The following Fedora 15 Security updates need testing: https://admin.fedoraproject.org/updates/FEDORA-2012-8114/libreoffice-3.3.4.1-5.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8205/python-tornado-2.2.1-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-6630/dokuwiki-0-0.10.20110525.a.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-7246/libsoup-2.34.3-2.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-6629/gdb-7.3.1-50.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8339/rt3-3.8.12-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8360/drupal7-7.14-2.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8365/moodle-1.9.18-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8372/kernel-2.6.43.7-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8490/python-crypto-2.3-6.fc15 https://admin.fedoraproject.org/updates/FEDORA-2011-17233/tor-0.2.1.32-1500.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8488/globus-gridftp-server-6.10-2.fc15,globus-gridftp-server-control-2.5-2.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8024/openssl-1.0.0j-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-7131/seamonkey-2.9.1-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8041/xinetd-2.3.14-37.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8010/sudo-1.7.4p5-5.fc15 The following Fedora 15 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/FEDORA-2012-8372/kernel-2.6.43.7-1.fc15 https://admin.fedoraproject.org/updates/iproute-2.6.38.1-7.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8206/mdadm-3.2.5-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8027/libogg-1.3.0-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8010/sudo-1.7.4p5-5.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-8024/openssl-1.0.0j-1.fc15 https://admin.fedoraproject.org/updates/FEDORA-2012-7909/perl-5.12.4-166.fc15 https://admin.fedoraproject.org/updates/dracut-009-15.fc15 The following builds have been pushed to Fedora 15 updates-testing 389-ds-base-1.2.10.9-1.fc15 bdii-5.2.10-1.fc15 clamtk-4.40-1.fc15 collectl-3.6.3-1.fc15 dcap-2.47.6-1.fc15 dnssec-tools-1.12.1-2.fc15 fwsnort-1.6.2-1.fc15 globus-gridftp-server-6.10-2.fc15 globus-gridftp-server-control-2.5-2.fc15 jemalloc-3.0.0-2.fc15 python-crypto-2.3-6.fc15 sugar-flip-4-1.fc15 sugar-pukllanapac-9-1.fc15 voms-2.0.8-1.fc15 voms-api-java-2.0.8-1.fc15 voms-mysql-plugin-3.1.6-1.fc15 xen-4.1.2-7.fc15 Details about builds: ================================================================================ 389-ds-base-1.2.10.9-1.fc15 (FEDORA-2012-8489) 389 Directory Server (base) -------------------------------------------------------------------------------- Update Information: some repl and some crashing issues fix ldclt crash in previous fix a couple of crashes Ticket #348 - crash in ldap_initialize with multiple threads Ticket #347 - IPA dirsvr seg-fault during system longevity test crash bug with multiple transactions and range searches -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.2.10.9-1 - Ticket #382 - DS Shuts down intermittently - Trac Ticket #359 - Database RUV could mismatch the one in changelog under the stress - Bug #361: Bad DNs in ACIs can segfault ns-slapd - Trac Ticket #338 - letters in object's cn get converted to lowercase when renaming object * Thu May 3 2012 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.2.10.8-1 - Ticket #348 - crash in ldap_initialize with multiple threads - previous fix would crash in ldclt - this fixes that crash * Mon Apr 30 2012 Rich Megginson <rmeggins@xxxxxxxxxx> - 1.2.10.7-1 - Ticket #348 - crash in ldap_initialize with multiple threads - Ticket #347 - IPA dirsvr seg-fault during system longevity test -------------------------------------------------------------------------------- ================================================================================ bdii-5.2.10-1.fc15 (FEDORA-2012-8498) The Berkeley Database Information Index (BDII) -------------------------------------------------------------------------------- Update Information: New upstream version that includes a new DB_CONFIG Fixed a base64 encoding issue and added /var/run/bdii init script Performance improvements to reduce memory and disk usage -------------------------------------------------------------------------------- ChangeLog: * Thu Mar 8 2012 Laurence Field <laurence.field@xxxxxxx> - 5.2.10-1 - New upsteam version that includes a new DB_CONFIG * Wed Feb 8 2012 Laurence Field <laurence.field@xxxxxxx> - 5.2.9-1 - Fixed /var/run packaging issue * Wed Feb 8 2012 Laurence Field <laurence.field@xxxxxxx> - 5.2.8-1 - Fixed a base64 encoding issue and added /var/run/bdii to the package * Tue Feb 7 2012 Laurence Field <laurence.field@xxxxxxx> - 5.2.7-1 - Performance improvements to reduce memory and disk usage * Wed Jan 25 2012 Laurence Field <laurence.field@xxxxxxx> - 5.2.6-1 - New upstream version that includes fedora patches and fix for EGI RT 3235 * Thu Jan 12 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 5.2.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ clamtk-4.40-1.fc15 (FEDORA-2012-8486) Easy to use graphical user interface for Clam anti virus -------------------------------------------------------------------------------- Update Information: Update to 4.40 -------------------------------------------------------------------------------- ChangeLog: * Sat May 26 2012 Dave M. <dave.nerd@xxxxxxxxx> - 4.40-1 - Updated to release 4.40. - Images are grouped under images/ now. -------------------------------------------------------------------------------- ================================================================================ collectl-3.6.3-1.fc15 (FEDORA-2012-8491) A utility to collect various Linux performance data -------------------------------------------------------------------------------- Update Information: - update to upstream version 3.6.3 - upstream changelog at http://collectl.sourceforge.net/Releases.html -------------------------------------------------------------------------------- ChangeLog: * Fri May 25 2012 Dan Horák <dan[at]danny.cz> - 3.6.3-1 - upgrade to upstream version 3.6.3 -------------------------------------------------------------------------------- ================================================================================ dcap-2.47.6-1.fc15 (FEDORA-2012-8492) Client Tools for dCache -------------------------------------------------------------------------------- Update Information: New upstream release (EMI 2 release) -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 2.47.6-1 - New upstream release (EMI 2 release) - Drop patches dcap-aliasing.patch and dcap-libs.patch implemented upstream * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.47.5-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ dnssec-tools-1.12.1-2.fc15 (FEDORA-2012-8497) A suite of tools for managing dnssec aware DNS usage -------------------------------------------------------------------------------- Update Information: Fixes a path conflict with xmlbeans Updated to 1.12.1 to fix a bug in rollerd for zone rolls Updated to the 1.12 upstream release bringing multiple stability improvements and other features -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Wes Hardaker <wjhns174@xxxxxxxxxxxxx> - 1.12.1-2 - move validate to dt-validate to avoid a conflict * Fri May 18 2012 Wes Hardaker <wjhns174@xxxxxxxxxxxxx> - 1.12.1-1 - Upgraded to 1.12.1 * Fri Jan 27 2012 Wes Hardaker <wjhns174@xxxxxxxxxxxxx> - 1.12-1 - Upgraded to version 1.12 - Added a patch to fix the perl validator * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.11-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #797793 - dnssec-tools : Conflicts with xmlbeans-scripts https://bugzilla.redhat.com/show_bug.cgi?id=797793 -------------------------------------------------------------------------------- ================================================================================ fwsnort-1.6.2-1.fc15 (FEDORA-2012-8485) Translates Snort rules into equivalent iptables rules -------------------------------------------------------------------------------- Update Information: Updated version 1.6.2 -------------------------------------------------------------------------------- ChangeLog: * Sat May 26 2012 Guillermo Gómez <gomix@xxxxxxxxxxxxxxxxx> - 1.6.2-1 - Update to version 1.6.2 - Replaced Net::IPv4Addr with NetAddr::IP module which has support for IPv6 address network parsing and comparisons. - wget added as required to support default configuration. -------------------------------------------------------------------------------- ================================================================================ globus-gridftp-server-6.10-2.fc15 (FEDORA-2012-8488) Globus Toolkit - Globus GridFTP Server -------------------------------------------------------------------------------- Update Information: Fix for http://jira.globus.org/browse/GT-195 -------------------------------------------------------------------------------- ChangeLog: * Fri May 25 2012 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 6.10-2 - Backport security fix for JIRA ticket GT-195 -------------------------------------------------------------------------------- ================================================================================ globus-gridftp-server-control-2.5-2.fc15 (FEDORA-2012-8488) Globus Toolkit - Globus GridFTP Server Library -------------------------------------------------------------------------------- Update Information: Fix for http://jira.globus.org/browse/GT-195 -------------------------------------------------------------------------------- ChangeLog: * Fri May 25 2012 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 2.5-2 - Backport security fix for JIRA ticket GT-195 -------------------------------------------------------------------------------- ================================================================================ jemalloc-3.0.0-2.fc15 (FEDORA-2012-8493) General-purpose scalable concurrent malloc implementation -------------------------------------------------------------------------------- Update Information: Added a patch from upstream, fixing a crash in ptmalloc_lock_all New upstream release -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Ingvar Hagelund <ingvar@xxxxxxxxxxxxxxxxxx> - 3.0.0-2 - Added a patch from upstream, fixing a crash in ptmalloc_lock_all, closing #824646 * Mon May 14 2012 Ingvar Hagelund <ingvar@xxxxxxxxxxxxxxxxxx> - 3.0.0-1 - New upstream release - Updated no_pprof patch to match new release - Updated s390 patch to match new relase - Added make check - Added new script jemalloc.sh - Added a patch for atomic operations on epel5/ppc * Sat Apr 21 2012 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> - 2.2.5-5 - Improve ARM patch * Fri Apr 20 2012 Dennis Gilmore <dennis@xxxxxxxx> - 2.2.5-4 - no attomics on armv5tel * Wed Feb 8 2012 Dan Horák <dan[at]danny.cz> - 2.2.5-3 - substitute version information in the header (#788517) * Fri Jan 13 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.2.