The following Fedora 19 Security updates need testing: Age URL 17 https://admin.fedoraproject.org/updates/FEDORA-2013-4783/haproxy-1.4.23-1.fc19 17 https://admin.fedoraproject.org/updates/FEDORA-2013-4753/microcode_ctl-2.0-3.1.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2013-5411/php-geshi-1.0.8.11-3.fc19 8 https://admin.fedoraproject.org/updates/FEDORA-2013-5530/plexus-archiver-2.3-1.fc19 7 https://admin.fedoraproject.org/updates/FEDORA-2013-5600/owncloud-4.5.9-1.fc19 7 https://admin.fedoraproject.org/updates/FEDORA-2013-5604/phpMyAdmin-3.5.8-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2013-5801/mantis-1.2.15-1.fc19 3 https://admin.fedoraproject.org/updates/FEDORA-2013-5883/xorg-x11-server-1.14.0-6.fc19 3 https://admin.fedoraproject.org/updates/FEDORA-2013-5874/mediawiki-1.20.4-1.fc19 3 https://admin.fedoraproject.org/updates/FEDORA-2013-5877/icedtea-web-1.3.2-0.fc19 3 https://admin.fedoraproject.org/updates/FEDORA-2013-5861/java-1.7.0-openjdk-1.7.0.19-2.3.9.1.fc19 1 https://admin.fedoraproject.org/updates/FEDORA-2013-6077/php-twig-Twig-1.12.3-1.fc19 0 https://admin.fedoraproject.org/updates/FEDORA-2013-6147/libxml2-2.9.1-1.fc19 0 https://admin.fedoraproject.org/updates/FEDORA-2013-6185/qemu-1.4.1-1.fc19 The following builds have been pushed to Fedora 19 updates-testing gimp-2.8.4-3.fc19 guitarix-0.26.1-1.fc19 harfbuzz-0.9.16-1.fc19 metis-5.1.0-1.fc19 mingw-libxml2-2.9.1-1.fc19 nagios-3.5.0-2.fc19 ogre-1.8.1-6.fc19 php-pear-phing-2.5.0-2.fc19 qemu-1.4.1-1.fc19 sphinx-2.0.7-1.fc19 ultimaker-marlin-firmware-12.12-0.5.RC1.fc19 xscreensaver-5.21-3.fc19 Details about builds: ================================================================================ gimp-2.8.4-3.fc19 (FEDORA-2013-6181) GNU Image Manipulation Program -------------------------------------------------------------------------------- Update Information: Don't crash when deselecting tags. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Nils Philippsen <nils@xxxxxxxxxx> - 2:2.8.4-3 - don't crash upon deleting tags in popup (#892828) -------------------------------------------------------------------------------- References: [ 1 ] Bug #892828 - [abrt] gimp-2.8.2-6.fc18: gimp_tag_get_name: Process /usr/bin/gimp-2.8 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=892828 -------------------------------------------------------------------------------- ================================================================================ guitarix-0.26.1-1.fc19 (FEDORA-2013-6177) Mono amplifier to JACK -------------------------------------------------------------------------------- Update Information: This updates guitarix to minor release 0.26.1 * add ts9 tube screamer to lv2.plugs * add dunlop wah to lv2.plugs * add booster /treble/low to lv2.plugs * add factory settings file contributed by kokoko3k * add patch by Brendan Jones to set library install path * fix lv2 build on non ix86 arch * switch to use fixed block-size in zita-convolver for all lv2 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 12 2013 Brendan Jones <brendan.jones.it@xxxxxxxxx> 0.26.1-1 - Remove patches included upstream - Update to 0.26.1 -------------------------------------------------------------------------------- ================================================================================ harfbuzz-0.9.16-1.fc19 (FEDORA-2013-6183) Text shaping library -------------------------------------------------------------------------------- Update Information: http://cgit.freedesktop.org/harfbuzz/plain/NEWS?id=0.9.16 New upstream release -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Parag Nemade <pnemade AT redhat DOT com> - 0.9.16-1 - Update to 0.9.16 upstream release -------------------------------------------------------------------------------- ================================================================================ metis-5.1.0-1.fc19 (FEDORA-2013-6188) Serial Graph Partitioning and Fill-reducing Matrix Ordering -------------------------------------------------------------------------------- Update Information: Update to 5.1.0 -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 14 2013 Antonio Trande <sagitter@xxxxxxxxxxxxxxxxx> - 5.1.0-1 - Update to 5.1.0 -------------------------------------------------------------------------------- ================================================================================ mingw-libxml2-2.9.1-1.fc19 (FEDORA-2013-6182) MinGW Windows libxml2 XML processing library -------------------------------------------------------------------------------- Update Information: New upstream release 2.9.1 Fixes a couple of potential security issues and a number of bugs -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Erik van Pienbroek <epienbro@xxxxxxxxxxxxxxxxx> - 2.9.1-1 - Update to 2.9.1 -------------------------------------------------------------------------------- ================================================================================ nagios-3.5.0-2.fc19 (FEDORA-2013-6178) Nagios monitors hosts and services and yells if somethings breaks -------------------------------------------------------------------------------- Update Information: Update to 3.5.0; patch: plus signs instead of spaces -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Jose Pedro Oliveira <jpo at di.uminho.pt> - 3.5.0-2 - Patch nagios-3.4.3-spaces-to-plus-signs.patch (#952139) (upstream http://tracker.nagios.org/view.php?id=407) * Sat Apr 20 2013 Jose Pedro Oliveira <jpo at di.uminho.pt> - 3.5.0-1 - Update to 3.5.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #952139 - Nagios notifications contains "+" signs instead of spaces. https://bugzilla.redhat.com/show_bug.cgi?id=952139 -------------------------------------------------------------------------------- ================================================================================ ogre-1.8.1-6.fc19 (FEDORA-2013-6179) Object-Oriented Graphics Rendering Engine -------------------------------------------------------------------------------- Update Information: This fixes a couple of bugs, mostly of interest to packagers. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Bruno Wolff III <bruno@xxxxxxxx> - 1.8.1-6 - Avoid opening plugins twice * Sat Apr 20 2013 Bruno Wolff III <bruno@xxxxxxxx> - 1.8.1-5 - Allow for plugin names to not end in .so - bz 573672 - Put cmake files in cmake directory instead of an Ogre directory -------------------------------------------------------------------------------- References: [ 1 ] Bug #573672 - DynLib::load forces .so suffix https://bugzilla.redhat.com/show_bug.cgi?id=573672 [ 2 ] Bug #918421 - find_package(OGRE) fails in cmake with ogre-devel installed. https://bugzilla.redhat.com/show_bug.cgi?id=918421 -------------------------------------------------------------------------------- ================================================================================ php-pear-phing-2.5.0-2.fc19 (FEDORA-2013-6186) A project build system based on Apache Ant -------------------------------------------------------------------------------- Update Information: upstream 2.5.0, removal of non-free stuff -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Christof Damian <christof@xxxxxxxxxx> - 2.5.0-2 - remove more mentions of non-free stuff * Sat Apr 20 2013 Christof Damian <christof@xxxxxxxxxx> - 2.5.0-1 - upstream 2.5.0 - remove non-free stuff from defaults.properties (Remi Collet <fedora@xxxxxxxxxxxxxxxxx>) -------------------------------------------------------------------------------- References: [ 1 ] Bug #894748 - Non-free license https://bugzilla.redhat.com/show_bug.cgi?id=894748 [ 2 ] Bug #915717 - php-pear-phing-2.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=915717 -------------------------------------------------------------------------------- ================================================================================ qemu-1.4.1-1.fc19 (FEDORA-2013-6185) QEMU is a FAST! processor emulator -------------------------------------------------------------------------------- Update Information: * Rebased to version 1.4.1 * qemu stable release 1.4.1 (bz #952599) * CVE-2013-1922: qemu-nbd block format auto-detection vulnerability (bz #952574, bz #923219) -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Cole Robinson <crobinso@xxxxxxxxxx> - 2:1.4.1-1 - Rebased to version 1.4.1 - qemu stable release 1.4.1 (bz 952599) - CVE-2013-1922: qemu-nbd block format auto-detection vulnerability (bz 952574, bz 923219) -------------------------------------------------------------------------------- References: [ 1 ] Bug #923219 - CVE-2013-1922 qemu, qemu-kvm, kvm: qemu-nbd block format auto-detection vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=923219 -------------------------------------------------------------------------------- ================================================================================ sphinx-2.0.7-1.fc19 (FEDORA-2013-6184) Free open-source SQL full-text search engine -------------------------------------------------------------------------------- Update Information: upstream 2.0.7, tmpfiles support, aarch64 support -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Christof Damian <christof@xxxxxxxxxx> - 2.0.7-1 - upstream 2.0.7 - use tmpfiles.d to create pid directory - move default log file location to /var/log/sphinx - use systemd macros BZ 850323 * Wed Mar 6 2013 Michel Salim <salimma@xxxxxxxxxxxxxxxxx> - 2.0.6-1 - Update to 2.0.6 - Remove obsoleted patches -------------------------------------------------------------------------------- References: [ 1 ] Bug #689913 - FATAL: failed to create pid file '/var/run/sphinx/searchd.pid': No such file or directory https://bugzilla.redhat.com/show_bug.cgi?id=689913 [ 2 ] Bug #850323 - Introduce new systemd-rpm macros in sphinx spec file https://bugzilla.redhat.com/show_bug.cgi?id=850323 [ 3 ] Bug #868170 - sphinx-2.0.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=868170 [ 4 ] Bug #926564 - sphinx: Does not support aarch64 in f19 and rawhide https://bugzilla.redhat.com/show_bug.cgi?id=926564 -------------------------------------------------------------------------------- ================================================================================ ultimaker-marlin-firmware-12.12-0.5.RC1.fc19 (FEDORA-2013-6187) Ultimaker firmware for the 3D printer -------------------------------------------------------------------------------- Update Information: package now includes both boudrates -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 20 2013 Miro Hrončok <mhroncok@xxxxxxxxxx> - 12.12-0.5.RC1 - Filename changes * Sat Apr 20 2013 Miro Hrončok <mhroncok@xxxxxxxxxx> - 12.12-0.4.RC1 - Include both 115200 and 250000 baudrates -------------------------------------------------------------------------------- ================================================================================ xscreensaver-5.21-3.fc19 (FEDORA-2013-6180) X screen saver and locker -------------------------------------------------------------------------------- Update Information: Some issues are found on several hacks shipped in xscreensaver. Also an issue was reported that when installing gss rpms xscreensaver hacks appears in desktop entry. This new rpm will fix these issues. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 21 2013 Mamoru TASAKA <mtasaka@xxxxxxxxxxxxxxxxx> - 1:5.21-3 - Fix the iteration number for pentomino mode in polyominoes (bug 954077) - Convert maxlife option from 5.20- for fireworkx (bug 953916) - Fix broken Name entry for desktop file of GL hacks (bug 953558) - Add OnlyShownIn entry for desktop files (bug 953558) -------------------------------------------------------------------------------- References: [ 1 ] Bug #954077 - [abrt] xscreensaver-extras-5.21-2.fc19: make_one_sided_pentomino: Process /usr/libexec/xscreensaver/polyominoes was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=954077 [ 2 ] Bug #953916 - [abrt] xscreensaver-extras-5.21-2.fc18: rnd: Process /usr/libexec/xscreensaver/fireworkx was killed by signal 8 (SIGFPE) https://bugzilla.redhat.com/show_bug.cgi?id=953916 [ 3 ] Bug #953558 - Xfce-Panel adds Xscreensaver-Plugins into Panelsection 'Other' (German: Sonstiges) https://bugzilla.redhat.com/show_bug.cgi?id=953558 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test