The following Fedora 20 Security updates need testing: Age URL 101 https://admin.fedoraproject.org/updates/FEDORA-2013-19198/quassel-0.9.1-1.fc20 62 https://admin.fedoraproject.org/updates/FEDORA-2013-22130/chicken-4.8.0.5-1.fc20 47 https://admin.fedoraproject.org/updates/FEDORA-2013-23116/python-swiftclient-1.8.0-1.fc20 38 https://admin.fedoraproject.org/updates/FEDORA-2013-23636/rubygem-actionpack-4.0.0-2.fc20 30 https://admin.fedoraproject.org/updates/FEDORA-2013-24018/varnish-3.0.5-1.fc20 17 https://admin.fedoraproject.org/updates/FEDORA-2014-0579/flite-1.3-21.fc20 16 https://admin.fedoraproject.org/updates/FEDORA-2014-0602/graphviz-2.34.0-8.fc20 12 https://admin.fedoraproject.org/updates/FEDORA-2014-0792/libinfinity-0.5.5-1.fc20 11 https://admin.fedoraproject.org/updates/FEDORA-2014-0926/memcached-1.4.17-1.fc20 10 https://admin.fedoraproject.org/updates/FEDORA-2014-0978/ibus-chewing-1.4.6-1.fc20 8 https://admin.fedoraproject.org/updates/FEDORA-2014-1121/libreswan-3.8-1.fc20 6 https://admin.fedoraproject.org/updates/FEDORA-2014-1207/cxxtools-2.2.1-1.fc20 4 https://admin.fedoraproject.org/updates/FEDORA-2014-1396/moodle-2.5.4-1.fc20 4 https://admin.fedoraproject.org/updates/FEDORA-2014-1341/perl-MARC-XML-1.0.2-1.fc20 2 https://admin.fedoraproject.org/updates/FEDORA-2014-1463/openstack-nova-2013.2.1-3.fc20 2 https://admin.fedoraproject.org/updates/FEDORA-2014-1481/mupdf-1.1-5.fc20 1 https://admin.fedoraproject.org/updates/FEDORA-2014-1552/xen-4.3.1-8.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-1619/tntnet-2.2.1-2.fc20 The following Fedora 20 Critical Path updates have yet to be approved: Age URL 75 https://admin.fedoraproject.org/updates/FEDORA-2013-21163/libproxy-0.4.11-8.fc20 13 https://admin.fedoraproject.org/updates/FEDORA-2014-0772/openldap-2.4.38-1.fc20 10 https://admin.fedoraproject.org/updates/FEDORA-2014-0987/anaconda-20.25.16-1.fc20 6 https://admin.fedoraproject.org/updates/FEDORA-2014-1197/colord-1.1.6-1.fc20 6 https://admin.fedoraproject.org/updates/FEDORA-2014-1231/libwacom-0.8-2.fc20 5 https://admin.fedoraproject.org/updates/FEDORA-2014-1276/pcre-8.33-4.fc20 4 https://admin.fedoraproject.org/updates/FEDORA-2014-1395/krb5-1.11.3-39.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-1436/libnl3-3.2.24-1.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-1410/libsolv-0.4.1-1.gitbcedc98.fc20 3 https://admin.fedoraproject.org/updates/FEDORA-2014-1448/network-manager-applet-0.9.9.0-8.git20140123.fc20 2 https://admin.fedoraproject.org/updates/FEDORA-2014-1480/crda-1.1.3_2013.11.27-3.fc20 1 https://admin.fedoraproject.org/updates/FEDORA-2014-1535/clutter-1.16.2-3.fc20 0 https://admin.fedoraproject.org/updates/FEDORA-2014-1606/libgsf-1.14.29-1.fc20 The following builds have been pushed to Fedora 20 updates-testing cego-2.20.1-1.fc20 devscripts-2.14.1-1.fc20 drupal6-imageapi-1.10-4.fc20 drupal6-imagecache-2.0-6.rc1.fc20 drupal6-imagecache_profiles-1.4-0.2.rc1.fc20 drupal6-user_badges-2.0-1.fc20 drupal7-path_breadcrumbs-3.0-0.7.rc1.fc20 drupal7-variable-2.4-1.fc20 libgsf-1.14.29-1.fc20 malaga-suomi-voikko-1.15-1.fc20 mate-screensaver-1.6.1-5.fc20 ocaml-biniou-1.0.9-2.fc20 openslide-3.4.0-1.fc20 php-Monolog-1.7.0-3.fc20 python-astropy-0.3-7.fc20 sdformat-1.4.11-2.fc20 tntnet-2.2.1-2.fc20 tortoisehg-2.10.2-1.fc20 vdr-skinsoppalusikka-2.0.3-1.fc20 vtk-6.0.0-8.fc20 x2goserver-4.0.1.13-1.fc20 Details about builds: ================================================================================ cego-2.20.1-1.fc20 (FEDORA-2014-1611) A relational and transactional database -------------------------------------------------------------------------------- Update Information: Fix bTree test escaping. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 27 2014 Christopher Meng <rpm@xxxxxxxx> - 2.20.1-1 - Update to 2.20.1(bTree test fix) * Tue Jan 21 2014 Christopher Meng <rpm@xxxxxxxx> - 2.20.0-1 - Update to 2.20.0 -------------------------------------------------------------------------------- ================================================================================ devscripts-2.14.1-1.fc20 (FEDORA-2014-1609) Scripts for Debian Package maintainers -------------------------------------------------------------------------------- Update Information: Update to 2.14.1, see http://ftp-master.metadata.debian.org/changelogs//main/d/devscripts/devscripts_2.14.1_changelog for details -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Sandro Mani <manisandro@xxxxxxxxx> - 2.14.1-1 - Update to 2.13.9 -------------------------------------------------------------------------------- ================================================================================ drupal6-imageapi-1.10-4.fc20 (FEDORA-2014-1610) ImageAPI supporting multiple toolkits -------------------------------------------------------------------------------- Update Information: This API is meant to be used in place of the API provided by image.inc. You probably do not need to install this module unless another module are you using requires it. It provides no new features to your Drupal site. It only provides an API other modules can leverage. Currently GD2 and ImageMagick support are distributed with ImageAPI. This package provides the following Drupal modules: * imageapi * imageapi_gd * imageapi_imagemagick -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> - 1.10-4 - Spec cleanup -------------------------------------------------------------------------------- References: [ 1 ] Bug #829067 - Review Request: drupal6-imageapi - Image API Module for Drupal6 https://bugzilla.redhat.com/show_bug.cgi?id=829067 -------------------------------------------------------------------------------- ================================================================================ drupal6-imagecache-2.0-6.rc1.fc20 (FEDORA-2014-1591) Dynamic image manipulator and cache -------------------------------------------------------------------------------- Update Information: ImageCache allows you to setup presets for image processing. If an ImageCache derivative doesn't exist the web server's rewrite rules will pass the request to Drupal which in turn hands it off to ImageCache to dynamically generate the file. ImageCache allows you to setup presets for image processing. This package provides the following Drupal modules: * imagecache * imagecache_ui -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> - 2.0-6.rc1 - Spec cleanup -------------------------------------------------------------------------------- References: [ 1 ] Bug #829714 - Review Request: drupal6-imagecache - Image Cache module for drupal6 https://bugzilla.redhat.com/show_bug.cgi?id=829714 [ 2 ] Bug #656179 - Review Request: drupal6-imagecache - ImageCache allows you to setup presets for image processing https://bugzilla.redhat.com/show_bug.cgi?id=656179 -------------------------------------------------------------------------------- ================================================================================ drupal6-imagecache_profiles-1.4-0.2.rc1.fc20 (FEDORA-2014-1590) Utilizes image styles for user profile pictures -------------------------------------------------------------------------------- Update Information: ImageCache_Profiles module allows you to set user profile pictures that are consistent throughout your site and allows avatars on the user profile pages, nodes and comments to be a different size. This package provides the following Drupal module: * imagecache_profiles -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> - 1.4-0.2.rc1 - Spec cleanup * Thu Nov 28 2013 Peter Borsa <peter.borsa@xxxxxxxxx> - 1.4-0.1.rc1 - Update to upstream 1.4-rc1 release for bug fixes - Upstream changelog for this release is available at https://drupal.org/node/1304356 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1025986 - drupal6-imagecache_profiles-1.4-rc1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1025986 [ 2 ] Bug #829718 - Review Request: drupal6-imagecache_profiles - Image cache for User Profiles for Drupal6 https://bugzilla.redhat.com/show_bug.cgi?id=829718 -------------------------------------------------------------------------------- ================================================================================ drupal6-user_badges-2.0-1.fc20 (FEDORA-2014-1605) Enables assignment of graphical badges to users and roles -------------------------------------------------------------------------------- Update Information: Updated to 2.0 * Release notes: https://drupal.org/node/2170813 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> 2.0-1 - Updated to 2.0 (BZ #1051399; release notes https://drupal.org/node/2170813) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1051399 - drupal6-user_badges-2.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1051399 -------------------------------------------------------------------------------- ================================================================================ drupal7-path_breadcrumbs-3.0-0.7.rc1.fc20 (FEDORA-2014-1587) Allows creation of custom breadcrumbs for any page using contexts -------------------------------------------------------------------------------- Update Information: Updated to 3.0-rc1 Release notes: * 3.0-rc1: https://drupal.org/node/2181867 * 3.0-beta7: https://drupal.org/node/2169557 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> 3.0-0.7-rc1 - Updated to 3.0-rc1 (BZ #1050855; release notes https://drupal.org/node/2181867) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1050855 - drupal7-path_breadcrumbs-3.0-rc1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1050855 -------------------------------------------------------------------------------- ================================================================================ drupal7-variable-2.4-1.fc20 (FEDORA-2014-1593) Provides a registry for meta-data about Drupal variables -------------------------------------------------------------------------------- Update Information: Updated to 2.4 * Release notes: https://drupal.org/node/2178137 -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 25 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> - 2.4-1 - Updated to 2.4 (BZ #1056423; release notes https://drupal.org/node/2178137) - Spec cleanup * Sat Aug 10 2013 Peter Borsa <peter.borsa@xxxxxxxxx> - 2.3-1 - Update to upstream 2.3 release for bug fixes - Upstream changelog for this release is available at https://drupal.org/node/2061163 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1056423 - drupal7-variable-2.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1056423 -------------------------------------------------------------------------------- ================================================================================ libgsf-1.14.29-1.fc20 (FEDORA-2014-1606) GNOME Structured File library -------------------------------------------------------------------------------- Update Information: Update to 1.14.29 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Peter Robinson <pbrobinson@xxxxxxxxxxxxxxxxx> 1.14.29-1 - Update to 1.14.29 -------------------------------------------------------------------------------- ================================================================================ malaga-suomi-voikko-1.15-1.fc20 (FEDORA-2014-1602) A description of Finnish morphology written in Malaga (Voikko edition) -------------------------------------------------------------------------------- Update Information: New words have been added and various small bugs have been fixed. -------------------------------------------------------------------------------- ChangeLog: * Sat Jan 25 2014 Ville-Pekka Vainio <vpvainio AT iki.fi> - 1.15-1 - Suomi-malaga 1.15 -------------------------------------------------------------------------------- ================================================================================ mate-screensaver-1.6.1-5.fc20 (FEDORA-2014-1600) MATE Screensaver -------------------------------------------------------------------------------- Update Information: - fix pam file, rhbz (#1056591), (#1056591), (#1049479) and (1047823) - re-work configure flags -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Wolfgang Ulbrich <chat-to-me@xxxxxxxxx> - 1.6.1-5 - fix pam file, rhbz (#1056591) and (#1056591) - re-work configure flags -------------------------------------------------------------------------------- References: [ 1 ] Bug #1057402 - [abrt] mate-screensaver: _dbus_abort(): mate-screensaver-dialog killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=1057402 [ 2 ] Bug #1056591 - Missing keyring https://bugzilla.redhat.com/show_bug.cgi?id=1056591 [ 3 ] Bug #1047823 - [abrt] mate-screensaver: link_before(): mate-screensaver-dialog killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1047823 [ 4 ] Bug #1049479 - [abrt] mate-screensaver: _dbus_abort(): mate-screensaver-dialog killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=1049479 -------------------------------------------------------------------------------- ================================================================================ ocaml-biniou-1.0.9-2.fc20 (FEDORA-2014-1620) Safe and fast binary data format -------------------------------------------------------------------------------- Update Information: Initial Fedora release of ocaml-biniou -------------------------------------------------------------------------------- References: [ 1 ] Bug #1055393 - Review Request: ocaml-biniou - Safe and fast binary data format https://bugzilla.redhat.com/show_bug.cgi?id=1055393 -------------------------------------------------------------------------------- ================================================================================ openslide-3.4.0-1.fc20 (FEDORA-2014-1604) C library for reading virtual slides -------------------------------------------------------------------------------- Update Information: OpenSlide 3.4.0 adds support for Hamamatsu NDPI, Leica slides with multiple coplanar main images, MIRAX slides with PNG and BMP encodings, Sakura SVSLIDE, and Ventana BIF (preliminary). It also changes the Leica level size/origin to encompass the entire slide, and improves compatibility with certain MIRAX slides. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Benjamin Gilbert <bgilbert@xxxxxxxxxxxx> - 3.4.0-1 - New release -------------------------------------------------------------------------------- ================================================================================ php-Monolog-1.7.0-3.fc20 (FEDORA-2014-1597) Sends your logs to files, sockets, inboxes, databases and various web services -------------------------------------------------------------------------------- Update Information: RPM-only release. Removed sub-packages (optional dependencies note in description instead). -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 16 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> 1.7.0-3 - Properly obsolete sub-packages * Wed Jan 15 2014 Shawn Iwinski <shawn.iwinski@xxxxxxxxx> 1.7.0-2 - Removed sub-packages (optional dependencies note in description instead) -------------------------------------------------------------------------------- ================================================================================ python-astropy-0.3-7.fc20 (FEDORA-2014-1616) A Community Python Library for Astronomy -------------------------------------------------------------------------------- Update Information: Fixed a missing dependency on python3-six Fixed missing file required for tests -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 27 2014 Sergio Pascual <sergiopr@xxxxxxxxxxxxxxxxx> - 0.3-7 - Add missing requires python3-six * Sat Jan 18 2014 Sergio Pascual <sergiopr@xxxxxxxxxxxxxxxxx> - 0.3-6 - Do not exclude hidden file, it breaks tests -------------------------------------------------------------------------------- ================================================================================ sdformat-1.4.11-2.fc20 (FEDORA-2014-1617) The Simulation Description Format -------------------------------------------------------------------------------- Update Information: Declare LIB_INSTALL_DIR relative to CMAKE_INSTALL_PREFIX (rhbz#1057939). This fix should allow CMake projects to successfully compile against the sdformat library. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Rich Mattes <richmattes@xxxxxxxxx> - 1.4.11-2 - Declare LIB_INSTALL_DIR relative to CMAKE_INSTALL_PREFIX (rhbz#1057939) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1057939 - Wrong library directory in cmake config https://bugzilla.redhat.com/show_bug.cgi?id=1057939 -------------------------------------------------------------------------------- ================================================================================ tntnet-2.2.1-2.fc20 (FEDORA-2014-1619) A web application server for web applications -------------------------------------------------------------------------------- Update Information: Own the %{_datadir}/tntnet dir. this is a security update that fixes the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=1055374 [Bug 1055374] CVE-2013-7299 tntnet: information leak via crafted HTTP request -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Martin Gansser <martinkg@xxxxxxxxxxxxxxxxx> - 2.2.1-2 - Own the %{_datadir}/tntnet dir. - Run unit tests during build. * Mon Jan 20 2014 Martin Gansser <martinkg@xxxxxxxxxxxxxxxxx> - 2.2.1-1 - new release * Sun Sep 22 2013 Michael Schwendt <mschwendt@xxxxxxxxxxxxxxxxx> - 2.2-8 - Add missing dependency on cxxtools-devel in tntnet-devel (#896003). - Add missing /sbin/ldconfig calls in %post and %postun. - Using %defattr is not needed anymore. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1055374 - CVE-2013-7299 tntnet: information leak via crafted HTTP request https://bugzilla.redhat.com/show_bug.cgi?id=1055374 -------------------------------------------------------------------------------- ================================================================================ tortoisehg-2.10.2-1.fc20 (FEDORA-2014-1595) Mercurial GUI command line tool thg -------------------------------------------------------------------------------- Update Information: https://bitbucket.org/tortoisehg/thg/wiki/ReleaseNotes#!tortoisehg-2102 -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Mads Kiilerich <mads@xxxxxxxxxxxxx> - 2.10.2-1 - tortoisehg 2.10.2 -------------------------------------------------------------------------------- ================================================================================ vdr-skinsoppalusikka-2.0.3-1.fc20 (FEDORA-2014-1613) The "Soppalusikka" skin for VDR -------------------------------------------------------------------------------- Update Information: Fixed a memory leak and issues reported by scan-build and cppcheck tools. -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Ville-Pekka Vainio <vpvainio AT iki.fi> - 2.0.3-1 - New upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1051783 - vdr-skinsoppalusikka-2.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1051783 -------------------------------------------------------------------------------- ================================================================================ vtk-6.0.0-8.fc20 (FEDORA-2014-1608) The Visualization Toolkit - A high level 3D visualization library -------------------------------------------------------------------------------- Update Information: Add Requires: libfreetype-devel; libxml2-devel to vtk-devel (bug #1057924) -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 6.0.0-8 - Add Requires: libfreetype-devel; libxml2-devel to vtk-devel (bug #1057924) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1057924 - vtk-devel is missing dependencies on libxml2-devel and freetype-devel https://bugzilla.redhat.com/show_bug.cgi?id=1057924 -------------------------------------------------------------------------------- ================================================================================ x2goserver-4.0.1.13-1.fc20 (FEDORA-2014-1584) X2Go Server -------------------------------------------------------------------------------- Update Information: - Update to 4.0.1.13 - Add xsession sub-package - Fix sound -------------------------------------------------------------------------------- ChangeLog: * Sun Jan 26 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.13-1 - Update 4.0.1.13 - Add xsession sub-package * Tue Jan 7 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.12-1 - Update 4.0.1.12 * Mon Jan 6 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.11-1 - Update 4.0.1.11 - Drop mimetype patch applied upstream -------------------------------------------------------------------------------- References: [ 1 ] Bug #1038834 - /etc/x2go/Xsession script broken https://bugzilla.redhat.com/show_bug.cgi?id=1038834 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test