The following Fedora 19 Security updates need testing: Age URL 344 https://admin.fedoraproject.org/updates/FEDORA-2013-19963/openstack-glance-2013.1.4-1.fc19 156 https://admin.fedoraproject.org/updates/FEDORA-2014-5896/nrpe-2.15-2.fc19 107 https://admin.fedoraproject.org/updates/FEDORA-2014-7496/readline-6.2-8.fc19 105 https://admin.fedoraproject.org/updates/FEDORA-2014-6774/claws-mail-3.10.1-1.fc19,claws-mail-plugins-3.10.0-1.fc19,libetpan-1.5-1.fc19 96 https://admin.fedoraproject.org/updates/FEDORA-2014-7939/lzo-2.08-1.fc19 58 https://admin.fedoraproject.org/updates/FEDORA-2014-9162/xulrunner-31.0-1.fc19 50 https://admin.fedoraproject.org/updates/FEDORA-2014-9427/pipelight-0.2.7.3-3.fc19 37 https://admin.fedoraproject.org/updates/FEDORA-2014-9830/glibc-2.17-21.fc19 25 https://admin.fedoraproject.org/updates/FEDORA-2014-10366/icecream-1.0.1-8.20140822git.fc19 24 https://admin.fedoraproject.org/updates/FEDORA-2014-10640/libreoffice-4.1.6.2-8.fc19 22 https://admin.fedoraproject.org/updates/FEDORA-2014-10714/curl-7.29.0-23.fc19 22 https://admin.fedoraproject.org/updates/FEDORA-2014-10794/squid-3.3.13-2.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11348/kdelibs-4.11.5-5.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11370/nginx-1.4.7-3.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11428/perl-Data-Dumper-2.154-1.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11464/krfb-4.11.5-4.fc19 8 https://admin.fedoraproject.org/updates/FEDORA-2014-11565/nss-softokn-3.17.1-2.fc19,nss-util-3.17.1-1.fc19,nss-3.17.1-1.fc19 8 https://admin.fedoraproject.org/updates/FEDORA-2014-11522/python-2.7.5-14.fc19 8 https://admin.fedoraproject.org/updates/FEDORA-2014-11544/drupal6-6.33-1.fc19 7 https://admin.fedoraproject.org/updates/FEDORA-2014-11649/rubygem-bundler-1.7.3-1.fc19 7 https://admin.fedoraproject.org/updates/FEDORA-2014-11745/seamonkey-2.29.1-1.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-11838/fish-2.1.1-1.fc19 4 https://admin.fedoraproject.org/updates/FEDORA-2014-11929/check-mk-1.2.4p5-2.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-11972/cscope-15.8-5.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-11983/phpMyAdmin-4.2.9.1-1.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-12059/torque-3.0.4-5.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-12057/krb5-1.11.3-29.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-11971/golang-1.3.3-1.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-12000/xen-4.2.5-3.fc19 1 https://admin.fedoraproject.org/updates/FEDORA-2014-12165/mantis-1.2.17-3.fc19 0 https://admin.fedoraproject.org/updates/FEDORA-2014-12235/mksh-50c-1.fc19 The following Fedora 19 Critical Path updates have yet to be approved: Age URL 292 https://admin.fedoraproject.org/updates/FEDORA-2013-22326/fedora-bookmarks-15-5.fc19 218 https://admin.fedoraproject.org/updates/FEDORA-2014-3245/testdisk-6.14-2.fc19.1,ntfs-3g-2014.2.15-1.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11348/kdelibs-4.11.5-5.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11443/firefox-32.0.2-1.fc19 9 https://admin.fedoraproject.org/updates/FEDORA-2014-11394/thunderbird-31.1.1-1.fc19 8 https://admin.fedoraproject.org/updates/FEDORA-2014-11522/python-2.7.5-14.fc19 8 https://admin.fedoraproject.org/updates/FEDORA-2014-11565/nss-softokn-3.17.1-2.fc19,nss-util-3.17.1-1.fc19,nss-3.17.1-1.fc19 7 https://admin.fedoraproject.org/updates/FEDORA-2014-11671/koji-1.9.0-5.fc19 5 https://admin.fedoraproject.org/updates/FEDORA-2014-11828/dash-0.5.8-1.fc19 2 https://admin.fedoraproject.org/updates/FEDORA-2014-12057/krb5-1.11.3-29.fc19 The following builds have been pushed to Fedora 19 updates-testing Lmod-5.7.5-1.fc19 at-3.1.13-15.fc19 hercules-3.11-1.fc19 mksh-50c-1.fc19 python-fedmsg-meta-fedora-infrastructure-0.3.3-1.fc19 x2goserver-4.0.1.17-1.fc19 Details about builds: ================================================================================ Lmod-5.7.5-1.fc19 (FEDORA-2014-12230) Environmental Modules System in Lua -------------------------------------------------------------------------------- Update Information: Update to 5.7.5. There are several bug fixes and some better explantation to the user when there is a bad collection that must be rebuilt and some other small things. The big new feature that is available in 5.7.5 is the ability to group the output of avail into blocks with labels other than the directory name. -------------------------------------------------------------------------------- ================================================================================ at-3.1.13-15.fc19 (FEDORA-2014-12221) Job spooling tools -------------------------------------------------------------------------------- Update Information: Fix regression