The following Fedora 25 Security updates need testing: Age URL 80 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d79ba708cb exim-4.87.1-1.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-534e23bad9 rabbitmq-server-3.6.6-2.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-003fa5648c rpm-ostree-2017.3-2.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-df53d02da7 knot-resolver-1.2.4-1.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ae18216e75 rkward-0.6.5-5.fc25 rpy-2.8.5-3.fc25 R-3.3.3-1.fc25 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-47a4910f07 openslp-2.0.0-10.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9ed1b89530 mbedtls-2.4.2-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-837115524e cloud-init-0.7.8-6.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-06f4b88ceb php-onelogin-php-saml-2.10.5-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9801754fd7 drupal8-8.2.7-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e8e717e2b7 kernel-4.10.3-200.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-3d16d348eb xen-4.7.2-2.fc25 The following Fedora 25 Critical Path updates have yet to be approved: Age URL 23 https://bodhi.fedoraproject.org/updates/FEDORA-2017-c5dbde322a epiphany-3.22.6-2.fc25 10 https://bodhi.fedoraproject.org/updates/FEDORA-2017-803e6bacb4 pungi-4.1.13-1.fc25 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-7799a1cc7c appliance-tools-008.0-4.fc25 livecd-tools-24.2-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-4d66e799ca flatpak-0.9.1-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9a242eb73d nss-3.28.3-1.1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e8e717e2b7 kernel-4.10.3-200.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-72e25d39ba gnome-settings-daemon-3.22.2-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0b5012df30 control-center-3.22.2-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-eb8924136a sssd-1.15.2-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-19f5b1c9b3 python-idna-2.5-1.fc25 The following builds have been pushed to Fedora 25 updates-testing amsynth-1.7.1-1.fc25 appcenter-0.1.4-1.fc25 cargo-0.17.0-1.fc25 check-mk-1.2.8p18-1.fc25 clang-3.9.1-2.fc25 distribution-gpg-keys-1.10-1.fc25 fedora-upgrade-26.1-1.fc25 golang-github-grpc-ecosystem-go-grpc-prometheus-1.1-0.1.git6b7015e.fc25 golang-github-grpc-ecosystem-grpc-gateway-1.0.0-0.4.git84398b9.fc25 golang-github-grpc-grpc-go-1.0.0-0.4.git777daa1.fc25 golang-github-matttproud-golang_protobuf_extensions-0-0.12.gitc12348c.fc25 golang-github-prometheus-client_golang-0.7.0-7.fc25 golang-github-prometheus-common-0-0.7.git195bde7.fc25 golang-github-prometheus-procfs-0-0.17.gitfcdb11c.fc25 golang-github-stretchr-testify-1.0-0.9.git976c720.fc25 ibus-typing-booster-1.5.27-1.fc25 icoutils-0.31.3-1.fc25 kernel-4.10.3-200.fc25 libvmi-0.11.0-5.20170214git1a85386.fc25 nss-3.28.3-1.1.fc25 perl-BSON-1.4.0-1.fc25 perl-Function-Parameters-1.0706-1.fc25 perl-Tree-Simple-1.30-1.fc25 php-bartlett-PHP-CompatInfo-5.0.5-1.fc25 php-bartlett-php-compatinfo-db-1.19.0-1.fc25 php-zendframework-zend-validator-2.9.0-1.fc25 python-idna-2.5-1.fc25 python-leather-0.3.3-2.gite85dd30.fc25 root-6.08.06-2.fc25 rust-1.16.0-1.fc25 sway-0.12.1-1.fc25 vdr-epg-daemon-1.1.110-1.fc25 vdr-epg2vdr-1.1.48-1.fc25 xen-4.7.2-2.fc25 xlockmore-5.51-1.fc25 xorg-x11-drv-amdgpu-1.3.0-1.fc25 Details about builds: ================================================================================ amsynth-1.7.1-1.fc25 (FEDORA-2017-619a51fe69) A classic synthesizer with dual oscillators -------------------------------------------------------------------------------- Update Information: Update to new upstream -------------------------------------------------------------------------------- References: [ 1 ] Bug #1432693 - amsynth-1.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1432693 -------------------------------------------------------------------------------- ================================================================================ appcenter-0.1.4-1.fc25 (FEDORA-2017-630407ca35) Software Center for the Pantheon desktop -------------------------------------------------------------------------------- Update Information: Update to version 0.1.4. This minor upstream release includes a small number of non-critical bugfixes and usability improvements. More information at: https://launchpad.net/appcenter/loki/0.1.4 -------------------------------------------------------------------------------- ================================================================================ cargo-0.17.0-1.fc25 (FEDORA-2017-987ab27b07) Rust's package manager and build tool -------------------------------------------------------------------------------- Update Information: New versions of Rust and Cargo -- see the release notes for [1.16](https://blog .rust-lang.org/2017/03/16/Rust-1.16.html). -------------------------------------------------------------------------------- ================================================================================ check-mk-1.2.8p18-1.fc25 (FEDORA-2017-10d1913128) A new general purpose Nagios-plugin for retrieving data -------------------------------------------------------------------------------- Update Information: New upstream release. -------------------------------------------------------------------------------- ================================================================================ clang-3.9.1-2.fc25 (FEDORA-2017-b12f9264a6) A C language family front-end for LLVM -------------------------------------------------------------------------------- Update Information: Fix build-id regression from 3.8.1->3.9.1 upgrade. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1432403 - regression: build-id is no longer produced by default https://bugzilla.redhat.com/show_bug.cgi?id=1432403 -------------------------------------------------------------------------------- ================================================================================ distribution-gpg-keys-1.10-1.fc25 (FEDORA-2017-666aabc8e8) GPG keys of various Linux distributions -------------------------------------------------------------------------------- Update Information: * updated Copr keys * added F26 key -------------------------------------------------------------------------------- ================================================================================ fedora-upgrade-26.1-1.fc25 (FEDORA-2017-dd545c2d9e) Upgrade Fedora to next version using dnf upgrade (unofficial tool) -------------------------------------------------------------------------------- Update Information: * Add upgrade from F25 to F26 * Add upgrade from F26 to rawhide -------------------------------------------------------------------------------- ================================================================================ golang-github-grpc-ecosystem-go-grpc-prometheus-1.1-0.1.git6b7015e.fc25 (FEDORA-2017-baaf33ffbf) Prometheus monitoring for your gRPC Go servers -------------------------------------------------------------------------------- Update Information: First package for Fedora -------------------------------------------------------------------------------- References: [ 1 ] Bug #1433121 - Review Request: golang-github-grpc-ecosystem-go-grpc-prometheus - Prometheus monitoring for your gRPC Go servers https://bugzilla.redhat.com/show_bug.cgi?id=1433121 -------------------------------------------------------------------------------- ================================================================================ golang-github-grpc-ecosystem-grpc-gateway-1.0.0-0.4.git84398b9.fc25 (FEDORA-2017-4c04d60f2a) GRPC to JSON proxy generator -------------------------------------------------------------------------------- Update Information: Bump to upstream 84398b94e188ee336f307779b57b3aa91af7063c -------------------------------------------------------------------------------- References: [ 1 ] Bug #1405682 - Tracker for golang-github-grpc-ecosystem-grpc-gateway https://bugzilla.redhat.com/show_bug.cgi?id=1405682 -------------------------------------------------------------------------------- ================================================================================ golang-github-grpc-grpc-go-1.0.0-0.4.git777daa1.fc25 (FEDORA-2017-03b8b06796) The Go language implementation of gRPC. HTTP/2 based RPC -------------------------------------------------------------------------------- Update Information: Bump to upstream 777daa17ff9b5daef1cfdf915088a2ada3332bf0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1250461 - Tracker for golang-github-grpc-grpc-go https://bugzilla.redhat.com/show_bug.cgi?id=1250461 -------------------------------------------------------------------------------- ================================================================================ golang-github-matttproud-golang_protobuf_extensions-0-0.12.gitc12348c.fc25 (FEDORA-2017-db89a71ea7) Support for streaming Protocol Buffer messages for the Go language (golang) -------------------------------------------------------------------------------- Update Information: Bump to upstream c12348ce28de40eed0136aa2b644d0ee0650e56c -------------------------------------------------------------------------------- References: [ 1 ] Bug #1214797 - Tracker for golang-github-matttproud-golang_protobuf_extensions https://bugzilla.redhat.com/show_bug.cgi?id=1214797 -------------------------------------------------------------------------------- ================================================================================ golang-github-prometheus-client_golang-0.7.0-7.fc25 (FEDORA-2017-82db93d983) Prometheus instrumentation library for Go applications -------------------------------------------------------------------------------- Update Information: Bump to upstream c5b7fccd204277076155f10851dad72b76a49317 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1214784 - Tracker for golang-github-prometheus-client_golang https://bugzilla.redhat.com/show_bug.cgi?id=1214784 -------------------------------------------------------------------------------- ================================================================================ golang-github-prometheus-common-0-0.7.git195bde7.fc25 (FEDORA-2017-30ddf79fe3) Go libraries shared across Prometheus components and libraries -------------------------------------------------------------------------------- Update Information: Bump to upstream 195bde7883f7c39ea62b0d92ab7359b5327065cb -------------------------------------------------------------------------------- References: [ 1 ] Bug #1315096 - Tracker for golang-github-prometheus-common https://bugzilla.redhat.com/show_bug.cgi?id=1315096 -------------------------------------------------------------------------------- ================================================================================ golang-github-prometheus-procfs-0-0.17.gitfcdb11c.fc25 (FEDORA-2017-b469db63cd) Functions to retrieve system, kernel and process metrics from the /proc fs -------------------------------------------------------------------------------- Update Information: Bump to upstream fcdb11ccb4389efb1b210b7ffb623ab71c5fdd60 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1326057 - buggy spec for s390x/gcc-go https://bugzilla.redhat.com/show_bug.cgi?id=1326057 -------------------------------------------------------------------------------- ================================================================================ golang-github-stretchr-testify-1.0-0.9.git976c720.fc25 (FEDORA-2017-21766e836c) Tools for testifying that your code will behave as you intend -------------------------------------------------------------------------------- Update Information: Bump to upstream 976c720a22c8eb4eb6a0b4348ad85ad12491a506 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1246684 - Tracker for golang-github-stretchr-testify https://bugzilla.redhat.com/show_bug.cgi?id=1246684 -------------------------------------------------------------------------------- ================================================================================ ibus-typing-booster-1.5.27-1.fc25 (FEDORA-2017-ff24cf50f4) A completion input method -------------------------------------------------------------------------------- Update Information: update to 1.5.27 ---- update to 1.5.26 -------------------------------------------------------------------------------- ================================================================================ icoutils-0.31.3-1.fc25 (FEDORA-2017-0fec29b7f3) Utility for extracting and converting Microsoft icon and cursor files -------------------------------------------------------------------------------- Update Information: This release has an improved code base, fixes a couple of potential memory issues, and adds further checks for invalid data to prevent undefined behavior. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1431386 - icoutils-0.31.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1431386 -------------------------------------------------------------------------------- ================================================================================ kernel-4.10.3-200.fc25 (FEDORA-2017-e8e717e2b7) The Linux kernel -------------------------------------------------------------------------------- Update Information: The 4.10.3 kernel rebase contains a number of new features, important fixes, and additional hardware support. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1432429 - CVE-2017-6874 kernel: Race condition in kernel/ucount.c https://bugzilla.redhat.com/show_bug.cgi?id=1432429 -------------------------------------------------------------------------------- ================================================================================ libvmi-0.11.0-5.20170214git1a85386.fc25 (FEDORA-2017-3028339a8d) A library for performing virtual-machine introspection -------------------------------------------------------------------------------- Update Information: Update to Git master -------------------------------------------------------------------------------- ================================================================================ nss-3.28.3-1.1.fc25 (FEDORA-2017-9a242eb73d) Network Security Services -------------------------------------------------------------------------------- Update Information: This fixes a crash discovered in: https://bugzilla.mozilla.org/show_bug.cgi?id=1342358 -------------------------------------------------------------------------------- ================================================================================ perl-BSON-1.4.0-1.fc25 (FEDORA-2017-2ad73858f9) BSON serialization and deserialization -------------------------------------------------------------------------------- Update Information: This release fixes serialization and deserialziation on big-endian platforms. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1433156 - perl-BSON-v1.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1433156 -------------------------------------------------------------------------------- ================================================================================ perl-Function-Parameters-1.0706-1.fc25 (FEDORA-2017-20ef564c02) Subroutine definitions with parameter lists -------------------------------------------------------------------------------- Update Information: This release fixes building on Perl without "." in @INC path. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1433324 - perl-Function-Parameters-1.0706 is available https://bugzilla.redhat.com/show_bug.cgi?id=1433324 -------------------------------------------------------------------------------- ================================================================================ perl-Tree-Simple-1.30-1.fc25 (FEDORA-2017-cf2e71aef4) Tree::Simple Perl module -------------------------------------------------------------------------------- Update Information: -------------------------------------------------------------------------------- ================================================================================ php-bartlett-PHP-CompatInfo-5.0.5-1.fc25 (FEDORA-2017-b216d20326) Find out version and the extensions required for a piece of code to run -------------------------------------------------------------------------------- Update Information: **Version 5.0.5** From git history: * fixed #228 `const FOO = null;` does not require PHP 5.6.0 -------------------------------------------------------------------------------- ================================================================================ php-bartlett-php-compatinfo-db-1.19.0-1.fc25 (FEDORA-2017-f62dc42211) Reference Database to be used with php-compatinfo library -------------------------------------------------------------------------------- Update Information: **Version 1.19.0** - 2017-03-16 * Added * Support to PHP 7.0.17 * Changed * Xdebug reference updated to version 2.5.1 (stable) * Fixed * [security: uses db from known path](https://github.com/llaville/php-compatinfo-db/issues/9) (RPM not affected) -------------------------------------------------------------------------------- ================================================================================ php-zendframework-zend-validator-2.9.0-1.fc25 (FEDORA-2017-c709f29b00) Zend Framework Validator component -------------------------------------------------------------------------------- Update Information: **Version 2.9.0** - 2017-03-17 * Added * [#78](https://github.com/zendframework/zend-validator/pull/78) added `%length%` as an optional message variable in StringLength validator * Removed * [#151](https://github.com/zendframework/zend-validator/pull/151) dropped php 5.5 support * Fixed * [#147](https://github.com/zendframework/zend- validator/issues/147) [#148](https://github.com/zendframework/zend- validator/pull/148) adds further `"suggest"` clauses in `composer.json`, since some dependencies are not always required, and may lead to runtime failures. * [#66](https://github.com/zendframework/zend-validator/pull/66) fixed EmailAddress validator applying IDNA conversion to local part * [#88](https://github.com/zendframework/zend-validator/pull/88) fixed NotEmpty validator incorrectly applying types bitmaps * [#150](https://github.com/zendframework/zend-validator/pull/150) fixed Hostname validator not allowing some characters in .dk IDN -------------------------------------------------------------------------------- ================================================================================ python-idna-2.5-1.fc25 (FEDORA-2017-19f5b1c9b3) Internationalized Domain Names in Applications (IDNA) -------------------------------------------------------------------------------- Update Information: - Fix bug with Katakana middle dot context-rule (Thanks, Greg Shikhman.) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1429896 - python-idna-2.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=1429896 -------------------------------------------------------------------------------- ================================================================================ python-leather-0.3.3-2.gite85dd30.fc25 (FEDORA-2017-c04a15f2b6) Python charting for 80% of humans -------------------------------------------------------------------------------- Update Information: Add package -------------------------------------------------------------------------------- References: [ 1 ] Bug #1409802 - Review Request: python-leather - Python charting for 80% of humans https://bugzilla.redhat.com/show_bug.cgi?id=1409802 -------------------------------------------------------------------------------- ================================================================================ root-6.08.06-2.fc25 (FEDORA-2017-829416a358) Numerical data analysis framework -------------------------------------------------------------------------------- Update Information: https://root.cern.ch/doc/v608/release-notes.html#release-6.0806 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1428713 - root-config:: command not found quite late during the build https://bugzilla.redhat.com/show_bug.cgi?id=1428713 -------------------------------------------------------------------------------- ================================================================================ rust-1.16.0-1.fc25 (FEDORA-2017-987ab27b07) The Rust Programming Language -------------------------------------------------------------------------------- Update Information: New versions of Rust and Cargo -- see the release notes for [1.16](https://blog .rust-lang.org/2017/03/16/Rust-1.16.html). -------------------------------------------------------------------------------- ================================================================================ sway-0.12.1-1.fc25 (FEDORA-2017-7438f3a9e8) i3-compatible window manager for Wayland -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1432455 - sway-0.12.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1432455 -------------------------------------------------------------------------------- ================================================================================ vdr-epg-daemon-1.1.110-1.fc25 (FEDORA-2017-23b920df42) A daemon to download EPG data from internet and manage it in a mysql database -------------------------------------------------------------------------------- Update Information: Update to 1.1.110 ---- Update to 1.1.108 ---- Update to 1.1.107 ---- Update to 1.1.106 ---- Update to 1.1.103 ---- Update to 1.1.102 ---- Update to 1.1.101 ---- Update to 1.1.100 ---- Update to 1.1.99 ---- Changed INIT_AFTER to mariadb.service in Make.config ---- Update to 1.1.97 ---- Update to 1.1.95 ---- Update to 1.94 ---- Update to 1.1.93 ---- Update to 1.1.91 ---- Update to 1.1.90 ---- Update to 1.1.89 -------------------------------------------------------------------------------- ================================================================================ vdr-epg2vdr-1.1.48-1.fc25 (FEDORA-2017-375f6af2bf) A plugin to retrieve EPG data from a mysql database into VDR -------------------------------------------------------------------------------- Update Information: Update to 1.1.48 ---- Update to 1.1.47 ---- Update to 1.1.46 -------------------------------------------------------------------------------- ================================================================================ xen-4.7.2-2.fc25 (FEDORA-2017-3d16d348eb) Xen is a virtual machine monitor -------------------------------------------------------------------------------- Update Information: Cirrus VGA Heap overflow via display refresh [XSA-211, CVE-2016-9603] (#1432041) Qemu: usb: an infinite loop issue in ohci_service_ed_list [CVE-2017-6505] (#1429433) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1430056 - CVE-2016-9603 Qemu: cirrus: heap buffer overflow via vnc connection https://bugzilla.redhat.com/show_bug.cgi?id=1430056 [ 2 ] Bug #1429432 - CVE-2017-6505 Qemu: usb: an infinite loop issue in ohci_service_ed_list https://bugzilla.redhat.com/show_bug.cgi?id=1429432 -------------------------------------------------------------------------------- ================================================================================ xlockmore-5.51-1.fc25 (FEDORA-2017-25b596b1c5) Screen lock and screen saver -------------------------------------------------------------------------------- Update Information: updated to 5.51 -------------------------------------------------------------------------------- ================================================================================ xorg-x11-drv-amdgpu-1.3.0-1.fc25 (FEDORA-2017-8edb25d6c5) AMD GPU video driver -------------------------------------------------------------------------------- Update Information: Update to 1.3.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1432936 - Update to 1.3.0 https://bugzilla.redhat.com/show_bug.cgi?id=1432936 -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx