The following Fedora 21 Security updates need testing: Age URL 1 https://admin.fedoraproject.org/updates/FEDORA-2014-15142/mantis-1.2.17-4.fc21 1 https://admin.fedoraproject.org/updates/FEDORA-2014-14888/arm-none-eabi-binutils-cs-2014.05.28-3.fc21 1 https://admin.fedoraproject.org/updates/FEDORA-2014-14995/avr-binutils-2.24-4.fc21 1 https://admin.fedoraproject.org/updates/FEDORA-2014-15143/moodle-2.7.3-1.fc21 1 https://admin.fedoraproject.org/updates/FEDORA-2014-15150/kwebkitpart-1.3.4-5.fc21 The following Fedora 21 Critical Path updates have yet to be approved: Age URL 5 https://admin.fedoraproject.org/updates/FEDORA-2014-14752/createrepo_c-0.7.3-1.fc21 The following builds have been pushed to Fedora 21 updates-testing Zim-0.62-2.fc21 erlang-edown-0.4-1.fc21 erlang-getopt-0.8.2-1.fc21 erlang-lfe-0.9.0-2.fc21 kde-partitionmanager-1.1.0-3.fc21 libgpod-0.8.3-7.fc21 libguestfs-1.28.3-2.fc21 lonote-3.2.11-1.fc21 mock-1.2.1-1.fc21 php-5.6.3-2.fc21 python-shadowsocks-2.4.3-2.fc21 scummvm-tools-1.7.0-1.fc21 uget-1.99.4-1.fc21 vim-latex-1.8.23-14.20141116.812.gitd0f31c9.fc21 vtun-3.0.3-9.fc21 xfdesktop-4.10.3-1.fc21 xscreensaver-5.31-1.fc21 Details about builds: ================================================================================ Zim-0.62-2.fc21 (FEDORA-2014-15227) Desktop wiki & notekeeper -------------------------------------------------------------------------------- Update Information: Backport upstream bzr755 to fix mis-matched gtk and pygtk in Fedora/RHEL -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Robin Lee <cheeselee@xxxxxxxxxxxxxxxxx> - 0.62-2 - Backport upstream bzr755 to fix mis-matched gtk and pygtk in Fedora/RHEL -------------------------------------------------------------------------------- References: [ 1 ] Bug #1046099 - [abrt] Zim: ipc.py:756:call:ValueError: No such object: <RemoteObject: zim.gui.GtkInterface(file:///home/apjena/Dropbox/ZIM)> https://bugzilla.redhat.com/show_bug.cgi?id=1046099 -------------------------------------------------------------------------------- ================================================================================ erlang-edown-0.4-1.fc21 (FEDORA-2014-15225) EDoc extension for generating Github-flavored Markdown -------------------------------------------------------------------------------- Update Information: * Ver. 0.4 -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Peter Lemenkov <lemenkov@xxxxxxxxx> - 0.4-1 - Ver. 0.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1074175 - erlang-edown-0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1074175 -------------------------------------------------------------------------------- ================================================================================ erlang-getopt-0.8.2-1.fc21 (FEDORA-2014-15242) Erlang module to parse command line arguments using the GNU getopt syntax -------------------------------------------------------------------------------- Update Information: * Ver. 0.8.2 -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Peter Lemenkov <lemenkov@xxxxxxxxx> - 0.8.2-1 - Ver. 0.8.2 * Sun Nov 16 2014 Peter Lemenkov <lemenkov@xxxxxxxxx> - 0.8.2-0 - Bootstrap ver. 0.8.2 with disabled tests -------------------------------------------------------------------------------- References: [ 1 ] Bug #929395 - erlang-getopt-0.8.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=929395 -------------------------------------------------------------------------------- ================================================================================ erlang-lfe-0.9.0-2.fc21 (FEDORA-2014-15233) Lisp Flavoured Erlang -------------------------------------------------------------------------------- Update Information: * Ver. 0.9.0 -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Peter Lemenkov <lemenkov@xxxxxxxxx> - 0.9.0-2 - Disable debuginfo * Sun Nov 16 2014 Peter Lemenkov <lemenkov@xxxxxxxxx> - 0.9.0-1 - Ver. 0.9.0 - Drop support for EL5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1089942 - erlang-lfe-0.9.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1089942 -------------------------------------------------------------------------------- ================================================================================ kde-partitionmanager-1.1.0-3.fc21 (FEDORA-2014-15240) KDE Partition Manager -------------------------------------------------------------------------------- Update Information: Backport upstream patch to fix detection of devices without partition table. -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Mattia Verga <mattia.verga@xxxxxxxxxx> - 1.1.0-3 - Fix detection of devices without partition table -------------------------------------------------------------------------------- ================================================================================ libgpod-0.8.3-7.fc21 (FEDORA-2014-15235) Library to access the contents of an iPod -------------------------------------------------------------------------------- Update Information: switch to mono_arches from a hand written list in ifarch -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Dan Horák <dan[at]danny.cz> - 0.8.3-7 - switch to mono_arches -------------------------------------------------------------------------------- ================================================================================ libguestfs-1.28.3-2.fc21 (FEDORA-2014-15216) Access and modify virtual machine disk images -------------------------------------------------------------------------------- Update Information: New upstream version 1.28.3. -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 15 2014 Richard W.M. Jones <rjones@xxxxxxxxxx> - 1:1.28.3-2 - New upstream version 1.28.3. - Remove patches which are now upstream. -------------------------------------------------------------------------------- ================================================================================ lonote-3.2.11-1.fc21 (FEDORA-2014-15219) Personal Notebook on browser -------------------------------------------------------------------------------- Update Information: Major upstream update -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Robin Lee <cheeselee@xxxxxxxxxxxxxxxxx> - 3.2.11-1 - Update to 3.2.11 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1160436 - [abrt] lonote: im3.py:245:<module>:AttributeError: 'module' object has no attribute 'ABCMeta' https://bugzilla.redhat.com/show_bug.cgi?id=1160436 [ 2 ] Bug #958167 - lonote-3.0.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=958167 [ 3 ] Bug #1030888 - lonote-3.2.11 is available https://bugzilla.redhat.com/show_bug.cgi?id=1030888 -------------------------------------------------------------------------------- ================================================================================ mock-1.2.1-1.fc21 (FEDORA-2014-15224) Builds packages inside chroots -------------------------------------------------------------------------------- Update Information: Bump in plugin ABI. New LVM plugin. Nosync for better IO performance. DNF support. Printing more useful output on terminal. Concurrent shell acces to buildroot. Executing package management commands. --enablerepo and --disablerepo options Short circuit options. Automatic initialization. Python 3 support. Experimantal support for building using systemd-nspawn. Accept path as config. New compress_logs plugin. And lots of bugfixes. -------------------------------------------------------------------------------- ChangeLog: * Sat Nov 15 2014 Miroslav Suchý <msuchy@xxxxxxxxxx> - 1.2.1-1 - allow mockchain to accept path as config - end yum's installroot path with a slash [RHBZ#1160428] - add --mount option [RHBZ#1162637] - add some missing bash completation strings - run --shell as root with --new-chroot - Don't fail scrub when there's no pool [RHBZ#1162631] - Globbing and tilde expansion - move restoring priviledges to finally [RHBZ#1162720] - Remove "Buildroot must be already initialized" note - Add missing --print-root-path to manpage - Do not print ANSI escape characters into log [RHBZ#1163037] - in site-defaults.cfg initialize dictionary of plugins [RHBZ#1162595] - Disable empty names and values in config_opts[macros] [RHBZ#1160765] - Disable single macros in -D cmd option [RHBZ#1160765] - rpmbuild is in /usr/bin [RHBZ#1161112] - man page for --macro-file [RHBZ#1160326] - Added option [--macro-file] to support external rpm macros file [RHBZ#1160326] - Don't output installation/build output when redirected - Better log message for intial buildroot installation - Be more specific when installing configs - Install into correct sitelib when using Python 3 - Fix nosync on aarch64 - wrap all remaining getcwd() [RHBZ#1159300] - do not use rpm in %post scriptlet [RHBZ#1131279] - Fix unclear legal host output [RHBZ#1159794] - allow running from directory, which is deleted [RHBZ#1159300] - create compress_logs plugin [RHBZ#1100923] - when default.cfg exists create default.cfg.rpmnew [RHBZ#1085308] - accept paths to target definition files [RHBZ#1126117] - set title bar in xterm [RHBZ#1126235] - pass --enablerepo/--disablerepo to yum in the same order as provided to mock [RHBZ#1154604] - Fix incorrect printing of binary strings on py3 - Add missing Requires rpm-python3 - Don't print Yum and build output when quiet - Prevent output being printed twice with --verbose (rhbz#1152971) - Fix printing non-ascii characters with output redirected (rhbz#1152952) - replace urlgrabber by python-requests - use python3 for Fedora22+ - Don't print we're doing rpmbuild -bb, when it may not be true - 'prep' choice missing in short-circuit option parser - Don't execute prebuild in short-circuit mode * Thu Oct 9 2014 Miroslav Suchý <msuchy@xxxxxxxxxx> - 1.2.0-1 - update configs for secondary architecture (Dan Horák) - caching of buildroots using LVM (Michael Simacek) - add support for DNF (Michael Simacek) - initial porting to python3 (Michael Simacek) - new config option nosync (Michael Simacek) - add CentOS extra repository [BZ# 1108402] - correctly create default.cfg on arm [BZ# 1033786] - postpone loading of rpm after chroot is set [BZ# 1111147] - use systemd-nspawn instead of chroot [RHBZ# 1132762] - in --copyout do not fail on symlinks [BZ# 971474] - allow to short circuit to prep phase [BZ# 966985] -------------------------------------------------------------------------------- References: [ 1 ] Bug #1160428 - mock 1.2.0 tries to install f21 packages in f19 chroot https://bugzilla.redhat.com/show_bug.cgi?id=1160428 [ 2 ] Bug #1162637 - Provide --umount counterpart for LVM plugin https://bugzilla.redhat.com/show_bug.cgi?id=1162637 [ 3 ] Bug #1162631 - With LVM plugin enabled, I can't scrub traditional directories https://bugzilla.redhat.com/show_bug.cgi?id=1162631 [ 4 ] Bug #1162720 - --copyout prints confusing errors when the copied file doesn't exist https://bugzilla.redhat.com/show_bug.cgi?id=1162720 [ 5 ] Bug #1163037 - Do not print ANSI escape characters into log https://bugzilla.redhat.com/show_bug.cgi?id=1163037 [ 6 ] Bug #1162595 - lvm_root_opts options in site-defaults.cfg don't work https://bugzilla.redhat.com/show_bug.cgi?id=1162595 [ 7 ] Bug #1160765 - empty and single values for rpm macros in mock cfg file and cmd option https://bugzilla.redhat.com/show_bug.cgi?id=1160765 [ 8 ] Bug #1161112 - pre-UsrMove profiles stopped working after update of mock https://bugzilla.redhat.com/show_bug.cgi?id=1161112 [ 9 ] Bug #1160326 - mock new command line option --macro-file for defining rpm macros file https://bugzilla.redhat.com/show_bug.cgi?id=1160326 [ 10 ] Bug #1159300 - running mock from chroot path directory produces "error retrieving current directory: getcwd" https://bugzilla.redhat.com/show_bug.cgi?id=1159300 [ 11 ] Bug #1131279 - mock package has a questionable scriptlet, leading to errors about rpm db version mismatch https://bugzilla.redhat.com/show_bug.cgi?id=1131279 [ 12 ] Bug #1159794 - invalid legal_host_arches option can cause unclear output https://bugzilla.redhat.com/show_bug.cgi?id=1159794 [ 13 ] Bug #1100923 - RFE: compress mock build logs when done building https://bugzilla.redhat.com/show_bug.cgi?id=1100923 [ 14 ] Bug #1085308 - mock: User configuration is lost during update https://bugzilla.redhat.com/show_bug.cgi?id=1085308 [ 15 ] Bug #1126117 - Mock should accept paths to target definition files https://bugzilla.redhat.com/show_bug.cgi?id=1126117 [ 16 ] Bug #1126235 - PROMPT_COMMAND does not include required escape codes https://bugzilla.redhat.com/show_bug.cgi?id=1126235 [ 17 ] Bug #1154604 - mock: enablerepo doesn't work if used after disablerepo https://bugzilla.redhat.com/show_bug.cgi?id=1154604 [ 18 ] Bug #1152971 - Verbose mode is repeating lines https://bugzilla.redhat.com/show_bug.cgi?id=1152971 [ 19 ] Bug #1152952 - [mock] UnicodeEncodeError: 'ascii' codec can't encode characters in position 6-7: ordinal not in range(128) https://bugzilla.redhat.com/show_bug.cgi?id=1152952 -------------------------------------------------------------------------------- ================================================================================ php-5.6.3-2.fc21 (FEDORA-2014-15053) PHP scripting language for creating dynamic web sites -------------------------------------------------------------------------------- Update Information: 13 Nov 2014, PHP 5.6.3 Core: * Implemented 64-bit format codes for pack() and unpack(). (Leigh) * Fixed bug #51800 (proc_open on Windows hangs forever). (Anatol) * Fixed bug #67633 (A foreach on an array returned from a function not doing copy-on-write). (Nikita) * Fixed bug #67739 (Windows 8.1/Server 2012 R2 OS build number reported as 6.2 (instead of 6.3)). (Christian Wenz) * Fixed bug #67949 (DOMNodeList elements should be accessible through array notation) (Florian) * Fixed bug #68095 (AddressSanitizer reports a heap buffer overflow in php_getopt()). (Stas) * Fixed bug #68118 ($a->foo .= 'test'; can leave $a->foo undefined). (Nikita) * Fixed bug #68129 (parse_url() - incomplete support for empty usernames and passwords) (Tjerk) * Fixed bug #68365 (zend_mm_heap corrupted after memory overflow in zend_hash_copy). (Dmitry) CURL: * Add CURL_SSLVERSION_TLSv1_0, CURL_SSLVERSION_TLSv1_1, and CURL_SSLVERSION_TLSv1_2 constants if supported by libcurl (Rasmus) Fileinfo: * Fixed bug #66242 (libmagic: don't assume char is signed). (ArdB) * Fixed bug #68224 (buffer-overflow in libmagic/readcdf.c caught by AddressSanitizer). (Remi) * Fixed bug #68283 (fileinfo: out-of-bounds read in elf note headers). (CVE-2014-3710) (Remi) FPM: * Fixed bug #65641 (PHP-FPM incorrectly defines the SCRIPT_NAME variable when using Apache, mod_proxy-fcgi and ProxyPass). (Remi) * Implemented FR #55508 (listen and listen.allowed_clients should take IPv6 addresses). (Robin Gloster) GD: * Fixed bug #65171 (imagescale() fails without height param). (Remi) GMP: * Implemented gmp_random_range() and gmp_random_bits(). (Leigh) * Fixed bug #63595 (GMP memory management conflicts with other libraries using GMP). (Remi) Mysqli: * Fixed bug #68114 (linker error on some OS X machines with fixed width decimal support) (Keyur Govande) ODBC: * Fixed bug #68087 (ODBC not correctly reading DATE column when preceded by a VARCHAR column) (Keyur Govande) OpenSSL: * Fixed bug #68074 (Allow to use system cipher list instead of hardcoded value). (Remi) PDO_pgsql: * Fixed bug #68199 (PDO::pgsqlGetNotify doesn't support NOTIFY payloads) (Matteo, Alain Laporte) * Fixed bug #66584 (Segmentation fault on statement deallocation) (Matteo) Reflection: * Fixed bug #68103 (Duplicate entry in Reflection for class alias). (Remi) SPL: * Fixed bug #68128 (Regression in RecursiveRegexIterator) (Tjerk) Backported from 5.6.4 FPM: * Fixed bug #68420 (listen=9000 listens to ipv6 localhost instead of all addresses). (Remi) * Fixed bug #68421 (access.format='%R' doesn't log ipv6 address). (Remi) * Fixed bug #68423 (PHP-FPM will no longer load all pools). (Remi) Packaging changes: * fix case sensitivity for some timezones * disable opcache.fast_shutdown in default config -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Remi Collet <remi@xxxxxxxxxxxxxxxxx> 5.6.3-2 - FPM: add upstream patch for https://bugs.php.net/68421 access.format=R doesn't log ipv6 address - FPM: add upstream patch for https://bugs.php.net/68420 listen=9000 listens to ipv6 localhost instead of all addresses - FPM: add upstream patch for https://bugs.php.net/68423 will no longer load all pools * Thu Nov 13 2014 Remi Collet <remi@xxxxxxxxxxxxxxxxx> 5.6.3-1 - Update to PHP 5.6.3 http://php.net/releases/5_6_3.php * Fri Oct 31 2014 Remi Collet <rcollet@xxxxxxxxxx> 5.6.3-0.2.RC1 - php 5.6.3RC1 (refreshed, phpdbg changes reverted) - new version of systzdata patch, fix case sensitivity - ignore Factory in date tests * Wed Oct 29 2014 Remi Collet <rcollet@xxxxxxxxxx> 5.6.3-0.1.RC1 - php 5.6.3RC1 - disable opcache.fast_shutdown in default config - enable phpdbg_webhelper new extension (in php-dbg) -------------------------------------------------------------------------------- ================================================================================ python-shadowsocks-2.4.3-2.fc21 (FEDORA-2014-15221) A fast tunnel proxy that help you get through firewalls -------------------------------------------------------------------------------- Update Information: Upstream release with python3 support -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Robin Lee <cheeselee@xxxxxxxxxxxxxxxxx> - 2.4.3-2 - Build a subpackage for python3 * Sun Nov 16 2014 Robin Lee <cheeselee@xxxxxxxxxxxxxxxxx> - 2.4.3-1 - Update to 2.4.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1143001 - python-shadowsocks-2.4.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1143001 -------------------------------------------------------------------------------- ================================================================================ scummvm-tools-1.7.0-1.fc21 (FEDORA-2014-15220) Tools for scummVM / S.C.U.M.M scripting language -------------------------------------------------------------------------------- Update Information: Update to latest upstream release. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 12 2014 Christian Krause <chkr@xxxxxxxxxxxxxxxxx> - 1.7.0-1 - new upstream release -------------------------------------------------------------------------------- ================================================================================ uget-1.99.4-1.fc21 (FEDORA-2014-15226) Download manager using GTK+ and libcurl -------------------------------------------------------------------------------- Update Information: New version 1.99.4 is released. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 17 2014 Mamoru TASAKA <mtasaka@xxxxxxxxxxxxxxxxx> - 1.99.4-1 - 1.99.4 -------------------------------------------------------------------------------- ================================================================================ vim-latex-1.8.23-14.20141116.812.gitd0f31c9.fc21 (FEDORA-2014-15234) Tools to view, edit and compile LaTeX documents in Vim -------------------------------------------------------------------------------- Update Information: New upstream release with several bug fixes and appdata support. -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Till Maas <opensource@xxxxxxxxx> - 1.8.23-14.20141116.812.gitd0f31c9 - Update to new release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1128816 - Add Addon metadata for GNOME Software to vim-latex https://bugzilla.redhat.com/show_bug.cgi?id=1128816 [ 2 ] Bug #1163518 - LaTeX-suite clobbers the "a" macro https://bugzilla.redhat.com/show_bug.cgi?id=1163518 -------------------------------------------------------------------------------- ================================================================================ vtun-3.0.3-9.fc21 (FEDORA-2014-15236) Virtual tunnel over TCP/IP networks -------------------------------------------------------------------------------- Update Information: added /etc/sysconfig/vtun environment file, updated unit files -------------------------------------------------------------------------------- ChangeLog: * Fri Nov 14 2014 Gabriel Somlo <somlo at cmu.edu> 3.0.3-9 - added /etc/sysconfig/vtun environment file - updated unit files -------------------------------------------------------------------------------- ================================================================================ xfdesktop-4.10.3-1.fc21 (FEDORA-2014-15237) Desktop manager for the Xfce Desktop Environment -------------------------------------------------------------------------------- Update Information: Update to 4.10.3 with various fixes. -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Kevin Fenzi <kevin@xxxxxxxxx> 4.10.3-1 - Update to 4.10.3 with various fixes. -------------------------------------------------------------------------------- ================================================================================ xscreensaver-5.31-1.fc21 (FEDORA-2014-15230) X screen saver and locker -------------------------------------------------------------------------------- Update Information: New version 5.31 is released. -------------------------------------------------------------------------------- ChangeLog: * Sun Nov 16 2014 Mamoru TASAKA <mtasaka@xxxxxxxxxxxxxxxxx> - 1:5.31-1 - Update to 5.31 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test