caused by the bash shellshock fix. -------------------------------------------------------------------------------- ChangeLog: * Sat Oct 4 2014 Tomáš Mráz <tmraz@xxxxxxxxxx> - 3.1.13-15 - filter environment variables not acceptable in bash input (#1147043) -------------------------------------------------------------------------------- ================================================================================ hercules-3.11-1.fc19 (FEDORA-2014-12223) Hercules S/370, ESA/390, and z/Architecture emulator -------------------------------------------------------------------------------- Update Information: updated to 3.11 - Floating-Point-Extension Facility (Roger Bowler) - Enhanced Channel-to-Channel Adapter via TCP/IP (Peter J. Jansen) - Load/Store-on-Condition Facility corrections (Neale Ferguson) - LCS corrections (Paul Gorlinsky, David "Fish" Trout, Ivan Warren) - Floating-Point-Extension Facility corrections (Neale Ferguson) - CMPSC corrections (Bernard van der Helm) - Load sequential datasets from XMIT files (Roger Bowler) - Eliminate compiler warnings for Linux and Mac (Roger Bowler) -------------------------------------------------------------------------------- ChangeLog: * Mon Sep 29 2014 Dan Horák <dan[at]danny.cz> - 3.11-1 - updated to 3.11 (#1142927) * Sat Aug 16 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 3.10-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 3.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1142927 - hercules-3.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1142927 -------------------------------------------------------------------------------- ================================================================================ mksh-50c-1.fc19 (FEDORA-2014-12235) MirBSD enhanced version of the Korn Shell -------------------------------------------------------------------------------- Update Information: R50c is a security fix release: * Know more rare signals when generating sys_signame[] replacement * OpenBSD sync (mostly RCSID only) * Document HISTSIZE limit; found by luigi_345 on IRC * Fix link to Debian .mkshrc * Cease exporting $RANDOM (Debian #760857) * Fix C99 compatibility * Work around klibc bug causing a coredump (Debian #763842) * Use issetugid(2) as additional check if we are FPRIVILEGED * SECURITY: do not permit += from environment * Fix more field splitting bugs reported by Stephane Chazelas and mikeserv; document current status wrt. ambiguous ones as testcases too -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 3 2014 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> 50c-1 - Upgrade to 50c -------------------------------------------------------------------------------- ================================================================================ python-fedmsg-meta-fedora-infrastructure-0.3.3-1.fc19 (FEDORA-2014-12203) Metadata providers for Fedora Infrastructure's fedmsg deployment -------------------------------------------------------------------------------- Update Information: New koschei and anitya processors. Handle new pkgdb messages, certain legacy messages, and new bugzilla messages. git messages now return the full patch via a call to msg2long_form -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 3 2014 Ralph Bean <rbean@xxxxxxxxxx> - 0.3.3-1 - New koschei and anitya processors. * Mon Sep 29 2014 Ralph Bean <rbean@xxxxxxxxxx> - 0.3.2-1 - Latest upstream. - Handle different types of legacy messages. - git messages now return the full patch via a call to msg2long_form. - future-proofing against new types of bugzilla messages. -------------------------------------------------------------------------------- ================================================================================ x2goserver-4.0.1.17-1.fc19 (FEDORA-2014-12204) X2Go Server -------------------------------------------------------------------------------- Update Information: Update to 4.0.1.14: o Fix upgrading from X2Go Server 4.0.1.15 and below if there are still running/suspended sessions. Running and suspended sessions should be restarted after upgrade. o Fix clean-up of X11 socket files. o Fix desktop icon removal. o Wipe-out incomplete sessions from the session DB (can happen on session startup failures). Update to 4.0.1.16: o Complete rewrite of the NX session state control / monitoring o Enhance support for other desktop session types (OpenBox, IceWM) o Attempt at supporting GNOMEv3 Flashback session in X2Go o Support for Cinnamon 1.4 X2Go Sessions o Support configuration of clipboard behaviour (server-side _and_ client-side) o Fix issues with non-resumable sessions after connection disrupture. o Support desktop sharing if sharable sessions is on a kernel namespace socket only. o Move all NX session files to /tmp. Don't store session information in $HOME anymore. Only place symlinks in $HOME pointing to /tmp. Fixes performance and stability of X2Go with homes on network file systems. o Fix privilege upgrades for applications launched via pkexec. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. Update to 4.0.1.16: o Complete rewrite of the NX session state control / monitoring o Enhance support for other desktop session types (OpenBox, IceWM) o Attempt at supporting GNOMEv3 Flashback session in X2Go o Support for Cinnamon 1.4 X2Go Sessions o Support configuration of clipboard behaviour (server-side _and_ client-side) o Fix issues with non-resumable sessions after connection disrupture. o Support desktop sharing if sharable sessions is on a kernel namespace socket only. o Move all NX session files to /tmp. Don't store session information in $HOME anymore. Only place symlinks in $HOME pointing to /tmp. Fixes performance and stability of X2Go with homes on network file systems. o Fix privilege upgrades for applications launched via pkexec. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. Update to 4.0.1.16: o Complete rewrite of the NX session state control / monitoring o Enhance support for other desktop session types (OpenBox, IceWM) o Attempt at supporting GNOMEv3 Flashback session in X2Go o Support for Cinnamon 1.4 X2Go Sessions o Support configuration of clipboard behaviour (server-side _and_ client-side) o Fix issues with non-resumable sessions after connection disrupture. o Support desktop sharing if sharable sessions is on a kernel namespace socket only. o Move all NX session files to /tmp. Don't store session information in $HOME anymore. Only place symlinks in $HOME pointing to /tmp. Fixes performance and stability of X2Go with homes on network file systems. o Fix privilege upgrades for applications launched via pkexec. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. Update to 4.0.1.16: o Complete rewrite of the NX session state control / monitoring o Enhance support for other desktop session types (OpenBox, IceWM) o Attempt at supporting GNOMEv3 Flashback session in X2Go o Support for Cinnamon 1.4 X2Go Sessions o Support configuration of clipboard behaviour (server-side _and_ client-side) o Fix issues with non-resumable sessions after connection disrupture. o Support desktop sharing if sharable sessions is on a kernel namespace socket only. o Move all NX session files to /tmp. Don't store session information in $HOME anymore. Only place symlinks in $HOME pointing to /tmp. Fixes performance and stability of X2Go with homes on network file systems. o Fix privilege upgrades for applications launched via pkexec. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. New upstream release (4.0.1.14): - Log SSHFS output and errors to ~/.x2go/C-<session>/sshfs-mounts.log. (Fixes: #415). - If x2golistmounts is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - If x2goumount-session is used without cmd option <session_id>, then the env var $X2GO_SESSION (current session) will be attempted to use. - Fix x2gostartagent. Make sure the -nolisten tcp option is configurable via x2goagent.options. (Fixes: #424). - Safely remove desktop files for client-side shared folders. Remove the correct desktop file, even if the shared folder has already been (forcefully) umounted. Such situations occur in cases where the connection gets interrupted. SSHFS will then get removed by the Linux kernel and we have to "guess" what desktop icons is actually to be removed. - Fix broken file descriptor closures in x2gocleansessions. (Fixes: #441). - x2gofm.desktop: Drop obsolete Encoding key from .desktop file. - Fix typos / hyphen-as-minus signs issues in x2goversion.8 and x2gomountdirs.8. -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 3 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.17-1 - Update to 4.0.1.17 * Thu Oct 2 2014 Rex Dieter <rdieter@xxxxxxxxxxxxxxxxx> 4.0.1.16-2 - -fmbindings: update mime scriptlets * Thu Sep 25 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.16-1 - Update to 4.0.1.16 * Tue Sep 9 2014 Jitka Plesnikova <jplesnik@xxxxxxxxxx> - 4.0.1.15-7 - Perl 5.20 mass * Wed Aug 27 2014 Jitka Plesnikova <jplesnik@xxxxxxxxxx> - 4.0.1.15-6 - Perl 5.20 rebuild * Tue Aug 26 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.15-5 - Fix scriptlet requires * Mon Aug 18 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 4.0.1.15-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sun Jun 8 2014 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 4.0.1.15-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Fri May 2 2014 Orion Poplawski <orion@xxxxxxxxxxxxx> - 4.0.1.15-2 - Add Requires xorg-x11-xauth -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test