patches included for: * openssl 1.1.0 support (https://sourceforge.net/p/opendkim/patches/35/) * strl.h location (https://sourceforge.net/p/opendkim/patches/37/) Thanks @adamwill for the nudge on re-diffing patches. -------------------------------------------------------------------------------- ================================================================================ python-egenix-mx-base-3.2.9-1.el7 (FEDORA-EPEL-2016-2654cd9eda) A collection of Python software tools -------------------------------------------------------------------------------- Update Information: Upstream v3.2.9 -------------------------------------------------------------------------------- ================================================================================ python3-zope-interface-4.3.3-1.el7 (FEDORA-EPEL-2016-ae61512e6e) Zope 3 Interface Infrastructure -------------------------------------------------------------------------------- Update Information: New package for Python 3. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1404502 - python3-zope-interface-4.3.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1404502 -------------------------------------------------------------------------------- ================================================================================ tor-0.2.8.12-1.el7 (FEDORA-EPEL-2016-403020225c) Anonymizing overlay network for TCP -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-1254 ---- update to upstream release 0.2.8.11 ---- update to upstream release 0.2.8.10 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406314 - CVE-2016-1254 tor: Remote DoS via parsing problem https://bugzilla.redhat.com/show_bug.cgi?id=1406314 -------------------------------------------------------------------------------- ================================================================================ uwsgi-2.0.14-3.el7 (FEDORA-EPEL-2016-dc198994cb) Fast, self-healing, application container server -------------------------------------------------------------------------------- Update Information: enable psgi plugin on el7 -------------------------------------------------------------------------------- ================================================================================ webalizer-2.23_08-5.el7 (FEDORA-EPEL-2016-f2f5bb1856) A flexible Web server log file analysis program -------------------------------------------------------------------------------- Update Information: Build on EPEL >= 7 against libdb-devel to enable DNS/GeoDB code -------------------------------------------------------------------------------- ================================================================================ wine-1.8.6-1.el7 (FEDORA-EPEL-2016-3ea90287b0) A compatibility layer for windows applications -------------------------------------------------------------------------------- Update Information: - Fix a regression introduced in 1.8.5 (#41627) - Various bug fixes. - A few more cards added to the GPU description table. -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx