The following Fedora 19 Security updates need testing: Age URL 177 https://admin.fedoraproject.org/updates/FEDORA-2013-19963/openstack-glance-2013.1.4-1.fc19 114 https://admin.fedoraproject.org/updates/FEDORA-2013-24023/varnish-3.0.5-1.fc19 60 https://admin.fedoraproject.org/updates/FEDORA-2014-2710/zabbix-2.0.11-2.fc19 18 https://admin.fedoraproject.org/updates/FEDORA-2014-4676/a2ps-4.14-23.fc19 18 https://admin.fedoraproject.org/updates/FEDORA-2014-4711/cups-filters-1.0.41-6.fc19 11 https://admin.fedoraproject.org/updates/FEDORA-2014-4960/jbigkit-2.0-9.fc19 6 https://admin.fedoraproject.org/updates/FEDORA-2014-5024/smb4k-1.1.1-2.fc19 6 https://admin.fedoraproject.org/updates/FEDORA-2014-5004/httpd-2.4.9-1.fc19 6 https://admin.fedoraproject.org/updates/FEDORA-2014-4975/json-c-0.11-6.fc19 6 https://admin.fedoraproject.org/updates/FEDORA-2014-5031/elfutils-0.158-3.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-4384/cups-1.6.4-5.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-5111/knot-1.4.5-1.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-5139/check-mk-1.2.4p2-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5028/wordpress-3.8.3-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5214/znc-1.2-3.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5238/strongswan-5.1.3-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5236/syncevolution-1.4.1-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5233/kernel-3.13.10-100.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-5290/java-1.8.0-openjdk-1.8.0.5-1.b13.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-5308/srm-1.2.13-1.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-5284/drupal7-7.27-1.fc19,drupal6-6.31-1.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-5337/stunnel-5.01-1.fc19 1 https://admin.fedoraproject.org/updates/FEDORA-2014-5396/community-mysql-5.5.37-1.fc19 1 https://admin.fedoraproject.org/updates/FEDORA-2014-5409/mariadb-5.5.37-1.fc19 1 https://admin.fedoraproject.org/updates/FEDORA-2014-5375/ansible-1.5.5-1.fc19 0 https://admin.fedoraproject.org/updates/FEDORA-2014-5414/bugzilla-4.2.9-1.fc19 The following Fedora 19 Critical Path updates have yet to be approved: Age URL 125 https://admin.fedoraproject.org/updates/FEDORA-2013-22326/fedora-bookmarks-15-5.fc19 51 https://admin.fedoraproject.org/updates/FEDORA-2014-3245/testdisk-6.14-2.fc19.1,ntfs-3g-2014.2.15-1.fc19 12 https://admin.fedoraproject.org/updates/FEDORA-2014-4900/libreport-2.2.1-1.fc19 12 https://admin.fedoraproject.org/updates/FEDORA-2014-4915/kde-workspace-4.11.8-1.fc19 11 https://admin.fedoraproject.org/updates/FEDORA-2014-4934/procps-ng-3.3.8-13.fc19 6 https://admin.fedoraproject.org/updates/FEDORA-2014-5031/elfutils-0.158-3.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-5073/iscsi-initiator-utils-6.2.0.873-21.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-5117/audit-2.3.6-1.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-4384/cups-1.6.4-5.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5223/bash-4.2.47-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5213/xdg-utils-1.1.0-0.24.rc2.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-5233/kernel-3.13.10-100.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-5341/libjpeg-turbo-1.3.1-2.fc19 The following builds have been pushed to Fedora 19 updates-testing apper-0.8.2-1.fc19 autoarchive-1.1.1-1.fc19 bugzilla-4.2.9-1.fc19 gtk-murrine-engine-0.98.2-5.fc19 gtkspell3-3.0.5-1.fc19 mingw-gtkspell3-3.0.5-1.fc19 nodejs-bindings-1.2.0-1.fc19 nodejs-chalk-0.4.0-2.fc19 nodejs-ejs-1.0.0-1.fc19 nodejs-grunt-0.4.4-2.fc19 nodejs-grunt-contrib-concat-0.4.0-1.fc19 nodejs-grunt-contrib-internal-0.4.9-1.fc19 nodejs-grunt-contrib-nodeunit-0.3.3-1.fc19 nodejs-has-color-0.1.7-1.fc19 nodejs-i2c-0.1.4-9.fc19 nodejs-jasmine-reporters-0.4.1-1.fc19 nodejs-jwt-simple-0.2.0-1.fc19 nodejs-libxmljs-0.9.0-1.fc19 nodejs-ltx-0.5.0-1.fc19 nodejs-pubcontrol-0.3.5-1.fc19 nodejs-sax-0.6.0-1.fc19 nodejs-strip-ansi-0.2.0-1.fc19 nodejs-stylus-0.43.1-1.fc19 nodejs-xml2js-0.2.8-3.fc19 nodeunit-0.8.6-4.fc19 pcc-1.1.0-0.1.20140420cvs.fc19 Details about builds: ================================================================================ apper-0.8.2-1.fc19 (FEDORA-2014-5429) KDE interface for PackageKit -------------------------------------------------------------------------------- Update Information: An update of Apper to the latest upstream release, version 0.8.2, fixing a small memory leak and adding an appdata XML file. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> 0.8.2-1 - update to 0.8.2 - drop upstreamed apper-updater-l10n.patch - update file list for the new apper.appdata.xml -------------------------------------------------------------------------------- ================================================================================ autoarchive-1.1.1-1.fc19 (FEDORA-2014-5423) A simple backup tool that uses tar -------------------------------------------------------------------------------- Update Information: Update to latest upstream version 1.1.1 -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Fabian Affolter <mail@xxxxxxxxxxxxxxxxxx> - 1.1.1-1 - Update to latest upstream version 1.1.1 -------------------------------------------------------------------------------- ================================================================================ bugzilla-4.2.9-1.fc19 (FEDORA-2014-5414) Bug tracking system -------------------------------------------------------------------------------- Update Information: Previous versions of bugzilla had the following security issues: * The login form had no CSRF protection, meaning that an attacker could force the victim to log in using the attacker's credentials. * Dangerous control characters can be inserted into Bugzilla, notably into bug comments, which can then be used to execute local commands. The first issue has the CVE number CVE-2014-1517. Please see http://www.bugzilla.org/security/4.0.11/ for all the gory details. Both issues were fixed in 4.2.8 but it introduced a regression in bug commenting that was fixed in 4.2.9. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Emmanuel Seyman <emmanuel@xxxxxxxxx> - 4.2.9-1 - Update to 4.2.9 (regression fix for 4.2.8 which was a security update) - Drop backported patches -------------------------------------------------------------------------------- ================================================================================ gtk-murrine-engine-0.98.2-5.fc19 (FEDORA-2014-5419) Murrine GTK2 engine -------------------------------------------------------------------------------- Update Information: Silence deprecation warnings (#1046757) -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Martin Sourada <mso@xxxxxxxxxxxxxxxxx> - 0.98.2-5 - Silence deprecation warnings (#1046757) * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.98.2-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1046757 - Murrine configuration option "scrollbar_color" is no longer supported and will be ignored. https://bugzilla.redhat.com/show_bug.cgi?id=1046757 -------------------------------------------------------------------------------- ================================================================================ gtkspell3-3.0.5-1.fc19 (FEDORA-2014-5434) On-the-fly spell checking for GtkTextView widgets -------------------------------------------------------------------------------- Update Information: Update to version 3.0.5, see http://gtkspell.sourceforge.net/ChangeLog for details. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Sandro Mani <manisandro@xxxxxxxxx> - 3.0.5-1 - Update to 3.0.5 -------------------------------------------------------------------------------- ================================================================================ mingw-gtkspell3-3.0.5-1.fc19 (FEDORA-2014-5441) MinGW Windows GtkSpell3 library -------------------------------------------------------------------------------- Update Information: Update to version 3.0.5, see http://gtkspell.sourceforge.net/ChangeLog for details. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Sandro Mani <manisandro@xxxxxxxxx> - 3.0.5-1 - Update to 3.0.5 -------------------------------------------------------------------------------- ================================================================================ nodejs-bindings-1.2.0-1.fc19 (FEDORA-2014-5421) Helper module for loading your native module's .node file -------------------------------------------------------------------------------- Update Information: Update to latest releases. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 1.2.0-1 - update to upstream release 1.2.0 -------------------------------------------------------------------------------- ================================================================================ nodejs-chalk-0.4.0-2.fc19 (FEDORA-2014-5440) Terminal string styling done right -------------------------------------------------------------------------------- Update Information: Update to latest releases of has-color and strip-ansi. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.4.0-2 - fix versioned dependencies -------------------------------------------------------------------------------- ================================================================================ nodejs-ejs-1.0.0-1.fc19 (FEDORA-2014-5415) Embedded JavaScript templates for Node.js -------------------------------------------------------------------------------- Update Information: Update to latest releases of nodejs-grunt-contrib-nodeunit and nodejs-ejs. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 1.0.0 - update to upstream release 1.0.0 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.8.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ nodejs-grunt-0.4.4-2.fc19 (FEDORA-2014-5439) Grunt is a JavaScript library used for automation and running tasks -------------------------------------------------------------------------------- Update Information: Update to latest release of grunt-contrib-internal and grunt-contrib-concat. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.4.4-2 - add missing internal-tasks/ folder -------------------------------------------------------------------------------- ================================================================================ nodejs-grunt-contrib-concat-0.4.0-1.fc19 (FEDORA-2014-5439) Concatenate files with grunt -------------------------------------------------------------------------------- Update Information: Update to latest release of grunt-contrib-internal and grunt-contrib-concat. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.4.0-1 - update to upstream release 0.4.0 -------------------------------------------------------------------------------- ================================================================================ nodejs-grunt-contrib-internal-0.4.9-1.fc19 (FEDORA-2014-5439) Internal tasks for managing the grunt-contrib project -------------------------------------------------------------------------------- Update Information: Update to latest release of grunt-contrib-internal and grunt-contrib-concat. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.4.9-1 - update to upstream release 0.4.9 -------------------------------------------------------------------------------- ================================================================================ nodejs-grunt-contrib-nodeunit-0.3.3-1.fc19 (FEDORA-2014-5415) Run Nodeunit unit tests with grunt -------------------------------------------------------------------------------- Update Information: Update to latest releases of nodejs-grunt-contrib-nodeunit and nodejs-ejs. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.3.3-2 - update to upstream release 0.3.3 -------------------------------------------------------------------------------- ================================================================================ nodejs-has-color-0.1.7-1.fc19 (FEDORA-2014-5440) Detects whether a terminal supports color -------------------------------------------------------------------------------- Update Information: Update to latest releases of has-color and strip-ansi. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.1.7-1 - update to upstream release 0.1.7 -------------------------------------------------------------------------------- ================================================================================ nodejs-i2c-0.1.4-9.fc19 (FEDORA-2014-5421) Node.js native bindings for i2c-dev -------------------------------------------------------------------------------- Update Information: Update to latest releases. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.1.4-9 - fix version of npm(underscore) dependency * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.1.4-8 - put nodejs_default_filter before nodejs_find_provides_and_requires * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.1.4-7 - fix version of npm(bindings) dependency * Fri Apr 18 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.1.4-6 - fix version of npm(underscore) dependency * Fri Feb 14 2014 T.C. Hollingsworth <tchollingsworth@xxxxxxxxx> - 0.1.4-5 - rebuild for icu-53 (via v8) * Sun Jan 19 2014 T.C. Hollingsworth <tchollingsworth@xxxxxxxxx> - 0.1.4-4 - fix underscore for 1.5.1 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.1.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild * Sat Jul 13 2013 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.1.4-2 - add macro for Provides and Requires -------------------------------------------------------------------------------- ================================================================================ nodejs-jasmine-reporters-0.4.1-1.fc19 (FEDORA-2014-5422) Reporters for the Jasmine behavior-driven development (BDD) framework -------------------------------------------------------------------------------- Update Information: Update to latest release. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.4.1-1 - update to upstream release 0.4.1 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.2.1-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ nodejs-jwt-simple-0.2.0-1.fc19 (FEDORA-2014-5417) JWT(JSON Web Token) encode and decode module for Node.js -------------------------------------------------------------------------------- Update Information: Update to latest releases. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.2.0-1 - update to upstream release 0.2.0 * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.1.0-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ nodejs-libxmljs-0.9.0-1.fc19 (FEDORA-2014-5421) Node.js module that provides libxml bindings for the v8 javascript engine -------------------------------------------------------------------------------- Update Information: Update to latest releases. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.9.0-1 - update to upstream release 0.9.0 * Fri Feb 14 2014 T.C. Hollingsworth <tchollingsworth@xxxxxxxxx> - 0.8.1-4 - rebuild for icu-53 (via v8) -------------------------------------------------------------------------------- ================================================================================ nodejs-ltx-0.5.0-1.fc19 (FEDORA-2014-5430) A Node.js module for parsing, modifying and building XML -------------------------------------------------------------------------------- Update Information: Update to latest releases of stylus, sax and ltx. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.5.0-1 - update to upstream release 0.5.0 -------------------------------------------------------------------------------- ================================================================================ nodejs-pubcontrol-0.3.5-1.fc19 (FEDORA-2014-5417) HTTP Extensible Pubsub Control Protocol (EPCP) library for Node.js -------------------------------------------------------------------------------- Update Information: Update to latest releases. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.3.5-1 - update to upstream release 0.3.5 -------------------------------------------------------------------------------- ================================================================================ nodejs-sax-0.6.0-1.fc19 (FEDORA-2014-5430) A streaming SAX-style XML parser in JavaScript for Node.js -------------------------------------------------------------------------------- Update Information: Update to latest releases of stylus, sax and ltx. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.6.0-1 - update to upstream release 0.6.0 -------------------------------------------------------------------------------- ================================================================================ nodejs-strip-ansi-0.2.0-1.fc19 (FEDORA-2014-5440) Strip ANSI escape codes (used for colorizing strings in the terminal) -------------------------------------------------------------------------------- Update Information: Update to latest releases of has-color and strip-ansi. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.2.0-1 - update to upstream release 0.2.0 -------------------------------------------------------------------------------- ================================================================================ nodejs-stylus-0.43.1-1.fc19 (FEDORA-2014-5430) Robust, expressive, and feature-rich CSS super-set for Node.js -------------------------------------------------------------------------------- Update Information: Update to latest releases of stylus, sax and ltx. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.43.1-1 - update to upstream release 0.43.1 -------------------------------------------------------------------------------- ================================================================================ nodejs-xml2js-0.2.8-3.fc19 (FEDORA-2014-5430) Simple XML to JavaScript object converter -------------------------------------------------------------------------------- Update Information: Update to latest releases of stylus, sax and ltx. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.2.8-3 - fix version of npm(sax) dependency * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.2.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ nodeunit-0.8.6-4.fc19 (FEDORA-2014-5415) Easy asynchronous unit testing framework for Node.js -------------------------------------------------------------------------------- Update Information: Update to latest releases of nodejs-grunt-contrib-nodeunit and nodejs-ejs. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 19 2014 Jamie Nguyen <jamielinux@xxxxxxxxxxxxxxxxx> - 0.8.6-4 - fix version of npm(ejs) dependency -------------------------------------------------------------------------------- ================================================================================ pcc-1.1.0-0.1.20140420cvs.fc19 (FEDORA-2014-5416) The Portable C Compiler -------------------------------------------------------------------------------- Update Information: Disable inlining in low level functions where it should not be done. Update to newest CVS release. -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 20 2014 Susi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 1.1.0-0.1.20140420cvs - Disable inlining in low level functions where it should not be done. - Update to newest CVS release. * Mon Aug 19 2013 Susi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 1.0.0-3.20111216cvs - Fix FTBFS on rawhide. * Sat Aug 3 2013 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.0.0-2.20111216cvs.2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test