Fedora EPEL 8 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The following Fedora EPEL 8 Security updates need testing:
 Age  URL
   5  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-76db503610   seamonkey-2.53.18-1.el8
   4  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2023-ad7d095358   rdiff-backup-2.2.6-3.el8


The following builds have been pushed to Fedora EPEL 8 updates-testing

    chromium-120.0.6099.109-1.el8
    lagrange-1.17.5-1.el8
    netdata-1.44.1-1.el8
    python-colcon-override-check-0.0.1-1.el8
    squashfs-tools-ng-1.2.0-3.el8
    the_foundation-1.7.0-1.el8

Details about builds:


================================================================================
 chromium-120.0.6099.109-1.el8 (FEDORA-EPEL-2023-a79d31df77)
 A WebKit (Blink) powered web browser that Google doesn't want you to use
--------------------------------------------------------------------------------
Update Information:

update to 120.0.6099.109     - High CVE-2023-6702: Type Confusion in V8    -
High CVE-2023-6703: Use after free in Blink    - High CVE-2023-6704: Use after
free in libavif    - High CVE-2023-6705: Use after free in WebRTC    - High
CVE-2023-6706: Use after free in FedCM    - Medium CVE-2023-6707: Use after free
in CSS   ----  Update to 120.0.6099.71  ----  Update to 120.0.6099.62, upstream
release fixes follow security issues:  * High CVE-2023-6508: Use after free in
Media Stream * High CVE-2023-6509: Use after free in Side Panel Search * Medium
CVE-2023-6510: Use after free in Media Capture * Low CVE-2023-6511:
Inappropriate implementation in Autofill * Low CVE-2023-6512: Inappropriate
implementation in Web Browser UI   ----  update to 119.0.6045.199, upstream
security release  * High CVE-2023-6348: Type Confusion in Spellcheck * High
CVE-2023-6347: Use after free in Mojo * High CVE-2023-6346: Use after free in
WebAudio * High CVE-2023-6350: Out of bounds memory access in libavif * High
CVE-2023-6351: Use after free in libavif * High CVE-2023-6345: Integer overflow
in Skia
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec 13 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.109-1
- update to 120.0.6099.109
   * High CVE-2023-6702: Type Confusion in V8
   * High CVE-2023-6703: Use after free in Blink
   * High CVE-2023-6704: Use after free in libavif
   * High CVE-2023-6705: Use after free in WebRTC
   * High CVE-2023-6706: Use after free in FedCM
   * Medium CVE-2023-6707: Use after free in CSS
* Fri Dec  8 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.71-1
- update to 120.0.6099.71
* Wed Dec  6 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.62-2
- drop unsupported ldflag which caused build failure
* Tue Dec  5 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.62-1
- update to 120.0.6099.62
- fixed bz#2252874, built with control flow integrity (CFI) support
* Sat Dec  2 2023 Than Ngo <than@xxxxxxxxxx> - 120.0.6099.56-1
- update to 120.0.6099.56 
- enable qt6 UI backend
* Sat Dec  2 2023 Than Ngo <than@xxxxxxxxxx> - 119.0.6045.199-2
- fixed bz#2242271, built with bundleminizip in fedora > 39
- fixed bz#2251884, built with fstack-protector-strong for improved security
* Wed Nov 29 2023 Than Ngo <than@xxxxxxxxxx> - 119.0.6045.199-1
- update to 119.0.6045.199
* Sun Nov 19 2023 Than Ngo <than@xxxxxxxxxx> - 119.0.6045.159-2
- fix ffmpeg conflicts
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2252009 - CVE-2023-6346 CVE-2023-6347 CVE-2023-6350 CVE-2023-6351 chromium: various flaws [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2252009
  [ 2 ] Bug #2252188 - CVE-2023-6345 chromium: chromium-browser: Integer overflow [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2252188
  [ 3 ] Bug #2252191 - CVE-2023-6348 chromium: chromium-browser: Type Confusion in Spellcheck [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2252191
  [ 4 ] Bug #2253151 - CVE-2023-6508 chromium: Use after free in Media Stream [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253151
  [ 5 ] Bug #2253154 - CVE-2023-6509 chromium: Use after free in Side Panel Search [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253154
  [ 6 ] Bug #2253157 - CVE-2023-6510 chromium: Use after free in Media Capture [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253157
  [ 7 ] Bug #2253161 - CVE-2023-6511 chromium: Inappropriate implementation in Autofill [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253161
  [ 8 ] Bug #2253164 - CVE-2023-6512 chromium: Inappropriate implementation in Web Browser UI [epel-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=2253164
--------------------------------------------------------------------------------


================================================================================
 lagrange-1.17.5-1.el8 (FEDORA-EPEL-2023-2ae1e3d0dc)
 A Beautiful Gemini Client
--------------------------------------------------------------------------------
Update Information:

Latest 1.17 release, see https://git.skyjake.fi/gemini/lagrange/releases for
changes since 1.16.7
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec 13 2023 Michel Lind <salimma@xxxxxxxxxxxxxxxxx> - 1.17.5-1
- Update to 1.17.5
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2242724 - the_foundation-1.7.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242724
  [ 2 ] Bug #2242736 - lagrange-1.17.5 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242736
--------------------------------------------------------------------------------


================================================================================
 netdata-1.44.1-1.el8 (FEDORA-EPEL-2023-3701a5686c)
 Real-time performance monitoring
--------------------------------------------------------------------------------
Update Information:

Update from upstream  ----  Update from upstream
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 14 2023 Didier Fabert <didier.fabert@xxxxxxxxx> 1.44.1-1
- Update from upstream
* Thu Dec  7 2023 Didier Fabert <didier.fabert@xxxxxxxxx> 1.44.0-1
- Update from upstream
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2254283 - netdata-1.44.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2254283
--------------------------------------------------------------------------------


================================================================================
 python-colcon-override-check-0.0.1-1.el8 (FEDORA-EPEL-2023-28c9266d57)
 Extension for colcon to check for problems overriding installed packages
--------------------------------------------------------------------------------
Update Information:

Initial build of the `colcon-override-check` package.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Nov 10 2022 Scott K Logan <logans@xxxxxxxxxxx> - 0.0.1-1
- Initial package (rhbz#2143071)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2143071 - Review Request: python-colcon-override-check - Extension for colcon to check for problems overriding installed packages
        https://bugzilla.redhat.com/show_bug.cgi?id=2143071
--------------------------------------------------------------------------------


================================================================================
 squashfs-tools-ng-1.2.0-3.el8 (FEDORA-EPEL-2023-4aabe0950f)
 A new set of tools and libraries for working with SquashFS images
--------------------------------------------------------------------------------
Update Information:

Add libselinux-devel build dep.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Dec 14 2023 David Trudgian <david.trudgian@xxxxxxxxx> - 1.2.0-3
- RPMAUTOSPEC: unresolvable merge
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2254110 - squashfs-tools-ng needs libselinux-devel
        https://bugzilla.redhat.com/show_bug.cgi?id=2254110
--------------------------------------------------------------------------------


================================================================================
 the_foundation-1.7.0-1.el8 (FEDORA-EPEL-2023-2ae1e3d0dc)
 Opinionated C11 library for low-level functionality
--------------------------------------------------------------------------------
Update Information:

Latest 1.17 release, see https://git.skyjake.fi/gemini/lagrange/releases for
changes since 1.16.7
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec 13 2023 Michel Lind <salimma@xxxxxxxxxxxxxxxxx> - 1.7.0-1
- Update to 1.7.0
* Sat Jul 22 2023 Fedora Release Engineering <releng@xxxxxxxxxxxxxxxxx> - 1.6.1-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2242724 - the_foundation-1.7.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242724
  [ 2 ] Bug #2242736 - lagrange-1.17.5 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=2242736
--------------------------------------------------------------------------------

--
_______________________________________________
epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue




[Index of Archives]     [Fedora Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Announce]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Linux Apps]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux