The following Fedora EPEL 6 Security updates need testing: Age URL 760 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7031 python-virtualenv-12.0.7-1.el6 754 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7168 rubygem-crack-0.3.2-2.el6 644 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-e2b4b5b2fb mcollective-2.8.4-1.el6 616 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-35e240edd9 thttpd-2.25b-24.el6 226 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e3e50897ac libbsd-0.8.3-2.el6 122 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-c0d33ae70f tnef-1.4.14-1.el6 24 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e8124f23c8 heimdal-7.4.0-1.el6 14 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-515cca9a02 GraphicsMagick-1.3.26-3.el6 14 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-99fb0d61b0 chicken-4.12.0-3.el6 14 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-ab5ed7f894 python-tablib-0.11.5-1.el6 13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-70562ba4d2 python-django-ckeditor-5.3.0-1.el6 13 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-f4a2132f26 seamonkey-2.48-1.el6 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-b1d8b4aed9 globus-ftp-client-8.36-1.el6 globus-ftp-control-7.8-1.el6 globus-gass-cache-program-6.7-1.el6 globus-gass-copy-9.27-1.el6 globus-gram-client-13.19-1.el6 globus-gram-job-manager-14.36-1.el6 globus-gram-job-manager-condor-2.6-5.el6 globus-gridftp-server-12.2-1.el6 globus-gridftp-server-control-5.1-1.el6 globus-gssapi-gsi-12.17-3.el6 globus-io-11.9-1.el6 globus-net-manager-0.17-1.el6 globus-xio-5.16-1.el6 globus-xio-gsi-driver-3.11-1.el6 globus-xio-pipe-driver-3.10-1.el6 globus-xio-udt-driver-1.28-1.el6 myproxy-6.1.28-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-72e0f4a914 php-horde-Horde-Core-2.30.0-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-2a557f0b9c php-horde-Horde-Form-2.0.18-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-3e60244bf3 php-horde-Horde-Url-2.2.6-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-4340a6e0a8 php-horde-horde-5.2.16-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-4654acd4ee php-horde-kronolith-4.2.22-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-19c0b8ff89 php-horde-nag-4.2.15-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-5b8e6e0279 php-horde-turba-4.2.20-1.el6 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-d015ef3016 gsoap-2.7.16-5.el6 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-cbc54495c7 qpdf-5.1.1-3.el6 0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-22a20c457f libarchive3-3.3.1-1.el6 The following builds have been pushed to Fedora EPEL 6 updates-testing libarchive3-3.3.1-1.el6 nrpe-3.2.0-6.el6 Details about builds: ================================================================================ libarchive3-3.3.1-1.el6 (FEDORA-EPEL-2017-22a20c457f) A library for handling streaming archive formats -------------------------------------------------------------------------------- Update Information: - Update to 3.3.1 - Drop obsolete patches -------------------------------------------------------------------------------- References: [ 1 ] Bug #1449532 - CVE-2016-10349 CVE-2016-10350 libarchive3: various flaws [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1449532 [ 2 ] Bug #1439704 - CVE-2016-10209 libarchive3: libarchive: NULL pointer dereference in archive_wstring_append_from_mbs function [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1439704 [ 3 ] Bug #1417917 - CVE-2017-5601 libarchive: Out of bounds read in lha_read_file_header_1() function [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1417917 [ 4 ] Bug #1385676 - CVE-2016-8687 CVE-2016-8688 CVE-2016-8689 libarchive3: various flaws [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1385676 [ 5 ] Bug #1375280 - CVE-2016-5418 libarchive3: libarchive: Archive Entry with type 1 (hardlink), but has a non-zero data size file overwrite [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1375280 -------------------------------------------------------------------------------- ================================================================================ nrpe-3.2.0-6.el6 (FEDORA-EPEL-2017-bb989d629b) Host/service/network monitoring agent for Nagios -------------------------------------------------------------------------------- Update Information: Found the problem. Fixed and ready to push ---- Put in fix for 1204683 ---- Fix patch name. Silly human. Do a fedpkg srpm before build. ---- Fix bug due to /etc/nrpe.d/ includes was above other defined entries BZ# 1467971 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1476298 - NRPE selinux module broken https://bugzilla.redhat.com/show_bug.cgi?id=1476298 [ 2 ] Bug #1204683 - check_ide_smart cannot be started by nrpe https://bugzilla.redhat.com/show_bug.cgi?id=1204683 [ 3 ] Bug #1318773 - nrpe.service sets User/Group, prevents normal .cfg user/group setting https://bugzilla.redhat.com/show_bug.cgi?id=1318773 [ 4 ] Bug #1467808 - Segfault when starting epel https://bugzilla.redhat.com/show_bug.cgi?id=1467808 [ 5 ] Bug #1467971 - Regression to Bug 963703 - nrpe.cfg sets config values after including user configuration https://bugzilla.redhat.com/show_bug.cgi?id=1467971 [ 6 ] Bug #1469210 - NRPE behavior changed, include_dir no longer overrides commands defined in /etc/nagios/nrpe.cfg https://bugzilla.redhat.com/show_bug.cgi?id=1469210 -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx