Fedora EPEL 8 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The following Fedora EPEL 8 Security updates need testing:
 Age  URL
   5  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-1d852648ca   libssh2-1.10.0-1.el8


The following builds have been pushed to Fedora EPEL 8 updates-testing

    borgbackup-1.1.18-2.el8
    calceph-3.5.3-2.el8
    chromium-116.0.5845.179-1.el8
    eccodes-2.31.0-1.el8
    gitqlient-1.6.2-1.el8
    lexertl14-0.1.0-18.20230904git86c90c3.el8
    python-calcephpy-3.5.3-2.el8
    rdiff-backup-2.2.6-1.el8

Details about builds:


================================================================================
 borgbackup-1.1.18-2.el8 (FEDORA-EPEL-2023-9c17eb827f)
 A deduplicating backup program with compression and authenticated encryption
--------------------------------------------------------------------------------
Update Information:

fix for CVE-2023-36811: spoofed archive leads to data loss  This version
contains additional patches on top of 1.1.18 to fix the CVE mentioned above. The
release notes for borgbackup 1.2.5+ regarding TAM authentication apply to this
version as well:
https://github.com/borgbackup/borg/blob/1.2.6/docs/changes.rst#pre-125-archives-
spoofing-vulnerability-cve-2023-36811
--------------------------------------------------------------------------------
ChangeLog:

* Fri Sep  8 2023 Felix Schwarz <fschwarz@xxxxxxxxxxxxxxxxx> - 1.1.18-2
- add patches to fix CVE-2023-36811
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2236304 - CVE-2023-36811 borgbackup: spoofed archive leads to data loss [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2236304
--------------------------------------------------------------------------------


================================================================================
 calceph-3.5.3-2.el8 (FEDORA-EPEL-2023-71a0ccc267)
 Astronomical library to access planetary ephemeris files
--------------------------------------------------------------------------------
Update Information:

Update to 3.5.3
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  9 2023 Mattia Verga <mattia.verga@xxxxxxxxx> - 3.5.3-2
- Correctly disable static libs building
* Wed Sep  6 2023 Mattia Verga <mattia.verga@xxxxxxxxx> - 3.5.3-1
- Update to 3.5.3 (fedora#2237641)
* Wed Jul 19 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 3.5.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 chromium-116.0.5845.179-1.el8 (FEDORA-EPEL-2023-4cc86adbd2)
 A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:

update to 116.0.5845.179. Fixes following security issues: CVE-2023-4427
CVE-2023-4428 CVE-2023-4429 CVE-2023-4430 CVE-2023-4431 CVE-2023-4572
CVE-2023-4761 CVE-2023-4762 CVE-2023-4763 CVE-2023-4764
--------------------------------------------------------------------------------
ChangeLog:

* Fri Sep  8 2023 Than Ngo <than@xxxxxxxxxx> - 116.0.5845.179-1
- update to 116.0.5845.179
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2234749 - CVE-2023-4427 CVE-2023-4428 CVE-2023-4429 CVE-2023-4430 CVE-2023-4431 chromium: various flaws [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2234749
  [ 2 ] Bug #2234750 - CVE-2023-4427 CVE-2023-4428 CVE-2023-4429 CVE-2023-4430 CVE-2023-4431 chromium: various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2234750
  [ 3 ] Bug #2235800 - CVE-2023-4572 chromium: chromium-browser: Use after free in MediaStream [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2235800
  [ 4 ] Bug #2235801 - CVE-2023-4572 chromium: chromium-browser: Use after free in MediaStream [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2235801
  [ 5 ] Bug #2236152 - CVE-2021-29390 chromium: libjpeg-turbo: heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2236152
  [ 6 ] Bug #2237509 - CVE-2023-4761 CVE-2023-4762 CVE-2023-4763 CVE-2023-4764 chromium: various flaws [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2237509
  [ 7 ] Bug #2237510 - CVE-2023-4761 CVE-2023-4762 CVE-2023-4763 CVE-2023-4764 chromium: various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2237510
--------------------------------------------------------------------------------


================================================================================
 eccodes-2.31.0-1.el8 (FEDORA-EPEL-2023-a05ffd9a53)
 WMO data format decoding and encoding
--------------------------------------------------------------------------------
Update Information:

Upgrade to upstream version 2.31.0
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  9 2023 Jos de Kloe <josdekloe@xxxxxxxxx> - 2.31.0-1
- Upgrade to upstream version 2.31.0
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2236797 - request to upgrade to upstream version 2.31.0
        https://bugzilla.redhat.com/show_bug.cgi?id=2236797
--------------------------------------------------------------------------------


================================================================================
 gitqlient-1.6.2-1.el8 (FEDORA-EPEL-2023-c2cce018da)
 Multi-platform Git client written with Qt
--------------------------------------------------------------------------------
Update Information:

Update to latest version
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  9 2023 Artem Polishchuk <ego.cordatus@xxxxxxxxx> - 1.6.2-1
- chore: Update to 1.6.2
* Wed Jul 19 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.6.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
--------------------------------------------------------------------------------


================================================================================
 lexertl14-0.1.0-18.20230904git86c90c3.el8 (FEDORA-EPEL-2023-c85dc6eac3)
 The Modular Lexical Analyser Generator
--------------------------------------------------------------------------------
Update Information:

Update to the latest commit
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-18
- Use a proper patch to fix multilib paths, and offer it upstream
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-16
- Improve the Summary
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-15
- Update to 86c90c3 (Restore the ability to run tests with BUILD_TESTING
  and ctest)
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-14
- Update to 5bd3180
- Changed from std::size_t to uint16_t for ease of use
- Added missing #include and functions
- regex macro BOL and EOL fixes
- Added exit state syntax check for missing right chevron
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-13
- Update to c4bcaf8
- More SonarLint etc changes
- Applied SA changes
- Added tests
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-12
- Update to 2e2893c
- Added replace.hpp
- Now throwing exception in case of stack underflow
- Updated serialization support
- More use of auto
- Use cend()
- More UTF-32 support
- Added stream_num.hpp
- Fixed #include
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-11
- Update to aeddda8 (Unicode 15.1.0 and other minor enhancements)
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-10
- Indicate dirs. in files list with trailing slashes
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-9
- Update to 8b8ead2 (Update to the latest Unicode standard)
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-8
- Update License to SPDX
* Sat Sep  9 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 0.1.0-7
- Update to cd5a1f1 (Unicode 15)
--------------------------------------------------------------------------------


================================================================================
 python-calcephpy-3.5.3-2.el8 (FEDORA-EPEL-2023-71a0ccc267)
 Astronomical library to access planetary ephemeris files
--------------------------------------------------------------------------------
Update Information:

Update to 3.5.3
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  9 2023 Mattia Verga <mattia.verga@xxxxxxxxxx> - 3.5.3-2
- Fix build flags
* Wed Sep  6 2023 Mattia Verga <mattia.verga@xxxxxxxxxx> - 3.5.3-1
- Update to 3.5.3 (fedora#2237640)
- Fix compatibility with Cython 3.x (fedora#2226167)
* Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 3.5.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Tue Jun 13 2023 Python Maint <python-maint@xxxxxxxxxx> - 3.5.2-2
- Rebuilt for Python 3.12
--------------------------------------------------------------------------------


================================================================================
 rdiff-backup-2.2.6-1.el8 (FEDORA-EPEL-2023-6c95ab5e24)
 Convenient and transparent local/remote incremental mirror/backup
--------------------------------------------------------------------------------
Update Information:

Final minor release v2.2.6 - Fedora/EPEL Release
--------------------------------------------------------------------------------
ChangeLog:

* Sat Sep  9 2023 Frank Crawford <frank@xxxxxxxxxxxxxxxxxx> - 2.2.6-2
- Final minor release v2.2.6 - Fedora/EPEL Release
* Fri Sep  8 2023 Frank Crawford <frank@xxxxxxxxxxxxxxxxxx> - 2.2.6-1
- Final minor release v2.2.6 - COPR Release
* Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 2.2.5-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Tue Jun 13 2023 Python Maint <python-maint@xxxxxxxxxx> - 2.2.5-3
- Rebuilt for Python 3.12
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2238101 - rdiff-backup-2.2.6 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2238101
--------------------------------------------------------------------------------

_______________________________________________
epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Index of Archives]     [Fedora Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Announce]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Linux Apps]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux