The following Fedora 18 Security updates need testing: Age URL 0 https://admin.fedoraproject.org/updates/FEDORA-2012-11900/libotr-3.2.1-1.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2012-11962/phpMyAdmin-3.5.2.2-1.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2012-11963/glibc-2.16-8.fc18 The following builds have been pushed to Fedora 18 updates-testing activemq-protobuf-1.1-2.fc18 anaconda-18.5-1.fc18 asterisk-gui-2.0-7.20120518svn5220.fc18 evolution-3.5.5-2.fc18 glibc-2.16-8.fc18 gstreamer1-0.11.93-1.fc18 gstreamer1-plugins-base-0.11.93-1.fc18 leechcraft-0.5.80-1.fc18 libguestfs-1.19.31-1.fc18 lorax-18.13-1.fc18 opensips-1.8.1-1.fc18 php-pear-XML-RPC-1.5.5-2.fc18 phpMyAdmin-3.5.2.2-1.fc18 qxmpp-dev-0.6.3.1-1.fc18 sugar-artwork-0.97.0-1.fc18 sugar-toolkit-gtk3-0.97.0-1.fc18 systemtap-2.0-0.2.git10c737f.fc18 vfrnav-20120815-1.fc18 votca-csg-1.2.1-5.fc18 xorg-x11-drv-intel-2.20.3-1.fc18 Details about builds: ================================================================================ activemq-protobuf-1.1-2.fc18 (FEDORA-2012-11969) ActiveMQ Protocol Buffers -------------------------------------------------------------------------------- Update Information: Initial import. -------------------------------------------------------------------------------- References: [ 1 ] Bug #822929 - Review Request: activemq-protobuf - ActiveMQ Protocol Buffers https://bugzilla.redhat.com/show_bug.cgi?id=822929 -------------------------------------------------------------------------------- ================================================================================ anaconda-18.5-1.fc18 (FEDORA-2012-11964) Graphical system installer -------------------------------------------------------------------------------- Update Information: This update fixes bugs in the anaconda dracut modules that affect starting the installer and adds a preliminary text mode interface. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Chris Lumens <clumens@xxxxxxxxxx> - 18.5-1 - Mark/unmark some strings for translation, as appropriate. (clumens) - Save the distro label into the right variable for retranslation. (clumens) - Add custom widget files to POTFILES.in. (clumens) - Fix attribution on common UI code. (clumens) - don't set armMachine in class definition (bcl) - libudev now has a version of .1 (hamzy) - Load anaconda-lib.sh if necessary (jkeating) - Use shell code to work around missing basename (jkeating) - Enable text mode once again! (jkeating) - Update text prompt to include c for continue (jkeating) - Don't continue if incomplete spokes exist (jkeating) - Return a bool for timezone completed property (jkeating) - Add a text progress hub to do the install (jkeating) - text based storage spoke. (jkeating) - Allow updating tmux.conf via makeupdates. (clumens) - Prevent yum messages from showing on tty (jkeating) - Remove unused imports from the installclasses. (clumens) - NoSuchGroup is provided by packaging now. yuminstall is on the way out. (clumens) - Set transaction color in case of multilib install. (clumens) - Add selinux-specific RPM macro setup. (clumens) - Add the user-agent to urlgrabber from the old yuminstall.py. (clumens) - Fix inheritance problems with the gui *Spoke classes. (clumens) - Only setup python-meh when doing graphical installs (jkeating) - Call the correct method to schedule the screen (jkeating) - Add a missing import of os (jkeating) - Don't display indirect spokes in the hub (jkeating) - Revert "Remove unncessary __init__ definition. (clumens)" (jkeating) - Honor displayMode from kickstart files (jkeating) - Merge master into newtui (jkeating) - Remove the base_tests file for now (jkeating) - Remove unused import of UIObject (jkeating) - Fix up detailederror for new common UI code (jkeating) - Translate the base text hub class (jkeating) - Translate the base tui class strings (jkeating) - Remove unncessary __init__ definition. (clumens) (jkeating) - Translate some strings in the base tui spokes classes (jkeating) - Always use collect directly from common (jkeating) - Add comment headers to the new files (jkeating) - Ad source files to POTFILES.in (msivak) - Merge remote-tracking branch 'origin/master' into newtui (msivak) - import localization stuff and use it to translate more strings (msivak) - finish renaming _mainloop (msivak) - Fix naming for data attribute and move the NormalSpoke.__init__ under the proper class (msivak) - Improve documentation and add licensing headers (msivak) - Add translations to the simpleline framework (msivak) - Add translations to Password Spoke (msivak) - Add elementary timezone spoke (msivak) - Pass screen args argument to prompt and input methods + fix for run-text- spoke (msivak) - Merge master into newtui (msivak) - Add automake files for TUI (msivak) - add couple of tests and fix write method of widget (newline added unwanted space) (msivak) - add couple of tests and support for them (msivak) - add documentation and comments to TUI classes (msivak) - Add documentation to the simpleline library for TUI (msivak) - Add the new Summary hub and Password TUI spokes + tools to test TUI stuff (msivak) - Fix bits and pieces to make TUI hub and spoke model work + example Hub and Password spoke (msivak) - Create common abstract classes usable for all types of UI (msivak) - Create the base classes for TUI Hub and Spoke model (msivak) - Make collect and part of UserInterface setup more generic (msivak) - Text based UI framework core (msivak) -------------------------------------------------------------------------------- ================================================================================ asterisk-gui-2.0-7.20120518svn5220.fc18 (FEDORA-2012-11967) Graphical interface for Asterisk configuration -------------------------------------------------------------------------------- Update Information: Add French translation in spec file -------------------------------------------------------------------------------- ChangeLog: * Thu Aug 16 2012 Matthieu Saulnier <fantom@xxxxxxxxxxxxxxxxx> - 2.0-7.20120518svn5220 - Add French translation in spec file -------------------------------------------------------------------------------- ================================================================================ evolution-3.5.5-2.fc18 (FEDORA-2012-11972) Mail and calendar client for GNOME -------------------------------------------------------------------------------- Update Information: This update backports the upstream fix for https://bugzilla.gnome.org/show_bug.cgi?id=678408 , which was making Evo more or less unusable for me. Evo 3.5.90 would have this fix anyway, but I wanted it sooner. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Adam Williamson <awilliam@xxxxxxxxxx> - 3.5.5-2 - backport the fix for BGO #678408 and #681321 (libxml2 build) -------------------------------------------------------------------------------- ================================================================================ glibc-2.16-8.fc18 (FEDORA-2012-11963) The GNU libc libraries -------------------------------------------------------------------------------- Update Information: - Fix integer overflow leading to buffer overflow in strto* (#847718) -------------------------------------------------------------------------------- ChangeLog: * Sat Aug 25 2012 Jeff Law <law@xxxxxxxxxx> - 2.16-8 - Fix integer overflow leading to buffer overflow in strto* (#847718) -------------------------------------------------------------------------------- References: [ 1 ] Bug #847715 - CVE-2012-3480 glibc: Integer overflows, leading to stack-based buffer overflows in strto* related routines https://bugzilla.redhat.com/show_bug.cgi?id=847715 -------------------------------------------------------------------------------- ================================================================================ gstreamer1-0.11.93-1.fc18 (FEDORA-2012-11899) GStreamer streaming media framework runtime -------------------------------------------------------------------------------- Update Information: Latest stable release. -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 14 2012 Brian Pepple <bpepple@xxxxxxxxxxxxxxxxx> - 0.11.93-1 - Update to 0.11.93. - Bump minimum version of glib2 needed. -------------------------------------------------------------------------------- References: [ 1 ] Bug #841243 - Review Request: gstreamer1-plugins-base - GStreamer streaming media framework base plugins https://bugzilla.redhat.com/show_bug.cgi?id=841243 -------------------------------------------------------------------------------- ================================================================================ gstreamer1-plugins-base-0.11.93-1.fc18 (FEDORA-2012-11899) GStreamer streaming media framework base plugins -------------------------------------------------------------------------------- Update Information: Latest stable release. -------------------------------------------------------------------------------- References: [ 1 ] Bug #841243 - Review Request: gstreamer1-plugins-base - GStreamer streaming media framework base plugins https://bugzilla.redhat.com/show_bug.cgi?id=841243 -------------------------------------------------------------------------------- ================================================================================ leechcraft-0.5.80-1.fc18 (FEDORA-2012-11975) A Cross-Platform Modular Internet-Client -------------------------------------------------------------------------------- Update Information: rebuild for boost-1.50 -------------------------------------------------------------------------------- ChangeLog: * Sat Aug 11 2012 Minh Ngo <nlminhtl@xxxxxxxxx> 0.5.80-1 - Azoth Birthday notifier plugin - LMP mp3tunes plugin * Sun Jul 29 2012 Minh Ngo <nlminhtl@xxxxxxxxx> 0.5.75-1 - Removing poshuku wyfv - Storage device manager plugin package -------------------------------------------------------------------------------- ================================================================================ libguestfs-1.19.31-1.fc18 (FEDORA-2012-11977) Access and modify virtual machine disk images -------------------------------------------------------------------------------- Update Information: New development version 1.19.31. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Richard W.M. Jones <rjones@xxxxxxxxxx> - 1:1.19.31-1 - New upstream version 1.19.31. -------------------------------------------------------------------------------- ================================================================================ lorax-18.13-1.fc18 (FEDORA-2012-11976) Tool for creating the anaconda install images -------------------------------------------------------------------------------- Update Information: A stack of fixes for F18. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Brian C. Lane <bcl@xxxxxxxxxx> 18.13-1 - Add a command line option to override the ARM platform. (dmarlin@xxxxxxxxxx) - Don't remove krb5-libs (#848227) (mgracik@xxxxxxxxxx) - Add grub2-efi support and Secure Boot shim support. (pjones@xxxxxxxxxx) - Fix GPT code to allocate space for /2/ tables. (pjones@xxxxxxxxxx) - Add platforms to the treeinfo for Beaker support. (dmarlin@xxxxxxxxxx) - add logging to lorax (bcl@xxxxxxxxxx) - move live templates into their own subdir of share (bcl@xxxxxxxxxx) - clean up command execution (bcl@xxxxxxxxxx) - livemedia-creator: cleanup logging a bit (bcl@xxxxxxxxxx) -------------------------------------------------------------------------------- References: [ 1 ] Bug #848227 - anaconda fails to initialize in F18 Alpha TC1 because it uses libgssapi_krb5.so.2, which lorax purges during compose https://bugzilla.redhat.com/show_bug.cgi?id=848227 -------------------------------------------------------------------------------- ================================================================================ opensips-1.8.1-1.fc18 (FEDORA-2012-11974) Open Source SIP Server -------------------------------------------------------------------------------- Update Information: * Ver. 1.8.1 -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Peter Lemenkov <lemenkov@xxxxxxxxx> - 1.8.1-1 - Ver. 1.8.1 - Dropped all upstreamed patches -------------------------------------------------------------------------------- ================================================================================ php-pear-XML-RPC-1.5.5-2.fc18 (FEDORA-2012-11966) PHP implementation of the XML-RPC protocol -------------------------------------------------------------------------------- Update Information: A PEAR-ified version of Useful Inc's XML-RPC for PHP. It has support for HTTP/HTTPS transport, proxies and authentication. In previous version of fedora, this extension was provided by php-pear main package, but pear doesn't use it anymore wince version 1.8.0. -------------------------------------------------------------------------------- References: [ 1 ] Bug #847690 - Review Request: php-pear-XML-RPC - PHP implementation of the XML-RPC protocol https://bugzilla.redhat.com/show_bug.cgi?id=847690 -------------------------------------------------------------------------------- ================================================================================ phpMyAdmin-3.5.2.2-1.fc18 (FEDORA-2012-11962) Handle the administration of MySQL over the World Wide Web -------------------------------------------------------------------------------- Update Information: phpMyAdmin 3.5.2.2 (2012-08-12) =============================== * [security] Fixed XSS vulnerabilities, see PMASA-2012-4 (http://www.phpmyadmin.net/home_page/security/PMASA-2012-4.php) phpMyAdmin 3.5.2.1 (2012-08-03) =============================== * [security] Fixed local path disclosure vulnerability, see PMASA-2012-3 (http://www.phpmyadmin.net/home_page/security/PMASA-2012-3.php) -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> 3.5.2.2-1 - Upgrade to 3.5.2.2 (#845736) -------------------------------------------------------------------------------- References: [ 1 ] Bug #845736 - phpMyAdmin-3.5.2.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=845736 -------------------------------------------------------------------------------- ================================================================================ qxmpp-dev-0.6.3.1-1.fc18 (FEDORA-2012-11975) Qt XMPP Library -------------------------------------------------------------------------------- Update Information: rebuild for boost-1.50 -------------------------------------------------------------------------------- ChangeLog: * Sat Aug 11 2012 Minh Ngo <nlminhtl@xxxxxxxxx> 0.6.3.1-1 - Updating to the new version - Changelog https://raw.github.com/0xd34df00d/qxmpp-dev/master/CHANGELOG * Sat Jul 21 2012 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ sugar-artwork-0.97.0-1.fc18 (FEDORA-2012-11978) Artwork for Sugar look-and-feel -------------------------------------------------------------------------------- Update Information: New upstream devel release -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> - 0.97.0-1 - 0.97.0 devel release -------------------------------------------------------------------------------- ================================================================================ sugar-toolkit-gtk3-0.97.0-1.fc18 (FEDORA-2012-11970) Sugar toolkit GTK+ 3 -------------------------------------------------------------------------------- Update Information: New 0.97.0 devel release -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> - 0.97.0-1 - 0.97.0 devel release -------------------------------------------------------------------------------- ================================================================================ systemtap-2.0-0.2.git10c737f.fc18 (FEDORA-2012-11965) Programmable system-wide instrumentation system -------------------------------------------------------------------------------- Update Information: fix build on s390 -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Dan Horák <dan[at]danny.cz> 2.0-0.2.git10c737f - dyninst not available on s390(x) and arm -------------------------------------------------------------------------------- ================================================================================ vfrnav-20120815-1.fc18 (FEDORA-2012-11973) VFR/IFR Navigation -------------------------------------------------------------------------------- Update Information: rebuild for dependencies -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Thomas Sailer <t.sailer@xxxxxxxxxxxxxx> - 20120815-1 - update to 20120815; rebuild for dependencies -------------------------------------------------------------------------------- ================================================================================ votca-csg-1.2.1-5.fc18 (FEDORA-2012-11971) VOTCA coarse-graining engine -------------------------------------------------------------------------------- Update Information: Build against updated boost. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Jussi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 1.2.1-5 - Bump spec due to boost update. -------------------------------------------------------------------------------- ================================================================================ xorg-x11-drv-intel-2.20.3-1.fc18 (FEDORA-2012-11968) Xorg X11 Intel video driver -------------------------------------------------------------------------------- Update Information: Upstream 2.20.3 stable release. -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 15 2012 Adam Jackson <ajax@xxxxxxxxxx> 2.20.3-1 - intel 2.20.3 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test