The following Fedora 25 Security updates need testing: Age URL 150 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d79ba708cb exim-4.87.1-1.fc25 49 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e2d17af41e python-XStatic-jquery-ui-1.12.0.1-4.fc25 29 https://bodhi.fedoraproject.org/updates/FEDORA-2017-f85c37ae3d squirrelmail-1.4.22-19.fc25 7 https://bodhi.fedoraproject.org/updates/FEDORA-2017-5135c91b36 mupdf-1.10a-7.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a3c7d077c7 perltidy-20170521-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-8ad8d1bd86 puppet-4.2.1-5.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-8ff992386d systemd-231-15.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-6f06be3fe9 kernel-4.11.3-200.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-98bc28ae9e webkitgtk4-2.16.3-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-8e9bd58cbb dropbear-2017.75-1.fc25 The following Fedora 25 Critical Path updates have yet to be approved: Age URL 14 https://bodhi.fedoraproject.org/updates/FEDORA-2017-116fdd792f pungi-4.1.15-1.fc25 9 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b8d8e95f8a tigervnc-1.8.0-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-1a705b1ff4 libtiff-4.0.8-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-6dcf888128 iproute-4.11.0-1.fc25 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a4019cfe64 opus-1.1.5-1.fc25 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-923b506a22 gssproxy-0.7.0-8.fc25 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-5e531c7512 dmidecode-3.1-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-2e6196e73d flatpak-0.9.4-1.fc25 bubblewrap-0.1.8-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-98bc28ae9e webkitgtk4-2.16.3-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-6f06be3fe9 kernel-4.11.3-200.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-8ff992386d systemd-231-15.fc25 The following builds have been pushed to Fedora 25 updates-testing adwaita-qt-1.0-1.fc25 batctl-2017.1-1.fc25 bubblewrap-0.1.8-1.fc25 bugwarrior-1.5.1-1.fc25 cinnamon-3.4.1-1.fc25 cinnamon-desktop-3.4.1-1.fc25 cinnamon-session-3.4.0-6.fc25 cinnamon-settings-daemon-3.4.1-1.fc25 cinnamon-translations-3.4.2-1.fc25 cjs-3.4.1-1.fc25 dist-git-1.2-1.fc25 dropbear-2017.75-1.fc25 e16-1.0.18-1.fc25 e16-epplets-0.15-1.fc25 e16-keyedit-0.8-1.fc25 flatpak-0.9.4-1.fc25 golang-github-xtaci-kcp-go-3.16-1.fc25 kernel-4.11.3-200.fc25 lollypop-0.9.238-1.fc25 nemo-3.4.2-1.fc25 nuvolaplayer-3.1.3-6.fc25 purple-discord-0-6.20170525gitec1292a.fc25 python-idstools-0.6.1-2.fc25 screen-4.5.1-2.fc25 sugar-terminal-45-1.fc25 systemd-231-15.fc25 webkitgtk4-2.16.3-1.fc25 wireshark-2.2.6-2.fc25 Details about builds: ================================================================================ adwaita-qt-1.0-1.fc25 (FEDORA-2017-550fee988d) Adwaita theme for Qt-based applications -------------------------------------------------------------------------------- Update Information: Update to 1.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1431838 - Textbox not visible https://bugzilla.redhat.com/show_bug.cgi?id=1431838 -------------------------------------------------------------------------------- ================================================================================ batctl-2017.1-1.fc25 (FEDORA-2017-e1f3f4a518) B.A.T.M.A.N. advanced control and management tool -------------------------------------------------------------------------------- Update Information: Changelog states: No changes -------------------------------------------------------------------------------- ================================================================================ bubblewrap-0.1.8-1.fc25 (FEDORA-2017-2e6196e73d) Core execution tool for unprivileged containers -------------------------------------------------------------------------------- Update Information: Update flatpak to 0.9.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454750 - flatpak-0.9.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1454750 -------------------------------------------------------------------------------- ================================================================================ bugwarrior-1.5.1-1.fc25 (FEDORA-2017-1d5b2bb11c) Sync github, bitbucket, and trac issues with taskwarrior -------------------------------------------------------------------------------- Update Information: Latest upstream with a bazillion changes. Please make sure it actually works for you before providing karma. :) -------------------------------------------------------------------------------- ================================================================================ cinnamon-3.4.1-1.fc25 (FEDORA-2017-1ae435e0c0) Window management and application launching for GNOME -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ cinnamon-desktop-3.4.1-1.fc25 (FEDORA-2017-1ae435e0c0) Shared code among cinnamon-session, nemo, etc -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ cinnamon-session-3.4.0-6.fc25 (FEDORA-2017-1ae435e0c0) Cinnamon session manager -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ cinnamon-settings-daemon-3.4.1-1.fc25 (FEDORA-2017-1ae435e0c0) The daemon sharing settings from CINNAMON to GTK+/KDE applications -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ cinnamon-translations-3.4.2-1.fc25 (FEDORA-2017-1ae435e0c0) Translations for Cinnamon and Nemo -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ cjs-3.4.1-1.fc25 (FEDORA-2017-1ae435e0c0) Javascript Bindings for Cinnamon -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ dist-git-1.2-1.fc25 (FEDORA-2017-5164e4eba1) Package source version control system -------------------------------------------------------------------------------- Update Information: - Adds grokmirror support - no longer employs mail git post-receive hook -------------------------------------------------------------------------------- ================================================================================ dropbear-2017.75-1.fc25 (FEDORA-2017-8e9bd58cbb) Lightweight SSH server and client -------------------------------------------------------------------------------- Update Information: Security fixes for CVE-2017-9078 CVE-2017-9079 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1452738 - CVE-2017-9078 CVE-2017-9079 dropbear: Multiple vulnerabilities fixed in 2017.75 version https://bugzilla.redhat.com/show_bug.cgi?id=1452738 -------------------------------------------------------------------------------- ================================================================================ e16-1.0.18-1.fc25 (FEDORA-2017-fa6117b6d4) The Enlightenment window manager, DR16 -------------------------------------------------------------------------------- Update Information: Update to latest upstream release e16 1.0.18. -------------------------------------------------------------------------------- ================================================================================ e16-epplets-0.15-1.fc25 (FEDORA-2017-a190e032d0) Epplets for Enlightenment, DR16 -------------------------------------------------------------------------------- Update Information: Update to latest upstream release epplets 0.15. -------------------------------------------------------------------------------- ================================================================================ e16-keyedit-0.8-1.fc25 (FEDORA-2017-7a73275c8f) GUI for editing keybindings in Enlightenment, DR16 -------------------------------------------------------------------------------- Update Information: Update to latest upstream release e16 keyedit 0.8. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1440367 - [abrt] e16-keyedit: _g_log_abort(): e16keyedit killed by SIGTRAP https://bugzilla.redhat.com/show_bug.cgi?id=1440367 -------------------------------------------------------------------------------- ================================================================================ flatpak-0.9.4-1.fc25 (FEDORA-2017-2e6196e73d) Application deployment framework for desktop apps -------------------------------------------------------------------------------- Update Information: Update flatpak to 0.9.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454750 - flatpak-0.9.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1454750 -------------------------------------------------------------------------------- ================================================================================ golang-github-xtaci-kcp-go-3.16-1.fc25 (FEDORA-2017-647ea02376) Production-Grade Reliable-UDP Library for golang -------------------------------------------------------------------------------- Update Information: Update to version 3.16. -------------------------------------------------------------------------------- ================================================================================ kernel-4.11.3-200.fc25 (FEDORA-2017-6f06be3fe9) The Linux kernel -------------------------------------------------------------------------------- Update Information: Rebase to 4.11.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1452744 - CVE-2017-9077 kernel: net: tcp_v6_syn_recv_sock function mishandles inheritance https://bugzilla.redhat.com/show_bug.cgi?id=1452744 [ 2 ] Bug #1452688 - CVE-2017-9076 kernel: net: IPv6 DCCP implementation mishandles inheritance https://bugzilla.redhat.com/show_bug.cgi?id=1452688 [ 3 ] Bug #1452691 - CVE-2017-9075 kernel: net: sctp_v6_create_accept_sk function mishandles inheritance https://bugzilla.redhat.com/show_bug.cgi?id=1452691 [ 4 ] Bug #1452679 - CVE-2017-9074 kernel: net: IPv6 fragmentation implementation of nexthdr field may be associated with an invalid option https://bugzilla.redhat.com/show_bug.cgi?id=1452679 [ 5 ] Bug #1450972 - CVE-2017-8890 kernel: Double free in the inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c https://bugzilla.redhat.com/show_bug.cgi?id=1450972 -------------------------------------------------------------------------------- ================================================================================ lollypop-0.9.238-1.fc25 (FEDORA-2017-1c1f978d2a) Music player for GNOME -------------------------------------------------------------------------------- Update Information: Update to 0.9.238 -------------------------------------------------------------------------------- ================================================================================ nemo-3.4.2-1.fc25 (FEDORA-2017-1ae435e0c0) File manager for Cinnamon -------------------------------------------------------------------------------- Update Information: Update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1454869 - [abrt] nemo: nemo_centered_placement_grid_clear_grid_for_selection(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454869 [ 2 ] Bug #1454930 - [abrt] nemo: nemo_centered_placement_grid_get_next_free_position(): nemo-desktop killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1454930 [ 3 ] Bug #1383173 - [abrt] cinnamon: nm_setting_ip6_config_clear_addresses(): python2.7 killed by SIGSEGV https://bugzilla.redhat.com/show_bug.cgi?id=1383173 [ 4 ] Bug #1429934 - None (or only a few) desktop icons shown after login https://bugzilla.redhat.com/show_bug.cgi?id=1429934 [ 5 ] Bug #1452870 - In Cinnamon 3.4.0, UK English panel menus show German for 'Remove'. https://bugzilla.redhat.com/show_bug.cgi?id=1452870 [ 6 ] Bug #1452876 - Invalid symlink in /usr/bin/cinnamon-settings-daemon https://bugzilla.redhat.com/show_bug.cgi?id=1452876 -------------------------------------------------------------------------------- ================================================================================ nuvolaplayer-3.1.3-6.fc25 (FEDORA-2017-5a0d6456c1) Cloud Music Integration for your Linux Desktop -------------------------------------------------------------------------------- Update Information: Update to 3.1.3-6 -------------------------------------------------------------------------------- ================================================================================ purple-discord-0-6.20170525gitec1292a.fc25 (FEDORA-2017-d79b35e0e8) Discord plugin for libpurple -------------------------------------------------------------------------------- Update Information: Updated to latest snapshot. -------------------------------------------------------------------------------- ================================================================================ python-idstools-0.6.1-2.fc25 (FEDORA-2017-cba1b81f31) Snort and Suricata Rule and Event Utilities -------------------------------------------------------------------------------- Update Information: default to python2 scripts -------------------------------------------------------------------------------- ================================================================================ screen-4.5.1-2.fc25 (FEDORA-2017-a41e73423b) A screen manager that supports multiple logins on one terminal -------------------------------------------------------------------------------- Update Information: Fix several bugs (missing info document, changes in spec and screenrc files) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1434671 - info document missing https://bugzilla.redhat.com/show_bug.cgi?id=1434671 [ 2 ] Bug #1429174 - remove %{localstatedir} from %{localstatedir}/run in spec https://bugzilla.redhat.com/show_bug.cgi?id=1429174 [ 3 ] Bug #1428337 - screen: apply "alternate window buffer" setting to xterm-256color terminals https://bugzilla.redhat.com/show_bug.cgi?id=1428337 -------------------------------------------------------------------------------- ================================================================================ sugar-terminal-45-1.fc25 (FEDORA-2017-aa262b828d) Terminal for Sugar -------------------------------------------------------------------------------- Update Information: Version 45 -------------------------------------------------------------------------------- ================================================================================ systemd-231-15.fc25 (FEDORA-2017-8ff992386d) A System and Service Manager -------------------------------------------------------------------------------- Update Information: A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant only to systemd-resolved users (not enabled by default). No need to reboot or logout. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1455493 - CVE-2017-9217 systemd: Null pointer dereference in dns_packet_is_reply_for function https://bugzilla.redhat.com/show_bug.cgi?id=1455493 -------------------------------------------------------------------------------- ================================================================================ webkitgtk4-2.16.3-1.fc25 (FEDORA-2017-98bc28ae9e) GTK+ Web content engine library -------------------------------------------------------------------------------- Update Information: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus first input field of HTTP authentication dialog. * Fix rendering glitches in HiDPI in long GitHub Gist pages when focusing the comments textarea. * Remove Firefox user agent quirk for Google domains. * Remove LATEST_RECORD_VERSION from GnuTLS priority string. * Fix several crashes and rendering issues. -------------------------------------------------------------------------------- ================================================================================ wireshark-2.2.6-2.fc25 (FEDORA-2017-f994c12a2d) Network traffic analyzer -------------------------------------------------------------------------------- Update Information: pkg-config patch was dropped. We are using the upstream version now. Please try if you can compile your applications. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1401463 - wireshark-devel lost all pkg-config dependencies https://bugzilla.redhat.com/show_bug.cgi?id=1401463 -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx