The following Fedora EPEL 7 Security updates need testing: Age URL 66 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-f005e1b879 debmirror-2.35-1.el7 4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-70fe95babd openssl11-1.1.1k-2.el7 The following builds have been pushed to Fedora EPEL 7 updates-testing libdxfrw-1.0.1-1.el7 librecad-2.2.0-0.11.rc2.el7 ncview-2.1.8-14.el7 Details about builds: ================================================================================ libdxfrw-1.0.1-1.el7 (FEDORA-EPEL-2021-cd37548bc5) Library to read/write DXF files -------------------------------------------------------------------------------- Update Information: Update libdxfrw to 1.0.1 (from upstream git). Rebuild librecad against it. This fixes CVE-2021-21898, CVE-2021-21899, and CVE-2021-21900. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 22 2021 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.0.1-1 - rebase to new code home, fixes CVE-2021-21898/21899/21900 * Thu Jul 22 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Thu May 27 2021 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.3-18 - disable rpath * Tue Jan 26 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-17 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Thu Dec 31 2020 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.3-16 - more fixes from LibreCAD git * Wed Nov 4 2020 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.3-15 - add all of the current fixes from LibreCAD git * Tue Jul 28 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Wed Jan 29 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Thu Jul 25 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Fri Feb 1 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Nov 12 2018 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.3-10 - add fix from librecad for CVE-2018-19105 * Fri Jul 13 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Feb 7 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Wed Jul 26 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Mon May 15 2017 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.6.3-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_27_Mass_Rebuild * Fri Feb 10 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Mon Jun 6 2016 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.3-3 - apply changes from LibreCad 2.1.0 * Thu Feb 4 2016 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.6.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Tue Jan 12 2016 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.3-1 - update to 0.6.3 * Fri Sep 11 2015 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 0.6.1-1 - update to 0.6.1 * Wed Jun 17 2015 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.5.11-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Sat May 2 2015 Kalev Lember <kalevlember@xxxxxxxxx> - 0.5.11-5 - Rebuilt for GCC 5 C++11 ABI change * Thu Mar 26 2015 Kalev Lember <kalevlember@xxxxxxxxx> - 0.5.11-4 - Rebuilt for GCC 5 ABI change * Sun Aug 17 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.5.11-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2025628 - CVE-2021-21899 librecad: heap out-of-bounds write in dwgCompressor:copyCompBytes21 https://bugzilla.redhat.com/show_bug.cgi?id=2025628 [ 2 ] Bug #2025631 - CVE-2021-21900 librecad: use-after-free in dxfRW:processLType() https://bugzilla.redhat.com/show_bug.cgi?id=2025631 [ 3 ] Bug #2025634 - CVE-2021-21898 librecad: out-of-bounds write in dwgCompressor:decompress18() https://bugzilla.redhat.com/show_bug.cgi?id=2025634 -------------------------------------------------------------------------------- ================================================================================ librecad-2.2.0-0.11.rc2.el7 (FEDORA-EPEL-2021-cd37548bc5) Computer Assisted Design (CAD) Application -------------------------------------------------------------------------------- Update Information: Update libdxfrw to 1.0.1 (from upstream git). Rebuild librecad against it. This fixes CVE-2021-21898, CVE-2021-21899, and CVE-2021-21900. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 22 2021 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.2.0-0.11.rc2 - rebuild against new libdxfrw - rebase to 1d31427 * Thu Jul 22 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.0-0.10.rc2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.0-0.9.rc2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Thu Dec 31 2020 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.2.0-0.8.rc2 - update to rc2 * Wed Nov 4 2020 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.2.0-0.7.rc1 - update to latest git main * Tue Jul 28 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.0-0.6.rc1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Wed Jan 29 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.0-0.5.rc1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Thu Jul 25 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.0-0.4.rc1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Thu Jun 6 2019 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.2.0-0.3.rc1 - apply fix for non-unique shared object naming conflicts * Fri Feb 1 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.0-0.2.rc1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Jul 23 2018 