The following Fedora EPEL 7 Security updates need testing: Age URL 3 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-7f33ec2b58 proftpd-1.3.5e-11.el7 The following builds have been pushed to Fedora EPEL 7 updates-testing drupal7-7.82-1.el7 python-rpm-head-signing-1.4.1-1.el7 Details about builds: ================================================================================ drupal7-7.82-1.el7 (FEDORA-EPEL-2021-8f7f2eda61) An open-source content-management platform -------------------------------------------------------------------------------- Update Information: - https://www.drupal.org/project/drupal/releases/7.82 - https://www.drupal.org/sa-core-2021-004 (CVE-2021-32610) - https://www.drupal.org/project/drupal/releases/7.81 - https://www.drupal.org/project/drupal/releases/7.80 - https://www.drupal.org/sa-core-2021-002 (CVE-2020-13672) - https://www.drupal.org/project/drupal/releases/7.79 - https://www.drupal.org/project/drupal/releases/7.78 - https://www.drupal.org/sa-core-2021-001 (CVE-2020-36193) - https://www.drupal.org/project/drupal/releases/7.77 - https://www.drupal.org/project/drupal/releases/7.76 - https://www.drupal.org/project/drupal/releases/7.75 - https://www.drupal.org/sa-core-2020-013 (CVE-2020-28949, CVE-2020-28948) -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 8 2021 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> - 7.82-1 - Update to 7.82 - SA-CORE-2020-013 / CVE-2020-28948 / CVE-2020-28949 - SA-CORE-2021-001 / CVE-2020-36193 - SA-CORE-2021-002 / CVE-2020-13672 (RHBZ #1953010, #1953011) - SA-CORE-2021-004 / CVE-2021-32610 * Wed Jul 21 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 7.74-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 7.74-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1953010 - drupal7: drupal: Cross-site scripting - SA-CORE-2021-002 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1953010 [ 2 ] Bug #1953011 - drupal7: drupal: Cross-site scripting - SA-CORE-2021-002 [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1953011 -------------------------------------------------------------------------------- ================================================================================ python-rpm-head-signing-1.4.1-1.el7 (FEDORA-EPEL-2021-a463ea5717) Small python module to extract RPM header and file digests -------------------------------------------------------------------------------- Update Information: Ensure xattrs are passed in as bytes -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 10 2021 Patrick Uiterwijk <patrick@xxxxxxxxxxxxxx> - 1.4.1-1 - Ensure xattrs are passed in as bytes -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure