The following Fedora 18 Security updates need testing: Age URL 231 https://admin.fedoraproject.org/updates/FEDORA-2013-6117/eucalyptus-3.2.2-1.fc18 77 https://admin.fedoraproject.org/updates/FEDORA-2013-17195/spice-gtk-0.18-3.fc18 74 https://admin.fedoraproject.org/updates/FEDORA-2013-17431/thunderbird-17.0.9-1.fc18 72 https://admin.fedoraproject.org/updates/FEDORA-2013-17635/wireshark-1.10.2-4.fc18 70 https://admin.fedoraproject.org/updates/FEDORA-2013-17853/davfs2-1.4.7-3.fc18 13 https://admin.fedoraproject.org/updates/FEDORA-2013-21875/389-ds-base-1.3.0.9-1.fc18 8 https://admin.fedoraproject.org/updates/FEDORA-2013-22315/ruby-1.9.3.484-32.fc18 8 https://admin.fedoraproject.org/updates/FEDORA-2013-22313/subversion-1.7.14-1.fc18 5 https://admin.fedoraproject.org/updates/FEDORA-2013-22422/php-symfony2-Security-2.2.10-1.fc18,php-symfony2-Yaml-2.2.10-1.fc18,php-symfony2-Translation-2.2.10-1.fc18,php-symfony2-Finder-2.2.10-1.fc18,php-symfony2-Routing-2.2.10-1.fc18,php-symfony2-Console-2.2.10-1.fc18,php-symfony2-HttpFoundation-2.2.10-1.fc18,php-symfony2-Config-2.2.10-1.fc18,php-symfony2-Validator-2.2.10-1.fc18,php-symfony2-ClassLoader-2.2.10-1.fc18,php-symfony2-PropertyAccess-2.2.10-1.fc18,php-symfony2-Filesystem-2.2.10-1.fc18,php-symfony2-Templating-2.2.10-1.fc18,php-symfony2-DependencyInjection-2.2.10-1.fc18,php-symfony2-HttpKernel-2.2.10-1.fc18,php-symfony2-BrowserKit-2.2.10-1.fc18,php-symfony2-DomCrawler-2.2.10-1.fc18,php-symfony2-EventDispatcher-2.2.10-1.fc18,php-symfony2-Form-2.2.10-1.fc18,php-symfony2-CssSelector-2.2.10-1.fc18,php-symfony2-OptionsResolver-2.2.10-1.fc18,php-symfony2-Process-2.2.10-1.fc18,php-symfony2-Serializer-2.2.10-1.fc18,php-symfony2-Locale-2.2.10-1.fc18 5 https://admin.fedoraproject.org/updates/FEDORA-2013-22456/seamonkey-2.22.1-1.fc18 5 https://admin.fedoraproject.org/updates/FEDORA-2013-22497/ganglia-3.6.0-3.fc18 3 https://admin.fedoraproject.org/updates/FEDORA-2013-22686/tuxcut-5.0-15.fc18 3 https://admin.fedoraproject.org/updates/FEDORA-2013-22607/nbd-3.5-1.fc18 3 https://admin.fedoraproject.org/updates/FEDORA-2013-22606/maradns-2.0.07d-1.fc18 3 https://admin.fedoraproject.org/updates/FEDORA-2013-22695/kernel-3.11.10-100.fc18 1 https://admin.fedoraproject.org/updates/FEDORA-2013-22758/lynis-1.3.6-1.fc18 1 https://admin.fedoraproject.org/updates/FEDORA-2013-22771/gimp-2.8.10-4.fc18 1 https://admin.fedoraproject.org/updates/FEDORA-2013-22786/mod_nss-1.0.8-27.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22949/net-snmp-5.7.2-7.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22911/qt-4.8.5-12.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22866/xen-4.2.3-11.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22929/dcraw-9.19-4.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22899/ufraw-0.19.2-10.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22890/qt3-3.3.8b-54.fc18 The following Fedora 18 Critical Path updates have yet to be approved: Age URL 300 https://admin.fedoraproject.org/updates/FEDORA-2013-2192/nautilus-3.6.3-5.fc18 13 https://admin.fedoraproject.org/updates/FEDORA-2013-21825/gvfs-1.14.2-5.fc18 13 https://admin.fedoraproject.org/updates/FEDORA-2013-21847/sane-backends-1.0.24-7.fc18 10 https://admin.fedoraproject.org/updates/FEDORA-2013-22215/taglib-1.9.1-2.fc18 10 https://admin.fedoraproject.org/updates/FEDORA-2013-22253/kde-settings-4.9-22.fc18 8 https://admin.fedoraproject.org/updates/FEDORA-2013-22299/fedora-bookmarks-15-4.fc18 5 https://admin.fedoraproject.org/updates/FEDORA-2013-22457/libbluray-0.4.0-2.fc18 3 https://admin.fedoraproject.org/updates/FEDORA-2013-22690/libfm-1.1.3-1.fc18 3 https://admin.fedoraproject.org/updates/FEDORA-2013-22695/kernel-3.11.10-100.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22918/opus-1.1-1.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22911/qt-4.8.5-12.fc18 0 https://admin.fedoraproject.org/updates/FEDORA-2013-22917/colord-1.0.5-1.fc18 The following builds have been pushed to Fedora 18 updates-testing SDL-1.2.15-4.fc18 argyllcms-1.6.2-1.fc18 colord-1.0.5-1.fc18 dcraw-9.19-4.fc18 fail2ban-0.8.11-2.fc18 gammaray-1.3.2-1.fc18 geda-gaf-1.8.2-1.fc18 ghc-hjsmin-0.1.4.4-1.fc18 gimp-separate+-0.5.8-10.fc18 globus-callout-2.4-2.fc18 globus-common-14.10-2.fc18 globus-gass-transfer-7.2-9.fc18 globus-gsi-callback-4.6-2.fc18 globus-gsi-cert-utils-8.6-2.fc18 globus-gsi-credential-6.0-2.fc18 globus-gsi-openssl-error-2.1-10.fc18 globus-gsi-proxy-core-6.2-9.fc18 globus-gsi-proxy-ssl-4.1-10.fc18 globus-gsi-sysconfig-5.3-8.fc18 globus-gssapi-error-4.1-10.fc18 globus-gssapi-gsi-10.10-2.fc18 globus-openssl-module-3.3-2.fc18 globus-rls-client-5.2-14.fc18 globus-xio-3.6-2.fc18 gnome-color-manager-3.6.1-2.fc18 ibus-input-pad-1.4.1-1.fc18 input-pad-1.0.3-1.fc18 libkgapi-2.0.2-1.fc18 net-snmp-5.7.2-7.fc18 ocspd-1.9.0-2.fc18 opus-1.1-1.fc18 perl-PAR-Packer-1.017-1.fc18 php-twig-Twig-1.15.0-1.fc18 python-fmn-rules-0.1.3-1.fc18 python-glue-0.4-1.fc18 python-scss-1.2.0-2.fc18 qpid-cpp-0.24-5.fc18 qt-4.8.5-12.fc18 qt3-3.3.8b-54.fc18 salt-api-0.8.3-1.fc18 spring-95.0-3.fc18 springlobby-0.169-8.fc18 ufraw-0.19.2-10.fc18 xen-4.2.3-11.fc18 youtube-dl-2013.12.04-1.fc18 Details about builds: ================================================================================ SDL-1.2.15-4.fc18 (FEDORA-2013-22901) A cross-platform multimedia library -------------------------------------------------------------------------------- Update Information: This release corrects joystick axis event handling. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Petr Pisar <ppisar@xxxxxxxxxx> - 1.2.15-4 - Ignore joystick axis events if they aren't in a sane range (bug #990677) - Adapt to libX11-1.5.99.901 -------------------------------------------------------------------------------- References: [ 1 ] Bug #990677 - SDL1.2.15 has a bug which kills some axis on devices with many axis https://bugzilla.redhat.com/show_bug.cgi?id=990677 -------------------------------------------------------------------------------- ================================================================================ argyllcms-1.6.2-1.fc18 (FEDORA-2013-22895) ICC compatible color management system -------------------------------------------------------------------------------- Update Information: - Update to 1.6.2 - Added "dark region emphasis" -V parameter to targen and colprof - Changed i1d3 driver to be more forgiving of EEProm checksum calculation - Fixed "edges don't match" bug in printarg when -iCM -h -s/-S used. - Fixed bug in -H flag in chartread, dispcal, dispread, illumread & spotread - Fixed bug in dispcal black point optimization to err on the black side - Fixed bug introduced into ColorMunki (spectro) reflective measurement - Fixed major bug in illumread - result was being corrupted. - Fixed problem with TV encoded output and dispread -E -k/-K -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 26 2013 Richard Hughes <rhughes@xxxxxxxxxx> - 1.6.2-1 - Update to 1.6.2 - Added "dark region emphasis" -V parameter to targen and colprof - Changed i1d3 driver to be more forgiving of EEProm checksum calculation - Fixed "edges don't match" bug in printarg when -iCM -h -s/-S used. - Fixed bug in -H flag in chartread, dispcal, dispread, illumread & spotread - Fixed bug in dispcal black point optimization to err on the black side - Fixed bug introduced into ColorMunki (spectro) reflective measurement - Fixed major bug in illumread - result was being corrupted. - Fixed problem with TV encoded output and dispread -E -k/-K * Mon Aug 19 2013 Richard Hughes <rhughes@xxxxxxxxxx> - 1.6.0-1 - Update to 1.6.0 * Tue May 28 2013 Richard Hughes <rhughes@xxxxxxxxxx> - 1.5.1-1 - Update to 1.5.1 -------------------------------------------------------------------------------- ================================================================================ colord-1.0.5-1.fc18 (FEDORA-2013-22917) Color daemon -------------------------------------------------------------------------------- Update Information: - New upstream version - Detect at runtime if the lcms2 function MemoryWrite is faulty - Do not write an invalid dict or mluc data when the resaving - Don't crash with an empty ICC file - Don't create legacy locations when loading stores - Ensure the version is set when using cd_icc_create_from_edid() - Never add USB hubs as scanner devices even if tagged by libsane - Never create color managed webcam devices -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 4 2013 Richard Hughes <richard@xxxxxxxxxxx> 1.0.5-1 - New upstream version - Detect at runtime if the lcms2 function MemoryWrite is faulty - Do not write an invalid dict or mluc data when the resaving - Don't crash with an empty ICC file - Don't create legacy locations when loading stores - Ensure the version is set when using cd_icc_create_from_edid() - Never add USB hubs as scanner devices even if tagged by libsane - Never create color managed webcam devices -------------------------------------------------------------------------------- ================================================================================ dcraw-9.19-4.fc18 (FEDORA-2013-22929) Tool for decoding raw image data from digital cameras -------------------------------------------------------------------------------- Update Information: This update hardens dcraw against corrupt input files which might trigger a division by zero, an infinite loop, or a null pointer dereference otherwise. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2013 Nils Philippsen <nils@xxxxxxxxxx> - 9.19-4 - harden against corrupt input files (CVE-2013-1438) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1002714 - CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws https://bugzilla.redhat.com/show_bug.cgi?id=1002714 -------------------------------------------------------------------------------- ================================================================================ fail2ban-0.8.11-2.fc18 (FEDORA-2013-22238) Ban IPs that make too many password failures -------------------------------------------------------------------------------- Update Information: Update to the 0.8.11 release which contains various bugfixes and support for firewalld actions. -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 3 2013 Adam Tkac <vonsch@xxxxxxxxx> - 0.8.11-2 - include post-release patch for apache-auth filter - fix firewalld support (#979622, comment 18) * Mon Nov 25 2013 Adam Tkac <vonsch@xxxxxxxxx> - 0.8.11-1 - update to 0.8.11 (#1034355) - drop part of the fail2ban-0.8.3-init.patch (merged) - fail2ban-hostsdeny.patch has been merged - fail2ban-mailx.patch has been merged - fail2ban-notmp.patch has been merged -------------------------------------------------------------------------------- References: [ 1 ] Bug #1034355 - Update fail2ban to the 0.8.11 https://bugzilla.redhat.com/show_bug.cgi?id=1034355 [ 2 ] Bug #979622 - [RFE] fail2ban should use firewall-cmd instead of iptables https://bugzilla.redhat.com/show_bug.cgi?id=979622 -------------------------------------------------------------------------------- ================================================================================ gammaray-1.3.2-1.fc18 (FEDORA-2013-22887) A tool for examining internals of Qt applications -------------------------------------------------------------------------------- Update Information: GammaRay 1.3.2 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Daniel Vrátil <dvratil@xxxxxxxxxx> - 1.3.2-1 - GammaRay 1.3.2 * Tue Aug 27 2013 Daniel Vrátil <dvratil@xxxxxxxxxx> - 1.3.1-3 - fix duplicate documentation files (#1001275) * Tue Aug 27 2013 Daniel Vrátil <dvratil@xxxxxxxxxx> - 1.3.1-2 - update Qt sources - fix build against VTK 6.0 -------------------------------------------------------------------------------- ================================================================================ geda-gaf-1.8.2-1.fc18 (FEDORA-2013-22936) Design Automation toolkit for electronic design -------------------------------------------------------------------------------- Update Information: Updated to 1.8.2 -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 1 2013 Shakthi Kannan <shakthimaan [AT] fedoraproject dot org> - 1.8.2-1 - Updated to upstream 1.8.2 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1:1.8.1-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Thu Jul 18 2013 Petr Pisar <ppisar@xxxxxxxxxx> - 1:1.8.1-3 - Perl 5.18 rebuild * Wed Feb 13 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1:1.8.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ ghc-hjsmin-0.1.4.4-1.fc18 (FEDORA-2013-22915) Haskell implementation of a javascript minifier -------------------------------------------------------------------------------- Update Information: Latest release -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Ricky Elrod <codeblock@xxxxxxxxxxxxxxxxx> - 0.1.4.4-1 - Latest upstream release. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038491 - ghc-hjsmin-0.1.4.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1038491 -------------------------------------------------------------------------------- ================================================================================ gimp-separate+-0.5.8-10.fc18 (FEDORA-2013-22910) Rudimentary CMYK support for The GIMP -------------------------------------------------------------------------------- Update Information: New package containing rudimentary CMYK support for The GIMP. New package containing rudimentary CMYK support for The GIMP. