The following Fedora 15 Security updates need testing: https://admin.fedoraproject.org/updates/moodle-1.9.14-1.fc15 https://admin.fedoraproject.org/updates/nss-3.12.10-7.fc15 https://admin.fedoraproject.org/updates/hardlink-1.0-12.fc15 https://admin.fedoraproject.org/updates/kernel-2.6.41.1-1.fc15 https://admin.fedoraproject.org/updates/openswan-2.6.37-1.fc15 https://admin.fedoraproject.org/updates/ocsinventory-1.3.3-5.fc15 https://admin.fedoraproject.org/updates/kdeutils-4.6.5-3.fc15 https://admin.fedoraproject.org/updates/phpldapadmin-1.2.1.1-2.20111006= git.fc15 https://admin.fedoraproject.org/updates/wireshark-1.4.10-1.fc15 https://admin.fedoraproject.org/updates/squid-3.1.16-1.fc15 https://admin.fedoraproject.org/updates/net6-1.3.14-1.fc15 https://admin.fedoraproject.org/updates/krb5-1.9.1-14.fc15 https://admin.fedoraproject.org/updates/puppet-2.6.12-1.fc15 https://admin.fedoraproject.org/updates/cherokee-1.2.101-1.fc15 https://admin.fedoraproject.org/updates/drupal6-views-2.13-1.fc15 https://admin.fedoraproject.org/updates/arora-0.11.0-3.fc15 https://admin.fedoraproject.org/updates/proftpd-1.3.4-1.fc15 https://admin.fedoraproject.org/updates/rest-0.7.12-1.fc15,libsocialweb= -0.25.20-1.fc15 https://admin.fedoraproject.org/updates/phpMyAdmin-3.4.7.1-1.fc15 The following Fedora 15 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/rest-0.7.12-1.fc15,libsocialweb= -0.25.20-1.fc15 https://admin.fedoraproject.org/updates/kernel-2.6.41.1-1.fc15 https://admin.fedoraproject.org/updates/libass-0.10.0-1.fc15 https://admin.fedoraproject.org/updates/zlib-1.2.5-5.fc15 https://admin.fedoraproject.org/updates/phonon-4.5.1-1.fc15 https://admin.fedoraproject.org/updates/libjpeg-turbo-1.1.1-2.fc15 https://admin.fedoraproject.org/updates/mdadm-3.2.2-14.fc15 https://admin.fedoraproject.org/updates/gdb-7.3.1-46.fc15 https://admin.fedoraproject.org/updates/nss-3.12.10-7.fc15 https://admin.fedoraproject.org/updates/perl-5.12.4-163.fc15 https://admin.fedoraproject.org/updates/qt-4.7.4-6.fc15 https://admin.fedoraproject.org/updates/virtuoso-opensource-6.1.4-2.fc15 https://admin.fedoraproject.org/updates/gtk2-2.24.7-3.fc15 https://admin.fedoraproject.org/updates/tzdata-2011n-2.fc15 https://admin.fedoraproject.org/updates/sendmail-8.14.5-2.fc15.2 https://admin.fedoraproject.org/updates/orc-0.4.16-3.fc15 https://admin.fedoraproject.org/updates/cryptopp-5.6.1-5.fc15 https://admin.fedoraproject.org/updates/parted-2.3-11.fc15 https://admin.fedoraproject.org/updates/nss-softokn-3.12.10-5.fc15 https://admin.fedoraproject.org/updates/system-setup-keyboard-0.8.8-1.f= c15 https://admin.fedoraproject.org/updates/glibc-2.14.1-1 https://admin.fedoraproject.org/updates/abrt-2.0.3-5.fc15,libreport-2.0= .4-4.fc15 https://admin.fedoraproject.org/updates/xorg-x11-drv-ati-6.14.2-1.20110= 921gitd78860ba5.fc15 https://admin.fedoraproject.org/updates/phonon-backend-gstreamer-4.5.90= -2.fc15,phonon-4.5.57-1.20110914.fc15 https://admin.fedoraproject.org/updates/evolution-data-server-3.0.3.1-1= .fc15 https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-5.fc15 https://admin.fedoraproject.org/updates/openldap-2.4.24-5.fc15 https://admin.fedoraproject.org/updates/evolution-mapi-3.0.3-2.fc15,evo= lution-exchange-3.0.3-1.fc15,evolution-3.0.3-1.fc15,evolution-data-server-3= .0.3-1.fc15,gtkhtml3-4.0.2-1.fc15 https://admin.fedoraproject.org/updates/nspr-4.8.8-4.fc15 https://admin.fedoraproject.org/updates/mash-0.5.22-1.fc15 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904= -14.fc15.1 https://admin.fedoraproject.org/updates/libfprint-0.4.0-1.fc15,fprintd-= 0.4.1-1.fc15 The following builds have been pushed to Fedora 15 updates-testing R2spec-4.0.0-1.fc15 condor-7.7.3-0.2.fc15 cvs2cl-2.73-1.fc15 dvb-apps-1.1.2-0.d4e8bf5658ce.fc15 ghc-7.0.2-16.8.fc15 ghc-rpm-macros-0.14-1.fc15 kernel-2.6.41.1-1.fc15 libass-0.10.0-1.fc15 libsocialweb-0.25.20-1.fc15 mingw32-filesystem-69-4.fc15 phpMyAdmin-3.4.7.1-1.fc15 rest-0.7.12-1.fc15 sound-theme-acoustic-1.0-1.fc15 timidity++-2.13.2-25.fc15.1 Details about builds: =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D R2spec-4.0.0-1.fc15 (FEDORA-2011-15837) Python script to generate R spec file ---------------------------------------------------------------------------= ----- Update Information: Rewrite R2spec in version 4.0.0 \=C3=B3/ ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Pierre-Yves Chibon <pingou@xxxxxxxxxxxx> - 4.0.0-1 - Update to 4.0.0 which is an almost complete rewrite ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D condor-7.7.3-0.2.fc15 (FEDORA-2011-15855) Condor: High Throughput Computing ---------------------------------------------------------------------------= ----- Update Information: Bug fix and update ---------------------------------------------------------------------------= ----- ChangeLog: * Fri Nov 11 2011 <tstclair@xxxxxxxxxx> - 7.7.3-0.2 - Update install process for tmpfiles.d * Tue Oct 25 2011 <tstclair@xxxxxxxxxx> - 7.7.3-0.1 - Fast forward to 7.7.3 pre release ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #656562 - Please Update Spec File to use %ghost on files in /va= r/run and /var/lock https://bugzilla.redhat.com/show_bug.cgi?id=3D656562 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D cvs2cl-2.73-1.fc15 (FEDORA-2011-15844) Generate ChangeLogs from CVS working copies ---------------------------------------------------------------------------= ----- Update Information: An update of cvs2cl to the latest upstream release, adding the '--xml-style= sheet' option. ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> - 2.73-1 - Update to 2.73 (#753407) ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #753407 - cvs2cl-2.73 is available https://bugzilla.redhat.com/show_bug.cgi?id=3D753407 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D dvb-apps-1.1.2-0.d4e8bf5658ce.fc15 (FEDORA-2011-15851) Utility, demo and test applications using the Linux DVB API ---------------------------------------------------------------------------= ----- Update Information: Update to the latest repository snapshot to include all the latest tuning d= ata ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> - 1.1.2-0.d= 4e8bf5658ce - Move to hg snapshot d4e8bf5658ce ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #617153 - scandvb doesn't output all channels https://bugzilla.redhat.com/show_bug.cgi?id=3D617153 [ 2 ] Bug #733952 - UK switchover: DVB-T mux details have changed signifi= cantly https://bugzilla.redhat.com/show_bug.cgi?id=3D733952 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D ghc-7.0.2-16.8.fc15 (FEDORA-2011-14846) Glasgow Haskell Compiler ---------------------------------------------------------------------------= ----- Update Information: - Base package now installs all of ghc, including new ghc-compiler and ghc-= libraries subpackages - Add HaskellReport license tag to subpackages with Haskell Report code - Support armv5tel arch (Henrik Nordstr=C3=B6m) - Dependency autogeneration for bootstrap builds ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Jens Petersen <petersen@xxxxxxxxxx> - 7.0.2-16.8 - build with ghc-rpm-macros-0.14 for ghc-compiler * Fri Nov 11 2011 Jens Petersen <petersen@xxxxxxxxxx> - 7.0.2-16.7 - move ghc-doc and ghc-libs obsoletes - the post and postun scripts are now for the compiler subpackage - rename ghc-devel metapackage to ghc-libraries - move compiler and tools to ghc-compiler - the ghc base package is now a metapackage that installs all of ghc, ie ghc-compiler and ghc-devel (#750317) - add HaskellReport license tag to some of the library subpackages which contain some code from the Haskell Reports * Mon Oct 24 2011 Jens Petersen <petersen@xxxxxxxxxx> - 7.0.2-16.6 - setup ghc-deps.sh after ghc_version_override for bootstrapping - add armv5tel (ported by Henrik Nordstr=C3=B6m) - use ghc_arches - also use ghc-deps.sh when bootstrapping (ghc-rpm-macros-0.13.13) - include the ghc (ghci) library in ghc-devel (Narasim) ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #750317 - make ghc base package install all of ghc https://bugzilla.redhat.com/show_bug.cgi?id=3D750317 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D ghc-rpm-macros-0.14-1.fc15 (FEDORA-2011-14846) Macros for building packages for GHC ---------------------------------------------------------------------------= ----- Update Information: - Base package now installs all of ghc, including new ghc-compiler and ghc-= libraries subpackages - Add HaskellReport license tag to subpackages with Haskell Report code - Support armv5tel arch (Henrik Nordstr=C3=B6m) - Dependency autogeneration for bootstrap builds ---------------------------------------------------------------------------= ----- ChangeLog: * Tue Nov 1 2011 Jens Petersen <petersen@xxxxxxxxxx> - 0.14-1 - replace devel ghc requires with ghc-compiler - disable testsuite in ghc_bootstrap ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #750317 - make ghc base package install all of ghc https://bugzilla.redhat.com/show_bug.cgi?id=3D750317 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D kernel-2.6.41.1-1.fc15 (FEDORA-2011-15856) The Linux kernel ---------------------------------------------------------------------------= ----- Update Information: Rebase to upstream 3.1.1 kernel Fix boot regression on 64-bit EFI machines Update to the Linux 3.0.8 (2.6.40.8) stable release. Fix assorted security bugs. Bugfix update Update to the latest 3.0.7 stable kernel release which includes a variety of fixes. ---------------------------------------------------------------------------= ----- ChangeLog: * Fri Nov 11 2011 Josh Boyer <jwboyer@xxxxxxxxxx> 2.6.41.1-1 - Linux 3.1.1 * Fri Nov 11 2011 John W. Linville <linville@xxxxxxxxxx> - Remove overlap between bcma/b43 and brcmsmac and reenable bcm4331 * Thu Nov 10 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - Sync samsung-laptop driver with what's in 3.2 (rhbz 747560) * Wed Nov 9 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> 2.6.41.1-1.rc1 - Linux 3.1.1-rc1 (Fedora 2.6.41.1-rc1) - Comment out merged patches, will drop when release is final: ums-realtek-driver-uses-stack-memory-for-DMA.patch epoll-fix-spurious-lockdep-warnings.patch crypto-register-cryptd-first.patch add-macbookair41-keyboard.patch powerpc-Fix-deadlock-in-icswx-code.patch iwlagn-fix-ht_params-NULL-pointer-dereference.patch mmc-Always-check-for-lower-base-frequency-quirk-for-.patch media-DiBcom-protect-the-I2C-bufer-access.patch media-dib0700-protect-the-dib0700-buffer-access.patch WMI-properly-cleanup-devices-to-avoid-crashes.patch * Wed Nov 9 2011 John W. Linville <linville@xxxxxxxxxx> - Backport brcm80211 from 3.2-rc1 * Mon Nov 7 2011 Dave Jones <davej@xxxxxxxxxx> - Rebase to 3.1.0 * Thu Nov 3 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Add patches queued for 3.2 for elantech driver (rhbz 728607) * Wed Nov 2 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Add patch to fix oops when removing wmi module (rhbz 706574) * Tue Nov 1 2011 Dave Jones <davej@xxxxxxxxxx> 2.6.40.8-5 - allow building the perf rpm for ARM (rhbz 741325) * Tue Nov 1 2011 Josh Boyer <jwboyer@xxxxxxxxxx> 2.6.40.8-4 - Drop x86-efi-Calling-__pa-with-an-ioremap-address-is-invalid (rhbz 748516) * Tue Nov 1 2011 Dave Jones <davej@xxxxxxxxxx> - Add another Sony laptop to the nonvs blacklist. (rhbz 641789) * Mon Oct 31 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - CVE-2011-4097: oom_badness() integer overflow (rhbz 750402) * Fri Oct 28 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Add patch to prevent tracebacks on a warning in floppy.c (rhbz 749887) * Wed Oct 26 2011 Josh Boyer <jwboyer@xxxxxxxxxx> 2.6.40.8-2 - CVE-2011-4077: xfs: potential buffer overflow in xfs_readlink() (rhbz 749= 166) * Tue Oct 25 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - CVE-2011-3347: be2net: promiscuous mode and non-member VLAN packets DoS (= rhbz 748691) - CVE-2011-1083: excessive in kernel CPU consumption when creating large ne= sted epoll structures (rhbz 748668) * Tue Oct 25 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Linux 3.0.8 stable release * Mon Oct 24 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - Add patch from LKML to fix Samsung notebook brightness flicker (rhbz 7371= 08) * Mon Oct 24 2011 Dave Jones <davej@xxxxxxxxxx> - Print modules list from bad_page() * Mon Oct 24 2011 Josh Boyer <jwboyer@xxxxxxxxxx> 2.6.40.7-3 - Backport 3 fixed from linux-next to fix dib0700 playback (rhbz 733827) * Fri Oct 21 2011 Dave Jones <davej@xxxxxxxxxx> - Lower severity of Radeon lockup messages. * Thu Oct 20 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Add backport for P4 watchdog and perf support from Don Zickus (rhbz 71367= 5) * Wed Oct 19 2011 Dave Jones <davej@xxxxxxxxxx> - Add Sony VGN-FW21E to nonvs blacklist. (rhbz 641789) * Tue Oct 18 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Add patch to fix invalid EFI remap calls from Matt Fleming - Add patch to fix lock inversion introduced in 3.0.7 * Mon Oct 17 2011 Josh Boyer <jwboyer@xxxxxxxxxx> 2.6.40.7-0 - Linux 3.0.7 stable release - Add two patches to fix stalls in khugepaged (rhbz 735946) * Thu Oct 13 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Update usb-add-quirk-for-logitech-webcams.patch with C600 ID (rhbz 742010) * Thu Oct 13 2011 Adam Jackson <ajax@xxxxxxxxxx> - drm/i915: Treat SDVO LVDS as digital when parsing EDID (#729882) * Tue Oct 11 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - fix memory leak in fuse (rhbz 745241) * Tue Oct 11 2011 Dave Jones <davej@xxxxxxxxxx> - add e1000e workaround for packet drop on 82579 at 100Mbps (rhbz 713315) * Thu Oct 6 2011 Josh Boyer <jwboyer@xxxxxxxxxx> - Add patch to fix base frequency check for Ricoh e823 devices (rhbz 722509) ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #748516 - kernel does not boot with patch to fix invalid EFI re= map calls from 2011-10-18 https://bugzilla.redhat.com/show_bug.cgi?id=3D748516 [ 2 ] Bug #641789 - Kernel on F14 needs acpi_sleep=3Dnonvs to resume from= suspend correctly https://bugzilla.redhat.com/show_bug.cgi?id=3D641789 [ 3 ] Bug #750402 - CVE-2011-4097 kernel: oom_badness() integer overflow = [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=3D750402 [ 4 ] Bug #749887 - [abrt] kernel: WARNING: at drivers/block/floppy.c:104= 1 setup_rw_floppy+0x188/0x241 [floppy]() https://bugzilla.redhat.com/show_bug.cgi?id=3D749887 [ 5 ] Bug #749166 - CVE-2011-4077 kernel: xfs: potential buffer overflow = in xfs_readlink() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=3D749166 [ 6 ] Bug #748691 - CVE-2011-3347 kernel: be2net: promiscuous mode and no= n-member VLAN packets DoS [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=3D748691 [ 7 ] Bug #748668 - CVE-2011-1083 kernel: excessive in kernel CPU consump= tion when creating large nested epoll structures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=3D748668 [ 8 ] Bug #737108 - Backlight on Samsung N127 laptop blinks after update = to kernel-2.6.40.3 https://bugzilla.redhat.com/show_bug.cgi?id=3D737108 [ 9 ] Bug #733827 - dib0700: tx buffer length is larger than 4. Not suppo= rted. https://bugzilla.redhat.com/show_bug.cgi?id=3D733827 [ 10 ] Bug #713675 - F15 regression: perf top does not work on Intel(R) P= entium(R) 4 CPU 3.00GHz https://bugzilla.redhat.com/show_bug.cgi?id=3D713675 [ 11 ] Bug #735946 - khugepaged stalls system https://bugzilla.redhat.com/show_bug.cgi?id=3D735946 [ 12 ] Bug #742010 - Logitech WebCam C300 microphone produces squeaky "ch= ipmunk" audio https://bugzilla.redhat.com/show_bug.cgi?id=3D742010 [ 13 ] Bug #729882 - [Eaglelake]=C2=A0After upgrade from FC11(where 1680x= 1050 worked) to FC15 display is 1600x1200 and cannot change https://bugzilla.redhat.com/show_bug.cgi?id=3D729882 [ 14 ] Bug #745241 - OOM killer activated by leak in fuse https://bugzilla.redhat.com/show_bug.cgi?id=3D745241 [ 15 ] Bug #713315 - Laggy network / dropped packets using Intel 82579V https://bugzilla.redhat.com/show_bug.cgi?id=3D713315 [ 16 ] Bug #722509 - SD card write errors https://bugzilla.redhat.com/show_bug.cgi?id=3D722509 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D libass-0.10.0-1.fc15 (FEDORA-2011-15832) Portable library for SSA/ASS subtitles rendering ---------------------------------------------------------------------------= ----- Update Information: Update to 0.10.0. Fixes some crashes with newer freetype, adds bidirectiona= l text support (via fribidi), contains some other improvements and fixes. ---------------------------------------------------------------------------= ----- ChangeLog: * Fri Nov 11 2011 Martin Sourada <mso@xxxxxxxxxxxxxxxxx> - 0.10.0-1 - New upstream release - various improvements and fixes - BuildRequires: fribidi-devel (bidirectional text suport) - Fixes some wierd memory allocation related crash with freetype 2.4.6 - rhbz 753017, rhbz 753065 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D libsocialweb-0.25.20-1.fc15 (FEDORA-2011-15839) A social network data aggregator ---------------------------------------------------------------------------= ----- Update Information: CVE-2011-4129 A security flaw was found in the way the libsocialweb, a social network dat= a aggregator, performed its initialization when this service start was init= iated by the dbus daemon. Due to a deficiency in a way the libsocialweb ser= vice was initialized, an untrusted (non-SSL) network connection has been op= ened to remote Twitter service servers without explicit approval of the use= r, running the libsocialweb service on the local host. A remote attacker co= uld use this flaw to conduct various MITM attacks and potentially alter int= egrity of the user account in question. * libsocialweb: The views will try and fetch content from the web service e= ven if they aren't configured. * rest: enforce that the SSL certificate is valid ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 0.25.20-1 - update to 0.25.20. Fixes CVE-2011-4129, RHBZ 752022 * Mon Jul 4 2011 Bastien Nocera <bnocera@xxxxxxxxxx> 0.25.19-1 - Update to 0.25.19 ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #752022 - CVE-2011-4129 libsocialweb: Untrusted connection to T= witter without user's approval upon service start via dbus https://bugzilla.redhat.com/show_bug.cgi?id=3D752022 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D mingw32-filesystem-69-4.fc15 (FEDORA-2011-15840) MinGW base filesystem and environment ---------------------------------------------------------------------------= ----- Update Information: Provide a more complete list of Win32 default DLLs and a bugfix for the dep= endency extractor with upper case dll names ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Erik van Pienbroek <epienbro@xxxxxxxxxxxxxxxxx> - 69-4 - Backported the changes from f16/master up to 69-8 excluding 69-3 This contains a more complete list of Win32 default DLLs and a bugfix for the dependency extractor with upper case dll names ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D phpMyAdmin-3.4.7.1-1.fc15 (FEDORA-2011-15846) Handle the administration of MySQL over the World Wide Web ---------------------------------------------------------------------------= ----- Update Information: Changes for 3.4.7.1 (2011-11-10): - [security] Fixed possible local file inclusion in XML import (CVE-2011-4107) ---------------------------------------------------------------------------= ----- ChangeLog: * Sat Nov 12 2011 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> 3.4.7.1-1 - Upgrade to 3.4.7.1 (#753119) ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #753119 - phpMyAdmin-3.4.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=3D753119 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D rest-0.7.12-1.fc15 (FEDORA-2011-15839) A library for access to RESTful web services ---------------------------------------------------------------------------= ----- Update Information: CVE-2011-4129 A security flaw was found in the way the libsocialweb, a social network dat= a aggregator, performed its initialization when this service start was init= iated by the dbus daemon. Due to a deficiency in a way the libsocialweb ser= vice was initialized, an untrusted (non-SSL) network connection has been op= ened to remote Twitter service servers without explicit approval of the use= r, running the libsocialweb service on the local host. A remote attacker co= uld use this flaw to conduct various MITM attacks and potentially alter int= egrity of the user account in question. * libsocialweb: The views will try and fetch content from the web service e= ven if they aren't configured. * rest: enforce that the SSL certificate is valid ---------------------------------------------------------------------------= ----- ChangeLog: * Thu Nov 10 2011 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 0.7.12-1 - Release 0.7.12. Fixes CVE-2011-4129 RHBZ 752022 * Fri Oct 28 2011 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 0.7.11-1 - Release 0.7.11 ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #752022 - CVE-2011-4129 libsocialweb: Untrusted connection to T= witter without user's approval upon service start via dbus https://bugzilla.redhat.com/show_bug.cgi?id=3D752022 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D sound-theme-acoustic-1.0-1.fc15 (FEDORA-2011-15850) Sound theme made on an acoustic guitar ---------------------------------------------------------------------------= ----- Update Information: Package for F15 ---------------------------------------------------------------------------= ----- =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D timidity++-2.13.2-25.fc15.1 (FEDORA-2011-15631) A software wavetable MIDI synthesizer ---------------------------------------------------------------------------= ----- Update Information: This update fixes the following issue: * garbled sound when start playing * loading of sf2 files with stereo instrument samples with missing link-ids= between the left and right samples * segfault cause by uninitialized data ---------------------------------------------------------------------------= ----- ChangeLog: * Fri Nov 11 2011 Christian Krause <chkr@xxxxxxxxxxxxxxxxx> - 2.13.2-25.1 - Add a patch which fixes the loading of sf2 files with stereo instrument samples with missing link-ids between the left and right samples (#710927) * Mon Nov 7 2011 Christian Krause <chkr@xxxxxxxxxxxxxxxxx> - 2.13.2-25 - add upstream patch to fix garbled sound when start playing (#710927) * Wed Jul 27 2011 Jindrich Novy <jnovy@xxxxxxxxxx> - 2.13.2-24 - fix segfault in detect() introduced by libao-first patch (#711224) ---------------------------------------------------------------------------= ----- References: [ 1 ] Bug #711224 - [abrt] timidity++-2.13.2-21.fc14: strlen: Process /us= r/bin/timidity was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=3D711224 [ 2 ] Bug #710927 - Short garbled noise at the beginning when playing a m= idi file https://bugzilla.redhat.com/show_bug.cgi?id=3D710927 ---------------------------------------------------------------------------= ----- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test