The following Fedora EPEL 7 Security updates need testing: Age URL 9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-86538d58b1 strongswan-5.6.3-1.el7 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-3835d39d1a unrtf-0.21.9-8.el7 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-04bf550089 nikto-2.1.6-1.el7 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-656b24ec40 chromium-67.0.3396.79-1.el7 2 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-e70dca1af5 thunderbird-enigmail-2.0.7-1.el7 1 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-15b7dc35af pass-1.7.2-1.el7 The following builds have been pushed to Fedora EPEL 7 updates-testing ansible-2.5.5-1.el7 epel-rpm-macros-7-19 fleet-commander-admin-0.10.8-3.el7 gnome-shell-extension-openweather-1-0.33.20180616git401d68e.el7 marco-1.16.1-3.el7 nodejs-6.14.3-1.el7 python-pytoml-0.1.16-1.el7 vim-fugitive-2.3-1.el7 Details about builds: ================================================================================ ansible-2.5.5-1.el7 (FEDORA-EPEL-2018-fa11f61de0) SSH-based configuration management, deployment, and task execution system -------------------------------------------------------------------------------- Update Information: Update to 2.5.5 bugfix/security release See https://github.com/ansible/ansible/blob/stable-2.5/changelogs/CHANGELOG-v2.5.rst for full changes. Fixes CVE-2018-10855 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 14 2018 Kevin Fenzi <kevin@xxxxxxxxx> - 2.5.5-1 - Update to 2.5.5. Fixes bug #1580530 and #1584927 - Fixes 1588855,1590200 (fedora) and 1588855,1590199 (epel) CVE-2018-10855 (security bug with no_log handling) * Thu May 31 2018 Kevin Fenzi <kevin@xxxxxxxxx> - 2.5.4-1 - Update to 2.5.4. Fixes bug #1584927 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1580530 - ansible-2.5.3-1.fc28 broke "synchronize" task https://bugzilla.redhat.com/show_bug.cgi?id=1580530 [ 2 ] Bug #1584927 - ansible-2.5.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1584927 [ 3 ] Bug #1590199 - CVE-2018-10855 ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1590199 [ 4 ] Bug #1590200 - CVE-2018-10855 ansible: Failed tasks do not honour no_log option allowing for secrets to be disclosed in logs [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1590200 -------------------------------------------------------------------------------- ================================================================================ epel-rpm-macros-7-19 (FEDORA-EPEL-2018-99aa68bf61) Extra Packages for Enterprise Linux RPM macros -------------------------------------------------------------------------------- Update Information: Add the %set_build_flags macro, to enhance specfile compatibility with Fedora. -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 15 2018 Jason L Tibbitts III <tibbs@xxxxxxxxxxx> - 7-19 - Add %set_build_flags macro. -------------------------------------------------------------------------------- ================================================================================ fleet-commander-admin-0.10.8-3.el7 (FEDORA-EPEL-2018-cbefb06724) Fleet Commander -------------------------------------------------------------------------------- Update Information: Fixed python3 dependency for EPEL7 ---- Updated to version 0.10.8 -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 15 2018 Oliver Gutierrez <ogutierrez@xxxxxxxxxx> - 0.10.8-3 - Fixed python3 dependency for EPEL7 * Thu Jun 14 2018 Oliver Gutierrez <ogutierrez@xxxxxxxxxx> - 0.10.8-2 - Fixed dependency for EPEL7 * Thu Jun 7 2018 Oliver Gutierrez <ogutierrez@xxxxxxxxxx> - 0.10.8-1 - Updated to release 0.10.8 - Migrated logger to python3 -------------------------------------------------------------------------------- ================================================================================ gnome-shell-extension-openweather-1-0.33.20180616git401d68e.el7 (FEDORA-EPEL-2018-f48311d606) Display weather information from many locations in the world -------------------------------------------------------------------------------- Update Information: Moved upstream to gitlab, updated urls accordingly. Update some language-files. Make max location-length configurable. -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 16 2018 Jens Lody <fedora@xxxxxxxxxxx> - 1-0.33.20180616git401d68e - Moved the upstream repo to gitlab. - Fixed some locale-files. - Added option to cinfigure the max location-length. * Wed Feb 7 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1-0.32.20171030gita86b949 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Sun Nov 26 2017 Jens Lody <fedora@xxxxxxxxxxx> - 1-0.32.20171126gitcac94f2 - Fix search-results popup not shown in last revision. -------------------------------------------------------------------------------- ================================================================================ marco-1.16.1-3.el7 (FEDORA-EPEL-2018-75111625de) MATE Desktop window manager -------------------------------------------------------------------------------- Update Information: - fix for rhbz (#1591973) -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 16 2018 Wolfgang Ulbrich <chat-to-me@xxxxxxxxx> - 1.16.1-3 - fix for rhbz (#1591973) * Sat Jun 16 2018 Wolfgang Ulbrich <chat-to-me@xxxxxxxxx> - 1.16.1-2 - fix for rhbz (#1591973) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1591973 - Windows get permanently composited on the screen https://bugzilla.redhat.com/show_bug.cgi?id=1591973 -------------------------------------------------------------------------------- ================================================================================ nodejs-6.14.3-1.el7 (FEDORA-EPEL-2018-871d88af0e) JavaScript runtime -------------------------------------------------------------------------------- Update Information: Update for security fixes -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 14 2018 Stephen Gallagher <sgallagh@xxxxxxxxxx> - 1:6.14.3-1 - Update to 6.14.3 security release - https://nodejs.org/en/blog/release/v6.14.3/ -------------------------------------------------------------------------------- References: [ 1 ] Bug #1591019 - CVE-2018-7162 nodejs: denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591019 [ 2 ] Bug #1591014 - CVE-2018-7161 nodejs: denial of service (DoS) by causing a node server providing an http2 server to crash [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591014 [ 3 ] Bug #1591009 - CVE-2018-7167 nodejs: Denial of Service by calling Buffer.fill() or Buffer.alloc() with specially crafted parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591009 -------------------------------------------------------------------------------- ================================================================================ python-pytoml-0.1.16-1.el7 (FEDORA-EPEL-2018-a8a4d06fc5) Parser for TOML -------------------------------------------------------------------------------- Update Information: Update to 0.1.16 -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 16 2018 Julien Enselme <jujens@xxxxxxxxx> - 0.1.16-1 - Update to 0.1.16 * Fri Mar 16 2018 Tomas Orsava <torsava@xxxxxxxxxx> - 0.1.14-5.git7dea353 - Conditionalize the Python 2 subpackage - Don't build the Python 2 subpackage on EL > 7 and Fedora > 28 * Sat Jan 27 2018 Iryna Shcherbina <ishcherb@xxxxxxxxxx> - 0.1.14-3.git7dea353 - Update Python 2 dependency declarations to new packaging standards (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1581006 - python-pytoml-v0.1.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=1581006 -------------------------------------------------------------------------------- ================================================================================ vim-fugitive-2.3-1.el7 (FEDORA-EPEL-2018-0ea67b631f) A Git wrapper so awesome, it should be illegal -------------------------------------------------------------------------------- Update Information: - Latest upstream - Mark documentation file as %%doc -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 15 2018 Carl George <carl@george.computer> - 2.3-1 - Latest upstream - Mark documentation file as %doc -------------------------------------------------------------------------------- References: [ 1 ] Bug #1585397 - vim-fugitive-2.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1585397 -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx/message/QLYLELY44UCQMQOXGCKBL4EC3WNSOBAR/