The following Fedora 25 Security updates need testing: Age URL 109 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d79ba708cb exim-4.87.1-1.fc25 30 https://bodhi.fedoraproject.org/updates/FEDORA-2017-06f4b88ceb php-onelogin-php-saml-2.10.5-1.fc25 9 https://bodhi.fedoraproject.org/updates/FEDORA-2017-cc029be02d tnef-1.4.14-1.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-c0ef6054d7 python-django-1.9.13-1.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e2d17af41e python-XStatic-jquery-ui-1.12.0.1-4.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-7bd002b77c xorgxrdp-0.2.1-1.fc25 xrdp-0.9.2-5.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-d43d46f1ca ming-0.4.8-1.fc25 5 https://bodhi.fedoraproject.org/updates/FEDORA-2017-c6f424c3ff proftpd-1.3.5e-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-2a90185a04 php-pear-CAS-1.3.5-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a3a47973eb libxml2-2.9.4-2.fc25 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b83c0eeab0 xstream-1.4.9-5.fc25 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a902f8db61 jenkins-xstream-1.4.7-11.jenkins1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-6ef28e38d6 dovecot-2.2.29.1-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-8dce7a3940 backintime-1.1.20-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-db77ca450f ansible-2.3.0.0-1.fc25 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-26c9ecd7a4 kernel-4.10.10-200.fc25 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-11ac1e31eb yara-3.5.0-7.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-80763c8c03 collectd-5.7.1-3.fc25 The following Fedora 25 Critical Path updates have yet to be approved: Age URL 17 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ea86a8123b pungi-4.1.14-1.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a919011cf0 sssd-1.15.2-2.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b19d9e3c3d gnutls-3.5.11-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a3a47973eb libxml2-2.9.4-2.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-4efaae68fe thunderbird-52.0-2.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-3c25dd541a livecd-tools-24.3-2.fc25 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-26c9ecd7a4 kernel-4.10.10-200.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-19451b76d6 highlight-3.36-1.fc25 The following builds have been pushed to Fedora 25 updates-testing collectd-5.7.1-3.fc25 dnfdaemon-0.3.16-3.fc25 dnfdragora-1.0.1-1.fc25 drupal7-webform-4.15-1.fc25 drupal8-8.3.0-1.fc25 fail2ban-0.9.6-4.fc25 highlight-3.36-1.fc25 konversation-1.7-1.fc25 libyui-3.3.1-5.fc25 libyui-gtk-2.44.9-2.fc25 libyui-ncurses-2.48.1-4.fc25 libyui-qt-2.47.1-4.fc25 lumina-desktop-1.2.0-1.p1.Ld700dea.fc25 magic-8.1.158-1.fc25 php-asm89-stack-cors-1.1.0-1.fc25 php-di-5.4.3-1.fc25 php-symfony-psr-http-message-bridge-1.0.0-1.fc25 php-zendframework-zend-diactoros-1.4.0-1.fc25 postbooks-4.10.0-11.fc25 rpm-ostree-2017.4-2.fc25 rpmlint-1.9-9.fc25 xcircuit-3.9.66-1.fc25 xtuple-csvimp-0.5.4-8.fc25 xtuple-openrpt-3.3.12-8.fc25 Details about builds: ================================================================================ collectd-5.7.1-3.fc25 (FEDORA-2017-80763c8c03) Statistics collection daemon for filling RRD files -------------------------------------------------------------------------------- Update Information: Fix CVE-2017-7401 collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions. This is a bug in the network plugin. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1439674 - CVE-2017-7401 collectd: Infinite loop due to incorrect interaction of parse_packet() and parse_part_sign_sha256() functions https://bugzilla.redhat.com/show_bug.cgi?id=1439674 -------------------------------------------------------------------------------- ================================================================================ dnfdaemon-0.3.16-3.fc25 (FEDORA-2017-6250e8f561) DBus daemon for dnf package actions -------------------------------------------------------------------------------- Update Information: Add -selinux subpackage and drag it in through boolean Supplements -------------------------------------------------------------------------------- References: [ 1 ] Bug #1395531 - dnfdaemon package requires many SELinux-related dependencies https://bugzilla.redhat.com/show_bug.cgi?id=1395531 -------------------------------------------------------------------------------- ================================================================================ dnfdragora-1.0.1-1.fc25 (FEDORA-2017-e1efb1f4d6) DNF package-manager based on libYui abstraction -------------------------------------------------------------------------------- Update Information: * New upstream release -------------------------------------------------------------------------------- ================================================================================ drupal7-webform-4.15-1.fc25 (FEDORA-2017-187f8a1808) Enables the creation of forms and questionnaires -------------------------------------------------------------------------------- Update Information: * [7.x-4.15](https://www.drupal.org/project/webform/releases/7.x-4.15) ---- * [7.x-4.15-rc1](https://www.drupal.org/project/webform/releases/7.x-4.15-rc1) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1442289 - drupal7-webform-4.15 is available https://bugzilla.redhat.com/show_bug.cgi?id=1442289 [ 2 ] Bug #1437695 - drupal7-webform-4.15-rc1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1437695 -------------------------------------------------------------------------------- ================================================================================ drupal8-8.3.0-1.fc25 (FEDORA-2017-fce573134a) An open source content management platform -------------------------------------------------------------------------------- Update Information: # drupal8 * [8.3.0](https://www.drupal.org/project/drupal/releases/8.3.0) # php-symfony-psr-http-message-bridge ## 1.0.0 * Initial release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1370802 - php-symfony-psr-http-message-bridge-v1.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1370802 [ 2 ] Bug #1439698 - drupal8-8.3.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1439698 -------------------------------------------------------------------------------- ================================================================================ fail2ban-0.9.6-4.fc25 (FEDORA-2017-4b1566eee1) Daemon to ban hosts that cause multiple authentication errors -------------------------------------------------------------------------------- Update Information: Properly handle /run/fail2ban -------------------------------------------------------------------------------- References: [ 1 ] Bug #1442368 - fail2ban is missing /var/run/fail2ban after installation and refuses to start https://bugzilla.redhat.com/show_bug.cgi?id=1442368 -------------------------------------------------------------------------------- ================================================================================ highlight-3.36-1.fc25 (FEDORA-2017-19451b76d6) Universal source code to formatted text converter -------------------------------------------------------------------------------- Update Information: - Updated to new 3.36 upstream version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1117261 - highlight package not available on epel-7-ppc64 (available on x86_64) https://bugzilla.redhat.com/show_bug.cgi?id=1117261 -------------------------------------------------------------------------------- ================================================================================ konversation-1.7-1.fc25 (FEDORA-2017-999d901717) A user friendly IRC client -------------------------------------------------------------------------------- Update Information: New stable 1.7 release, see also https://konversation.kde.org/ -------------------------------------------------------------------------------- References: [ 1 ] Bug #1390814 - konversation requires Python 2 https://bugzilla.redhat.com/show_bug.cgi?id=1390814 -------------------------------------------------------------------------------- ================================================================================ libyui-3.3.1-5.fc25 (FEDORA-2017-57ab8a49a1) GUI-abstraction library -------------------------------------------------------------------------------- Update Information: * Updated patches from upstream -------------------------------------------------------------------------------- ================================================================================ libyui-gtk-2.44.9-2.fc25 (FEDORA-2017-125f105204) Gtk3 User Interface for libyui -------------------------------------------------------------------------------- Update Information: * New upstream release * Change Supplements: back to gtk3, since libYUI provides selection of UI-plugin based on used desktop environment -------------------------------------------------------------------------------- ================================================================================ libyui-ncurses-2.48.1-4.fc25 (FEDORA-2017-ac41a10b5f) Character Based User Interface for libyui -------------------------------------------------------------------------------- Update Information: * Fix hardlinking of html-docs -------------------------------------------------------------------------------- ================================================================================ libyui-qt-2.47.1-4.fc25 (FEDORA-2017-1158f3e883) Qt User Interface for libyui -------------------------------------------------------------------------------- Update Information: * Change Supplements: back to qt5-qtbase-gui, since libYUI provides selection of UI-plugin based on used desktop environment * Fix hardlinking of html-docs -------------------------------------------------------------------------------- ================================================================================ lumina-desktop-1.2.0-1.p1.Ld700dea.fc25 (FEDORA-2017-006be96873) A lightweight, portable desktop environment -------------------------------------------------------------------------------- Update Information: Version bump -------------------------------------------------------------------------------- ================================================================================ magic-8.1.158-1.fc25 (FEDORA-2017-8b4cb4b8bb) A very capable VLSI layout tool -------------------------------------------------------------------------------- Update Information: New version 8.1.158 is released. -------------------------------------------------------------------------------- ================================================================================ php-asm89-stack-cors-1.1.0-1.fc25 (FEDORA-2017-09212bb924) Cross-origin resource sharing library and stack middleware -------------------------------------------------------------------------------- Update Information: ### 1.1.0 New release containing several improvements/bug fixes: * Skip empty Access-Control-Request-Headers. Working around some browser bugs. #30 * Requests from the same origin are not modified anymore. #11 * Updated dependencies to 2017. E.g. `php >= 5.5.9` and Symfony deps now have a lower bound of `~2.7`. #41 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1441443 - php-asm89-stack-cors-1.1.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1441443 -------------------------------------------------------------------------------- ================================================================================ php-di-5.4.3-1.fc25 (FEDORA-2017-6c3a772904) The dependency injection container for humans -------------------------------------------------------------------------------- Update Information: ### 5.4.3 * \#467: register the container against the PSR ContainerInterface -------------------------------------------------------------------------------- References: [ 1 ] Bug #1442382 - php-di-5.4.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1442382 -------------------------------------------------------------------------------- ================================================================================ php-symfony-psr-http-message-bridge-1.0.0-1.fc25 (FEDORA-2017-fce573134a) Symfony PSR HTTP message bridge -------------------------------------------------------------------------------- Update Information: # drupal8 * [8.3.0](https://www.drupal.org/project/drupal/releases/8.3.0) # php-symfony-psr-http-message-bridge ## 1.0.0 * Initial release -------------------------------------------------------------------------------- References: [ 1 ] Bug #1370802 - php-symfony-psr-http-message-bridge-v1.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1370802 [ 2 ] Bug #1439698 - drupal8-8.3.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1439698 -------------------------------------------------------------------------------- ================================================================================ php-zendframework-zend-diactoros-1.4.0-1.fc25 (FEDORA-2017-542934832c) PSR HTTP Message implementations -------------------------------------------------------------------------------- Update Information: ## 1.4.0 ### Added * \#219 adds two new classes, `Zend\Diactoros\Request\ArraySerializer` and `Zend\Diactoros\Response\ArraySerializer`. Each exposes the static methods `toArray()` and `fromArray()`, allowing de/serialization of messages from and to arrays. * \#236 adds two new constants to the `Response` class: `MIN_STATUS_CODE_VALUE` and `MAX_STATUS_CODE_VALUE`. ### Changes * \#240 changes the behavior of `ServerRequestFactory::fromGlobals()` when no `$cookies` argument is present. Previously, it would use `$_COOKIES`; now, if a `Cookie` header is present, it will parse and use that to populate the instance instead. * This change allows utilizing cookies that contain period characters (`.`) in their names (PHP's built-in cookie handling renames these to replace `.` with `_`, which can lead to synchronization issues with clients). * \#235 changes the behavior of `Uri::__toString()` to better follow proscribed behavior in PSR-7. In particular, prior to this release, if a scheme was missing but an authority was present, the class was incorrectly returning a value that did not include a `//` prefix. As of this release, it now does this correctly. ### Deprecated Nothing. ### Removed Nothing. ### Fixed Nothing. ## 1.3.11 ### Added Nothing. ### Changes * \#241 changes the constraint by which the package provides `psr/http-message-implementation` to simply `1.0` instead of `~1.0.0`, to follow how other implementations provide PSR-7. ### Deprecated Nothing. ### Removed Nothing. ### Fixed * \#161 adds additional validations to header names and values to ensure no malformed values are provided. * \#234 fixes a number of reason phrases in the `Response` instance, and adds automation from the canonical IANA sources to ensure any new phrases added are correct. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1440332 - php-zendframework-zend-diactoros-1.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1440332 -------------------------------------------------------------------------------- ================================================================================ postbooks-4.10.0-11.fc25 (FEDORA-2017-6b54ad73b1) xTuple Accounting/ERP suite desktop client -------------------------------------------------------------------------------- Update Information: Postbooks 4.10.0 release -------------------------------------------------------------------------------- ================================================================================ rpm-ostree-2017.4-2.fc25 (FEDORA-2017-6ba7dbb4ce) Hybrid image/package system -------------------------------------------------------------------------------- Update Information: New upstream release v2017.4. See full changelog at https://github.com/projectatomic/rpm-ostree/releases/tag/v2017.4. -------------------------------------------------------------------------------- ================================================================================ rpmlint-1.9-9.fc25 (FEDORA-2017-30c8498f8a) Tool for checking common errors in RPM packages -------------------------------------------------------------------------------- Update Information: Upstream fix for str object has no attribute decode (bz1439941) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1441988 - AttributeError: 'str' object has no attribute 'decode' https://bugzilla.redhat.com/show_bug.cgi?id=1441988 -------------------------------------------------------------------------------- ================================================================================ xcircuit-3.9.66-1.fc25 (FEDORA-2017-eecf9f4def) Electronic circuit schematic drawing program -------------------------------------------------------------------------------- Update Information: New version 3.9.66 is released. -------------------------------------------------------------------------------- ================================================================================ xtuple-csvimp-0.5.4-8.fc25 (FEDORA-2017-6b54ad73b1) xTuple data import utility -------------------------------------------------------------------------------- Update Information: Postbooks 4.10.0 release -------------------------------------------------------------------------------- ================================================================================ xtuple-openrpt-3.3.12-8.fc25 (FEDORA-2017-6b54ad73b1) xTuple / PostBooks reporting utility and libraries -------------------------------------------------------------------------------- Update Information: Postbooks 4.10.0 release -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx