The following Fedora 22 Security updates need testing: Age URL 246 https://bodhi.fedoraproject.org/updates/FEDORA-2015-5878 echoping-6.1-0.beta.r434svn.1.fc22 195 https://bodhi.fedoraproject.org/updates/FEDORA-2015-9185 ceph-deploy-1.5.25-1.fc22 128 https://bodhi.fedoraproject.org/updates/FEDORA-2015-12781 python-kdcproxy-0.3.2-1.fc22 113 https://bodhi.fedoraproject.org/updates/FEDORA-2015-13823 python-django-1.8.4-1.fc22 112 https://bodhi.fedoraproject.org/updates/FEDORA-2015-1aee5e6f0b conntrack-tools-1.4.2-9.fc22 82 https://bodhi.fedoraproject.org/updates/FEDORA-2015-16239 nagios-4.0.8-1.fc22 76 https://bodhi.fedoraproject.org/updates/FEDORA-2015-05490fc42d squid-3.4.13-3.fc22 76 https://bodhi.fedoraproject.org/updates/FEDORA-2015-be2c11d456 subversion-1.8.14-1.fc22 71 https://bodhi.fedoraproject.org/updates/FEDORA-2015-2d37e7dacf openstack-swift-2.2.0-6.fc22 69 https://bodhi.fedoraproject.org/updates/FEDORA-2015-3e4043f088 python-pymongo-3.0.3-1.fc22 46 https://bodhi.fedoraproject.org/updates/FEDORA-2015-de44abca87 ntp-4.2.6p5-34.fc22 40 https://bodhi.fedoraproject.org/updates/FEDORA-2015-0552500cd7 python-pygments-2.0.2-3.fc22 40 https://bodhi.fedoraproject.org/updates/FEDORA-2015-9039c25f1d miniupnpc-1.9-6.fc22 23 https://bodhi.fedoraproject.org/updates/FEDORA-2015-c7b1be8823 seamonkey-2.39-1.fc22 22 https://bodhi.fedoraproject.org/updates/FEDORA-2015-7dfbe09bb4 libpng-1.6.16-4.fc22 22 https://bodhi.fedoraproject.org/updates/FEDORA-2015-6c07ab1fa6 libpng-1.6.16-5.fc22 16 https://bodhi.fedoraproject.org/updates/FEDORA-2015-8413bdd343 abrt-2.6.1-7.fc22 14 https://bodhi.fedoraproject.org/updates/FEDORA-2015-89468612f5 jenkins-1.609.3-4.fc22 13 https://bodhi.fedoraproject.org/updates/FEDORA-2015-fff2073f50 wget-1.16.3-2.fc22 12 https://bodhi.fedoraproject.org/updates/FEDORA-2015-f683150aa0 thttpd-2.25b-36.fc22 9 https://bodhi.fedoraproject.org/updates/FEDORA-2015-6565f29415 pax-utils-1.1.4-1.fc22 8 https://bodhi.fedoraproject.org/updates/FEDORA-2015-6d64c257cf thunderbird-38.4.0-1.fc22 7 https://bodhi.fedoraproject.org/updates/FEDORA-2015-3461e976cb libpng10-1.0.65-1.fc22 5 https://bodhi.fedoraproject.org/updates/FEDORA-2015-d87d60b9a9 openssl-1.0.1k-13.fc22 4 https://bodhi.fedoraproject.org/updates/FEDORA-2015-d5cc306730 p7zip-15.09-4.fc22 4 https://bodhi.fedoraproject.org/updates/FEDORA-2015-3a5cebb105 ImageMagick-6.9.2.7-1.fc22 4 https://bodhi.fedoraproject.org/updates/FEDORA-2015-39522bb8c9 php-PHPMailer-5.2.14-1.fc22 4 https://bodhi.fedoraproject.org/updates/FEDORA-2015-020f4b9400 xsupplicant-2.2.0-13.fc22 3 https://bodhi.fedoraproject.org/updates/FEDORA-2015-686f289aa5 qemu-2.3.1-8.fc22 3 https://bodhi.fedoraproject.org/updates/FEDORA-2015-233750b6ab libpng15-1.5.25-1.fc22 2 https://bodhi.fedoraproject.org/updates/FEDORA-2015-b406a8e4f2 qemu-2.3.1-9.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-c4ed00a68f kernel-4.2.7-200.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-8dd01b09a9 arts-1.5.10-30.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-2f4b92ed2e kdelibs3-3.5.10-71.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-08e4af5a20 xen-4.5.2-5.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-90c27b6e91 grub2-2.02-0.18.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-463143720f shellinabox-2.19-1.fc22 The following Fedora 22 Critical Path updates have yet to be approved: Age URL 121 https://bodhi.fedoraproject.org/updates/FEDORA-2015-13210 yum-3.4.3-508.fc22 107 https://bodhi.fedoraproject.org/updates/FEDORA-2015-14218 xulrunner-40.0-1.fc22 40 https://bodhi.fedoraproject.org/updates/FEDORA-2015-2123de044f libgphoto2-2.5.8-1.fc22 36 https://bodhi.fedoraproject.org/updates/FEDORA-2015-48f718ed1b vim-7.4.909-1.fc22 33 https://bodhi.fedoraproject.org/updates/FEDORA-2015-069fea7e6b livecd-tools-22.3-1.fc22 22 https://bodhi.fedoraproject.org/updates/FEDORA-2015-6c07ab1fa6 libpng-1.6.16-5.fc22 22 https://bodhi.fedoraproject.org/updates/FEDORA-2015-7dfbe09bb4 libpng-1.6.16-4.fc22 22 https://bodhi.fedoraproject.org/updates/FEDORA-2015-82b7665427 koji-1.10.1-1.fc22 18 https://bodhi.fedoraproject.org/updates/FEDORA-2015-1d21e7f650 unzip-6.0-23.fc22 16 https://bodhi.fedoraproject.org/updates/FEDORA-2015-efc06edc85 NetworkManager-vpnc-1.0.8-1.fc22 NetworkManager-openconnect-1.0.8-1.fc22 NetworkManager-openvpn-1.0.8-1.fc22 NetworkManager-openswan-1.0.8-1.fc22 NetworkManager-fortisslvpn-1.0.8-1.fc22 NetworkManager-1.0.8-1.fc22 8 https://bodhi.fedoraproject.org/updates/FEDORA-2015-f194dc9900 librsvg2-2.40.12-1.fc22 8 https://bodhi.fedoraproject.org/updates/FEDORA-2015-6d64c257cf thunderbird-38.4.0-1.fc22 5 https://bodhi.fedoraproject.org/updates/FEDORA-2015-4daef06c07 nautilus-3.16.3-1.fc22 5 https://bodhi.fedoraproject.org/updates/FEDORA-2015-d87d60b9a9 openssl-1.0.1k-13.fc22 4 https://bodhi.fedoraproject.org/updates/FEDORA-2015-f03bcc3731 perl-libwww-perl-6.15-1.fc22 3 https://bodhi.fedoraproject.org/updates/FEDORA-2015-1b2b67ac30 gnome-online-accounts-3.16.5-1.fc22 2 https://bodhi.fedoraproject.org/updates/FEDORA-2015-3c934e07c3 kdelibs-4.14.14-4.fc22 2 https://bodhi.fedoraproject.org/updates/FEDORA-2015-8083abc683 selinux-policy-3.13.1-128.22.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-d68f8a1cba lua-5.3.2-2.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-c2041fe5a6 gtk2-2.24.29-1.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-8be6e502c3 gcc-5.3.1-2.fc22 gcc-python-plugin-0.14-4.2.fc22 libtool-2.4.2-35.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-c4ed00a68f kernel-4.2.7-200.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-1c93bbd1a7 sqlite-3.9.0-2.fc22 0 https://bodhi.fedoraproject.org/updates/FEDORA-2015-473007accf util-linux-2.26.2-4.fc22 The following builds have been pushed to Fedora 22 updates-testing GeoIP-GeoLite-data-2015.12-1.fc22 calligra-2.9.10-1.fc22 calligra-l10n-2.9.10-1.fc22 emacs-php-mode-1.17.0-3.fc22 figlet-2.2.5-9.fc22 gtk2-2.24.29-1.fc22 ibus-libzhuyin-1.7.6-1.fc22 k3d-0.8.0.5-1.fc22 lua-5.3.2-2.fc22 luarocks-2.2.3-0.2.rc2.fc22 ola-0.9.8-7.fc22 perl-App-grindperl-0.004-1.fc22 perl-Compress-Bzip2-2.24-1.fc22 perl-ExtUtils-MakeMaker-CPANfile-0.07-1.fc22 php-Slim-2.6.2-3.fc22 php-pear-Console-CommandLine-1.2.1-1.fc22 php-pear-PHP-CodeSniffer-2.5.0-1.fc22 python-assimulo-2.8-7.fc22 python-flask-restful-0.3.5-1.fc22 rubygem-nokogiri-1.6.6.4-1.fc22 shellinabox-2.19-1.fc22 tor-0.2.7.6-3.fc22 vertica-python-0.5.5-1.fc22 wildmagic5-5.13-13.fc22 zanata-python-client-1.4.0-1.fc22 Details about builds: ================================================================================ GeoIP-GeoLite-data-2015.12-1.fc22 (FEDORA-2015-f7d2b8c448) Free GeoLite IP geolocation country database -------------------------------------------------------------------------------- Update Information: Periodic database update. -------------------------------------------------------------------------------- ================================================================================ calligra-2.9.10-1.fc22 (FEDORA-2015-881786d0d2) An integrated office suite -------------------------------------------------------------------------------- Update Information: New stable upstream release, see also https://www.calligra.org/news/calligra-2-9-10-released/ -------------------------------------------------------------------------------- ================================================================================ calligra-l10n-2.9.10-1.fc22 (FEDORA-2015-881786d0d2) Language files for calligra -------------------------------------------------------------------------------- Update Information: New stable upstream release, see also https://www.calligra.org/news/calligra-2-9-10-released/ -------------------------------------------------------------------------------- ================================================================================ emacs-php-mode-1.17.0-3.fc22 (FEDORA-2015-249309599b) Major GNU Emacs mode for editing PHP code -------------------------------------------------------------------------------- Update Information: emacs-php-mode - Major GNU Emacs mode for editing PHP code -------------------------------------------------------------------------------- References: [ 1 ] Bug #1289860 - Review Request: emacs-php-mode - Major GNU Emacs mode for editing PHP code https://bugzilla.redhat.com/show_bug.cgi?id=1289860 -------------------------------------------------------------------------------- ================================================================================ figlet-2.2.5-9.fc22 (FEDORA-2015-2fd4c2bca6) A program for making large letters out of ordinary text -------------------------------------------------------------------------------- Update Information: Fix memory corruption. -------------------------------------------------------------------------------- ================================================================================ gtk2-2.24.29-1.fc22 (FEDORA-2015-c2041fe5a6) The GIMP ToolKit (GTK+), a library for creating GUIs for X -------------------------------------------------------------------------------- Update Information: gtk+ 2.24.29 release. Bug fixes: - 345345 PrintOperation::paginate is not emitted for class handler - 745127 Changing order of file in "Places" crashes the application - 749507 gtk-2.0.m4 fails to detect a prefixed pkg-config - 752638 notebook tab dragging doesn't work on Quartz (patches... - 753644 Switching from Multipress input method to None immedi... - 753691 make install -j2 fails when building for MinGW - 753992 im-quartz discard_preedit segmentation fault - 754046 annotate gtk_color_button_get_color Translation updates: - Occitan -------------------------------------------------------------------------------- ================================================================================ ibus-libzhuyin-1.7.6-1.fc22 (FEDORA-2015-f2726a71f7) New Zhuyin engine based on libzhuyin for IBus -------------------------------------------------------------------------------- Update Information: new upstream release. ---- Fixes crash -------------------------------------------------------------------------------- ================================================================================ k3d-0.8.0.5-1.fc22 (FEDORA-2015-afac462fa7) A 3D Modeling, Animation and Rendering System -------------------------------------------------------------------------------- Update Information: -------------------------------------------------------------------------------- References: [ 1 ] Bug #1088763 - Missing yafray for k3d/update k3d to 0.8.0.3 https://bugzilla.redhat.com/show_bug.cgi?id=1088763 -------------------------------------------------------------------------------- ================================================================================ lua-5.3.2-2.fc22 (FEDORA-2015-d68f8a1cba) Powerful light-weight programming language -------------------------------------------------------------------------------- Update Information: Update lua to 5.3.2. Fix multi-lib support. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1173984 - Version's OLD https://bugzilla.redhat.com/show_bug.cgi?id=1173984 [ 2 ] Bug #1229992 - lua-devel package is not mutilib compatible https://bugzilla.redhat.com/show_bug.cgi?id=1229992 [ 3 ] Bug #1039249 - lua-5.3.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1039249 -------------------------------------------------------------------------------- ================================================================================ luarocks-2.2.3-0.2.rc2.fc22 (FEDORA-2015-1b10c6bdc6) A deployment and management system for Lua modules -------------------------------------------------------------------------------- Update Information: Fix luarocks to be an arch-specific package and to properly install components into the lua system path (when installing as root). -------------------------------------------------------------------------------- References: [ 1 ] Bug #1073462 - luarocks package doesn't support multilib https://bugzilla.redhat.com/show_bug.cgi?id=1073462 -------------------------------------------------------------------------------- ================================================================================ ola-0.9.8-7.fc22 (FEDORA-2015-dc1a9bc6d3) Open Lighting Architecture -------------------------------------------------------------------------------- Update Information: This is a new package. The Open Lighting Architecture is a framework for lighting control information. It supports a range of protocols and over a dozen USB devices. It can run as a standalone service, which is useful for converting signals between protocols, or alternatively using the OLA API, it can be used as the back-end for lighting control software. OLA runs on many different platforms including ARM, which makes it a perfect fit for low cost Ethernet to DMX gateways. -------------------------------------------------------------------------------- ================================================================================ perl-App-grindperl-0.004-1.fc22 (FEDORA-2015-02678a16bd) Command-line tool to help build and test blead perl -------------------------------------------------------------------------------- Update Information: This release adds "-A" option for specifying additinonal Configure options. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1290609 - perl-App-grindperl-0.004 is available https://bugzilla.redhat.com/show_bug.cgi?id=1290609 -------------------------------------------------------------------------------- ================================================================================ perl-Compress-Bzip2-2.24-1.fc22 (FEDORA-2015-26121b9061) Interface to Bzip2 compression library -------------------------------------------------------------------------------- Update Information: This release improves build script and fixes some compiler warnings. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1289785 - perl-Compress-Bzip2-2.24 is available https://bugzilla.redhat.com/show_bug.cgi?id=1289785 -------------------------------------------------------------------------------- ================================================================================ perl-ExtUtils-MakeMaker-CPANfile-0.07-1.fc22 (FEDORA-2015-f79c3f0a99) CPANfile support for ExtUtils::MakeMaker -------------------------------------------------------------------------------- Update Information: This release adds support for recommends, suggests, and conflicts directives. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1290614 - perl-ExtUtils-MakeMaker-CPANfile-0.07 is available https://bugzilla.redhat.com/show_bug.cgi?id=1290614 -------------------------------------------------------------------------------- ================================================================================ php-Slim-2.6.2-3.fc22 (FEDORA-2015-c363d57481) PHP micro framework -------------------------------------------------------------------------------- Update Information: * fix autoloader name ---- php-Slim-2.6.2-1.fc22 - Last upstream release php-Slim-2.6.2-1.fc23 - Last upstream release ---- php-Slim-2.6.2-2.fc22 - provide php-composer(slim/slim) - don't ignore test suite result - add a simpler autoloader php-Slim-2.6.2-2.fc23 - provide php-composer(slim/slim) - don't ignore test suite result - add a simpler autoloader -------------------------------------------------------------------------------- ================================================================================ php-pear-Console-CommandLine-1.2.1-1.fc22 (FEDORA-2015-07fea65284) A full featured command line options and arguments parser -------------------------------------------------------------------------------- Update Information: **Upstream changelog:** * Fixed bug #18397: List action example is wrong [cweiske] * Fixed bug #18682: columnWrap() in refault renderer eats up lines with only a EOL [izi, thanks Helgi] * Fixed bug #18703: No way to override reading of stdin with - [izi, thanks Gwynne Raskind] * Fixed bug #19683: Unit tests are broken [farell] * Fixed bug #19921: package dependencies don't include dom [cweiske] * Fixed unit tests [izi] * Fixed comparison on PHP 7 [Jan Olsen] * Allow multiple instances of the parser by making static variables private [Greg Oriol] * Add composer support -------------------------------------------------------------------------------- ================================================================================ php-pear-PHP-CodeSniffer-2.5.0-1.fc22 (FEDORA-2015-d17240a787) PHP coding standards enforcement tool -------------------------------------------------------------------------------- Update Information: **Upstream changelog:** - PHPCS will now look for a phpcs.xml file in parent directories as well as the current directory (request #626) - PHPCS will now use a phpcs.xml file even if files are specified on the command line. This file is still only used if no standard is specified on the command line - Added support for a phpcs.xml.dist file (request #583). If both a phpcs.xml and phpcs.xml.dist file are present, the phpcs.xml file will be used - Added support for setting PHP ini values in ruleset.xml files (request #560). Setting the value of the new ini tags to name="memory_limit" value="32M" is the same as -d memory_limit=32M - Added support for one or more bootstrap files to be run before processing begins. Use the --bootstrap=file,file,file command line argument to include bootstrap files. Useful if you want to override some of the high-level settings of PHPCS or PHPCBF. Thanks to John Maguire for the patch - Added additional verbose output for CSS tokenizing - Squiz ComparisonOperatorUsageSniff now checks FOR, WHILE and DO-WHILE statements. Thanks to Arnout Boks for the patch - Fixed bug #660 : Syntax checks can fail on Windows with PHP5.6 - Fixed bug #784 : $this->trait is seen as a T_TRAIT token - Fixed bug #786 : Switch indent issue with short array notation - Fixed bug #787 : SpacingAfterDefaultBreak confused by multi-line statements - Fixed bug #797 : Parsing CSS url() value breaks further parsing - Fixed bug #805 : Squiz.Commenting.FunctionComment.InvalidTypeHint on Scalar types on PHP7 - Fixed bug #807 : Cannot fix line endings when open PHP tag is not on the first line - Fixed bug #808 : JS tokeniser incorrectly setting some function and class names to control structure tokens - Fixed bug #809 : PHPCBF can break a require_once statement with a space before the open parenthesis - Fixed bug #813 : PEAR FunctionCallSignature checks wrong indent when first token on line is part of a multi-line string -------------------------------------------------------------------------------- ================================================================================ python-assimulo-2.8-7.fc22 (FEDORA-2015-2aa8ee8762) Ordinary differential and differential algebraic equations solver -------------------------------------------------------------------------------- Update Information: - New Python package -------------------------------------------------------------------------------- References: [ 1 ] Bug #1215354 - Review Request: python-assimulo - Ordinary differential and differential algebraic equations solver https://bugzilla.redhat.com/show_bug.cgi?id=1215354 -------------------------------------------------------------------------------- ================================================================================ python-flask-restful-0.3.5-1.fc22 (FEDORA-2015-fe85615fcf) Simple framework for creating REST APIs for Flask -------------------------------------------------------------------------------- Update Information: update to newest version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1290616 - python-flask-restful-0.3.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1290616 -------------------------------------------------------------------------------- ================================================================================ rubygem-nokogiri-1.6.6.4-1.fc22 (FEDORA-2015-ee99449ea1) An HTML, XML, SAX, and Reader parser -------------------------------------------------------------------------------- Update Information: libxml2 version unmatching warning is not needed and it is killed with this rpm. nokogiri is updaed to 1.6.6.4 (but actually no source change) -------------------------------------------------------------------------------- ================================================================================ shellinabox-2.19-1.fc22 (FEDORA-2015-463143720f) Web based AJAX terminal emulator -------------------------------------------------------------------------------- Update Information: * Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1287579 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287579 [ 2 ] Bug #1287578 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287578 -------------------------------------------------------------------------------- ================================================================================ tor-0.2.7.6-3.fc22 (FEDORA-2015-9c43216367) Anonymizing overlay network for TCP -------------------------------------------------------------------------------- Update Information: update to 0.2.7.6 ---- improve systemd scriptlets and service file ---- update to 0.2.7.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1288644 - tor multi-instance service fails to reload ('systemctl reload tor@foo') https://bugzilla.redhat.com/show_bug.cgi?id=1288644 [ 2 ] Bug #1282022 - tor fails to start at boot if ORPort/DirPort is specified with IP address https://bugzilla.redhat.com/show_bug.cgi?id=1282022 [ 3 ] Bug #1286359 - tor multi-instance services do not restart/reload when they should https://bugzilla.redhat.com/show_bug.cgi?id=1286359 -------------------------------------------------------------------------------- ================================================================================ vertica-python-0.5.5-1.fc22 (FEDORA-2015-536149598a) A native Python adapter for the Vertica database -------------------------------------------------------------------------------- Update Information: update to version 0.5.5 ---- update to version 0.5.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1285768 - vertica-python-0.5.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1285768 [ 2 ] Bug #1287914 - vertica-python-0.5.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1287914 -------------------------------------------------------------------------------- ================================================================================ wildmagic5-5.13-13.fc22 (FEDORA-2015-6dbbb6962b) Wild Magic libraries -------------------------------------------------------------------------------- Update Information: - Fix compilation flags of 'libWm5Applications.so' library -------------------------------------------------------------------------------- ================================================================================ zanata-python-client-1.4.0-1.fc22 (FEDORA-2015-9579934276) Python Client for Zanata Server -------------------------------------------------------------------------------- Update Information: Upstream update to 1.4.0 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: http://lists.fedoraproject.org/admin/lists/test@xxxxxxxxxxxxxxxxxxxxxxx