The following Fedora 23 Security updates need testing: Age URL 15 https://bodhi.fedoraproject.org/F23/FEDORA-2015-12739 14 https://bodhi.fedoraproject.org/F23/FEDORA-2015-12852 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13287 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13358 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13314 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13463 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13515 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13641 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13721 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13759 0 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13824 The following Fedora 23 Critical Path updates have yet to be approved: Age URL 14 https://bodhi.fedoraproject.org/F23/FEDORA-2015-12876 14 https://bodhi.fedoraproject.org/F23/FEDORA-2015-12852 12 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13032 10 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13101 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13282 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13283 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13290 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13312 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13323 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13298 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13287 7 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13284 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13515 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13438 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13499 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13530 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13451 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13447 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13464 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13531 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13504 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13475 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13503 5 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13450 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13694 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13725 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13697 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13626 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13748 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13713 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13449 1 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13372 0 https://bodhi.fedoraproject.org/F23/FEDORA-2015-13831 The following builds have been pushed to Fedora 23 updates-testing anaconda-23.19.1-1.fc23 dnf-plugin-spacewalk-2.4.15-1.fc23 gfbgraph-0.2.3-1.fc23 mate-themes-1.10.4-1.fc23 perl-CGI-Application-Structured-Tools-0.015-10.fc23 python-blivet-1.12.1-1.fc23 python-django-1.8.4-1.fc23 python-gssapi-1.1.2-1.fc23 python-rpmfluff-0.4.2-1.fc23 qmasterpassword-1.2.1-1.fc23 Details about builds: ================================================================================ anaconda-23.19.1-1.fc23 (FEDORA-2015-13831) Graphical system installer -------------------------------------------------------------------------------- Update Information: anaconda-23.19.1-1.fc23 - Destroy the keyboard layout dialog when finished (#1254150) (dshea) - Do not encode the geoloc timezone to bytes (#1240812) (dshea) - Skip source url checks when network is off (#1251130) (bcl) - Don't set net.device to link if there is no ksdevice (#1085310) (bcl) - Reading carrier while link is down raises IOError (#1085310) (bcl) - Make sure username entered in TUI if create a user chosen. (#1249660) (sbueno+anaconda) - Write the empty dnf langpacks.conf to the right directory (#1253469) (dshea) - Add pyanaconda test for network.check_ip_address (jkonecny) - Replace IPy package by ipaddress (jkonecny) - Fix crash when new device appear in Welcome screen (#1245960) (jkonecny) - Fix crash when connections are changing (#1245960) (jkonecny) - product.img buildstamp should override distribution buildstamp (#1240238) (bcl) - On incomplete ks, don't automatically proceed with install. (#1034282) (sbueno+anaconda) - Few fixes and amendments for the boot_options.rst file (vpodzime) - Prevent issues with encrypted LVs on renamed VGs (#1224045) (vpodzime) - Create and use snapshot of on-disk storage with no modifications (#1166598) (vpodzime) - Implement the class for storage snapshots (vpodzime) - Prevent any changes in the StorageSpoke if just going back (vpodzime) - Make StorageSpoke's on_back_clicked less complicated (vpodzime) - Change zanata.xml to match new f23-branch name. (sbueno+anaconda) python-blivet-1.12.1-1.fc23 - Change labelFormatOK to classmethods (vtrefny) - Remove the cacheRequest kwarg for thin(pool) LVs (#1254567) (vpodzime) - Fix copy method (#1254135) (bcl) - Add OSError to list of errors in updateSysfsPath (#1252949) (bcl) - Make sure LV's properties reporting size return a Size instance (#1253787) (vpodzime) - Use device name from udev only if it's available (#1252052) (vpodzime) - Fix _unalignedMaxPartSize for logical partitions (#1250890) (vtrefny) - Allow aligning free regions to disk grainSize (#1244671) (vtrefny) - Add test for getFreeSpace aligning (vtrefny) - Change zanata.xml to match new f23-branch name. (sbueno+anaconda) Multiple bugfixes: - Remove unusable free regions from list when setting up growth. (dlehman) - Merge pull request #190 from vpodzime/master-lvm_cache_creation (dlehman) - Merge pull request #194 from dwlehman/mount-cache-symlinks (dlehman) - Merge pull request #193 from dwlehman/md-fwraid-detection (dlehman) - Add unit tests to cover md containers. (dlehman) - Minor cleanup of blivet.formats.fs.BTRFS._preSetup. (dlehman) - Fix isDisk and partitionable properties for md fwraid. (dlehman) - Don't use MD_DEVNAME as device name for md partitions. (dlehman) - Use udev to find name of md members' container. (dlehman) - Call superclass ctor a bit later to get size attrs set up first. (dlehman) - updateSize for md containers is a no-op. (dlehman) - Fix UnboundLocalError in FSMinSize (#1249304) (vtrefny) - Fix mount cache resolution of devices with symlinks. (#1247803) (dlehman) - Add kwarg to udev.resolve_devspec to return canonical device name. (dlehman) - Use slow as well as fast PVs for cached LV's non-cache part (vpodzime) - Make VG determination in Blivet.newLV() less cryptic (vpodzime) - Reserve space for LVM cache(s) when growing LVM requests (vpodzime) - Create cached LVs before non- cached LVs (vpodzime) - Add support for LVM cache creation to LVM device classes (vpodzime) - Add generic class for cache creation requests (vpodzime) - Two minor fixes in LVMLogicalVolumeDevice's constructor's docstring (vpodzime) New release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1249304 - UnboundLocalError: local variable 'e' referenced before assignment https://bugzilla.redhat.com/show_bug.cgi?id=1249304 [ 2 ] Bug #1246842 - python3-blivet 1.10 pulls in X stack https://bugzilla.redhat.com/show_bug.cgi?id=1246842 [ 3 ] Bug #1247803 - _ped.IOException: Partition(s) 1 on /dev/md/Volume0_0 have been written, but we have been unable to inform the kernel of the change, probably because it/they are in use. As a result, the old partition(s) will remain in use. You should reboot now ... https://bugzilla.redhat.com/show_bug.cgi?id=1247803 -------------------------------------------------------------------------------- ================================================================================ dnf-plugin-spacewalk-2.4.15-1.fc23 (FEDORA-2015-13825) DNF plugin for Spacewalk -------------------------------------------------------------------------------- Update Information: This DNF plugin provides access to a Spacewalk server for software updates. dnf- plugin-spacewalk-2.4.15-1.fc22 - 1254551 - fixed error message output dnf- plugin-spacewalk-2.4.15-1.fc23 - 1254551 - fixed error message output -------------------------------------------------------------------------------- ================================================================================ gfbgraph-0.2.3-1.fc23 (FEDORA-2015-13817) GLib/GObject wrapper for the Facebook Graph API -------------------------------------------------------------------------------- Update Information: Updated the Facebook Graph API to version 2.3 due to deprecation of 1.0 -------------------------------------------------------------------------------- ================================================================================ mate-themes-1.10.4-1.fc23 (FEDORA-2015-13819) MATE Desktop themes -------------------------------------------------------------------------------- Update Information: mate-themes-1.10.4-1.fc23 - update to 1.10.4 release -------------------------------------------------------------------------------- ================================================================================ perl-CGI-Application-Structured-Tools-0.015-10.fc23 (FEDORA-2015-13832) Tools to generate and maintain CGI::Application::Structured based web apps -------------------------------------------------------------------------------- Update Information: perl-CGI-Application-Structured-Tools-0.015-10.fc23 - Apply patch to adapt to Module::Starter 1.71 (#1195343) -------------------------------------------------------------------------------- ================================================================================ python-blivet-1.12.1-1.fc23 (FEDORA-2015-13831) A python module for system storage configuration -------------------------------------------------------------------------------- Update Information: anaconda-23.19.1-1.fc23 - Destroy the keyboard layout dialog when finished (#1254150) (dshea) - Do not encode the geoloc timezone to bytes (#1240812) (dshea) - Skip source url checks when network is off (#1251130) (bcl) - Don't set net.device to link if there is no ksdevice (#1085310) (bcl) - Reading carrier while link is down raises IOError (#1085310) (bcl) - Make sure username entered in TUI if create a user chosen. (#1249660) (sbueno+anaconda) - Write the empty dnf langpacks.conf to the right directory (#1253469) (dshea) - Add pyanaconda test for network.check_ip_address (jkonecny) - Replace IPy package by ipaddress (jkonecny) - Fix crash when new device appear in Welcome screen (#1245960) (jkonecny) - Fix crash when connections are changing (#1245960) (jkonecny) - product.img buildstamp should override distribution buildstamp (#1240238) (bcl) - On incomplete ks, don't automatically proceed with install. (#1034282) (sbueno+anaconda) - Few fixes and amendments for the boot_options.rst file (vpodzime) - Prevent issues with encrypted LVs on renamed VGs (#1224045) (vpodzime) - Create and use snapshot of on-disk storage with no modifications (#1166598) (vpodzime) - Implement the class for storage snapshots (vpodzime) - Prevent any changes in the StorageSpoke if just going back (vpodzime) - Make StorageSpoke's on_back_clicked less complicated (vpodzime) - Change zanata.xml to match new f23-branch name. (sbueno+anaconda) python-blivet-1.12.1-1.fc23 - Change labelFormatOK to classmethods (vtrefny) - Remove the cacheRequest kwarg for thin(pool) LVs (#1254567) (vpodzime) - Fix copy method (#1254135) (bcl) - Add OSError to list of errors in updateSysfsPath (#1252949) (bcl) - Make sure LV's properties reporting size return a Size instance (#1253787) (vpodzime) - Use device name from udev only if it's available (#1252052) (vpodzime) - Fix _unalignedMaxPartSize for logical partitions (#1250890) (vtrefny) - Allow aligning free regions to disk grainSize (#1244671) (vtrefny) - Add test for getFreeSpace aligning (vtrefny) - Change zanata.xml to match new f23-branch name. (sbueno+anaconda) Multiple bugfixes: - Remove unusable free regions from list when setting up growth. (dlehman) - Merge pull request #190 from vpodzime/master-lvm_cache_creation (dlehman) - Merge pull request #194 from dwlehman/mount-cache-symlinks (dlehman) - Merge pull request #193 from dwlehman/md-fwraid-detection (dlehman) - Add unit tests to cover md containers. (dlehman) - Minor cleanup of blivet.formats.fs.BTRFS._preSetup. (dlehman) - Fix isDisk and partitionable properties for md fwraid. (dlehman) - Don't use MD_DEVNAME as device name for md partitions. (dlehman) - Use udev to find name of md members' container. (dlehman) - Call superclass ctor a bit later to get size attrs set up first. (dlehman) - updateSize for md containers is a no-op. (dlehman) - Fix UnboundLocalError in FSMinSize (#1249304) (vtrefny) - Fix mount cache resolution of devices with symlinks. (#1247803) (dlehman) - Add kwarg to udev.resolve_devspec to return canonical device name. (dlehman) - Use slow as well as fast PVs for cached LV's non-cache part (vpodzime) - Make VG determination in Blivet.newLV() less cryptic (vpodzime) - Reserve space for LVM cache(s) when growing LVM requests (vpodzime) - Create cached LVs before non- cached LVs (vpodzime) - Add support for LVM cache creation to LVM device classes (vpodzime) - Add generic class for cache creation requests (vpodzime) - Two minor fixes in LVMLogicalVolumeDevice's constructor's docstring (vpodzime) New release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1249304 - UnboundLocalError: local variable 'e' referenced before assignment https://bugzilla.redhat.com/show_bug.cgi?id=1249304 [ 2 ] Bug #1246842 - python3-blivet 1.10 pulls in X stack https://bugzilla.redhat.com/show_bug.cgi?id=1246842 [ 3 ] Bug #1247803 - _ped.IOException: Partition(s) 1 on /dev/md/Volume0_0 have been written, but we have been unable to inform the kernel of the change, probably because it/they are in use. As a result, the old partition(s) will remain in use. You should reboot now ... https://bugzilla.redhat.com/show_bug.cgi?id=1247803 -------------------------------------------------------------------------------- ================================================================================ python-django-1.8.4-1.fc23 (FEDORA-2015-13824) A high-level Python Web framework -------------------------------------------------------------------------------- Update Information: python-django-1.8.4-1.fc23 - Do not install bash completion for python executables (Ville Skyttä, rhbz#1253076) - CVE-2015-5963 Denial-of-service possibility in logout() view by filling session store (rhbz#1254911) - CVE-2015-5964 Denial-of-service possibility in logout() view by filling session store (rhbz#1252891) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1242721 - CVE-2015-5144 python-django: Django: possible header injection due to validators accepting newlines in input [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1242721 [ 2 ] Bug #1242720 - CVE-2015-5144 python-django: Django: possible header injection due to validators accepting newlines in input [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1242720 [ 3 ] Bug #1242715 - CVE-2015-5143 python-django: Django: possible DoS by filling session store [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1242715 [ 4 ] Bug #1254921 - CVE-2015-5964 python-django: Denial-of-service possibility in logout() view by filling session store [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1254921 [ 5 ] Bug #1254911 - CVE-2015-5963 python-django: Denial-of-service possibility in logout() view by filling session store [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1254911 [ 6 ] Bug #1253076 - Do not install bash completion for python executables https://bugzilla.redhat.com/show_bug.cgi?id=1253076 -------------------------------------------------------------------------------- ================================================================================ python-gssapi-1.1.2-1.fc23 (FEDORA-2015-13827) Python Bindings for GSSAPI (RFC 2743/2744 and extensions) -------------------------------------------------------------------------------- Update Information: python-gssapi-1.1.2-1.fc22 - New minor release. - Resolves #1254458 - Fixes a crash bug when inquiring incomplete security contexts python- gssapi-1.1.2-1.fc23 - New minor release. - Resolves #1254458 - Fixes a crash bug when inquiring incomplete security contexts python-gssapi-1.1.2-1.fc23 - New minor release. - Resolves #1254458 - Fixes a crash bug when inquiring incomplete security contexts -------------------------------------------------------------------------------- References: [ 1 ] Bug #1254458 - python-gssapi-1.1.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1254458 -------------------------------------------------------------------------------- ================================================================================ python-rpmfluff-0.4.2-1.fc23 (FEDORA-2015-13818) Lightweight way of building RPMs, and sabotaging them -------------------------------------------------------------------------------- Update Information: python-rpmfluff-0.4.2-1.fc23 - John Dulaney implemented weak dependencies -------------------------------------------------------------------------------- References: [ 1 ] Bug #1253059 - Add support for rpm Recommends, patch included https://bugzilla.redhat.com/show_bug.cgi?id=1253059 -------------------------------------------------------------------------------- ================================================================================ qmasterpassword-1.2.1-1.fc23 (FEDORA-2015-13836) Stateless graphical Master Password Manager -------------------------------------------------------------------------------- Update Information: qmasterpassword-1.2.1-1.fc23 - initial release --------------------------------------------------------------------------------
-- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test