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038024 - Wrong directory for gimp-separate+ https://bugzilla.redhat.com/show_bug.cgi?id=1038024 [ 2 ] Bug #34 - wrong permissions of /usr/doc/gimp-manual* https://bugzilla.redhat.com/show_bug.cgi?id=34 [ 3 ] Bug #913289 - Review Request: gimp-separate+ - A plug-in providing rudimentary CMYK support for The GIMP https://bugzilla.redhat.com/show_bug.cgi?id=913289 [ 4 ] Bug #35 - Bugs in /etc/rc.d/init.d/gated script https://bugzilla.redhat.com/show_bug.cgi?id=35 -------------------------------------------------------------------------------- ================================================================================ globus-callout-2.4-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus Callout Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 2.4-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-common-14.10-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Common Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 14.10-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gass-transfer-7.2-9.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus Gass Transfer -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 7.2-9 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-callback-4.6-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus GSI Callback Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 4.6-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-cert-utils-8.6-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus GSI Cert Utils Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 8.6-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-credential-6.0-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus GSI Credential Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 6.0-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-openssl-error-2.1-10.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus OpenSSL Error Handling -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 2.1-10 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-proxy-core-6.2-9.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus GSI Proxy Core Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 6.2-9 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-proxy-ssl-4.1-10.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus GSI Proxy SSL Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 4.1-10 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gsi-sysconfig-5.3-8.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus GSI System Config Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 5.3-8 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gssapi-error-4.1-10.fc18 (FEDORA-2013-22905) Globus Toolkit - GSSAPI Error Library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 4.1-10 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-gssapi-gsi-10.10-2.fc18 (FEDORA-2013-22905) Globus Toolkit - GSSAPI library -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 10.10-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-openssl-module-3.3-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus OpenSSL Module Wrapper -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 3.3-2 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-rls-client-5.2-14.fc18 (FEDORA-2013-22905) Globus Toolkit - Replica Location Service Client -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 5.2-14 - Remove directory man page -------------------------------------------------------------------------------- ================================================================================ globus-xio-3.6-2.fc18 (FEDORA-2013-22905) Globus Toolkit - Globus XIO Framework -------------------------------------------------------------------------------- Update Information: Documentation cleanup - remove junk man pages from doxygen. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 3.6-2 - Remove directory man pages -------------------------------------------------------------------------------- ================================================================================ gnome-color-manager-3.6.1-2.fc18 (FEDORA-2013-22895) Color management tools for GNOME -------------------------------------------------------------------------------- Update Information: - Update to 1.6.2 - Added "dark region emphasis" -V parameter to targen and colprof - Changed i1d3 driver to be more forgiving of EEProm checksum calculation - Fixed "edges don't match" bug in printarg when -iCM -h -s/-S used. - Fixed bug in -H flag in chartread, dispcal, dispread, illumread & spotread - Fixed bug in dispcal black point optimization to err on the black side - Fixed bug introduced into ColorMunki (spectro) reflective measurement - Fixed major bug in illumread - result was being corrupted. - Fixed problem with TV encoded output and dispread -E -k/-K -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Richard Hughes <rhughes@xxxxxxxxxx> - 3.6.1-2 - Fix calibration when using new versions of ArgyllCMS -------------------------------------------------------------------------------- ================================================================================ ibus-input-pad-1.4.1-1.fc18 (FEDORA-2013-22880) Input Pad for IBus -------------------------------------------------------------------------------- Update Information: Integrated the new release. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2013 Takao Fujiwara <tfujiwar@xxxxxxxxxx> - 1.4.1-1 - Bumped to 1.4.1 -------------------------------------------------------------------------------- ================================================================================ input-pad-1.0.3-1.fc18 (FEDORA-2013-22930) On-screen Input Pad to Send Characters with Mouse -------------------------------------------------------------------------------- Update Information: Integrated a new release. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2013 Takao Fujiwara <tfujiwar@xxxxxxxxxx> - 1.0.3-1 - Bumped to 1.0.3 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.0.2-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Thu Apr 4 2013 Takao Fujiwara <tfujiwar@xxxxxxxxxx> - 1.0.2-4 - Added autoreconf to use autoconf 2.69 or later. BZ#925590 * Thu Feb 14 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.0.2-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ libkgapi-2.0.2-1.fc18 (FEDORA-2013-22931) Library to access to Google services -------------------------------------------------------------------------------- Update Information: LibKGAPI 2.0.2 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Dan Vrátil <dvratil@xxxxxxxxxx> - 2.0.2-1 - 2.0.2 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.0.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ net-snmp-5.7.2-7.fc18 (FEDORA-2013-22949) A collection of SNMP protocol tools and libraries -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2012-6151: * snmpd crashes/hangs when AgentX subagent times-out -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Jan Safranek <jsafrane@xxxxxxxxxx> 1:5.7.2-7 - Fixed snmpd crashing when AgentX subagent disconnects in the middle of request processing (#1038011) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038007 - CVE-2012-6151 net-snmp: snmpd crashes/hangs when AgentX subagent times-out https://bugzilla.redhat.com/show_bug.cgi?id=1038007 -------------------------------------------------------------------------------- ================================================================================ ocspd-1.9.0-2.fc18 (FEDORA-2013-22891) OpenCA OCSP Daemon -------------------------------------------------------------------------------- Update Information: * Wed Dec 4 2013 Patrick Monnerat <pm@xxxxxxxxxxxxx> 1.9.0-2 - Patch "stealthy" fixes handling of stealthy connections. https://bugzilla.redhat.com/show_bug.cgi?id=1037717 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 4 2013 Patrick Monnerat <pm@xxxxxxxxxxxxx> 1.9.0-2 - Patch "stealthy" fixes handling of stealthy connections. https://bugzilla.redhat.com/show_bug.cgi?id=1037717 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1037717 - ERROR: Internal memory allocation error!: TCP_CHECK from keepalived balancer daemon https://bugzilla.redhat.com/show_bug.cgi?id=1037717 -------------------------------------------------------------------------------- ================================================================================ opus-1.1-1.fc18 (FEDORA-2013-22918) An audio codec for use in low-delay speech and audio communication -------------------------------------------------------------------------------- Update Information: After more than two years of development, we have released Opus 1.1. This includes: * new analysis code and tuning that significantly improves encoding quality, especially for variable-bitrate (VBR), * automatic detection of speech or music to decide which encoding mode to use * surround with good quality at 128 kbps for 5.1 and usable down to 48 kbps * speed improvements on all architectures, especially ARM, where decoding uses around 40% less CPU and encoding uses around 30% less CPU. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2013 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 1.1-1 - 1.1 release * Tue Dec 3 2013 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 1.1-0.3rc3 - Update to 1.1-rc3 * Thu Nov 28 2013 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 1.1-0.2rc2 - Update to 1.1-rc2 * Tue Nov 26 2013 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 1.1-0.1rc - Update to 1.1-rc * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.0.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ perl-PAR-Packer-1.017-1.fc18 (FEDORA-2013-22897) PAR Packager -------------------------------------------------------------------------------- Update Information: This release corrects build script and internal tests. This release removes an unsed variable from XS code. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Petr Pisar <ppisar@xxxxxxxxxx> - 1.017-1 - 1.017 bump * Mon Dec 2 2013 Petr Pisar <ppisar@xxxxxxxxxx> - 1.016-1 - 1.016 bump -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038511 - perl-PAR-Packer-1.017 is available https://bugzilla.redhat.com/show_bug.cgi?id=1038511 [ 2 ] Bug #1036594 - perl-PAR-Packer-1.016 is available https://bugzilla.redhat.com/show_bug.cgi?id=1036594 -------------------------------------------------------------------------------- ================================================================================ php-twig-Twig-1.15.0-1.fc18 (FEDORA-2013-22927) The flexible, fast, and secure template engine for PHP -------------------------------------------------------------------------------- Update Information: Updated to 1.15.0 This version comes with new functions: max and min, a new filter: round, and a new function: source. It also fixes some issues with the C extension when using the sandbox. Last, but not the least, the Template::getAttribute() works better when one of your classes uses __call() and throws a BadMethodCallException exception when the method is not supported. Release blog post: http://blog.twig.sensiolabs.org/post/69155402481/twig-1-15-0-released -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2013 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> 1.15.0-1 - Updated to 1.15.0 (BZ #1038972) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038972 - php-twig-Twig-1.15.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1038972 -------------------------------------------------------------------------------- ================================================================================ python-fmn-rules-0.1.3-1.fc18 (FEDORA-2013-22943) Message processing rules for Fedora Notifications -------------------------------------------------------------------------------- Update Information: Initial packaging. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1037821 - Review Request: python-fmn-rules - Message processing rules for Fedora Notifications https://bugzilla.redhat.com/show_bug.cgi?id=1037821 -------------------------------------------------------------------------------- ================================================================================ python-glue-0.4-1.fc18 (FEDORA-2013-22909) A simple command line tool to generate CSS sprites -------------------------------------------------------------------------------- Update Information: Update to upstream 0.8. -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 4 2013 Lorenzo Gil Sanchez <lorenzo.gil.sanchez@xxxxxxxxx> - 0.4-1 - Update upstream version to 0.4 * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1036604 - python-glue-0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1036604 -------------------------------------------------------------------------------- ================================================================================ python-scss-1.2.0-2.fc18 (FEDORA-2013-22923) A Scss compiler for Python -------------------------------------------------------------------------------- Update Information: Add new package -------------------------------------------------------------------------------- References: [ 1 ] Bug #1020467 - Review Request: python-scss - A Scss compiler for Python https://bugzilla.redhat.com/show_bug.cgi?id=1020467 -------------------------------------------------------------------------------- ================================================================================ qpid-cpp-0.24-5.fc18 (FEDORA-2013-22940) Libraries for Qpid C++ client applications -------------------------------------------------------------------------------- Update Information: Fixed package inter-dependencies and also the service startup. Fixed the circular depedencies between subpackages. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Darryl L. Pierce <dpierce@xxxxxxxxxx> - 0.24-5 - Fixed how qpid-cpp-server was depending on -store. - qpidd.service now starts after network.service - Resolves: BZ#1038674 - Resolves: BZ#1038094 * Sat Nov 30 2013 Darryl L. Pierce <dpierce@xxxxxxxxxx> - 0.24-4 - Removed rdma.so from the -server subpackage. - Removed rdmaconnector.so from the -client subpackage. - Resolves: BZ#1035323 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038674 - qpid-cpp-server incorrectly depends on qpid-cpp-server-store https://bugzilla.redhat.com/show_bug.cgi?id=1038674 [ 2 ] Bug #1038094 - Qpidd erratically not listening to 0.0.0.0 at boot if using DHCP https://bugzilla.redhat.com/show_bug.cgi?id=1038094 [ 3 ] Bug #1035323 - Package dependency from qpid-cpp-client-rdma https://bugzilla.redhat.com/show_bug.cgi?id=1035323 -------------------------------------------------------------------------------- ================================================================================ qt-4.8.5-12.fc18 (FEDORA-2013-22911) Qt toolkit -------------------------------------------------------------------------------- Update Information: Qt Project Security Advisory: XML Entity Expansion Denial of Service (CVE-2013-4549) See also http://lists.qt-project.org/pipermail/announce/2013-December/000036.html -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 4.8.5-12 - XML Entity Expansion Denial of Service (CVE-2013-4549) * Wed Oct 9 2013 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 4.8.5-11 - Discover printers shared by CUPS 1.6 (#980952) -------------------------------------------------------------------------------- ================================================================================ qt3-3.3.8b-54.fc18 (FEDORA-2013-22890) The shared library for the Qt 3 GUI toolkit -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2013-4549 (XML Entity Expansion Denial of Service) in Qt 3. See the Qt Project Security Advisory for details: http://lists.qt-project.org/pipermail/announce/2013-December/000036.html In addition, some minor packaging cleanups were made. -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> - 3.3.8b-54 - backport CVE-2013-4549 fix from Qt 4 * Tue Aug 27 2013 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 3.3.8b-53 - trim changelog * Tue Aug 27 2013 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 3.3.8b-52 - strip extraneous libs from .pc/.prl files - -devel: due to ^^, drop non-X11-related deps too * Mon Aug 26 2013 Jon Ciesla <limburgher@xxxxxxxxx> - 3.3.8b-51 - libmng rebuild. * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 3.3.8b-50 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Wed Jul 17 2013 Petr Pisar <ppisar@xxxxxxxxxx> - 3.3.8b-49 - Perl 5.18 rebuild * Thu Apr 25 2013 Than Ngo <than@xxxxxxxxxx> - 3.3.8b-48 - build with -fno-strict-aliasing - drop deprecated Encoding * Thu Feb 14 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 3.3.8b-47 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild * Mon Jan 21 2013 Adam Tkac <atkac redhat com> - 3.3.8b-46 - rebuild due to "jpeg8-ABI" feature drop -------------------------------------------------------------------------------- ================================================================================ salt-api-0.8.3-1.fc18 (FEDORA-2013-22903) A web api for to access salt the parallel remote execution system -------------------------------------------------------------------------------- Update Information: Updating to minor release 0.8.3 -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 5 2013 Andrew Niemantsverdriet <andrewniemants@xxxxxxxxx> - Minor bugfix version release * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.8.2-1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ spring-95.0-3.fc18 (FEDORA-2013-22869) Multiplayer, 3D realtime strategy combat game -------------------------------------------------------------------------------- Update Information: - ExclusiveArch should use %ix86 x86_64 instead of i386 x86_64 (#1036567). - Missing dependencies added (#1000755). -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 4 2013 Gilboa Davara <gilboad [AT] gmail [DOT] com> - 95.0-3 - ExclusiveArch should use i386 i486 i586 i686 pentium3 pentium4 athlon geode x86_64 instead of i386 x86_64 (#1036567). * Wed Nov 20 2013 Gilboa Davara <gilboad [AT] gmail [DOT] com> - 95.0-2 - Switch to ExclusiveArch. * Mon Nov 18 2013 Gilboa Davara <gilboad [AT] gmail [DOT] com> - 95.0-1 - Version 95.0, major spring/springlobby upstream release. - Remove EFX patch - applied upstream. * Mon Nov 18 2013 Dave Airlie <airlied@xxxxxxxxxx> - 94.1-7 - rebuilt for GLEW 1.10 * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 94.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Mon Jul 29 2013 Dennis Gilmore <dennis@xxxxxxxx> - 94.1-5 - Exclude arm it needs porting bz#989837 * Sat Jul 27 2013 pmachata@xxxxxxxxxx - 94.1-4 - Rebuild for boost 1.54.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1036567 - why ExclusiveArch? https://bugzilla.redhat.com/show_bug.cgi?id=1036567 [ 2 ] Bug #1000755 - missing dependencies https://bugzilla.redhat.com/show_bug.cgi?id=1000755 -------------------------------------------------------------------------------- ================================================================================ springlobby-0.169-8.fc18 (FEDORA-2013-22885) A lobby client for the spring RTS game engine -------------------------------------------------------------------------------- Update Information: - ExclusiveArch should use %ix86 x86_64 instead of i386 x86_64 (#1036567). - Missing dependencies added (#1000755). -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 4 2013 Gilboa Davara <gilboad [AT] gmail [DOT] com> - 0.169-8 - ExclusiveArch should use i386 i486 i586 i686 pentium3 pentium4 athlon geode x86_64 instead of i386 x86_64 (#1036567). * Wed Nov 20 2013 Gilboa Davara <gilboad [AT] gmail [DOT] com> - 0.169-7 - Switch to ExclusiveArch. * Mon Nov 18 2013 Gilboa Davara <gilboad [AT] gmail [DOT] com> - 0.169-6 - Exclude ARM. - Missing dependencies added (#1000755). - Changelog date cleanup. * Sun Aug 4 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.169-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Sun Jul 28 2013 Petr Machata <pmachata@xxxxxxxxxx> - 0.169-4 - Rebuild for boost 1.54.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1036567 - why ExclusiveArch? https://bugzilla.redhat.com/show_bug.cgi?id=1036567 [ 2 ] Bug #1000755 - missing dependencies https://bugzilla.redhat.com/show_bug.cgi?id=1000755 -------------------------------------------------------------------------------- ================================================================================ ufraw-0.19.2-10.fc18 (FEDORA-2013-22899) Raw image data retrieval tool for digital cameras -------------------------------------------------------------------------------- Update Information: This update hardens ufraw against corrupt input files which might trigger a division by zero, an infinite loop, or a null pointer dereference otherwise. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 6 2013 Nils Philippsen <nils@xxxxxxxxxx> - 0.19.2-10 - harden against corrupt input files (CVE-2013-1438) * Tue Dec 3 2013 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 0.19.2-9 - rebuild (exiv2) * Sat Oct 5 2013 Nils Philippsen <nils@xxxxxxxxxx> - 0.19.2-8 - actually require lcms2-devel for building - update lcms2 patch so that it builds with lcms2 < 2.5 * Wed Oct 2 2013 Nils Philippsen <nils@xxxxxxxxxx> - 0.19.2-7 - build against lcms2 - drop obsolete configure options (exiv2, lensfun, libexif) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1002714 - CVE-2013-1438 CVE-2013-1439 LibRaw: multiple denial of service flaws https://bugzilla.redhat.com/show_bug.cgi?id=1002714 -------------------------------------------------------------------------------- ================================================================================ xen-4.2.3-11.fc18 (FEDORA-2013-22866) Xen is a virtual machine monitor -------------------------------------------------------------------------------- Update Information: HVM guest triggerable AMD CPU erratum may cause host hang [XSA-82, CVE-2013-6885] -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 2 2013 Michael Young <m.a.young@xxxxxxxxxxxx> - 4.2.3-11 - HVM guest triggerable AMD CPU erratum may cause host hang [XSA-82, CVE-2013-6885] -------------------------------------------------------------------------------- ================================================================================ youtube-dl-2013.12.04-1.fc18 (FEDORA-2013-22894) A small command-line program to download online videos -------------------------------------------------------------------------------- Update Information: Update to 2013.12.04 -------------------------------------------------------------------------------- ChangeLog: * Tue Dec 3 2013 Christopher Meng <rpm@xxxxxxxx> - 2013.12.04-1 - Update to new release. * Tue Dec 3 2013 Christopher Meng <rpm@xxxxxxxx> - 2013.12.02-1 - Update to new release. * Fri Nov 29 2013 Christopher Meng <rpm@xxxxxxxx> - 2013.11.29-1 - Update to new release(BZ#1035738). -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038174 - youtube-dl-2013.12.04 is available https://bugzilla.redhat.com/show_bug.cgi?id=1038174 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test