The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/ecryptfs-utils-90-1.fc14 https://admin.fedoraproject.org/updates/gimp-2.6.11-21.fc14 https://admin.fedoraproject.org/updates/freetype-2.4.2-5.fc14 https://admin.fedoraproject.org/updates/nip2-7.24.2-1.fc14,vips-7.24.7-2.fc14 https://admin.fedoraproject.org/updates/bugzilla-3.6.6-1.fc14 https://admin.fedoraproject.org/updates/system-config-firewall-1.2.27-2.fc14 https://admin.fedoraproject.org/updates/libsndfile-1.0.25-1.fc14 https://admin.fedoraproject.org/updates/mingw32-libpng-1.4.8-1.fc14 https://admin.fedoraproject.org/updates/libcap-2.22-1.fc14 https://admin.fedoraproject.org/updates/libvpx-0.9.7.1-1.fc14 https://admin.fedoraproject.org/updates/dhcp-4.2.0-23.P2.fc14 https://admin.fedoraproject.org/updates/libsoup-2.32.2-2.fc14 https://admin.fedoraproject.org/updates/galeon-2.0.7-42.fc14.1,thunderbird-lightning-1.0-0.42.b3pre.fc14,gnome-web-photo-0.9-22.fc14.1,perl-Gtk2-MozEmbed-0.08-6.fc14.28,mozvoikko-1.0-23.fc14.1,thunderbird-3.1.12-1.fc14,firefox-3.6.20-1.fc14,xulrunner-1.9.2.20-1.fc14,gnome-python2-extras-2.25.3-32.fc14.1 https://admin.fedoraproject.org/updates/kernel-2.6.35.14-95.fc14 https://admin.fedoraproject.org/updates/tomcat6-6.0.26-21.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/kernel-2.6.35.14-95.fc14 https://admin.fedoraproject.org/updates/curl-7.21.0-9.fc14 https://admin.fedoraproject.org/updates/audit-2.1.3-1.fc14 https://admin.fedoraproject.org/updates/system-config-users-1.2.108-1.fc14 https://admin.fedoraproject.org/updates/tzdata-2011h-2.fc14 https://admin.fedoraproject.org/updates/PackageKit-0.6.12-4.fc14 https://admin.fedoraproject.org/updates/libsoup-2.32.2-2.fc14 https://admin.fedoraproject.org/updates/libcap-2.22-1.fc14 https://admin.fedoraproject.org/updates/libsndfile-1.0.25-1.fc14 https://admin.fedoraproject.org/updates/ModemManager-0.4.998-1.git20110706.fc14 https://admin.fedoraproject.org/updates/unique-1.1.6-3.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-savage-2.3.2-3.fc14 https://admin.fedoraproject.org/updates/mash-0.5.22-1.fc14 https://admin.fedoraproject.org/updates/perl-5.12.4-146.fc14 https://admin.fedoraproject.org/updates/policycoreutils-2.0.85-30.2.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-8.fc14.2 https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-3.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-nouveau-0.0.16-14.20101010git8c8f15c.fc14 https://admin.fedoraproject.org/updates/libconcord-0.23-5.fc14,udev-161-9.fc14,concordance-0.23-2.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 The following builds have been pushed to Fedora 14 updates-testing firefox-3.6.20-1.fc14 galeon-2.0.7-42.fc14.1 gnome-python2-extras-2.25.3-32.fc14.1 gnome-web-photo-0.9-22.fc14.1 gnumed-0.9.9-4.fc14 gstreamer-rtsp-0.10.8-1.fc14 kernel-2.6.35.14-95.fc14 libguestfs-1.8.12-1.fc14 mmseq-0.9.12-1.fc14 mozc-1.2.809.102-1.fc14 mozvoikko-1.0-23.fc14.1 perl-Gtk2-MozEmbed-0.08-6.fc14.28 thunderbird-3.1.12-1.fc14 thunderbird-lightning-1.0-0.42.b3pre.fc14 xulrunner-1.9.2.20-1.fc14 Details about builds: ================================================================================ firefox-3.6.20-1.fc14 (FEDORA-2011-11084) Mozilla Firefox Web browser -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 16 2011 Martin Stransky <stransky@xxxxxxxxxx> - 3.6.20-1 - Update to 3.6.20 -------------------------------------------------------------------------------- ================================================================================ galeon-2.0.7-42.fc14.1 (FEDORA-2011-11084) GNOME2 Web browser based on Mozilla -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 2.0.7-42.1 - Rebuild against newer gecko -------------------------------------------------------------------------------- ================================================================================ gnome-python2-extras-2.25.3-32.fc14.1 (FEDORA-2011-11084) Additional PyGNOME Python extension modules -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 2.25.3-32.1 - Rebuild against newer gecko -------------------------------------------------------------------------------- ================================================================================ gnome-web-photo-0.9-22.fc14.1 (FEDORA-2011-11084) HTML pages thumbnailer -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 0.9-22.1 - Rebuild against newer gecko -------------------------------------------------------------------------------- ================================================================================ gnumed-0.9.9-4.fc14 (FEDORA-2011-11111) The gnumed client -------------------------------------------------------------------------------- Update Information: * Initial push to updates. -------------------------------------------------------------------------------- References: [ 1 ] Bug #728757 - Review Request: gnumed - The gnumed client https://bugzilla.redhat.com/show_bug.cgi?id=728757 -------------------------------------------------------------------------------- ================================================================================ gstreamer-rtsp-0.10.8-1.fc14 (FEDORA-2011-11113) GStreamer RTSP server library -------------------------------------------------------------------------------- Update Information: New upstream 0.10.8 release -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 16 2011 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> - 0.10.8-1 - Update to 0.10.8, cleanup spec file * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.10.7-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ kernel-2.6.35.14-95.fc14 (FEDORA-2011-11103) The Linux kernel -------------------------------------------------------------------------------- Update Information: Update to kernel 2.6.35.14: http://ftp.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.35/ChangeLog-2.6.35.14 NOTE: These upstream commits from 2.6.35.14 were already in the previous Fedora 14 kernel 2.6.35.13-92: b934c20de1398d4a82d2ecfeb588a214a910f13f 3cd01976e702ccaffb907727caff4f8789353599 9c047157a20521cd525527947b13b950d168d2e6 6b4e81db2552bad04100e7d5ddeed7e848f53b48 3e9d08ec0a68f6faf718d5a7e050fe5ca0ba004f b522f02184b413955f3bc952e3776ce41edc6355 194b3da873fd334ef183806db751473512af29ce a1f74ae82d133ebb2aabb19d181944b4e83e9960 e9cdd343a5e42c43bcda01e609fa23089e026470 14fb57dccb6e1defe9f89a66f548fcb24c374c1d 221d1d797202984cb874e3ed9f1388593d34ee22 a294865978b701e4d0d90135672749531b9a900d -------------------------------------------------------------------------------- ChangeLog: * Mon Aug 15 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> 2.6.35.14-95 - CVE-2011-2905: perf tools: may parse user-controlled configuration file - CVE-2011-2695: ext4: kernel panic when writing data to the last block of sparse file - CVE-2011-2497: bluetooth: buffer overflow in l2cap config request - CVE-2011-2517: nl80211: missing check for valid SSID size in scan operations - CVE-2011-2699: ipv6: make fragment identifications less predictable * Wed Aug 3 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> 2.6.35.14-94 - Linux 2.6.35.14 - Drop merged patches: flexcop-fix-xlate_proc_name-warning.patch btusb-macbookpro-6-2.patch btusb-macbookpro-7-1.patch fix-i8k-inline-asm.patch virtio_net-add-schedule-check-to-napi_enable-call.patch agp-fix-arbitrary-kernel-memory-writes.patch agp-fix-oom-and-buffer-overflow.patch scsi-mpt2sas-prevent-heap-overflows-and-unchecked-reads.patch x86-amd-arat-bug-on-sempron-workaround.patch x86-amd-fix-arat-feature-setting-again.patch cifs-add-fallback-in-is_path_accessible-for-old-servers.patch dccp-handle-invalid-feature-options-length.patch * Mon Jun 20 2011 Kyle McMartin <kmcmartin@xxxxxxxxxx> 2.6.35.13-93 - [sgruszka@] iwlwifi: fix general 11n instability (#648732,#666646) -------------------------------------------------------------------------------- References: [ 1 ] Bug #729808 - CVE-2011-2905 kernel: perf tools: may parse user-controlled configuration file https://bugzilla.redhat.com/show_bug.cgi?id=729808 [ 2 ] Bug #722557 - CVE-2011-2695 kernel: ext4: kernel panic when writing data to the last block of sparse file https://bugzilla.redhat.com/show_bug.cgi?id=722557 [ 3 ] Bug #716805 - CVE-2011-2497 kernel: bluetooth: buffer overflow in l2cap config request https://bugzilla.redhat.com/show_bug.cgi?id=716805 [ 4 ] Bug #718152 - CVE-2011-2517 kernel: nl80211: missing check for valid SSID size in scan operations https://bugzilla.redhat.com/show_bug.cgi?id=718152 [ 5 ] Bug #723429 - CVE-2011-2699 kernel: ipv6: make fragment identifications less predictable https://bugzilla.redhat.com/show_bug.cgi?id=723429 [ 6 ] Bug #698057 - CVE-2011-1598 CVE-2011-1748 kernel: missing check in can/bcm and can/raw socket releases https://bugzilla.redhat.com/show_bug.cgi?id=698057 [ 7 ] Bug #714536 - CVE-2011-2213 kernel: inet_diag: insufficient validation https://bugzilla.redhat.com/show_bug.cgi?id=714536 [ 8 ] Bug #715436 - CVE-2011-2484 kernel: taskstats: duplicate entries in listener mode can lead to DoS https://bugzilla.redhat.com/show_bug.cgi?id=715436 [ 9 ] Bug #710338 - kernel: ksm: race between ksmd and exiting task https://bugzilla.redhat.com/show_bug.cgi?id=710338 -------------------------------------------------------------------------------- ================================================================================ libguestfs-1.8.12-1.fc14 (FEDORA-2011-11114) Access and modify virtual machine disk images -------------------------------------------------------------------------------- Update Information: New stable branch version 1.8.12. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Richard W.M. Jones <rjones@xxxxxxxxxx> - 1:1.8.12-1 - New upstream stable branch version 1.8.12. -------------------------------------------------------------------------------- ================================================================================ mmseq-0.9.12-1.fc14 (FEDORA-2011-11089) Haplotype and isoform specific expression estimation for RNA-seq -------------------------------------------------------------------------------- Update Information: New upstream release 0.9.12 to fix potential seg fault -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Adam Huffman <bloch@xxxxxxxxxxxx> - 0.9.12-1 - upstream release 0.9.12 fixing a possible segfault * Thu Jul 21 2011 Adam Huffman <bloch@xxxxxxxxxxxx> - 0.9.11-2 - rebuild for new Boost in Rawhide -------------------------------------------------------------------------------- ================================================================================ mozc-1.2.809.102-1.fc14 (FEDORA-2011-11108) Open-sourced Google Japanese Input -------------------------------------------------------------------------------- Update Information: * spell collection feature * search feature in the dictionary tool * various bug fixes -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Akira TAGOH <tagoh@xxxxxxxxxx> - 1.2.809.102-1 - New upstream release. -------------------------------------------------------------------------------- ================================================================================ mozvoikko-1.0-23.fc14.1 (FEDORA-2011-11084) Finnish Voikko spell-checker extension for Mozilla programs -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 1.0-23.1 - Rebuild against newer gecko -------------------------------------------------------------------------------- ================================================================================ perl-Gtk2-MozEmbed-0.08-6.fc14.28 (FEDORA-2011-11084) Interface to the Mozilla embedding widget -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 0.08-6.28 - Rebuild against newer gecko -------------------------------------------------------------------------------- ================================================================================ thunderbird-3.1.12-1.fc14 (FEDORA-2011-11084) Mozilla Thunderbird mail/newsgroup client -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 3.1.12-1 - Update to 3.1.12 -------------------------------------------------------------------------------- ================================================================================ thunderbird-lightning-1.0-0.42.b3pre.fc14 (FEDORA-2011-11084) The calendar extension to Thunderbird -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 17 2011 Jan Horak <jhorak@xxxxxxxxxx> - 1.0-0.42.b3pre - Rebuild due to Thunderbird 3.1.12 -------------------------------------------------------------------------------- ================================================================================ xulrunner-1.9.2.20-1.fc14 (FEDORA-2011-11084) XUL Runtime for Gecko Applications -------------------------------------------------------------------------------- Update Information: Update to new upstream Firefox version 3.6.20 and Thunderbird version 3.1.12, fixing multiple security issues detailed in the upstream advisories: * http://www.mozilla.org/security/announce/2011/mfsa2011-30.html * http://www.mozilla.org/security/announce/2011/mfsa2011-32.html This update also includes all packages depending on gecko-libs rebuilt against the new version of Firefox / XULRunner. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 16 2011 Jan Horak <stransky@xxxxxxxxxx> - 1.9.2.20-1 - Update to 1.9.2.20 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test