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.2.0-0.1.rc1 - update to 2.2.0-rc1 - add BuildRequires: gcc-c++ * Fri Jul 13 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.0-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Feb 7 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.0-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Wed Jul 26 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Fri Feb 10 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.0-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Fri Jan 27 2017 Jonathan Wakely <jwakely@xxxxxxxxxx> - 2.1.0-3 - Rebuilt for Boost 1.63 * Sun Dec 11 2016 Igor Gnatenko <ignatenko@xxxxxxxxxx> - 2.1.0-2 - Rebuild for shapelib SONAME bump * Mon Jun 6 2016 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.1.0-1 - update to 2.1.0 * Mon May 16 2016 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.0.10-1 - update to 2.0.10 * Thu Feb 4 2016 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.0.9-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Fri Jan 15 2016 Jonathan Wakely <jwakely@xxxxxxxxxx> - 2.0.9-2 - Rebuilt for Boost 1.60 * Tue Jan 12 2016 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.0.9-1 - update to 2.0.9 * Fri Sep 11 2015 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.0.8-1 - update to 2.0.8 * Thu Aug 27 2015 Jonathan Wakely <jwakely@xxxxxxxxxx> - 2.0.7-8 - Rebuilt for Boost 1.59 * Wed Jul 29 2015 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.0.7-7 - Rebuilt for https://fedoraproject.org/wiki/Changes/F23Boost159 * Wed Jul 22 2015 David Tardon <dtardon@xxxxxxxxxx> - 2.0.7-6 - rebuild for Boost 1.58 * Wed Jun 17 2015 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.0.7-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Sat May 2 2015 Kalev Lember <kalevlember@xxxxxxxxx> - 2.0.7-4 - Rebuilt for GCC 5 C++11 ABI change * Thu Mar 26 2015 Richard Hughes <rhughes@xxxxxxxxxx> - 2.0.7-3 - Add an AppData file for the software center * Tue Jan 27 2015 Petr Machata <pmachata@xxxxxxxxxx> - 2.0.7-2 - Rebuild for boost 1.57.0 * Mon Jan 5 2015 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.0.7-1 - update to 2.0.7 * Wed Nov 5 2014 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 2.0.6-1 - update to 2.0.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2025628 - CVE-2021-21899 librecad: heap out-of-bounds write in dwgCompressor:copyCompBytes21 https://bugzilla.redhat.com/show_bug.cgi?id=2025628 [ 2 ] Bug #2025631 - CVE-2021-21900 librecad: use-after-free in dxfRW:processLType() https://bugzilla.redhat.com/show_bug.cgi?id=2025631 [ 3 ] Bug #2025634 - CVE-2021-21898 librecad: out-of-bounds write in dwgCompressor:decompress18() https://bugzilla.redhat.com/show_bug.cgi?id=2025634 -------------------------------------------------------------------------------- ================================================================================ ncview-2.1.8-14.el7 (FEDORA-EPEL-2021-d2dc3d28aa) A visual browser for netCDF format files -------------------------------------------------------------------------------- Update Information: Update to 2.1.8 -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 11 2021 Orion Poplawski <orion@xxxxxxxx> - 2.1.8-14 - Rebuild for netcdf 4.8.0 * Tue Aug 10 2021 Orion Poplawski <orion@xxxxxxxx> - 2.1.8-13 - Rebuild for netcdf 4.8.0 * Thu Jul 22 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Tue Jan 26 2021 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Tue Jul 28 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Wed Jan 29 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Thu Jul 25 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Mon Mar 18 2019 Orion Poplawski <orion@xxxxxxxx> - 2.1.8-7 - Rebuild for netcdf 4.6.3 * Fri Feb 1 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Fri Jul 13 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Thu Feb 8 2018 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Wed Jul 26 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild * Wed Mar 8 2017 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.8-1 - Update to 2.1.8 * Fri Feb 10 2017 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.7-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild * Tue Mar 29 2016 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.7-1 - Update to 2.1.7 * Mon Mar 28 2016 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.6-1 - Update to 2.1.6 - Update license to GPLv3 * Thu Feb 4 2016 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.1.5-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild * Fri Jan 22 2016 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.5-3 - Rebuild for netcdf 4.4.0 * Wed Jun 17 2015 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.1.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Wed Mar 18 2015 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.5-1 - Update to 2.1.5 * Fri Nov 14 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.4-1 - Update to 2.1.4 * Sat Nov 1 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 2.1.3-1 - Update to 2.1.3 - Cleanup spec * Sun Aug 17 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.1.2-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.1.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.1.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure