Fedora EPEL 9 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The following Fedora EPEL 9 Security updates need testing:
 Age  URL
   4  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-7a05e8decc   rdiff-backup-2.2.6-3.el9
   0  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-4b1b8b8b25   llhttp-9.1.3-1.el9 python-aiohttp-3.9.1-1.el9


The following builds have been pushed to Fedora EPEL 9 updates-testing

    assimp-5.2.5-1.el9
    chromium-120.0.6099.109-1.el9
    composefs-1.0.2-1.el9
    lagrange-1.17.5-1.el9
    netcdf-cxx4-4.3.1-3.el9
    netdata-1.44.1-1.el9
    python-colcon-override-check-0.0.1-1.el9
    python-sphinx-mdinclude-0.5.3-4.el9
    squashfs-tools-ng-1.2.0-3.el9
    the_foundation-1.7.0-1.el9

Details about builds:


================================================================================
 assimp-5.2.5-1.el9 (FEDORA-EPEL-2023-d3f80c2d82)
 Library to import various 3D model formats into applications
--------------------------------------------------------------------------------
Update Information:

Initial build of assimp in EPEL 9
--------------------------------------------------------------------------------
ChangeLog:

* Fri Nov 24 2023 Rich Mattes <richmattes@xxxxxxxxx> - 5.2.5-1
- Add check section and fix ctest configuration
* Thu Oct 26 2023 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 5.2.5-1
- Ensure stb_image contains the latest CVE patches
* Fri Jul 28 2023 Scott K Logan <logans@xxxxxxxxxxx> - 5.2.5-1
- Update to release 5.2.5
* Wed Jul 19 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 5.0.1-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Tue Jun 13 2023 Python Maint <python-maint@xxxxxxxxxx> - 5.0.1-11
- Rebuilt for Python 3.12
* Wed Jan 18 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 5.0.1-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Wed Jul 20 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 5.0.1-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Mon Jun 13 2022 Python Maint <python-maint@xxxxxxxxxx> - 5.0.1-8
- Rebuilt for Python 3.11
* Sat Apr 23 2022 Benjamin A. Beasley <code@xxxxxxxxxxxxxxxxxx> - 5.0.1-7
- Security fix for CVE-2022-28041
- Drop dependency on pkgconfig(zzip-zlib-config), no longer available in
  zziplib; use zlib directly instead
* Wed Jan 19 2022 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 5.0.1-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Thu Dec 30 2021 Rich Mattes <richmattes@xxxxxxxxx> - 5.0.1-5
- Correct Unlicense shortname (rhbz#2036000)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2147378 - Please branch and build assimp for EPEL 9
        https://bugzilla.redhat.com/show_bug.cgi?id=2147378
--------------------------------------------------------------------------------


================================================================================
 chromium-120.0.6099.109-1.el9 (FEDORA-EPEL-2023-0bdf9bf395)
 A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:

update to 120.0.6099.109     - High CVE-2023-6702: Type Confusion in V8    -
High CVE-2023-6703: Use after free in Blink    - High CVE-2023-6704: Use after
free in libavif    - High CVE-2023-6705: Use after free in WebRTC    - High
CVE-2023-6706: Use after free in FedCM    - Medium CVE-2023-6707: Use after free
in CSS   ----  Update to 120.0.6099.71  ----  Update to 120.0.6099.62, upstream
release fixes follow security issues:  * High CVE-2023-6508: Use after free in
Media Stream * High CVE-2023-6509: Use after free in Side Panel Search * Medium
CVE-2023-6510: Use after free in Media Capture * Low CVE-2023-6511:
Inappropriate implementation in Autofill * Low CVE-2023-6512: Inappropriate
implementation in Web Browser UI   ----  update to 119.0.6045.199, upstream
security release  * High CVE-2023-6348: Type Confusion in Spellcheck * High
CVE-2023-6347: Use after free in Mojo * High CVE-2023-6346: Use after free in
WebAudio * High CVE-2023-6350: Out of bounds memory access in libavif * High
CVE-2023-6351: Use after free in libavif * High CVE-2023-6345: Integer overflow
in Skia
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec 13 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.109-1
- update to 120.0.6099.109
   * High CVE-2023-6702: Type Confusion in V8
   * High CVE-2023-6703: Use after free in Blink
   * High CVE-2023-6704: Use after free in libavif
   * High CVE-2023-6705: Use after free in WebRTC
   * High CVE-2023-6706: Use after free in FedCM
   * Medium CVE-2023-6707: Use after free in CSS
* Fri Dec  8 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.71-1
- update to 120.0.6099.71
* Wed Dec  6 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec  5 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec  2 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.56-1
- update to 120.0.6099.56 
- enable qt6 UI backend
* Sat Dec  2 2023 Than Ngo <than@xxxxxxxxxx> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than@xxxxxxxxxx> - 119.0.6045.199-1
- update to 119.0.6045.199
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2252009
  [ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2252188
  [ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2252191
  [ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253151
  [ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253154
  [ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253157
  [ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253161
  [ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------


================================================================================
 composefs-1.0.2-1.el9 (FEDORA-EPEL-2023-06857c55bb)
 Tools to handle creating and mounting composefs images
--------------------------------------------------------------------------------
Update Information:

Merge branch 'f39' into epel9
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 14 2023 Stephen Smoogen <ssmoogen@xxxxxxxxxx> - 1.0.2-4
- RPMAUTOSPEC: unresolvable merge
--------------------------------------------------------------------------------


================================================================================
 lagrange-1.17.5-1.el9 (FEDORA-EPEL-2023-922d85ed2e)
 A Beautiful Gemini Client
--------------------------------------------------------------------------------
Update Information:

Latest 1.17 release, see https://git.skyjake.fi/gemini/lagrange/releases for
changes since 1.16.7
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec 13 2023 Michel Lind <salimma@xxxxxxxxxxxxxxxxx> - 1.17.5-1
- Update to 1.17.5
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2242724 - the_foundation-1.7.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242724
  [ 2 ] Bug #2242736 - lagrange-1.17.5 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242736
--------------------------------------------------------------------------------


================================================================================
 netcdf-cxx4-4.3.1-3.el9 (FEDORA-EPEL-2023-2c9887c834)
 NetCDF-4 C++ library
--------------------------------------------------------------------------------
Update Information:

Build for EPEL9
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jul 28 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 4.3.1-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Wed Jan 29 2020 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 4.3.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Fri Sep 13 2019 Orion Poplawski <orion@xxxxxxxx> - 4.3.1-1
- Update to 4.3.1
* Thu Jul 25 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 4.3.0-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Mon Mar 18 2019 Orion Poplawski <orion@xxxxxxxx> - 4.3.0-10
- Rebuild for netcdf 4.6.3
* Thu Feb 14 2019 Orion Poplawski <orion@xxxxxxxx> - 4.3.0-9
- Rebuild for openmpi 3.1.3
* Fri Feb  1 2019 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 4.3.0-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2254155 - Requesting EPEL9 build of netcdf-cxx4
        https://bugzilla.redhat.com/show_bug.cgi?id=2254155
--------------------------------------------------------------------------------


================================================================================
 netdata-1.44.1-1.el9 (FEDORA-EPEL-2023-08ecbbe861)
 Real-time performance monitoring
--------------------------------------------------------------------------------
Update Information:

Update from upstream  ----  Update from upstream
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 14 2023 Didier Fabert <didier.fabert@xxxxxxxxx> 1.44.1-1
- Update from upstream
* Thu Dec  7 2023 Didier Fabert <didier.fabert@xxxxxxxxx> 1.44.0-1
- Update from upstream
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2254283 - netdata-1.44.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2254283
--------------------------------------------------------------------------------


================================================================================
 python-colcon-override-check-0.0.1-1.el9 (FEDORA-EPEL-2023-16b9ae7a4b)
 Extension for colcon to check for problems overriding installed packages
--------------------------------------------------------------------------------
Update Information:

Initial build of the `colcon-override-check` package.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Nov 10 2022 Scott K Logan <logans@xxxxxxxxxxx> - 0.0.1-1
- Initial package (rhbz#2143071)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2143071 - Review Request: python-colcon-override-check - Extension for colcon to check for problems overriding installed packages
        https://bugzilla.redhat.com/show_bug.cgi?id=2143071
--------------------------------------------------------------------------------


================================================================================
 python-sphinx-mdinclude-0.5.3-4.el9 (FEDORA-EPEL-2023-0497248ae5)
 Markdown extension for Sphinx
--------------------------------------------------------------------------------
Update Information:

Initial EPEL 9 release
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 14 2023 Michel Lind <salimma@xxxxxxxxxxxxxxxxx> - 0.5.3-4
- Relax Pygments requirement for EL9 build
* Fri Jul 21 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 0.5.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jun 15 2023 Python Maint <python-maint@xxxxxxxxxx> - 0.5.3-2
- Rebuilt for Python 3.12
* Sat Mar 18 2023 Michel Alexandre Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.5.3-1
- Initial Fedora package
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2223062 - Please branch and build python-sphinx-mdinclude for EPEL9
        https://bugzilla.redhat.com/show_bug.cgi?id=2223062
--------------------------------------------------------------------------------


================================================================================
 squashfs-tools-ng-1.2.0-3.el9 (FEDORA-EPEL-2023-5282355c4c)
 A new set of tools and libraries for working with SquashFS images
--------------------------------------------------------------------------------
Update Information:

Add libselinux-devel build dep.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 14 2023 David Trudgian <david.trudgian@xxxxxxxxx> - 1.2.0-3
- RPMAUTOSPEC: unresolvable merge
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2254110 - squashfs-tools-ng needs libselinux-devel
        https://bugzilla.redhat.com/show_bug.cgi?id=2254110
--------------------------------------------------------------------------------


================================================================================
 the_foundation-1.7.0-1.el9 (FEDORA-EPEL-2023-922d85ed2e)
 Opinionated C11 library for low-level functionality
--------------------------------------------------------------------------------
Update Information:

Latest 1.17 release, see https://git.skyjake.fi/gemini/lagrange/releases for
changes since 1.16.7
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec 13 2023 Michel Lind <salimma@xxxxxxxxxxxxxxxxx> - 1.7.0-1
- Update to 1.7.0
* Sat Jul 22 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2242724 - the_foundation-1.7.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242724
  [ 2 ] Bug #2242736 - lagrange-1.17.5 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242736
--------------------------------------------------------------------------------

--
_______________________________________________
epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Index of Archives]     [Fedora Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Announce]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Linux Apps]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux