Fedora 24 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


The following Fedora 24 Security updates need testing:
 Age  URL
  57  https://bodhi.fedoraproject.org/updates/FEDORA-2016-32eaf0c41e   redis-3.2.3-1.fc24
  40  https://bodhi.fedoraproject.org/updates/FEDORA-2016-0ef628998f   chicken-4.11.0-3.fc24
  13  https://bodhi.fedoraproject.org/updates/FEDORA-2016-89060100d7   mongodb-3.2.8-2.fc24
   7  https://bodhi.fedoraproject.org/updates/FEDORA-2016-a64716084e   irssi-0.8.20-2.fc24
   6  https://bodhi.fedoraproject.org/updates/FEDORA-2016-7f193a0c59   php-ZendFramework-1.12.20-1.fc24
   6  https://bodhi.fedoraproject.org/updates/FEDORA-2016-5706eeb875   python-django-1.9.10-1.fc24
   6  https://bodhi.fedoraproject.org/updates/FEDORA-2016-861b8c46b7   nodejs-4.6.0-5.fc24
   6  https://bodhi.fedoraproject.org/updates/FEDORA-2016-c23a8ce9e5   mingw-openjpeg2-2.1.2-1.fc24
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2016-c75bdc394a   zathura-pdf-mupdf-0.3.0-2.fc24 mujs-0-5.20160921git5c337af.fc24
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2016-328754be1c   libdwarf-20160929-1.fc24
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2016-1cc00cde2d   c-ares-1.12.0-1.fc24
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2016-a7f9e86df7   mingw-c-ares-1.12.0-1.fc24
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2016-e1d4972701   nsd-4.1.13-1.fc24
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-870236238e   perl-DBD-MySQL-4.037-1.fc24
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-d61c4f72da   chromium-53.0.2785.143-1.fc24
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-98768233b8   python-pillow-3.2.0-2.fc24
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-96045ad97b   ghostscript-9.16-5.fc24

The following Fedora 24 Critical Path updates have yet to be approved:
 Age URL
   6  https://bodhi.fedoraproject.org/updates/FEDORA-2016-229e5b4143   lorax-24.21-1.fc24
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2016-2bf9743359   pungi-4.1.9-2.fc24
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2016-cf7725e102   koji-1.10.1-13.fc24
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2016-a300f36043   perl-Scalar-List-Utils-1.46-1.fc24
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2016-639b10779f   hwdata-0.293-1.fc24

The following builds have been pushed to Fedora 24 updates-testing


Details about builds:

 LuxRender-1.4-1.fc24 (FEDORA-2016-0a6f58d32e)
 Lux Renderer, an unbiased rendering system
Update Information:

Update to version 1.4

 ceres-solver-1.11.0-9.fc24 (FEDORA-2016-ef6ba542f2)
 A non-linear least squares minimizer
Update Information:

Update to version 3.2.10, see
http://eigen.tuxfamily.org/index.php?title=ChangeLog#Eigen_3.2.10 for details.

 check-mk-1.2.8p11-2.fc24 (FEDORA-2016-d81e722d85)
 A new general purpose Nagios-plugin for retrieving data
Update Information:

Dist tag fix for mod_python to be a require on EL6 only.  ----  New upstream

 chromium-53.0.2785.143-1.fc24 (FEDORA-2016-d61c4f72da)
 A WebKit (Blink) powered web browser
Update Information:

Security fix for CVE-2016-5177, CVE-2016-5178

  [ 1 ] Bug #1380632 - CVE-2016-5178 chromium-browser: various fixes from internal audits
  [ 2 ] Bug #1380631 - CVE-2016-5177 chromium-browser: use after free in v8

 cmst-2016.10.03-1.gitf85b216.fc24 (FEDORA-2016-97f6ade2f1)
 A Qt based GUI front end for the connman connection manager with systemtray icon
Update Information:

Update to 2016.10.03-1.gitf85b216  ----  Update to 2016.10.02-1.git35ebb4b

 corebird-1.3.3-1.fc24 (FEDORA-2016-c298daa747)
 Native GTK Twitter client
Update Information:

corebird 1.3.3 release.    - Support longer tweets in a few more places   -
Properly escape ampersand characters in user mentions to fix     GtkLabel
warnings about wrong escape characters in tooltips   - Fix tweet length
calculations for whitespace-only tweets   - Check for duplicated entries in
media arrays. This is apparently a     problem on Twitter's side but led to
crashes in Corebird   - Use the correct nsfw status of a tweet, i.e. the one
that can     actually show images.   - Fix a crash when sending a tweet with
multiple images attached   - Fix tweet length calculation of quote tweets. This
previously led to     tweets getting rejected by the server even though Corebird
claimed     they were fine.

 dpm-dsi-1.9.9-1.fc24 (FEDORA-2016-486dfc8678)
 Disk Pool Manager (DPM) plugin for the Globus GridFTP server
Update Information:

* new upstream release

 eigen3-3.2.10-1.fc24 (FEDORA-2016-ef6ba542f2)
 A lightweight C++ template library for vector and matrix math
Update Information:

Update to version 3.2.10, see
http://eigen.tuxfamily.org/index.php?title=ChangeLog#Eigen_3.2.10 for details.

 exodusii-6.02-5.fc24 (FEDORA-2016-ef86cfeae3)
 Library to store and retrieve transient finite element data
Update Information:

Initial import

  [ 1 ] Bug #1336552 - None

 fail2ban-0.9.5-3.fc24 (FEDORA-2016-7db83f651b)
 Daemon to ban hosts that cause multiple authentication errors
Update Information:

- Update to 0.9.5 - see https://github.com/fail2ban/fail2ban/releases/tag/0.9.5
- Give up being PartOf iptables to allow firewalld restarts to work   (bug
#1379141) - Add journalmatch entries for sendmail (bug #1329919)

  [ 1 ] Bug #1379110 - None
  [ 2 ] Bug #1379141 - None

 gajim-0.16.6-1.fc24 (FEDORA-2016-5cf1ef1b53)
 Jabber client written in PyGTK
Update Information:

Gajim 0.16.6  * Fix using gpg2 * Improve message receips usage * Improve roster
filtering * Fix several minor bugs

  [ 1 ] Bug #1381214 - None

 gammu-1.37.4-2.fc24 (FEDORA-2016-d2fefc6a97)
 Command Line utility to work with mobile phones
Update Information:

Force the exact EVR for gammu and gammu-libs

 gasnet-1.26.4-5.fc24 (FEDORA-2016-c3ddd3e289)
 A Portable High-Performance Communication Layer for GAS Languages
Update Information:

Initial commit

  [ 1 ] Bug #1375744 - None

 ghostscript-9.16-5.fc24 (FEDORA-2016-96045ad97b)
 A PostScript interpreter and renderer
Update Information:

Security fix for BZ
[#1380415](https://bugzilla.redhat.com/show_bug.cgi?id=1380415).  IMPORTANT
NOTE: This release of ghostscript is **without OpenJPEG** support. The support
had to be **temporarily disabled** in order to deliver the security fix.  The
support for OpenJPEG  will be re-enabled as soon as possible.  -----------  You
can test if your system is vulnerable by these steps:  * Download the bash
[script](https://goo.gl/eyzZvG) for testing:          wget https://goo.gl/eyzZvG
* Optional - check the validity of the script:          md5 ./bz1380415-test.sh
[md5 hash of the script - **4ae552b75bc30e21ff066603a911b5fe**]   * Make the
script executable & run it:          chmod +x ./bz1380415-test.sh &&

  [ 1 ] Bug #1380415 - ghostscript: .libfile does not honor -dSAFER

 hwdata-0.293-1.fc24 (FEDORA-2016-639b10779f)
 Hardware identification and configuration data
Update Information:

Updated pci, usb and vendor ids.

 java-1.8.0-openjdk-aarch32- (FEDORA-2016-e81949ac7d)
 OpenJDK Runtime Environment in a preview of the OpenJDK AArch32 project
Update Information:

Fixes scala compile crash, #1379061

  [ 1 ] Bug #1379061 - None

 libgit2-0.24.2-1.fc24 (FEDORA-2016-cf79eeab6b)
 C implementation of the Git core methods as a library with a solid API
Update Information:

Update to 0.24.2

  [ 1 ] Bug #1381398 - None

 libreoffice- (FEDORA-2016-52beca6b00)
 Free Software Productivity Suite
Update Information:

- Resolves: tdf#101711 problems with attempt to remove unused backgrounds cause
slide backgrounds to disappear from the source document on copy to another
document - Only date autofilter menus need the space for the tree expanders -
Resolves: rhbz#1378521 csv dialog a11y returns a new a11y object each time

 liveusb-creator-3.95.4-1.fc24 (FEDORA-2016-6f076b93e5)
 Fedora LiveUSB Creator
Update Information:

Update to 3.95.4

 mingw-eigen3-3.2.10-1.fc24 (FEDORA-2016-ef6ba542f2)
 MinGW lightweight C++ template library for vector and matrix math
Update Information:

Update to version 3.2.10, see
http://eigen.tuxfamily.org/index.php?title=ChangeLog#Eigen_3.2.10 for details.

 mingw-gdk-pixbuf-2.34.0-1.fc24 (FEDORA-2016-748025980f)
 MinGW Windows GDK Pixbuf library
Update Information:

MinGW cross compiled gdk-pixbuf 2.34.0 release.

 mingw-opusfile-0.8-1.fc24 (FEDORA-2016-c0d81b7871)
 A high-level API for decoding and seeking within .opus files
Update Information:

Update to 0.8  - Add support for OpenSSL 1.1.x. - Fix issues with tag parsing
introduced in v0.7. - Fix skip logic for multiplexed non-Opus data.

 octave-parallel-3.1.1-1.fc24 (FEDORA-2016-75f9b0b94a)
 Parallel execution package for cluster computers for Octave
Update Information:

- update to 3.1.1

  [ 1 ] Bug #1311784 - None

 otter-browser-0.9.11-0.2.beta11gitc051a5e.fc24 (FEDORA-2016-21087fb9f8)
 Web browser controlled by the user, not vice-versa
Update Information:

fix BR for secondary arches  ----  - Update to 0.9.11-01.beta11 - Added BR qt5
-qtwebengine-devel - Added BR hunspell-devel

 perl-DBD-MySQL-4.037-1.fc24 (FEDORA-2016-870236238e)
 A MySQL interface for Perl
Update Information:

Updated to the latest version;  Security fix for CVE-2016-1246

  [ 1 ] Bug #1380375 - CVE-2016-1246 perl-DBD-MySQL: Buffer overflow triggered by user supplied data

 perl-Digest-SHA3-0.25-1.fc24 (FEDORA-2016-26f7b1d7bb)
 Perl extension for SHA-3
Update Information:

Updated to the latest version

  [ 1 ] Bug #1371941 - None

 perl-Qt-4.14.3-4.fc24 (FEDORA-2016-0224edac83)
 Perl bindings for Qt
Update Information:

This release fixes method resolution and a test.

 php-bartlett-php-compatinfo-db-1.13.0-1.fc24 (FEDORA-2016-47d2c4d228)
 Reference Database to be used with php-compatinfo library
Update Information:

**Version 1.13.0** - 2016-10-03  - Support to PHP 7.0.11 - Support to PHP 5.6.26
- Fixed: curl reference with libCurl dependency, see
[#7](https://github.com/llaville/php-compatinfo-db/issues/7)  **Version 1.12.0**
- 2016-09-26  - Support to PHP 7.0.10 - Support to PHP 5.6.25

 php-phpseclib-2.0.4-1.fc24 (FEDORA-2016-81fb7b5309)
 PHP Secure Communications Library
Update Information:

**Version 2.0.4** - 2016-08-18  *    fix E_DEPRECATED errors on PHP 7.1 (#1041)
*    SFTP: speed up downloads (#945) *    SFTP: fix infinite loop when uploading
empty file (#995) *    ASN1: fix possible infinite loop in decode (#1027)  ----
**Version 2.0.3** - 2016-08-18  - BigInteger/RSA: don't compare openssl versions
> 1.0 (#946) - RSA: don't attempt to use the CRT when zero value components
exist (#980) - RSA: zero salt length RSA signatures don't work (#1002) - ASN1:
fix PHP Warning on PHP 7.1 (#1013) - X509: set parameter fields to null for
CSR's / RSA (#914) - CRL optimizations (#1000) - SSH2: fix "Expected
SSH_FXP_STATUS or ..." error (#999) - SSH2: use stream_get_* instead of fread()
/ fgets() (#967) - SFTP: make symlinks support relative target's (#1004) - SFTP:
fix sending stream resulting in zero byte file (#995)

 php-symfony-2.8.12-2.fc24 (FEDORA-2016-e00f4e3d1d)
 PHP framework for web projects
Update Information:

**Twig 1.26.0** (2016-10-02)   * added template cache invalidation based on more
environment options  * added a missing deprecation notice  * fixed template
paths when a template is stored in a PHAR file  * allowed
filters/functions/tests implementation to use a different class than the
extension they belong to  * deprecated Twig_ExtensionInterface::getName()  ----
**Twig 1.25.0** (2016-09-21)   * changed the way we store template source in
template classes  * removed usage of realpath in cache keys  * fixed Twig cache
sharing when used with different versions of PHP  * removed embed parent
workaround for simple use cases  * deprecated the ability to store non Node
instances in Node::$nodes  * deprecated Twig_Environment::getLexer(),
Twig_Environment::getParser(), Twig_Environment::getCompiler()  * deprecated
Twig_Compiler::getFilename()  ----  **Symfony 2.8.12** (2016-10-03)   * bug
#20102 [Validator] Url validator not validating hosts ending in a number
(gwkunze)  * bug #20132 Use "more entropy" option for uniqid() (javiereguiluz)
* bug #20122 [Validator] Reset constraint options (ro0NL)  * bug #20116 fixed
AddConstraintValidatorsPass config (fabpot)  * bug #20078 Fix #19943 Make sure
to process each interface metadata only once (lemoinem)  * bug #20080 [Form]
compound forms without children should be considered rendered implicitly
(backbone87)  * bug #20087 [VarDumper] Fix PHP 7.1 compat (nicolas-grekas)  *
bug #20086 [VarDumper] Fix PHP 7.1 compat (nicolas-grekas)  * bug #20077
[Process] silent file operation to avoid open basedir issues (xabbuh)  * bug
#20079 fixed Twig support for 1.26 and 2.0 (fabpot)  * bug #20051 Fix indexBy
type extraction (lemoinem)  * bug #19951 [Finder] Trim trailing directory slash
in ExcludeDirectoryFilterIterator (ro0NL)  * bug #20018 [VarDumper] Fix test
(nicolas-grekas)  * bug #20011 Use UUID for error codes for Form validator.
(Koc)  * bug #20010 [DX] Fixed regression when exception message swallowed when
logging it. (Koc)  * bug #19983 [TwigBridge] removed Twig null nodes (deprecated
as of Twig 1.25) (fabpot)  * bug #19946 [Console] Fix parsing optionnal options
with empty value in argv (chalasr)  * bug #19636 [Finder] no PHP warning on
empty directory iteration (ggottwald)  * bug #19923 [bugfix] [Console] Set
`Input::$interactive` to `false` when command is executed with `--quiet` as
verbosity level (phansys)  * bug #19811 Fixed the nullable support for php 7.1
and below (2.7, 2.8, 3.0) (iltar)  * bug #19853 [PropertyInfo] Make
ReflectionExtractor compatible with ReflectionType changes in PHP 7.1
(teohhanhui)  * bug #19904 [Form] Fixed collapsed ChoiceType options attributes
(HeahDude)  * bug #19908 [Config] Handle open_basedir restrictions in
FileLocator (Nicofuma)  * bug #19924 [DoctrineBridge][PropertyInfo] Treat
Doctrine decimal type as string (teohhanhui)  * bug #19932 Fixed bad merge
(GrahamCampbell)  * bug #19922 [Yaml][TwigBridge] Use JSON_UNESCAPED_SLASHES for
lint commands output (chalasr)  * bug #19928 [Validator] Update IpValidatorTest
data set with a valid reserved IP (jakzal)  * bug #19813 [Console] fixed PHP7
Errors are now handled and converted to Exceptions (fonsecas72)  * bug #19879
[Form] Incorrect timezone with DateTimeLocalizedStringTransformer (mbeccati)  *
bug #19878 Fix translation:update command count (tgalopin)

 php-twig-1.26.0-1.fc24 (FEDORA-2016-e00f4e3d1d)
 The flexible, fast, and secure template engine for PHP
Update Information:

**Twig 1.26.0** (2016-10-02)   * added template cache invalidation based on more
environment options  * added a missing deprecation notice  * fixed template
paths when a template is stored in a PHAR file  * allowed
filters/functions/tests implementation to use a different class than the
extension they belong to  * deprecated Twig_ExtensionInterface::getName()  ----
**Twig 1.25.0** (2016-09-21)   * changed the way we store template source in
template classes  * removed usage of realpath in cache keys  * fixed Twig cache
sharing when used with different versions of PHP  * removed embed parent
workaround for simple use cases  * deprecated the ability to store non Node
instances in Node::$nodes  * deprecated Twig_Environment::getLexer(),
Twig_Environment::getParser(), Twig_Environment::getCompiler()  * deprecated
Twig_Compiler::getFilename()  ----  **Symfony 2.8.12** (2016-10-03)   * bug
#20102 [Validator] Url validator not validating hosts ending in a number
(gwkunze)  * bug #20132 Use "more entropy" option for uniqid() (javiereguiluz)
* bug #20122 [Validator] Reset constraint options (ro0NL)  * bug #20116 fixed
AddConstraintValidatorsPass config (fabpot)  * bug #20078 Fix #19943 Make sure
to process each interface metadata only once (lemoinem)  * bug #20080 [Form]
compound forms without children should be considered rendered implicitly
(backbone87)  * bug #20087 [VarDumper] Fix PHP 7.1 compat (nicolas-grekas)  *
bug #20086 [VarDumper] Fix PHP 7.1 compat (nicolas-grekas)  * bug #20077
[Process] silent file operation to avoid open basedir issues (xabbuh)  * bug
#20079 fixed Twig support for 1.26 and 2.0 (fabpot)  * bug #20051 Fix indexBy
type extraction (lemoinem)  * bug #19951 [Finder] Trim trailing directory slash
in ExcludeDirectoryFilterIterator (ro0NL)  * bug #20018 [VarDumper] Fix test
(nicolas-grekas)  * bug #20011 Use UUID for error codes for Form validator.
(Koc)  * bug #20010 [DX] Fixed regression when exception message swallowed when
logging it. (Koc)  * bug #19983 [TwigBridge] removed Twig null nodes (deprecated
as of Twig 1.25) (fabpot)  * bug #19946 [Console] Fix parsing optionnal options
with empty value in argv (chalasr)  * bug #19636 [Finder] no PHP warning on
empty directory iteration (ggottwald)  * bug #19923 [bugfix] [Console] Set
`Input::$interactive` to `false` when command is executed with `--quiet` as
verbosity level (phansys)  * bug #19811 Fixed the nullable support for php 7.1
and below (2.7, 2.8, 3.0) (iltar)  * bug #19853 [PropertyInfo] Make
ReflectionExtractor compatible with ReflectionType changes in PHP 7.1
(teohhanhui)  * bug #19904 [Form] Fixed collapsed ChoiceType options attributes
(HeahDude)  * bug #19908 [Config] Handle open_basedir restrictions in
FileLocator (Nicofuma)  * bug #19924 [DoctrineBridge][PropertyInfo] Treat
Doctrine decimal type as string (teohhanhui)  * bug #19932 Fixed bad merge
(GrahamCampbell)  * bug #19922 [Yaml][TwigBridge] Use JSON_UNESCAPED_SLASHES for
lint commands output (chalasr)  * bug #19928 [Validator] Update IpValidatorTest
data set with a valid reserved IP (jakzal)  * bug #19813 [Console] fixed PHP7
Errors are now handled and converted to Exceptions (fonsecas72)  * bug #19879
[Form] Incorrect timezone with DateTimeLocalizedStringTransformer (mbeccati)  *
bug #19878 Fix translation:update command count (tgalopin)

 php-udan11-sql-parser-3.4.10-1.fc24 (FEDORA-2016-0d4ea18758)
 A validating SQL lexer and parser with a focus on MySQL dialect
Update Information:

**Version 3.4.10** - 2016-10-03  * Fixed API regression on DELETE statement  ---
**Version 3.4.9** - 2016-10-03  * Added support for CASE expressions * Support
for parsing and building DELETE statement * Support for parsing subqueries in
FROM clause  ---  **Version 3.4.8** - 2016-09-22  * No change release to sync
GitHub releases with Packagist

 pjproject-2.4.5-8.fc24 (FEDORA-2016-d264a186d3)
 Libraries for building embedded/non-embedded VoIP applications
Update Information:

Commenting out latest patch for BZ 1381133

  [ 1 ] Bug #1381133 - None

 python-backports-functools_lru_cache-1.2.1-1.fc24 (FEDORA-2016-1065ca8dcb)
 A backport of functools.lru_cache from Python 3.3 as published at ActiveState
Update Information:

New package.

  [ 1 ] Bug #1380104 - None

 python-bitarray-0.8.1-4.fc24 (FEDORA-2016-894eb1888e)
 Efficient Array of Booleans --C Extensions
Update Information:

Add support to epel 7 and 6, disable python3 in el6

 python-blowfish-0.6.1-1.fc24 (FEDORA-2016-9b278118dc)
 Fast, efficient Blowfish cipher implementation in pure Python (3.4+)
Update Information:

New package.

  [ 1 ] Bug #1361632 - None

 python-marshmallow-2.10.3-1.fc24 (FEDORA-2016-faa4ef47a0)
 Python library for converting complex datatypes to and from primitive types
Update Information:

Update to 2.10.3

  [ 1 ] Bug #1381098 - None

 python-pillow-3.2.0-2.fc24 (FEDORA-2016-98768233b8)
 Python image processing library
Update Information:

Backport fix for three memory disclosure/corruption bugs from insufficient
parameter validation leading to integer overflow.

 python-statsmodels-0.6.1-7.fc24 (FEDORA-2016-86d0ff7206)
 Statistics in Python
Update Information:

Fixes bugzilla #1361854 (python3-statsmodels should depend on python3-patsy)

  [ 1 ] Bug #1361854 - None

 python26-2.6.9-2.fc24 (FEDORA-2016-47d9fcce7d)
 Version 2.6 of the Python programming language
Update Information:

Do not require /usr/bin/python

 sks-1.1.6-1.fc24 (FEDORA-2016-26c2d4c834)
 Synchronizing Key Server
Update Information:

Update to latest version of sks

  [ 1 ] Bug #1304429 - None
  [ 2 ] Bug #1365236 - None

 wine-1.9.20-1.fc24 (FEDORA-2016-127742eb3d)
 A compatibility layer for windows applications
Update Information:

- Reimplementation of the clipboard API.   - Message handling in WebServices.
- Many more API Set libraries.   - Various bug fixes.

  [ 1 ] Bug #1381013 - None

 xfce4-weather-plugin-0.8.8-2.fc24 (FEDORA-2016-aa38ea6337)
 Weather plugin for the Xfce panel
Update Information:

- Translation fix - Fixes #1377672

  [ 1 ] Bug #1377672 - None

 zstd-1.1.0-1.fc24 (FEDORA-2016-3355e1dae4)
 Zstd compression library
Update Information:

Initial release

  [ 1 ] Bug #1373218 - None
test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx

[Index of Archives]     [Fedora Desktop]     [Fedora SELinux]     [Photo Sharing]     [Yosemite Forum]     [KDE Users]

  Powered by Linux