The following Fedora EPEL 6 Security updates need testing: Age URL 5 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-d6ec1647e3 mbedtls-2.7.12-1.el6 The following builds have been pushed to Fedora EPEL 6 updates-testing copr-cli-1.82-1.el6 libapreq2-2.13-2.el6 opendmarc-1.3.2-1.el6 perl-Date-Holidays-DE-2.03-1.el6 python-copr-1.98-1.el6 singularity-3.4.1-1.2.el6 Details about builds: ================================================================================ copr-cli-1.82-1.el6 (FEDORA-EPEL-2019-2bd300951e) Command line interface for COPR -------------------------------------------------------------------------------- Update Information: copr-cli - manpage: update API token url - support multilib projects - fix traceback when lost connection during copr-cli build - adding cheat for copr python-copr: - packaging fixes - python: fix API for marshmallow 3+ (#934) ---- python: fix API for marshmallow 3+ (#934) -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 3 2019 Pavel Raiskup <praiskup@xxxxxxxxxx> 1.82-1 - manpage: update API token url - support multilib projects - fix traceback when lost connection during copr-cli build - adding cheat for copr * Tue Aug 13 2019 Pavel Raiskup <praiskup@xxxxxxxxxx> 1.81-1 - cli: pypi package needs to depend on 'humanize' -------------------------------------------------------------------------------- ================================================================================ libapreq2-2.13-2.el6 (FEDORA-EPEL-2019-e7cdb404e5) Apache HTTP request library -------------------------------------------------------------------------------- Update Information: Patch CVE-2019-12412. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 4 2019 Bojan Smojver <bojan@xxxxxxxxxxxxx> - 2.13-38 - patch CVE-2019-12412 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1758454 - CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1758454 [ 2 ] Bug #1758453 - CVE-2019-12412 libapreq2: libapreq: null pointer dereference in create_multipart_context() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1758453 -------------------------------------------------------------------------------- ================================================================================ opendmarc-1.3.2-1.el6 (FEDORA-EPEL-2019-5393542b88) A Domain-based Message Authentication, Reporting & Conformance (DMARC) milter and library -------------------------------------------------------------------------------- Update Information: This update provides the final 1.3.2 release (previously the package was 1.3.2 beta). It also includes the previously-omitted database schema directory (resolving [#1415753](https://bugzilla.redhat.com/show_bug.cgi?id=1415753)) and rddmarc tools, and backports proposed fixes for a [crasher bug](https://bugzilla.redhat.com/show_bug.cgi?id=1673293) and [security issue CVE-2019-16378](https://bugzilla.redhat.com/show_bug.cgi?id=1753081) from upstream submissions. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 4 2019 Adam Williamson <awilliam@xxxxxxxxxx> - 1.3.2-1 - Update to 1.3.2 final (belatedly) - Drop patches merged upstream - Backport proposed fix for upstream #227 (RHBZ #1673293) - Backport proposed fix for CVE-2019-16378 (RHBZ #1753082 and #1753081) - Ship database schema and rddmarc bits (#1415753) * Thu Jul 25 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.20 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri Feb 1 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Fri Jul 13 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri Feb 9 2018 Igor Gnatenko <ignatenkobrain@xxxxxxxxxxxxxxxxx> - 1.3.2-0.17 - Escape macros in %changelog * Thu Feb 8 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.16 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Thu Jul 27 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Sat Feb 11 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.3.2-0.13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1415753 - schema.mysql not in rpm https://bugzilla.redhat.com/show_bug.cgi?id=1415753 [ 2 ] Bug #1673293 - libopendmarc crashes on certain malformed records https://bugzilla.redhat.com/show_bug.cgi?id=1673293 [ 3 ] Bug #1753082 - CVE-2019-16378 opendmarc: Signature-bypass vulnerability with multiple 'From' addresses [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1753082 -------------------------------------------------------------------------------- ================================================================================ perl-Date-Holidays-DE-2.03-1.el6 (FEDORA-EPEL-2019-67e1c8c8d8) Perl module to determine German holidays -------------------------------------------------------------------------------- Update Information: Date::Holidays::DE 2.03 ======================= * Added International Childrens Day for Thueringen starting in 2019 -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 2 2019 Jitka Plesnikova <jplesnik@xxxxxxxxxx> - 2.03-1 - 2.03 bump -------------------------------------------------------------------------------- References: [ 1 ] Bug #1752411 - perl-Date-Holidays-DE-2.03 is available https://bugzilla.redhat.com/show_bug.cgi?id=1752411 -------------------------------------------------------------------------------- ================================================================================ python-copr-1.98-1.el6 (FEDORA-EPEL-2019-2bd300951e) Python interface for Copr -------------------------------------------------------------------------------- Update Information: copr-cli - manpage: update API token url - support multilib projects - fix traceback when lost connection during copr-cli build - adding cheat for copr python-copr: - packaging fixes - python: fix API for marshmallow 3+ (#934) ---- python: fix API for marshmallow 3+ (#934) -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 3 2019 Pavel Raiskup <praiskup@xxxxxxxxxx> 1.98-1 - enable dynamic buildrequires on F31+ - drop comments after %endif * Thu Sep 26 2019 Pavel Raiskup <praiskup@xxxxxxxxxx> 1.97-1 - python: fix API for marshmallow 3+ (#934) - frontend, cli, python: support multilib projects (#1) -------------------------------------------------------------------------------- ================================================================================ singularity-3.4.1-1.2.el6 (FEDORA-EPEL-2019-64f83ca2ce) Application and environment virtualization -------------------------------------------------------------------------------- Update Information: Add PR #4522 to fix sandbox rootless builds ---- Update to upstream 3.4.0-1, keeping only config fakeroot cli PR #4346 -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2019 Dave Dykstra <dwd@xxxxxxxxxxxxxxxxx> - 3.4.1-1.2 - Add PR #4522 to fix sandbox rootless builds * Mon Sep 23 2019 Dave Dykstra <dwd@xxxxxxxxxxxxxxxxx> - 3.4.1-1.1 - Update to upstream 3.4.0-1, keeping only config fakeroot cli PR #4346 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1753387 - singularity-3.4.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1753387 -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx