The following Fedora EPEL 6 Security updates need testing: Age URL 11 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-e4e96fbf3f drupal7-7.58-1.el6 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-b5d9f8f571 wordpress-4.9.5-1.el6 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-870a92fcc5 koji-1.15.1-1.el6 1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-5aca1d385d remctl-3.14-1.el6 The following builds have been pushed to Fedora EPEL 6 updates-testing globus-common-17.4-1.el6 globus-ftp-control-8.3-1.el6 globus-gridftp-server-12.5-1.el6 globus-gridftp-server-control-6.1-1.el6 globus-gsi-sysconfig-8.1-1.el6 globus-gssapi-gsi-13.5-1.el6 globus-xio-5.17-1.el6 globus-xio-udt-driver-1.29-1.el6 python-gunicorn-18.0-2.el6 Details about builds: ================================================================================ globus-common-17.4-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - Common Library -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-ftp-control-8.3-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - GridFTP Control Library -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-gridftp-server-12.5-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - Globus GridFTP Server -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-gridftp-server-control-6.1-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - Globus GridFTP Server Library -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-gsi-sysconfig-8.1-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - Globus GSI System Config Library -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-gssapi-gsi-13.5-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - GSSAPI library -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-xio-5.17-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - Globus XIO Framework -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ globus-xio-udt-driver-1.29-1.el6 (FEDORA-EPEL-2018-1017874535) Globus Toolkit - Globus XIO UDT Driver -------------------------------------------------------------------------------- Update Information: globus-gridftp-server-control (6.1): * Don't error if acquire_cred fails when vhost env is set globus-ftp-control (8.3) * Default to host authz when using tls control channel globus-xio (5.17): * Fix udp dual stack sockets when ipv6only is the default globus-xio-udt-driver (1.29), globus-gsi-sysconfig (8.1), globus-gssapi-gsi (13.5), globus-common (17.4), globus-gridftp-server (12.5): * Minor fixes, mostly related to windows -------------------------------------------------------------------------------- ================================================================================ python-gunicorn-18.0-2.el6 (FEDORA-EPEL-2018-158680d651) Python WSGI application server -------------------------------------------------------------------------------- Update Information: Fix HTTP header splitting vulnerability (RHBZ#1564941, CVE-2018-1000164) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1564940 - CVE-2018-1000164 python-gunicorn: Improper neutralization of CRLF Sequences http/wsgi.py:process_headers() can allow an attacker to cause a server to return arbitrary HTTP headers https://bugzilla.redhat.com/show_bug.cgi?id=1564940 -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx