The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/feh-1.14.1-1.fc14 https://admin.fedoraproject.org/updates/subversion-1.6.17-1.fc14 https://admin.fedoraproject.org/updates/drupal7-7.4-1.fc14 https://admin.fedoraproject.org/updates/wordpress-3.1.4-1.fc14 https://admin.fedoraproject.org/updates/dokuwiki-0-0.8.20110525.a.fc14 https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-2.git20110622.fc14 https://admin.fedoraproject.org/updates/mingw32-libpng-1.4.3-2.fc14 https://admin.fedoraproject.org/updates/libpng10-1.0.54-3.fc14 https://admin.fedoraproject.org/updates/asterisk-1.6.2.19-1.fc14 https://admin.fedoraproject.org/updates/tomcat6-6.0.26-21.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 https://admin.fedoraproject.org/updates/oprofile-0.9.6-21.fc14 https://admin.fedoraproject.org/updates/blender-2.49b-14.fc14 https://admin.fedoraproject.org/updates/curl-7.21.0-8.fc14 https://admin.fedoraproject.org/updates/weechat-0.3.5-1.fc14 https://admin.fedoraproject.org/updates/libxml-1.8.17-27.fc14 https://admin.fedoraproject.org/updates/xulrunner-1.9.2.18-1.fc14,firefox-3.6.18-1.fc14,mozvoikko-1.0-22.fc14.1,perl-Gtk2-MozEmbed-0.08-6.fc14.27,gnome-web-photo-0.9-21.fc14.1,galeon-2.0.7-41.fc14.1,gnome-python2-extras-2.25.3-31.fc14.1,thunderbird-3.1.11-1.fc14 https://admin.fedoraproject.org/updates/gdk-pixbuf2-2.22.0-2.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/cronie-1.4.8-2.fc14 https://admin.fedoraproject.org/updates/mash-0.5.22-1.fc14 https://admin.fedoraproject.org/updates/tzdata-2011h-1.fc14 https://admin.fedoraproject.org/updates/python-slip-0.2.17-1.fc14 https://admin.fedoraproject.org/updates/gdk-pixbuf2-2.22.0-2.fc14 https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-2.git20110622.fc14 https://admin.fedoraproject.org/updates/bash-4.1.7-4.fc14 https://admin.fedoraproject.org/updates/perl-5.12.4-146.fc14 https://admin.fedoraproject.org/updates/policycoreutils-2.0.85-30.1.fc14 https://admin.fedoraproject.org/updates/system-config-keyboard-1.3.1-5.fc14 https://admin.fedoraproject.org/updates/fedora-logos-14.0.2-1.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-8.fc14.2 https://admin.fedoraproject.org/updates/pygobject2-2.21.5-4.fc14 https://admin.fedoraproject.org/updates/pcre-8.10-2.fc14 https://admin.fedoraproject.org/updates/libpcap-1.1.1-3.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-3.fc14 https://admin.fedoraproject.org/updates/evolution-exchange-2.32.3-1.fc14,evolution-data-server-2.32.3-1.fc14,evolution-2.32.3-1.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-nouveau-0.0.16-14.20101010git8c8f15c.fc14 https://admin.fedoraproject.org/updates/libconcord-0.23-5.fc14,udev-161-9.fc14,concordance-0.23-2.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 The following builds have been pushed to Fedora 14 updates-testing R-AnnotationDbi-1.14.1-1.fc14 R-Biobase-2.12.1-1.fc14 R-BufferedMatrix-1.16.0-1.fc14 R-DynDoc-1.30.0-1.fc14 R-GeneR-2.22.0-1.fc14 R-IRanges-1.10.4-1.fc14 R-RUnit-0.4.26-2.fc14 R-affy-1.30.0-1.fc14 R-affyio-1.20.0-1.fc14 R-caTools-1.12-1.fc14 R-multtest-2.8.0-1.fc14 R-preprocessCore-1.14.0-1.fc14 R-qvalue-1.26.0-1.fc14 R-tkWidgets-1.30.0-1.fc14 R-widgetTools-1.30.0-1.fc14 asterisk-1.6.2.19-1.fc14 bullet-2.78-1.fc14 cppunit-1.12.1-5.fc14 cups-1.4.7-2.fc14 drupal7-7.4-1.fc14 imgtarget-0.1.4-7.fc14 kde-plasma-networkmanagement-0.9-0.41.1.20110616git.fc14 libphidget-2.1.8.20110615-1.fc14 python-msgpack-0.1.9-2.fc14 python-taboot-0.3.0-1.fc14 rubygem-gem2rpm-0.7.1-1.fc14 scap-workbench-0.4.0-1.fc14 tgif-4.2.5-1.fc14 wordpress-3.1.4-1.fc14 Details about builds: ================================================================================ R-AnnotationDbi-1.14.1-1.fc14 (FEDORA-2011-8883) Annotation Database Interface -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.14.1-1 - Update to version 1.14.1 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.12.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.12.0-1 - Update to version 1.12.0 -------------------------------------------------------------------------------- ================================================================================ R-Biobase-2.12.1-1.fc14 (FEDORA-2011-8883) Base functions for Bioconductor -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 2.12.1-1 - Update to version 2.12.1 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.10.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 2.10.0-1 - Update to version 2.10.0 -------------------------------------------------------------------------------- ================================================================================ R-BufferedMatrix-1.16.0-1.fc14 (FEDORA-2011-8883) A matrix data storage object method from bioconductor -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.16.0-1 - Update to version 1.16.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.14.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.14.0-1 - Update to version 1.14.0 -------------------------------------------------------------------------------- ================================================================================ R-DynDoc-1.30.0-1.fc14 (FEDORA-2011-8883) Functions for dynamic documents -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.30.0-1 - Update to version 1.30.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.28.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.28.0-1 - Update to version 1.28.0 -------------------------------------------------------------------------------- ================================================================================ R-GeneR-2.22.0-1.fc14 (FEDORA-2011-8883) R for genes and sequences analysis -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 2.22.0-1 - Update to version 2.22.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.20.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 2.20.0-1 - Update to version 2.20.0 -------------------------------------------------------------------------------- ================================================================================ R-IRanges-1.10.4-1.fc14 (FEDORA-2011-8883) Low-level containers for storing sets of integer ranges -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.10.4-1 - Update to version 1.10.4 * Tue Mar 15 2011 pingou <pingou@xxxxxxxxxxxx> 1.8.9-1 - Update to version 1.8.9 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.8.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Jan 18 2011 pingou <pingou@xxxxxxxxxxxx> 1.8.8-1 - Update to version 1.8.8 * Mon Dec 13 2010 pingou <pingou@xxxxxxxxxxxx> 1.8.7-1 - Update to version 1.8.7 * Thu Nov 25 2010 pingou <pingou@xxxxxxxxxxxx> 1.8.3-1 - Update to version 1.8.3 * Sun Nov 7 2010 pingou <pingou@xxxxxxxxxxxx> 1.8.2-1 - Update to version 1.8.2 - Change requires from R to R-core * Thu Oct 14 2010 pingou <pingou@xxxxxxxxxxxx> 1.6.17-1 - Update to version 1.6.17 -------------------------------------------------------------------------------- ================================================================================ R-RUnit-0.4.26-2.fc14 (FEDORA-2011-8883) R Unit test framework -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.4.26-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 0.4.26-1 - Update to version 0.4.26 * Thu Oct 14 2010 pingou <pingou@xxxxxxxxxxxx> 0.4.26-1 - Update to version 0.4.26 -------------------------------------------------------------------------------- ================================================================================ R-affy-1.30.0-1.fc14 (FEDORA-2011-8883) Methods for Affymetrix Oligonucleotide Arrays -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.30.0-1 - Update to version 1.30.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.28.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.28.0-1 - Update to version 1.28.0 -------------------------------------------------------------------------------- ================================================================================ R-affyio-1.20.0-1.fc14 (FEDORA-2011-8883) Tools for parsing Affymetrix data files -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.20.0-1 - Update to version 1.20.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.18.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.18.0-1 - Update to version 1.18.0 -------------------------------------------------------------------------------- ================================================================================ R-caTools-1.12-1.fc14 (FEDORA-2011-8883) Tools: moving window statistics, gif, base64, roc auc... -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.12-1 - Update to version 1.12 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.11-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Sat Jan 29 2011 pingou <pingou@xxxxxxxxxxxx> 1.11-2 - Fix URL - Fix source0 which fix the build... * Mon Dec 20 2010 pingou <pingou@xxxxxxxxxxxx> 1.11-1 - Update to version 1.11 -------------------------------------------------------------------------------- ================================================================================ R-multtest-2.8.0-1.fc14 (FEDORA-2011-8883) Multiple hypothesis testing library from Bioconductor -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 2.8.0-1 - Update to version 2.8.0 * Thu Feb 10 2011 pingou <pingou@xxxxxxxxxxxx> 2.6.0-3 - Remove the check section to test build * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.6.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Sat Jan 29 2011 pingou <pingou@xxxxxxxxxxxx> 2.6.0-1 - Update to version 2.6.0 -------------------------------------------------------------------------------- ================================================================================ R-preprocessCore-1.14.0-1.fc14 (FEDORA-2011-8883) A collection of pre-processing functions -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.14.0-1 - Update to version 1.14.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.12.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.12.0-1 - Update to version 1.12.0 -------------------------------------------------------------------------------- ================================================================================ R-qvalue-1.26.0-1.fc14 (FEDORA-2011-8883) Q-value estimation for false discovery rate control -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.26.0-1 - Update to version 1.26.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.24.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Thu Nov 25 2010 pingou <pingou@xxxxxxxxxxxx> 1.24.0-1 - Update to version 1.24.0 -------------------------------------------------------------------------------- ================================================================================ R-tkWidgets-1.30.0-1.fc14 (FEDORA-2011-8883) Widgets to provide user interfaces from bioconductor -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.30.0-1 - Update to version 1.30.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.28.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.28.0-1 - Update to version 1.28.0 -------------------------------------------------------------------------------- ================================================================================ R-widgetTools-1.30.0-1.fc14 (FEDORA-2011-8883) Bioconductor tools to support tcltk widgets -------------------------------------------------------------------------------- Update Information: Update to new Bioconductor -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 22 2011 pingou <pingou@xxxxxxxxxxxx> 1.30.0-1 - Update to version 1.30.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.28.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Tue Oct 26 2010 pingou <pingou@xxxxxxxxxxxx> 1.28.0-1 - Update to version 1.28.0 -------------------------------------------------------------------------------- ================================================================================ asterisk-1.6.2.19-1.fc14 (FEDORA-2011-8914) The Open Source PBX -------------------------------------------------------------------------------- Update Information: The Asterisk Development Team has announced the final maintenance release of Asterisk, version 1.6.2.19. This release is available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/ Please note that Asterisk 1.6.2.19 is the final maintenance release from the 1.6.2 branch. Support for security related issues will continue until April 21, 2012. For more information about support of the various Asterisk branches, see https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions The release of Asterisk 1.6.2.19 resolves several issues reported by the community and would have not been possible without your participation. Thank you! The following is a sample of the issues resolved in this release: * Don't broadcast FullyBooted to every AMI connection The FullyBooted event should not be sent to every AMI connection every time someone connects via AMI. It should only be sent to the user who just connected. (Closes issue #18168. Reported, patched by FeyFre) * Fix thread blocking issue in the sip TCP/TLS implementation. (Closes issue #18497. Reported by vois. Tested by vois, rossbeer, kowalma, Freddi_Fonet. Patched by dvossel) * Don't delay DTMF in core bridge while listening for DTMF features. (Closes issue #15642, #16625. Reported by jasonshugart, sharvanek. Tested by globalnetinc, jde. Patched by oej, twilson) * Fix chan_local crashs in local_fixup() Thanks OEJ for tracking down the issue and submitting the patch. (Closes issue #19053. Reported, patched by oej) * Don't offer video to directmedia callee unless caller offered it as well (Closes issue #19195. Reported, patched by one47) Additionally security announcements AST-2011-008, AST-2011-010, and AST-2011-011 have been resolved in this release. For a full list of changes in this release, please see the ChangeLog: http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.19 The Asterisk Development Team has announced the release of Asterisk versions 1.4.41.1, 1.6.2.18.1, and 1.8.4.3, which are security releases. These releases are available for immediate download at http://downloads.asterisk.org/pub/telephony/asterisk/releases The release of Asterisk 1.4.41.1, 1.6.2.18, and 1.8.4.3 resolves several issues as outlined below: * AST-2011-008: If a remote user sends a SIP packet containing a null, Asterisk assumes available data extends past the null to the end of the packet when the buffer is actually truncated when copied. This causes SIP header parsing to modify data past the end of the buffer altering unrelated memory structures. This vulnerability does not affect TCP/TLS connections. -- Resolved in 1.6.2.18.1 and 1.8.4.3 * AST-2011-009: A remote user sending a SIP packet containing a Contact header with a missing left angle bracket (<) causes Asterisk to access a null pointer. -- Resolved in 1.8.4.3 * AST-2011-010: A memory address was inadvertently transmitted over the network via IAX2 via an option control frame and the remote party would try to access it. -- Resolved in 1.4.41.1, 1.6.2.18.1, and 1.8.4.3 The issues and resolutions are described in the AST-2011-008, AST-2011-009, and AST-2011-010 security advisories. For more information about the details of these vulnerabilities, please read the security advisories AST-2011-008, AST-2011-009, and AST-2011-010, which were released at the same time as this announcement. For a full list of changes in the current releases, please see the ChangeLog: http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.4.41.1 http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.18.1 http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.4.3 Security advisories AST-2011-008, AST-2011-009, and AST-2011-010 are available at: http://downloads.asterisk.org/pub/security/AST-2011-008.pdf http://downloads.asterisk.org/pub/security/AST-2011-009.pdf http://downloads.asterisk.org/pub/security/AST-2011-010.pdf -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 29 2011 Jeffrey C. Ollie <jeff@xxxxxxxxxx> - 1.6.2.19-1: - The Asterisk Development Team has announced the final maintenance release of - Asterisk, version 1.6.2.19. This release is available for immediate download at - http://downloads.asterisk.org/pub/telephony/asterisk/ - - Please note that Asterisk 1.6.2.19 is the final maintenance release from the - 1.6.2 branch. Support for security related issues will continue until April 21, - 2012. For more information about support of the various Asterisk branches, see - https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions - - The release of Asterisk 1.6.2.19 resolves several issues reported by the - community and would have not been possible without your participation. - Thank you! - - The following is a sample of the issues resolved in this release: - - * Don't broadcast FullyBooted to every AMI connection - The FullyBooted event should not be sent to every AMI connection - every time someone connects via AMI. It should only be sent to - the user who just connected. - (Closes issue #18168. Reported, patched by FeyFre) - * Fix thread blocking issue in the sip TCP/TLS implementation. - (Closes issue #18497. Reported by vois. Tested by vois, rossbeer, kowalma, - Freddi_Fonet. Patched by dvossel) - * Don't delay DTMF in core bridge while listening for DTMF features. - (Closes issue #15642, #16625. Reported by jasonshugart, sharvanek. Tested by - globalnetinc, jde. Patched by oej, twilson) - * Fix chan_local crashs in local_fixup() - Thanks OEJ for tracking down the issue and submitting the patch. - (Closes issue #19053. Reported, patched by oej) - * Don't offer video to directmedia callee unless caller offered it as well - (Closes issue #19195. Reported, patched by one47) - - Additionally security announcements AST-2011-008, AST-2011-010, and - AST-2011-011 have been resolved in this release. - - For a full list of changes in this release, please see the ChangeLog: - - http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.19 * Tue Jun 28 2011 Jeffrey C. Ollie <jeff@xxxxxxxxxx> - 1.6.2.19-0.1: - The Asterisk Development Team has announced the first release - candidate of Asterisk 1.6.2.19. This release candidate is available - for immediate download at - http://downloads.asterisk.org/pub/telephony/asterisk/ - - Please note that Asterisk 1.6.2.19 will be the final maintenance - release from the 1.6.2 branch. Support for security related issues - will continue for one additional year. For more information about - support of the various Asterisk branches, see - https://wiki.asterisk.org/wiki/display/AST/Asterisk+Versions - - The release of Asterisk 1.6.2.19-rc1 resolves several issues reported - by the community and would have not been possible without your - participation. Thank you! - - The following is a sample of the issues resolved in this release candidate: - - * Don't broadcast FullyBooted to every AMI connection The FullyBooted - event should not be sent to every AMI connection every time someone - connects via AMI. It should only be sent to the user who just - connected. (Closes issue #18168. Reported, patched by FeyFre) - - * Fix thread blocking issue in the sip TCP/TLS implementation. - (Closes issue #18497. Reported by vois. Tested by vois, rossbeer, - kowalma, Freddi_Fonet. Patched by dvossel) - - * Don't delay DTMF in core bridge while listening for DTMF features. - (Closes issue #15642, #16625. Reported by jasonshugart, - sharvanek. Tested by globalnetinc, jde. Patched by oej, twilson) - - * Fix chan_local crashs in local_fixup() Thanks OEJ for tracking down - the issue and submitting the patch. (Closes issue #19053. Reported, - patched by oej) - - * Don't offer video to directmedia callee unless caller offered it as - well (Closes issue #19195. Reported, patched by one47) - - For a full list of changes in this release candidate, please see the - ChangeLog: - - http://downloads.asterisk.org/pub/telephony/asterisk/ChangeLog-1.6.2.19-rc1 * Sat Jun 25 2011 Jeffrey C. Ollie <jeff@xxxxxxxxxx> - 1.6.2.18.1-1 - The Asterisk Development Team has announced the release of Asterisk versions - 1.4.41.1, 1.6.2.18.1, and 1.8.4.3, which are security releases. - - These releases are available for immediate download at - http://downloads.asterisk.org/pub/telephony/asterisk/releases - - The release of Asterisk 1.4.41.1, 1.6.2.18, and 1.8.4.3 resolves several issues - as outlined below: - - * AST-2011-008: If a remote user sends a SIP packet containing a null, - Asterisk assumes available data extends past the null to the - end of the packet when the buffer is actually truncated when - copied. This causes SIP header parsing to modify data past - the end of the buffer altering unrelated memory structures. - This vulnerability does not affect TCP/TLS connections. - -- Resolved in 1.6.2.18.1 and 1.8.4.3 - - * AST-2011-009: A remote user sending a SIP packet containing a Contact header - with a missing left angle bracket (<) causes Asterisk to - access a null pointer. - -- Resolved in 1.8.4.3 - - * AST-2011-010: A memory address was inadvertently transmitted over the - network via IAX2 via an option control frame and the remote party would try - to access it. - -- Resolved in 1.4.41.1, 1.6.2.18.1, and 1.8.4.3 - - - The issues and resolutions are described in the AST-2011-008, AST-2011-009, and - AST-2011-010 security advisories. - - For more information about the details of these vulnerabilities, please read - the security advisories AST-2011-008, AST-2011-009, and AST-2011-010, which were - released at the same time as this announcement. - - For a full list of changes in the current releases, please see the ChangeLog: - - http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.4.41.1 - http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.6.2.18.1 - http://downloads.asterisk.org/pub/telephony/asterisk/releases/ChangeLog-1.8.4.3 - - Security advisories AST-2011-008, AST-2011-009, and AST-2011-010 are available - at: - - http://downloads.asterisk.org/pub/security/AST-2011-008.pdf - http://downloads.asterisk.org/pub/security/AST-2011-009.pdf - http://downloads.asterisk.org/pub/security/AST-2011-010.pdf -------------------------------------------------------------------------------- ================================================================================ bullet-2.78-1.fc14 (FEDORA-2011-8900) 3D Collision Detection and Rigid Body Dynamics Library -------------------------------------------------------------------------------- Update Information: Update to bullet-2.78 -------------------------------------------------------------------------------- ChangeLog: * Wed May 11 2011 Rich Mattes <richmattes@xxxxxxxxx> - 2.78-1 - Update to version 2.78 - Remove upstreamed patches -------------------------------------------------------------------------------- ================================================================================ cppunit-1.12.1-5.fc14 (FEDORA-2011-8898) C++ unit testing framework -------------------------------------------------------------------------------- Update Information: Bug 641350 - implicit destructor of CppUnit::Message causes segfault when test is built with debug. -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 28 2011 Steven M. Parrish <smparrish@xxxxxxxxx> - 1.12.1-5 - Fix for bug 452340 * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.12.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #641350 - implicit destructor of CppUnit::Message causes segfault when test is built with debug. STL https://bugzilla.redhat.com/show_bug.cgi?id=641350 -------------------------------------------------------------------------------- ================================================================================ cups-1.4.7-2.fc14 (FEDORA-2011-8916) Common Unix Printing System -------------------------------------------------------------------------------- Update Information: The new upstream release fixes a number of scheduler, driver, and backend issues. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 29 2011 Tim Waugh <twaugh@xxxxxxxxxx> 1:1.4.7-2 - Tag localization files correctly (bug #716421). * Tue Jun 28 2011 Jiri Popelka <jpopelka@xxxxxxxxxx> 1:1.4.7-1 - 1.4.7. * Thu Mar 10 2011 Tim Waugh <twaugh@xxxxxxxxxx> 1:1.4.6-7 - LSPP: only warn when unable to get printer context. * Fri Feb 25 2011 Tim Waugh <twaugh@xxxxxxxxxx> 1:1.4.6-6 - Fixed build failure due to php_zend_api macro type. * Fri Feb 25 2011 Tim Waugh <twaugh@xxxxxxxxxx> 1:1.4.6-5 - Fixed dbus notifier support for job-state-changed. * Thu Feb 10 2011 Jiri Popelka <jpopelka@xxxxxxxxxx> 1:1.4.6-4 - Remove testing cups-usb-buffer-size.patch (bug #661814). * Tue Jan 18 2011 Tim Waugh <twaugh@xxxxxxxxxx> 1:1.4.6-3 - Don't use --enable-pie configure option as it has been removed and is now assumed. See STR #3691. * Mon Jan 10 2011 Tim Waugh <twaugh@xxxxxxxxxx> 1:1.4.6-2 - Use a smaller buffer when writing to USB devices (bug #661814). - Handle EAI_NONAME when resolving hostnames (bug #617208). -------------------------------------------------------------------------------- References: [ 1 ] Bug #716421 - cups package doesn't tag localization files correctly https://bugzilla.redhat.com/show_bug.cgi?id=716421 -------------------------------------------------------------------------------- ================================================================================ drupal7-7.4-1.fc14 (FEDORA-2011-8879) An open-source content-management platform -------------------------------------------------------------------------------- Update Information: Remember to log in as user 1 prior to the RPM update, to perform the DB upgrade via http://yoursite/update.php. * Advisory ID: DRUPAL-SA-CORE-2011-002 * Project: Drupal core [1] * Version: 7.x * Date: 2011-JUNE-29 * Security risk: Highly critical [2] * Exploitable from: Remote * Vulnerability: Access bypass -------- DESCRIPTION --------------------------------------------------------- .... Access bypass in node listings Listings showing nodes but not JOINing the node table show all nodes regardless of restrictions imposed by the node_access system. In core, this affects the taxonomy and the forum subsystem. Note that fixing this issue in contributed modules requires a backwards-compatible API change for modules listing nodes. See http://drupal.org/node/1204572 [3] for more details. This issue affects Drupal 7.x only. -------- VERSIONS AFFECTED --------------------------------------------------- * Drupal 7.0, 7.1 and 7.2. -------- SOLUTION ------------------------------------------------------------ Install the latest version: * If you are running Drupal 7.x then upgrade to Drupal 7.3 or 7.4. The Security Team has released both a pure security update without other bug fixes and a security update combined with other bug fixes and improvements. You can choose to either only include the security update for an immediate fix (which might require less quality assurance and testing) or more fixes and improvements alongside the security fixes by choosing between Drupal 7.3 and Drupal 7.4. Read the announcement [4] for more information. See also the Drupal core [5] project page. -------- REPORTED BY --------------------------------------------------------- * The access bypass was reported independently by numerous people, including Sascha Grossenbacher [6], Khaled Alhourani [7], and Ben Ford [8]. -------- FIXED BY ------------------------------------------------------------ * The access bypass was fixed by Károly Négyesi [9], member of the Drupal security team -------- CONTACT AND MORE INFORMATION ---------------------------------------- The Drupal security team can be reached at security at drupal.org or via the contact form at http://drupal.org/contact [10]. Learn more about the Drupal Security team and their policies [11], writing secure code for Drupal [12], and securing your site [13]. [1] http://drupal.org/project/drupal [2] http://drupal.org/security-team/risk-levels [3] http://drupal.org/node/1204572 [4] http://drupal.org/drupal-7.4 [5] http://drupal.org/project/drupal [6] http://drupal.org/user/214652 [7] http://drupal.org/user/265439 [8] http://drupal.org/user/12534 [9] http://drupal.org/user/9446 [10] http://drupal.org/contact [11] http://drupal.org/security-team [12] http://drupal.org/writing-secure-code [13] http://drupal.org/security/secure-configuration -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 30 2011 Jon Ciesla <limb@xxxxxxxxxxxx> - 7.4-1 - New upstream, SA-CORE-2011-002, BZ 717874. - Dropped unused dirs in /etc/drupal7/, BZ 703736. * Fri Jun 17 2011 Jon Ciesla <limb@xxxxxxxxxxxx> - 7.2-2 - Bump and rebuild for BZ 712251. -------------------------------------------------------------------------------- References: [ 1 ] Bug #717874 - Remote access bypass vulnerability in Drupal 7 https://bugzilla.redhat.com/show_bug.cgi?id=717874 [ 2 ] Bug #706736 - Put modules and themes directories under /etc/drupal7/all/ https://bugzilla.redhat.com/show_bug.cgi?id=706736 -------------------------------------------------------------------------------- ================================================================================ imgtarget-0.1.4-7.fc14 (FEDORA-2011-8891) Front-end to functionality provided by ArgyllCMS -------------------------------------------------------------------------------- Update Information: F14FTBFS, F16FTBFS -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 30 2011 Ralf Corsépius <corsepiu@xxxxxxxxxxxxxxxxx> - 0.1.4-7 - Fix up broken spec-changelog entry. * Thu Jun 30 2011 Ralf Corsépius <corsepiu@xxxxxxxxxxxxxxxxx> - 0.1.4-6 - Append INCLUDES="-I/usr/include/netpbm" and LIBS="-lX11" to %configure (Fix FTBFS BZ#599895, BZ#715981). -------------------------------------------------------------------------------- ================================================================================ kde-plasma-networkmanagement-0.9-0.41.1.20110616git.fc14 (FEDORA-2011-8910) NetworkManager KDE 4 integration -------------------------------------------------------------------------------- Update Information: An update of the Network Management Plasma widget to a more recent snapshot, which fixes many bugs and adds support for system connections. (This matches what is now in Fedora 15, except that this is the version for NetworkManager 0.8, from upstream's git master branch, as opposed to the nm09 branch used in Fedora 15.) -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 17 2011 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> 1:0.9-0.41.1.20110616git - 20110616 snapshot (from git master) - drop NULL checks patch (fixed upstream) -------------------------------------------------------------------------------- ================================================================================ libphidget-2.1.8.20110615-1.fc14 (FEDORA-2011-8896) Drivers and API for Phidget devices -------------------------------------------------------------------------------- Update Information: Update to version 2.1.8.20110615 -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 29 2011 Rich Mattes <richmattes@xxxxxxxxx> - 2.1.8.20110615-1 - Update to 2.1.8.20110615 * Wed May 11 2011 Rich Mattes <richmattes@xxxxxxxxx> - 2.1.8.20110322-1 - Update to 2.1.8.20110322 -------------------------------------------------------------------------------- ================================================================================ python-msgpack-0.1.9-2.fc14 (FEDORA-2011-8901) A Python MessagePack (de)serializer -------------------------------------------------------------------------------- Update Information: MessagePack is a binary-based efficient data interchange format that is focused on high performance. It is like JSON, but very fast and small. This is a Python (de)serializer for MessagePack. -------------------------------------------------------------------------------- References: [ 1 ] Bug #691114 - Review Request: python-msgpack - A MessagePack (de)serializer https://bugzilla.redhat.com/show_bug.cgi?id=691114 -------------------------------------------------------------------------------- ================================================================================ python-taboot-0.3.0-1.fc14 (FEDORA-2011-8888) Client utility for scripted multi-system administration over Func -------------------------------------------------------------------------------- Update Information: Fixed #13 - Generate HTML versions of the man pages Fixed #6, #7, #11, #12 - Updated the Nagios task completely to use the native Func Nagios module Fixed #17 - sleep.Minutes not printing correct status message Fixed #20 - Be more helpful when YAML fails to load Fixed #22 - Taboots not processing YAML files with multiple documents inside Fixed #15 - Die gracefully when processing bad CLI options -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 23 2011 Tim Bielawa <tbielawa@xxxxxxxxxx> 0.3.0-1 - Update version. 0.3.0. If Linux can do it -- so can we. (tbielawa@xxxxxxxxxx) - Now included in EPEL and Fedora. Fixes #9 (tbielawa@xxxxxxxxxx) - Correct a lot of spelling errors. Fixes #23 (Taboot maintainer has atrocious spelling) (tbielawa@xxxxxxxxxx) - Correctly handle YAML files with multiple YAML documents inside. Fixes #22 (tbielawa@xxxxxxxxxx) - Better YAML loading debugging. Fixes #20 (tbielawa@xxxxxxxxxx) - Handle bad CLI options gracefully. Fixes #15 (tbielawa@xxxxxxxxxx) - Modify patch from jdetiber. Fixes #17 - sleep.Minutes not printing correct status message (tbielawa@xxxxxxxxxx) - Updated output for sleep.Minutes (jason.detiberus@xxxxxxxxxx) - Update man page (tbielawa@xxxxxxxxxx) - Update taboot-tasks manpage (tbielawa@xxxxxxxxxx) - Make HOST the default for downtime scheduling again (tbielawa@xxxxxxxxxx) - Updating Nagios task docs (tbielawa@xxxxxxxxxx) - Rewrite the Nagios task to use the new Func Nagios module instead of CURL. Fixes #6, #7, #11, #12 (tbielawa@xxxxxxxxxx) - Adding HTML versions of the man pages to the HTML docs. Fixes #13 (tbielawa@xxxxxxxxxx) -------------------------------------------------------------------------------- ================================================================================ rubygem-gem2rpm-0.7.1-1.fc14 (FEDORA-2011-8899) Generate rpm specfiles from gems -------------------------------------------------------------------------------- Update Information: Updated to the 0.7.1 version. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 30 2011 Vít Ondruch <vondruch@xxxxxxxxxx> - 0.7.1-1 - Updated to the 0.7.1 version. * Tue Sep 28 2010 Michael Stahnke <stahnma@xxxxxxxxxxxxxxxxx> - 0.6.0-5 - Breaking into a main and doc package -------------------------------------------------------------------------------- ================================================================================ scap-workbench-0.4.0-1.fc14 (FEDORA-2011-8880) Scanning, tailoring, editing and validation tool for SCAP content -------------------------------------------------------------------------------- Update Information: New release -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 30 2011 Maros Barabas <xbarry@xxxxxxxxx> 0.4.0-1 - Redesign of abstract classes in editor - New dialog module - New preview dialog - UI improvements - Added documentation - Fixed bugs -------------------------------------------------------------------------------- ================================================================================ tgif-4.2.5-1.fc14 (FEDORA-2011-8894) 2-D drawing tool -------------------------------------------------------------------------------- Update Information: New version 4.2.5 is released. New version 4.2.4 is released. -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 30 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxx> - 4.2.5-1 - 4.2.5 * Sun Jun 26 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxx> - 4.2.4-1 - 4.2.4 -------------------------------------------------------------------------------- ================================================================================ wordpress-3.1.4-1.fc14 (FEDORA-2011-8908) Blog tool and publishing platform -------------------------------------------------------------------------------- Update Information: Upstream security release. Details at http://wordpress.org/news/2011/06/wordpress-3-1-4/ Fix old FSF address and Summary to make rpmlint happy. Make wp-content directory owned by apache:apache. Correctly Provides/Obsoletes (with versions). Upgrade to the latest upstream version (security fixes and enhancements, BZ 707772). Move wp-content directory to /var/www/wordpress/ (BZ 522897). Simplify overly detailed files list. Actually, we just don't need gettext.php at all, it is provided by php itself. Just remove the file, don't make a symlink. Revert back to wp-content in /usr/share/wordpress, I am not able to make it work. Not fixing BZ 522897. -------------------------------------------------------------------------------- ChangeLog: * Wed Jun 29 2011 Matěj Cepl <mcepl@xxxxxxxxxx> - 3.1.4-1 - New upstream security release. * Thu Jun 2 2011 Matěj Cepl <mcepl@xxxxxxxxxx> - 3.1.3-3 - Actually, we just don't need gettext.php at all, it is provided by php itself. Just remove the file, don't make a symlink. - revert back to wp-content in /usr/share/wordpress, I am not able to make it work. Not fixing BZ 522897. * Wed Jun 1 2011 Matěj Cepl <mcepl@xxxxxxxxxx> - 3.1.3-2 - Fix old FSF address and Summary to make rpmlint happy. - Make wp-content directory owned by apache:apache - Correctly Provides/Obsoletes (with versions) * Wed May 25 2011 Matěj Cepl <mcepl@xxxxxxxxxx> - 3.1.3-1 - Upgrade to the latest upstream version (security fixes and enhancements, BZ 707772) - Move wp-content directory to /var/www/wordpress/ (BZ 522897) - Simplify overly detailed %files -------------------------------------------------------------------------------- References: [ 1 ] Bug #707772 - New upstream version 3.1.3 has been released https://bugzilla.redhat.com/show_bug.cgi?id=707772 [ 2 ] Bug #522897 - Unable To Upload Images To /usr/share/wordpress/wp-content/uploads/ https://bugzilla.redhat.com/show_bug.cgi?id=522897 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test