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ python-crypto-2.3-6.fc15 (FEDORA-2012-8490) Cryptography library for Python -------------------------------------------------------------------------------- Update Information: This update is a security fix for CVE-2012-2417 (insecure ElGamal key generation). Anyone using ElGamal keys should generate new keys as soon as practical (any additional information about this bug will be tracked at https://bugs.launchpad.net/pycrypto/+bug/985164). -------------------------------------------------------------------------------- ChangeLog: * Fri May 25 2012 Paul Howarth <paul@xxxxxxxxxxxx> - 2.3-6 - Fix insecure ElGamal key generation (#825164, CVE-2012-2417) * Wed May 11 2011 Paul Howarth <paul@xxxxxxxxxxxx> - 2.3-5 - Upstream rolled new tarball with top-level directory restored - Nobody else likes macros for commands -------------------------------------------------------------------------------- References: [ 1 ] Bug #825162 - CVE-2012-2417 python-crypto: Insecure ElGamal key generation https://bugzilla.redhat.com/show_bug.cgi?id=825162 -------------------------------------------------------------------------------- ================================================================================ sugar-flip-4-1.fc15 (FEDORA-2012-8495) Simple strategic game of flipping coins -------------------------------------------------------------------------------- Update Information: Release version 4 -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Kalpa Welivitigoda <callkalpa@xxxxxxxxx> - 4-1 - Release version 4 -------------------------------------------------------------------------------- ================================================================================ sugar-pukllanapac-9-1.fc15 (FEDORA-2012-8487) A sliding puzzle game -------------------------------------------------------------------------------- Update Information: Release version 9 -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Kalpa Welivitigofa <callkalpa@xxxxxxxxx> - 9-1 - Release version 9 * Sat Jan 14 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 8-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ voms-2.0.8-1.fc15 (FEDORA-2012-8494) Virtual Organization Membership Service -------------------------------------------------------------------------------- Update Information: Update of voms package to EMI 2 versions -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 2.0.8-1 - Update to version 2.0.8 (EMI 2 version) -------------------------------------------------------------------------------- ================================================================================ voms-api-java-2.0.8-1.fc15 (FEDORA-2012-8494) Virtual Organization Membership Service Java API -------------------------------------------------------------------------------- Update Information: Update of voms package to EMI 2 versions -------------------------------------------------------------------------------- ChangeLog: * Thu May 24 2012 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 2.0.8-1 - Update to version 2.0.8 (EMI 2 version) -------------------------------------------------------------------------------- ================================================================================ voms-mysql-plugin-3.1.6-1.fc15 (FEDORA-2012-8494) VOMS server plugin for MySQL -------------------------------------------------------------------------------- Update Information: Update of voms package to EMI 2 versions -------------------------------------------------------------------------------- ChangeLog: * Fri May 25 2012 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 3.1.6-1 - Update to version 3.1.6 (EMI 2 version) * Sat Jan 14 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 3.1.5.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ xen-4.1.2-7.fc15 (FEDORA-2012-8496) Xen is a virtual machine monitor -------------------------------------------------------------------------------- Update Information: Make the udev tap rule more specific as it breaks openvpn (#819452), load xen-acpi-processor module (kernel 3.4 onwards) if present -------------------------------------------------------------------------------- ChangeLog: * Tue May 8 2012 Michael Young <m.a.young@xxxxxxxxxxxx> - 4.1.2-7 - Make the udev tap rule more specific as it breaks openvpn (#819452) - load xen-acpi-processor module (kernel 3.4 onwards) if present -------------------------------------------------------------------------------- References: [ 1 ] Bug #819452 - OpenVPN with tap interface not working with libvirt installed https://bugzilla.redhat.com/show_bug.cgi?id=819452 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test