The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/libsoup-2.32.2-2.fc14 https://admin.fedoraproject.org/updates/foomatic-4.0.8-3.fc14 https://admin.fedoraproject.org/updates/librsvg2-2.32.0-4.fc14 https://admin.fedoraproject.org/updates/nss-3.12.10-4.fc14 https://admin.fedoraproject.org/updates/tomcat6-6.0.26-21.fc14 https://admin.fedoraproject.org/updates/wireshark-1.4.9-1.fc14 https://admin.fedoraproject.org/updates/zabbix-1.8.7-2.fc14 https://admin.fedoraproject.org/updates/Django-1.3.1-2.fc14 https://admin.fedoraproject.org/updates/cherokee-1.2.99-1.fc14 https://admin.fedoraproject.org/updates/quassel-0.7.3-1.fc14 https://admin.fedoraproject.org/updates/qt-4.7.4-2.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 https://admin.fedoraproject.org/updates/php-5.3.8-1.fc14,maniadrive-1.2-32.fc14,php-eaccelerator-0.9.6.1-9.fc14 https://admin.fedoraproject.org/updates/kernel-2.6.35.14-97.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/kernel-2.6.35.14-97.fc14 https://admin.fedoraproject.org/updates/lldpad-0.9.41-4.fc14 https://admin.fedoraproject.org/updates/librsvg2-2.32.0-4.fc14 https://admin.fedoraproject.org/updates/nss-3.12.10-4.fc14 https://admin.fedoraproject.org/updates/livecd-tools-14.3-1.fc14 https://admin.fedoraproject.org/updates/curl-7.21.0-10.fc14 https://admin.fedoraproject.org/updates/system-config-users-1.2.110-1.fc14 https://admin.fedoraproject.org/updates/ModemManager-0.4.998-1.git20110706.fc14 https://admin.fedoraproject.org/updates/unique-1.1.6-3.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-savage-2.3.2-3.fc14 https://admin.fedoraproject.org/updates/mash-0.5.22-1.fc14 https://admin.fedoraproject.org/updates/policycoreutils-2.0.85-30.3.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-8.fc14.2 https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-3.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-nouveau-0.0.16-14.20101010git8c8f15c.fc14 https://admin.fedoraproject.org/updates/libconcord-0.23-5.fc14,udev-161-9.fc14,concordance-0.23-2.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 The following builds have been pushed to Fedora 14 updates-testing ding-libs-0.1.3-5.fc14 espeak-1.45.05-1.fc14 gauche-0.9.2-1.fc14 gauche-gl-0.5.1-2.fc14 gauche-gtk-0.6-0.2.20110725git598828842a339.fc14 gpodder-2.19-1.fc14 kernel-2.6.35.14-97.fc14 libguestfs-1.8.13-1.fc14 malaga-suomi-voikko-1.10-1.fc14 olpc-kbdshim-20-1.fc14 plowshare-0.9.4-0.15.20110914git.fc14 python-dateutil-1.5-3.fc14 python-matplotlib-1.0.1-12.fc14 qt-4.7.4-2.fc14 sane-backends-1.0.22-4.fc14 snappy-1.0.4-1.fc14 tinc-1.0.16-1.fc14 Details about builds: ================================================================================ ding-libs-0.1.3-5.fc14 (FEDORA-2011-12863) "Ding is not GLib" assorted utility libraries -------------------------------------------------------------------------------- Update Information: Fixes a serious bug in libdhash with very large (> 1024 slots) initial size -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 15 2011 Stephen Gallagher <sgallagh@xxxxxxxxxx> - 0.1.3-5 - New upstream release 0.1.3 - Fixes a serious issue with libdhash and large initial hash sizes * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.1.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ espeak-1.45.05-1.fc14 (FEDORA-2011-12878) Software speech synthesizer (text-to-speech) -------------------------------------------------------------------------------- Update Information: This is new version of espeak that fixes crashes and many other bugs and also introduced new features. For full list see changelog on https://sourceforge.net/projects/espeak/files/espeak/espeak-1.45/ -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 15 2011 Jaroslav Škarvada <jskarvad@xxxxxxxxxx> - 1.45.05-1 - New version - Updated runtime_detection patch - Dropped gcc_no_libstdc++ patch * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.43-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #577941 - volume mixer changes to maximum when running espeak and some other apps https://bugzilla.redhat.com/show_bug.cgi?id=577941 -------------------------------------------------------------------------------- ================================================================================ gauche-0.9.2-1.fc14 (FEDORA-2011-12870) Scheme script interpreter with multibyte character handling -------------------------------------------------------------------------------- Update Information: Updates gauche and gauche-gl to the latest releases, and gauche-gtk to the latest Git snapshot -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 13 2011 Michel Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.9.2-1 - Update to 0.9.2 * Sun Feb 6 2011 Gérard Milmeister <gemi@xxxxxxxxxx> - 0.9.1-1 - new release 0.9.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #737869 - gauche-0.9.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=737869 -------------------------------------------------------------------------------- ================================================================================ gauche-gl-0.5.1-2.fc14 (FEDORA-2011-12870) OpenGL binding for Gauche -------------------------------------------------------------------------------- Update Information: Updates gauche and gauche-gl to the latest releases, and gauche-gtk to the latest Git snapshot -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 15 2011 Michel Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.5.1-2 - Put header in -devel subpackage - Fix overlapping directory ownerships * Thu Sep 15 2011 Michel Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.5.1-1 - Update to 0.5.1 * Mon Feb 14 2011 Gérard Milmeister <gemi@xxxxxxxxxx> - 0.5-1 - new release 0.5 matching gauche 0.9 * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.4.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #737869 - gauche-0.9.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=737869 -------------------------------------------------------------------------------- ================================================================================ gauche-gtk-0.6-0.2.20110725git598828842a339.fc14 (FEDORA-2011-12870) Gauche extension module to use GTK -------------------------------------------------------------------------------- Update Information: Updates gauche and gauche-gl to the latest releases, and gauche-gtk to the latest Git snapshot -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Michel Salim <salimma@xxxxxxxxxxxxxxxxx> - 1:0.6-0.2.20110725git598828842a339 - add Epoch field for upgrade path from mislabeled 0.9 release * Thu Sep 15 2011 Michel Salim <salimma@xxxxxxxxxxxxxxxxx> - 0.6-0.1.20110725git598828842a339 - Updated Git snapshot - Fix version numbering - Put header in -devel subpackage - Fix overlapping directory ownerships - Enable tests * Mon Feb 14 2011 Gerard Milmeister <gemi@xxxxxxxxxx> - 0.9-1.git20110214 - New release to match Gauche 0.9 -------------------------------------------------------------------------------- References: [ 1 ] Bug #737869 - gauche-0.9.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=737869 -------------------------------------------------------------------------------- ================================================================================ gpodder-2.19-1.fc14 (FEDORA-2011-12857) Podcast receiver/catcher written in Python -------------------------------------------------------------------------------- Update Information: This release fixes various bugs found since the last release in August: * Fix empty descriptions in the Soundcloud module * Ignore image enclosures for audio/video in Media RSS (bug 1430) * Add Spanish and Turkish translations (bug 1420) -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Ville-Pekka Vainio <vpvainio AT iki.fi> - 2.19-1 - New upstream release -------------------------------------------------------------------------------- ================================================================================ kernel-2.6.35.14-97.fc14 (FEDORA-2011-12874) The Linux kernel -------------------------------------------------------------------------------- Update Information: Fixes assorted CVEs CVE-2011-2918: perf: Fix software event overflow CVE-2011-3188: net: improve sequence number generation CVE-2011-2723: gro: Only reset frag0 when skb can be pulled CVE-2011-2928: befs: Validate length of long symbolic links CVE-2011-3191: cifs: fix possible memory corruption in CIFSFindNext CVE-2011-1833: ecryptfs: mount source TOCTOU race -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Josh Boyer <jwboyer@xxxxxxxxxx> 2.6.35.14-97 - CVE-2011-2918: perf: Fix software event overflow - CVE-2011-3188: net: improve sequence number generation * Thu Sep 15 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - CVE-2011-2723: gro: Only reset frag0 when skb can be pulled - CVE-2011-2928: befs: Validate length of long symbolic links - CVE-2011-3191: cifs: fix possible memory corruption in CIFSFindNext - CVE-2011-1833: ecryptfs: mount source TOCTOU race * Mon Sep 12 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Backport 5336377d to fix RHBZ #648571 -------------------------------------------------------------------------------- ================================================================================ libguestfs-1.8.13-1.fc14 (FEDORA-2011-12867) Access and modify virtual machine disk images -------------------------------------------------------------------------------- Update Information: New stable branch version 1.8.13. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Richard W.M. Jones <rjones@xxxxxxxxxx> - 1:1.8.13-1 - New upstream stable branch version 1.8.13. -------------------------------------------------------------------------------- ================================================================================ malaga-suomi-voikko-1.10-1.fc14 (FEDORA-2011-12885) A description of Finnish morphology written in Malaga (Voikko edition) -------------------------------------------------------------------------------- Update Information: New upstream release. After version 1.9 the following notable changes have been made: * New words have been added. Most new words are either geographical names or special vocabulary for mathematics and physics. * Many errors in morphological analysis have been fixed and new attributes are exported for use in libvoikko. Taking advantage of some of these features requires libvoikko 3.3 or later. * Improved handling of compound words containing foreign components. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Ville-Pekka Vainio <vpvainio AT iki.fi> - 1.10-1 - Suomi-malaga 1.10 -------------------------------------------------------------------------------- ================================================================================ olpc-kbdshim-20-1.fc14 (FEDORA-2011-12877) OLPC XO keyboard support daemon -------------------------------------------------------------------------------- Update Information: Ebook mode and XO-1.75 touchscreen improvements. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Daniel Drake <dsd@xxxxxxxxxx> 20-1 - ebook mode improvements, XO-1.75 touchscreen support -------------------------------------------------------------------------------- ================================================================================ plowshare-0.9.4-0.15.20110914git.fc14 (FEDORA-2011-12865) Download and upload files from file-sharing websites -------------------------------------------------------------------------------- Update Information: New upstream snapshot. -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 15 2011 Elder Marco <eldermarco@xxxxxxxxxxxxxxxxx> - 0.9.4-0.15.20110914git - New upstream snapshot -------------------------------------------------------------------------------- ================================================================================ python-dateutil-1.5-3.fc14 (FEDORA-2011-12892) Powerful extensions to the standard datetime module -------------------------------------------------------------------------------- Update Information: Use system tzdata by default -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 15 2011 Jef Spaleta <jspaleta@xxxxxxxxxxxxxxxxx> - 1.5-3 - Adjust patch to respect systemwide tzdata. Ref bug 729786 * Thu Sep 15 2011 Jef Spaleta <jspaleta@xxxxxxxxxxxxxxxxx> - 1.5-2 - Added a patch to respect systemwide tzdata. Ref bug 729786 * Wed Jul 13 2011 Rahul Sundaram <sundaram@xxxxxxxxxxxxxxxxx> - 1.5-1 - New upstream release - Fix UTF8 encoding correctly - Drop buildroot, clean, defattr and use macro for Source * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.4.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ python-matplotlib-1.0.1-12.fc14 (FEDORA-2011-12880) Python plotting library -------------------------------------------------------------------------------- Update Information: Adding timezeon handling in plotting with upstream backported fix -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 15 2011 Jef Spaleta <jspaleta@xxxxxxxxxxxxxxxxx> - 1.0.1-12 - Apply upstream patch for timezone in plotting (bug 735677) -------------------------------------------------------------------------------- References: [ 1 ] Bug #735677 - matplotlib.pyplot.plot_date() ignores timezone https://bugzilla.redhat.com/show_bug.cgi?id=735677 -------------------------------------------------------------------------------- ================================================================================ qt-4.7.4-2.fc14 (FEDORA-2011-12145) Qt toolkit -------------------------------------------------------------------------------- Update Information: Update Information: QtGui ----- - [QTBUG-20214] QRentBook: LSK and RSK of booking page will change somethimes - [QTBUG-19656] Spectrum: the Mode menu disappears after the device is changed from portrait to landscape. - [QTBUG-19260] Cursor cannot be placed between letters f and i - "fi" is interpreted as one character - [QTBUG-19157] Crash in QGLContextPrivate::bindTexture() when using QPainter::fillRect() with a brush having a size > max_texture_size - [QTBUG-19089] TextInput positionToRectangle doesn't return correct coordinates for the cursor in pre-edit mode - [QTBUG-19067] Font glyphs get clipped on the top - [QTBUG-18500] QTextBlock crash - [QTBUG-18303] Arabic multiline text is clipped on the right - [QTBUG-18185] QStaticText: Wrong kerning and baselines when rotating a QGraphicsView - [QTBUG-17443] Feedreadercrash: when opening feed with unicode characters - [QTBUG-17244] QGraphicsLayout Layouting should be done in one go. Ugly layouting visible otherwise - [QTBUG-17209] Bug-231 introduces an off-by-one error - [QTBUG-17117] Arabic reordering problem when 2 fonts are used - [QTBUG-11131] QAbstractScrollArea::setViewport() causes crash when used from within event handler method - [QTBUG-16422] Big coordinate values cause segfault on ARM when calling QGraphicsEllipseItem::contains - [QTBUG-18017] Regression: Text selection with shift-click stopped working - [QTBUG-18192] Crash when invoking blockBoundingRect over a QTextDocument documentLayout - [QTBUG-17505] Inflexible focus handling in QGraphicsScene - [QTBUG-17020] QPainter::drawText() fails to draw correct text in some circumstances. Related to QTBUG-12950 - [QTBUG-16401] QGraphicsScene returns focus incorrectly when QGraphicsView is focused - [QTBUG-17812] regression: qsortfilterproxymodel::reset doesn't invalidate the model (Windows) - [QTBUG-17230] QPlainTextEdit corruption/crash after scrolling - [QTBUG-17536] qguistatemachine::cloneEvent doesn't clone GraphicsSceneWheel Events correctly - [QTBUG-17254] XPM files crash QImage (write) - [QTBUG-16292] QTreeView crash in indexRowSizeHint/itemHeight - [QTBUG-17390] Child widgets don't inherit their parent's input contexts - [QTBUG-15910] setstylesheet on a QComboBox causes a segmentation fault - [QTBUG-16652] Compilation of "4.7" branch fails: private/qdrawhelper_arm_simd_p.h: No such file or directory QtNetwork --------- - [QTBUG-17464] SIGBUS in fetchAndAddOrdered from QlcdEngine::connectionStateSignalsSlot - [QTBUG-16022] QHttpNetworkConnectionChannel::expand discards data if gzip-stream has missing end-of-stream marker - [QTBUG-17199] ICD Bearer management: Causes the main thread to hang when ran on a different thread. QtCore ------ - [QTBUG-15421] QDirIterator returns hidden directories when it should only return files and returns hidden files when it should only return directories QtScript -------- - [QTBUG-17815] Missing APIShims in obsoleted QScriptValue constructor - [QTBUG-17788] Crash when calling collectGarbage() after requesting arguments object of native context QtDBus ------ - [QTBUG-14228] Ensure Qt 4.7 doesn't crash when a D-Bus message with file descriptors is received QtSql ----- - [QTBUG-14831] Dynamic sorting of a QSortFilterProxyModel on a QSqlTableModel with OnManualSubmit is broken (4.7 regression) Declarative ----------- - [QTBUG-20159] No effect of setting color on a QStaticText or a QML element - [QTBUG-18428] Colored and underlined styled text are not underlined or completely coloured on device - [QTBUG-18362] wigglytext.qml does not behave correctly in qmlscene - [QTBUG-18266] More than one XmlListModel - Lists randomly show data from wrong model - [QTBUG-15983] Cannot pass enum value as signal parameter from C++ to QML - [QTBUG-14974] ListView and GridView + contentY performance - [QTBUG-18412] Crash in sendPostedEvents() - QObject::isWidgetType() (issue with QDeclarativePixmapReply) - [QTBUG-15356] PathView doesn't update if preferredHighlightBegin and preferredHighlightEnd changed - [QTBUG-17562] TextInput text in echo mode PasswordEchoOnEdit revealed on refocus - [QTBUG-17775] Crash when using FolderListModel with a repeater - [QTBUG-17361] Nested pressDelays crashes application - [QTBUG-15705] QDeclarativeTextInput::mousePressEvent() doesn't call QInputContext::mouseHandler() - [QTBUG-17501] Focus: Tap any of the Rounded-cornered rectangle, the context menu doesn't disappear. - [QTBUG-17008] ListView + XmlListModel freeze application when change language key combination - [QTBUG-17324] incorrect 'version is not installed' error when importing QML module - [QTBUG-16999] QML TextInput doesn't scroll if writing preedit at the end of the line - [QTBUG-13451] Support property versioning in QML - [QTBUG-16959] Crash when using Grid.TopToBottom flow with Repeater inside Grid - [QTBUG-16522] QML ListView Should Support Dynamic Headers and Footers - [QTBUG-17114] QtQuick 1.1 alignment regression - [QTBUG-16283] TextEdit and TextInput need text selection modes - [QTBUG-16284] Disable drag and drop in TextEdit and TextInput OpenVG ------ - [QTBUG-18682] QImage convertToFormat does not work with certain image formats when default (OpenVG) rendering engine used. OpenGL ------ - [QTBUG-17256] Change QGLPixmapData load functions to use the 'convertInPlace' versions of QImage to save memory Qt for Linux/X11 ---------------- - Declarative * [QTBUG-19914] Segfault in QDeclarativeBinding::createBinding triggered by QMultimediaKit - gui * [QTBUG-16175] REG: Qt 4.7/Linux Qt Designer / Qt Creator show multiple warnings: "Application asked to unregister timer 0x17000002 which is not registered in this thread. Fix application." Additionally, this update fixes offline HTML documentation -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Lukas Tinkl <ltinkl@xxxxxxxxxx> - 1:4.7.4-2 - respun upstream tarball to fix offline HTML docu (https://bugreports.qt.nokia.com/browse/QTBUG-21454) * Thu Sep 1 2011 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 1:4.7.4-1 - 4.7.4 * Sat Aug 27 2011 Than Ngo <than@xxxxxxxxxx> - 1:4.7.3-9 - drop unused rhel conditional -------------------------------------------------------------------------------- References: [ 1 ] Bug #733119 - CVE-2011-3194 qt buffer overflow in greyscale images https://bugzilla.redhat.com/show_bug.cgi?id=733119 -------------------------------------------------------------------------------- ================================================================================ sane-backends-1.0.22-4.fc14 (FEDORA-2011-12861) Scanner access software -------------------------------------------------------------------------------- Update Information: This update should work with Epson Stylus SX125 all-in-one devices out of the box, makes the sane-config script multilib-compatible (again) and moves backend drivers to their own sub-package to allow leaving them out if space is constrained. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Nils Philippsen <nils@xxxxxxxxxx> - 1.0.22-4 - multilib: always use pkg-config in sane-config (#707910) - add USB id for Epson Stylus SX125 (#703529) * Thu Sep 15 2011 Nils Philippsen <nils@xxxxxxxxxx> - 1.0.22-4 - allow installing the libraries without the drivers (#736310): split off drivers into -drivers-scanners, rename -libs-gphoto2 to -drivers-cameras -------------------------------------------------------------------------------- ================================================================================ snappy-1.0.4-1.fc14 (FEDORA-2011-12876) Fast compression and decompression library -------------------------------------------------------------------------------- Update Information: The new upstream release fixes a couple of issues and somewhat speeds up the decompressor. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Martin Gieseking <martin.gieseking@xxxxxx> 1.0.4-1 - updated to release 1.0.4 -------------------------------------------------------------------------------- ================================================================================ tinc-1.0.16-1.fc14 (FEDORA-2011-12853) A virtual private network daemon -------------------------------------------------------------------------------- Update Information: * Fri Sep 16 2011 Fabian Affolter <mail@xxxxxxxxxxxxxxxxxx> - 1.0.16-1 - Updated to new upstream version 1.0.16 -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 16 2011 Fabian Affolter <mail@xxxxxxxxxxxxxxxxxx> - 1.0.16-1 - Updated to new upstream version 1.0.16 * Wed Apr 13 2011 Fabian Affolter <mail@xxxxxxxxxxxxxxxxxx> - 1.0.13-1 - Updated to new upstream version 1.0.13 * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.0.12-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test