The following Fedora 25 Security updates need testing: Age URL 197 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d79ba708cb exim-4.87.1-1.fc25 95 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e2d17af41e python-XStatic-jquery-ui-1.12.0.1-4.fc25 39 https://bodhi.fedoraproject.org/updates/FEDORA-2017-7dbbbafea6 runc-1.0.0-7.git6394544.fc25.2 34 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ec3c82e64d libstaroffice-0.0.3-3.fc25 34 https://bodhi.fedoraproject.org/updates/FEDORA-2017-5d7498559f nodejs-brace-expansion-1.1.7-1.fc25 25 https://bodhi.fedoraproject.org/updates/FEDORA-2017-bcfa3569d6 libmwaw-0.3.11-3.fc25 13 https://bodhi.fedoraproject.org/updates/FEDORA-2017-620085cede httpd-2.4.26-1.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9dd1004ad8 jabberd-2.6.1-1.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-486371ff24 perl-DBD-MySQL-4.043-1.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-1ca18683e4 openldap-2.4.44-11.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b674dc22ad php-7.0.21-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-f8e32f160e cacti-1.1.12-2.fc25 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b9e4c24094 subversion-1.9.6-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-d7a871850c poppler-0.45.0-4.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b0a2770a9b knot-2.4.5-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-90ad72e684 irssi-1.0.4-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-efdd962fee putty-0.70-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-c844713925 qt5-qtwebkit-5.212.0-0.5.alpha2.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-33c8085c5d groovy18-1.8.9-28.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a7a488d8d0 qt5-qtwebengine-5.9.1-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-92643d70b7 knot-resolver-1.3.1-1.fc25 The following Fedora 25 Critical Path updates have yet to be approved: Age URL 39 https://bodhi.fedoraproject.org/updates/FEDORA-2017-613a72e282 lorax-25.22-1.fc25 17 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0187b2a605 selinux-policy-3.13.1-225.19.fc25 11 https://bodhi.fedoraproject.org/updates/FEDORA-2017-118505dd77 libsoup-2.56.0-3.fc25 10 https://bodhi.fedoraproject.org/updates/FEDORA-2017-caf28c1846 flatpak-0.9.7-1.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a90ed7e59d libtirpc-1.0.2-0.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-1d2652d711 gnome-keyring-3.20.1-1.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-1ca18683e4 openldap-2.4.44-11.fc25 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-7cd9e81996 quota-4.03-8.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-b18eded0a5 glusterfs-3.10.4-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-00d20db471 samba-4.5.11-0.fc25 3 https://bodhi.fedoraproject.org/updates/FEDORA-2017-efabd0d782 ostree-2017.8-2.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9075f30365 vim-8.0.705-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-d7a871850c poppler-0.45.0-4.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e719edea40 koji-1.13.0-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ddd2aa1a04 xen-4.7.3-1.fc25 The following builds have been pushed to Fedora 25 updates-testing COPASI-4.19.156-1.fc25 R-3.4.1-1.fc25 Zim-0.67-1.fc25 aime-8.20170704-1.fc25 btrbk-0.25.0-4.fc25 caja-1.18.3-3.fc25 chirp-20170711-1.fc25 colorful-1.2-13.20170707.git.4db365a.fc25 criu-3.2.1-2.fc25 ctstream-27-1.fc25 dovecot-2.2.31-3.fc25 drupal7-metatag-1.22-1.fc25 freeipmi-1.5.6-1.fc25 gnome-chemistry-utils-0.14.17-3.fc25 gnumeric-1.12.35-1.fc25 goffice-0.10.35-1.fc25 grip-3.4.3-1.fc25 groovy18-1.8.9-28.fc25 haproxy-1.6.13-1.fc25 irssi-1.0.4-1.fc25 knot-2.4.5-1.fc25 knot-resolver-1.3.1-1.fc25 koji-1.13.0-1.fc25 libisds-0.10.7-1.fc25 libmediainfo-0.7.97-1.fc25 mate-panel-1.18.3-3.fc25 mediainfo-0.7.97-1.fc25 nordugrid-arc-5.3.2-3.fc25 nordugrid-arc-doc-2.0.16-1.fc25 nordugrid-arc-nagios-plugins-1.9.1-1.fc25 omniORB-4.2.2-1.fc25 omniORBpy-4.2.2-1.fc25 pciutils-3.5.5-1.fc25 pdns-recursor-4.0.6-1.fc25 perl-Dist-Zilla-6.010-1.fc25 php-Monolog-1.23.0-1.fc25 php-consolidation-output-formatters-3.1.10-1.fc25 php-phpmyadmin-sql-parser-4.1.8-1.fc25 php-symfony-polyfill-1.4.0-1.fc25 php-twig-extensions-1.5.1-1.fc25 poppler-0.45.0-4.fc25 putty-0.70-1.fc25 python-avocado-52.0-1.fc25 python-basemap-data-1.0.7-6.fc25 python-docker-py-1.10.6-2.fc25 python-hypothesis-3.12.0-1.fc25 python-pathspec-0.5.3-1.fc25 python-plaster-pastedeploy-0.3.2-2.fc25 python-sphinx-autobuild-0.7.1-1.fc25 qcad-3.17.3.1-1.fc25 qotd-0.11.3-1.fc25 qt5-qtwebengine-5.9.1-1.fc25 qt5-qtwebkit-5.212.0-0.5.alpha2.fc25 rkward-0.6.5-7.fc25 root-6.10.02-2.fc25 rpkg-1.49-6.fc25 rpy-2.8.6-1.fc25 rubygem-diffy-3.2.0-1.1.fc25 rust-srpm-macros-4-2.fc25 screen-4.6.1-1.fc25 tracer-0.6.13-1.fc25 vim-8.0.705-1.fc25 xen-4.7.3-1.fc25 xiphos-4.0.5-2.fc25 xoreos-tools-0.0.4-2.fc25 yash-2.45-1.fc25 Details about builds: ================================================================================ COPASI-4.19.156-1.fc25 (FEDORA-2017-1824d0701a) Biochemical network simulator -------------------------------------------------------------------------------- Update Information: - Update to version 4.19 -build 156 -------------------------------------------------------------------------------- ================================================================================ R-3.4.1-1.fc25 (FEDORA-2017-4acde45111) A language for data analysis and graphics -------------------------------------------------------------------------------- Update Information: Update to R 3.4.1. This contains several significant bugfixes introduced in 3.4.0, so updating is strongly recommended. Full release notes are here: https://cran.r-project.org/doc/manuals/r-release/NEWS.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1456452 - rpy-2.8.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1456452 -------------------------------------------------------------------------------- ================================================================================ Zim-0.67-1.fc25 (FEDORA-2017-07c94f0d12) Desktop wiki & notekeeper -------------------------------------------------------------------------------- Update Information: Update to 0.67 final release -------------------------------------------------------------------------------- ================================================================================ aime-8.20170704-1.fc25 (FEDORA-2017-cf35926b9f) An application embeddable programming language interpreter -------------------------------------------------------------------------------- Update Information: - Updated to new 8.20170704 upstream version, fixes rhbz #1465412 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1465412 - aime-8.20170704 is available https://bugzilla.redhat.com/show_bug.cgi?id=1465412 -------------------------------------------------------------------------------- ================================================================================ btrbk-0.25.0-4.fc25 (FEDORA-2017-1f684fda78) Tool for creating snapshots and remote backups of btrfs sub-volumes -------------------------------------------------------------------------------- Update Information: Initial package release -------------------------------------------------------------------------------- ================================================================================ caja-1.18.3-3.fc25 (FEDORA-2017-d9d7428fcf) File manager for MATE -------------------------------------------------------------------------------- Update Information: - Fix browsing autorun/media on insertion - https://github.com/mate- desktop/caja/issues/807 -------------------------------------------------------------------------------- ================================================================================ chirp-20170711-1.fc25 (FEDORA-2017-27e53be741) A tool for programming two-way radio equipment -------------------------------------------------------------------------------- Update Information: http://chirp.danplanet.com/projects/chirp/repository/revisions -------------------------------------------------------------------------------- ================================================================================ colorful-1.2-13.20170707.git.4db365a.fc25 (FEDORA-2017-58ffc6be4d) Side-view shooter game -------------------------------------------------------------------------------- Update Information: Update to the most recent upstream snapshot -------------------------------------------------------------------------------- ================================================================================ criu-3.2.1-2.fc25 (FEDORA-2017-2cfb8115c0) Tool for Checkpoint/Restore in User-space -------------------------------------------------------------------------------- Update Information: Added patches to handle unified hierarchy and new glibc -------------------------------------------------------------------------------- ================================================================================ ctstream-27-1.fc25 (FEDORA-2017-4df5162557) Get URLs of Czech Television video streams -------------------------------------------------------------------------------- Update Information: This release fixes stream segment's output not to contain bottom-level Apple play-list data. It also improves debugging output. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1468854 - ctstream-27 is available https://bugzilla.redhat.com/show_bug.cgi?id=1468854 -------------------------------------------------------------------------------- ================================================================================ dovecot-2.2.31-3.fc25 (FEDORA-2017-6bff5ec747) Secure imap and pop3 server -------------------------------------------------------------------------------- Update Information: enabled tcpwrap ---- fix broken NOTIFY support ---- - dovecot updated to 2.2.31 - Various fixes to handling mailbox listing. Especially related to handling nonexistent autocreated/autosubscribed mailboxes and ACLs. - Global ACL file was parsed as if it was local ACL file. This caused some of the ACL rule interactions to not work exactly as intended. - Using mail_sort_max_read_count may have caused very high CPU usage. - Message address parsing could have crashed on invalid input. - imapc_features=fetch-headers wasn't always working correctly and caused the full header to be fetched. - imapc: Various bugfixes related to connection failure handling. - quota=count: quota_warning = -storage=.. was never executed - quota=count: Add support for "ns" parameter - dsync: Fix incremental syncing for mails that don't have Date or Message-ID headers. - imap: Fix hang when client sends pipelined SEARCH + EXPUNGE/CLOSE/LOGOUT. - oauth2: Token validation didn't accept empty server responses. - imap: NOTIFY command has been almost completely broken since the beginning. - pigeonhole updated to 0.4.19 - Fixed bug in handling of implicit keep in some cases. - include extension: Fixed segfault that (sometimes) occurred when the global script location was left unconfigured. ---- - auth: Multiple failed authentications within short time caused crashes - push- notification: OX driver crashed at deinit ---- - auth: Use timing safe comparisons for everything related to passwords. It's unlikely that these could have been used for practical attacks, especially because Dovecot delays and flushes all failed authentications in 2 second intervals. Also it could have worked only when passwords were stored in plaintext in the passdb. - master process sends SIGQUIT to all running children at shutdown, which instructs them to close all the socket listeners immediately. This way restarting Dovecot should no longer fail due to some processes keeping the listeners open for a long time. - auth: Add passdb { mechanisms=none } to match separate passdb lookup - auth: Add passdb { username_filter } to use passdb only if user matches the filter. See https://wiki2.dovecot.org/PasswordDatabase - dsync: Add dsync_commit_msgs_interval setting. It attempts to commit the transaction after saving this many new messages. Because of the way dsync works, it may not always be possible if mails are copied or UIDs need to change. - imapc: Support imapc_features=search without ESEARCH extension. - imapc: Add imapc_features=fetch-bodystructure to pass through remote server's FETCH BODY and BODYSTRUCTURE. - imapc: Add quota=imapc backend to use GETQUOTA/GETQUOTAROOT on the remote server. - passdb imap: Add allow_invalid_cert and ssl_ca_file parameters. - If dovecot.index.cache corruption is detected, reset only the one corrupted mail instead of the whole file. - doveadm mailbox status: Add "firstsaved" field. - director_flush_socket: Add old host's up/down and vhost count as parameters - More fixes to automatically fix corruption in dovecot.list.index - dsync-server: Fix support for dsync_features=empty-header-workaround - imapc: Various bugfixes, including infinite loops on some errors - IMAP NOTIFY wasn't working for non-INBOX if IMAP client hadn't enabled modseq tracking via CONDSTORE/QRESYNC. - fts-lucene: Fix it to work again with mbox format - Some internal error messages may have contained garbage in v2.2.29 - mail-crypt: Re- encrypt when copying/moving mails and per-mailbox keys are used. Otherwise the copied mails can't be opened. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1450587 - activate tcpwrap https://bugzilla.redhat.com/show_bug.cgi?id=1450587 -------------------------------------------------------------------------------- ================================================================================ drupal7-metatag-1.22-1.fc25 (FEDORA-2017-f6edb6ff84) Adds support and an API to implement meta tags -------------------------------------------------------------------------------- Update Information: * [1.22](https://www.drupal.org/project/metatag/releases/7.x-1.22) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1467454 - drupal7-metatag-1.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467454 -------------------------------------------------------------------------------- ================================================================================ freeipmi-1.5.6-1.fc25 (FEDORA-2017-1c9ac4c9ff) IPMI remote console and system management software -------------------------------------------------------------------------------- Update Information: New version of freeipmi package is available (1.5.6) * In libfreeipmi locate (used by ipmi-locate), use DMI firmware in sysfs if it exists. * Minor mem-leak corner case fix in libfreeipmi. * Minor documentation fixes. * Minor error message clarifications. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1468984 - Man page for freeipmi should display lower case version for command examples https://bugzilla.redhat.com/show_bug.cgi?id=1468984 [ 2 ] Bug #1468062 - freeipmi-1.5.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1468062 -------------------------------------------------------------------------------- ================================================================================ gnome-chemistry-utils-0.14.17-3.fc25 (FEDORA-2017-16ac7fdb18) A set of chemical utilities -------------------------------------------------------------------------------- Update Information: An update to the latest gnumeric and goffice releases: * http://gnumeric.org/announcements/1.12/gnumeric-1.12.35.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1464742 - The summary of gnumeric-plugins-extras is a copy of gnumeric-devel https://bugzilla.redhat.com/show_bug.cgi?id=1464742 -------------------------------------------------------------------------------- ================================================================================ gnumeric-1.12.35-1.fc25 (FEDORA-2017-16ac7fdb18) Spreadsheet program for GNOME -------------------------------------------------------------------------------- Update Information: An update to the latest gnumeric and goffice releases: * http://gnumeric.org/announcements/1.12/gnumeric-1.12.35.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1464742 - The summary of gnumeric-plugins-extras is a copy of gnumeric-devel https://bugzilla.redhat.com/show_bug.cgi?id=1464742 -------------------------------------------------------------------------------- ================================================================================ goffice-0.10.35-1.fc25 (FEDORA-2017-16ac7fdb18) G Office support libraries -------------------------------------------------------------------------------- Update Information: An update to the latest gnumeric and goffice releases: * http://gnumeric.org/announcements/1.12/gnumeric-1.12.35.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1464742 - The summary of gnumeric-plugins-extras is a copy of gnumeric-devel https://bugzilla.redhat.com/show_bug.cgi?id=1464742 -------------------------------------------------------------------------------- ================================================================================ grip-3.4.3-1.fc25 (FEDORA-2017-44ec3c37f6) Front-end for CD rippers and Ogg Vorbis encoders -------------------------------------------------------------------------------- Update Information: Fix for disc tray ejection issue. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1468512 - grip-3.4.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1468512 -------------------------------------------------------------------------------- ================================================================================ groovy18-1.8.9-28.fc25 (FEDORA-2017-33c8085c5d) Dynamic language for the Java Platform -------------------------------------------------------------------------------- Update Information: Fixes information disclosure vulnerability (CVE-2016-6814) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1413466 - CVE-2016-6814 Apache Groovy: Remote code execution via deserialization https://bugzilla.redhat.com/show_bug.cgi?id=1413466 -------------------------------------------------------------------------------- ================================================================================ haproxy-1.6.13-1.fc25 (FEDORA-2017-283f771959) HAProxy reverse proxy for high availability environments -------------------------------------------------------------------------------- Update Information: Update to 1.6.13 -------------------------------------------------------------------------------- ================================================================================ irssi-1.0.4-1.fc25 (FEDORA-2017-90ad72e684) Modular text mode IRC client with Perl scripting -------------------------------------------------------------------------------- Update Information: This is an update fixing CVE-2017-10965 and CVE-2017-10966. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1468785 - irssi-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1468785 -------------------------------------------------------------------------------- ================================================================================ knot-2.4.5-1.fc25 (FEDORA-2017-b0a2770a9b) High-performance authoritative DNS server -------------------------------------------------------------------------------- Update Information: New upstream release: 2.4.5 -------------------------------------------------------------------------------- ================================================================================ knot-resolver-1.3.1-1.fc25 (FEDORA-2017-92643d70b7) Caching full DNS Resolver -------------------------------------------------------------------------------- Update Information: Update to upstream version 1.3.1. -------------------------------------------------------------------------------- ================================================================================ koji-1.13.0-1.fc25 (FEDORA-2017-e719edea40) Build system tools -------------------------------------------------------------------------------- Update Information: update to upstream 1.13.0 -------------------------------------------------------------------------------- ================================================================================ libisds-0.10.7-1.fc25 (FEDORA-2017-cd7e8bcc2a) Library for accessing the Czech Data Boxes -------------------------------------------------------------------------------- Update Information: This release adds new values to isds_UserType and isds_DbType enum types to support new user and box types introduced in recent ISDS specification and testing instanance. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1468925 - libisds-0.10.7 is available https://bugzilla.redhat.com/show_bug.cgi?id=1468925 -------------------------------------------------------------------------------- ================================================================================ libmediainfo-0.7.97-1.fc25 (FEDORA-2017-ab8a879330) Library for supplies technical and tag information about a video or audio file -------------------------------------------------------------------------------- Update Information: Update to 0.7.97. -------------------------------------------------------------------------------- ================================================================================ mate-panel-1.18.3-3.fc25 (FEDORA-2017-b4791a0dab) MATE Desktop panel and applets -------------------------------------------------------------------------------- Update Information: - fix Notification area icons disappears, - when apply a background image to the panel - https://github.com/mate-desktop/mate-panel/issues/585 -------------------------------------------------------------------------------- ================================================================================ mediainfo-0.7.97-1.fc25 (FEDORA-2017-ab8a879330) Supplies technical and tag information about a video or audio file (CLI) -------------------------------------------------------------------------------- Update Information: Update to 0.7.97. -------------------------------------------------------------------------------- ================================================================================ nordugrid-arc-5.3.2-3.fc25 (FEDORA-2017-0cacd54867) Advanced Resource Connector Grid Middleware -------------------------------------------------------------------------------- Update Information: http://www.nordugrid.org/arc/releases/15.03u15/release_notes_15.03u15.html -------------------------------------------------------------------------------- ================================================================================ nordugrid-arc-doc-2.0.16-1.fc25 (FEDORA-2017-0cacd54867) Advanced Resource Connector Documentation -------------------------------------------------------------------------------- Update Information: http://www.nordugrid.org/arc/releases/15.03u15/release_notes_15.03u15.html -------------------------------------------------------------------------------- ================================================================================ nordugrid-arc-nagios-plugins-1.9.1-1.fc25 (FEDORA-2017-0cacd54867) Nagios plugins for ARC -------------------------------------------------------------------------------- Update Information: http://www.nordugrid.org/arc/releases/15.03u15/release_notes_15.03u15.html -------------------------------------------------------------------------------- ================================================================================ omniORB-4.2.2-1.fc25 (FEDORA-2017-f18a9bc66f) A robust high performance CORBA ORB for C++ and Python -------------------------------------------------------------------------------- Update Information: Update to version 4.2.2, see https://sourceforge.net/p/omniorb/svn/6351/tree/bra nches/4_2/omniORB/ReleaseNotes.txt and https://sourceforge.net/p/omniorb/svn/635 1/tree/branches/4_2/omniORBpy/ReleaseNotes.txt for details. -------------------------------------------------------------------------------- ================================================================================ omniORBpy-4.2.2-1.fc25 (FEDORA-2017-f18a9bc66f) CORBA ORB for Python -------------------------------------------------------------------------------- Update Information: Update to version 4.2.2, see https://sourceforge.net/p/omniorb/svn/6351/tree/bra nches/4_2/omniORB/ReleaseNotes.txt and https://sourceforge.net/p/omniorb/svn/635 1/tree/branches/4_2/omniORBpy/ReleaseNotes.txt for details. -------------------------------------------------------------------------------- ================================================================================ pciutils-3.5.5-1.fc25 (FEDORA-2017-040991ca0a) PCI bus related utilities -------------------------------------------------------------------------------- Update Information: * Better decoding of AER capability. * "Slot Implemented" flag is decoded for PCI/PCI-X to PCIe bridges. * Minor fixes of decoding other capabilities. -------------------------------------------------------------------------------- ================================================================================ pdns-recursor-4.0.6-1.fc25 (FEDORA-2017-960f116bef) Modern, advanced and high performance recursing/non authoritative name server -------------------------------------------------------------------------------- Update Information: Update to 4.0.6. The most important change is the addition of the KSK-2017, the new root key for DNSSEC. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1413016 - pdns-recursor-4.0.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1413016 -------------------------------------------------------------------------------- ================================================================================ perl-Dist-Zilla-6.010-1.fc25 (FEDORA-2017-ea7235020e) Distribution builder; installer not included! -------------------------------------------------------------------------------- Update Information: A new version of Dist::Zilla is available for Fedora. See http://cpansearch.perl.org/src/RJBS/Dist-Zilla-6.010/Changes for the summary of changes in this release. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1469313 - perl-Dist-Zilla-6.010 is available https://bugzilla.redhat.com/show_bug.cgi?id=1469313 -------------------------------------------------------------------------------- ================================================================================ php-Monolog-1.23.0-1.fc25 (FEDORA-2017-0c8caf79de) Sends your logs to files, sockets, inboxes, databases and various web services -------------------------------------------------------------------------------- Update Information: ### 1.23.0 (2017-06-19) * Improved SyslogUdpHandler's support for RFC5424 and added optional `$ident` argument * Fixed GelfHandler truncation to be per field and not per message * Fixed compatibility issue with PHP <5.3.6 * Fixed support for headless Chrome in ChromePHPHandler * Fixed support for latest Aws SDK in DynamoDbHandler * Fixed support for SwiftMailer 6.0+ in SwiftMailerHandler ### 1.22.1 (2017-03-13) * Fixed lots of minor issues in the new Slack integrations * Fixed support for allowInlineLineBreaks in LineFormatter when formatting exception backtraces -------------------------------------------------------------------------------- References: [ 1 ] Bug #1432274 - php-Monolog-1.23.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1432274 -------------------------------------------------------------------------------- ================================================================================ php-consolidation-output-formatters-3.1.10-1.fc25 (FEDORA-2017-98169904d7) Format text by applying transformations provided by plug-in formatters -------------------------------------------------------------------------------- Update Information: ### 3.1.10 - 6 June 2017 - Typo in CalculateWidths::distributeLongColumns causes failure for some column width distributions ### 3.1.9 - 8 May 2017 - Improve wrapping algorithm -------------------------------------------------------------------------------- References: [ 1 ] Bug #1449852 - php-consolidation-output-formatters-3.1.10 is available https://bugzilla.redhat.com/show_bug.cgi?id=1449852 -------------------------------------------------------------------------------- ================================================================================ php-phpmyadmin-sql-parser-4.1.8-1.fc25 (FEDORA-2017-29a15a64c7) A validating SQL lexer and parser with a focus on MySQL dialect -------------------------------------------------------------------------------- Update Information: **Version 4.1.8** - 2017-07-09 * Fixed parsing SQL comment at the end of query. * Improved handing of non utf-8 strings. * Added query flag for SET queries. -------------------------------------------------------------------------------- ================================================================================ php-symfony-polyfill-1.4.0-1.fc25 (FEDORA-2017-5a671cc9cc) Symfony polyfills backporting features to lower PHP versions -------------------------------------------------------------------------------- Update Information: ## v1.4.0 * Added PHP 7.2 polyfill -------------------------------------------------------------------------------- References: [ 1 ] Bug #1460473 - php-symfony-polyfill-1.4.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1460473 -------------------------------------------------------------------------------- ================================================================================ php-twig-extensions-1.5.1-1.fc25 (FEDORA-2017-ddc19d6382) Twig extensions -------------------------------------------------------------------------------- Update Information: Changes since 1.4.1: https://github.com/twigphp/Twig- extensions/compare/v1.4.1...v1.5.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1456812 - php-twig-extensions-1.5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1456812 -------------------------------------------------------------------------------- ================================================================================ poppler-0.45.0-4.fc25 (FEDORA-2017-d7a871850c) PDF rendering library -------------------------------------------------------------------------------- Update Information: * CVE-2017-9406 CVE-2017-9408 various memory leak flaws -------------------------------------------------------------------------------- References: [ 1 ] Bug #1458703 - CVE-2017-9406 CVE-2017-9408 poppler: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1458703 -------------------------------------------------------------------------------- ================================================================================ putty-0.70-1.fc25 (FEDORA-2017-efdd962fee) SSH, Telnet and Rlogin client -------------------------------------------------------------------------------- Update Information: This is an update fixing CVE-2017-6542. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1431716 - CVE-2017-6542 putty: Integer overflow in the ssh_agent_channel_data https://bugzilla.redhat.com/show_bug.cgi?id=1431716 -------------------------------------------------------------------------------- ================================================================================ python-avocado-52.0-1.fc25 (FEDORA-2017-74f0ae8cef) Framework with tools and libraries for Automated Testing -------------------------------------------------------------------------------- Update Information: Sync python-avocado with latest upstream release. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1465409 - python-avocado-52.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1465409 -------------------------------------------------------------------------------- ================================================================================ python-basemap-data-1.0.7-6.fc25 (FEDORA-2017-a68a608525) Data for python-basemap -------------------------------------------------------------------------------- Update Information: Merge data into one RPM. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1203048 - Basemap data file split does not make sense https://bugzilla.redhat.com/show_bug.cgi?id=1203048 -------------------------------------------------------------------------------- ================================================================================ python-docker-py-1.10.6-2.fc25 (FEDORA-2017-9dd49fe665) An API client for docker written in Python -------------------------------------------------------------------------------- Update Information: add python2 provide, based on comment: https://bugzilla.redhat.com/show_bug.cgi?id=1443577#c11 -------------------------------------------------------------------------------- ================================================================================ python-hypothesis-3.12.0-1.fc25 (FEDORA-2017-cde90848d9) A library for property based testing -------------------------------------------------------------------------------- Update Information: Latest upstream version. Manpage and Python 3 version now built for EPEL7 as well. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1434387 - python-hypothesis-3.12.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1434387 -------------------------------------------------------------------------------- ================================================================================ python-pathspec-0.5.3-1.fc25 (FEDORA-2017-7874c99ead) Utility library for gitignore style pattern matching of file paths -------------------------------------------------------------------------------- Update Information: Initial import (#1465954) -------------------------------------------------------------------------------- ================================================================================ python-plaster-pastedeploy-0.3.2-2.fc25 (FEDORA-2017-6bdf44ab05) A PasteDeploy binding to the plaster configuration loader -------------------------------------------------------------------------------- Update Information: Depend on python2-paste-deploy instead of python-paste-deploy. ---- Initial release. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1467418 - Review Request: python-plaster-pastedeploy - A PasteDeploy binding to the plaster configuration loader https://bugzilla.redhat.com/show_bug.cgi?id=1467418 -------------------------------------------------------------------------------- ================================================================================ python-sphinx-autobuild-0.7.1-1.fc25 (FEDORA-2017-6dcbb5681a) Watch a Sphinx directory and rebuild the documentation -------------------------------------------------------------------------------- Update Information: Updated to version 0.7.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1467889 - python-sphinx-autobuild-0.7.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1467889 -------------------------------------------------------------------------------- ================================================================================ qcad-3.17.3.1-1.fc25 (FEDORA-2017-a66e0e253f) Powerful 2D CAD system -------------------------------------------------------------------------------- Update Information: - Update to 3.17.3.1 -------------------------------------------------------------------------------- ================================================================================ qotd-0.11.3-1.fc25 (FEDORA-2017-fa23e4d91b) A simple and lightweight Quote of the Day daemon -------------------------------------------------------------------------------- Update Information: A simple and lightweight Quote of the Day daemon -------------------------------------------------------------------------------- References: [ 1 ] Bug #1462472 - Review Request: qotd - A simple and lightweight Quote of the Day daemon https://bugzilla.redhat.com/show_bug.cgi?id=1462472 -------------------------------------------------------------------------------- ================================================================================ qt5-qtwebengine-5.9.1-1.fc25 (FEDORA-2017-a7a488d8d0) Qt5 - QtWebEngine components -------------------------------------------------------------------------------- Update Information: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078, CVE-2017-5079, CVE-2017-5083, CVE-2017-5088, and CVE-2017-5089 (security fixes from Chromium up to version 59.0.3071.104). Other notable bugfixes include: * [QTBUG-59690] Fixed issue with drops * [QTBUG-60588] Fixed error in updating user-agent and accept-language * [QTBUG-61047] Fixed assert in URLRequestContextGetterQt * [QTBUG-61186] Fixed cancellation of upload folder dialogs * [QTBUG-57675] Fixed WebEngineNewViewRequest::requestedUrl when opening window from JavaScript -------------------------------------------------------------------------------- ================================================================================ qt5-qtwebkit-5.212.0-0.5.alpha2.fc25 (FEDORA-2017-c844713925) Qt5 - QtWebKit components -------------------------------------------------------------------------------- Update Information: Qt5WebKit update to the new, maintained "annulen branch". Drop-in replacement for the old unmaintained QtWebKit. ---- Update to annulen-branch of qt5-qtwebkit, which contains a lot of security fixes. Drop-in replacement for the old unmaintained qt5-qtwebkit -------------------------------------------------------------------------------- ================================================================================ rkward-0.6.5-7.fc25 (FEDORA-2017-4acde45111) Graphical frontend for R language -------------------------------------------------------------------------------- Update Information: Update to R 3.4.1. This contains several significant bugfixes introduced in 3.4.0, so updating is strongly recommended. Full release notes are here: https://cran.r-project.org/doc/manuals/r-release/NEWS.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1456452 - rpy-2.8.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1456452 -------------------------------------------------------------------------------- ================================================================================ root-6.10.02-2.fc25 (FEDORA-2017-0bad35fdb1) Numerical data analysis framework -------------------------------------------------------------------------------- Update Information: root 6.10.02 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1469093 - CMake config broken due to scoped targets https://bugzilla.redhat.com/show_bug.cgi?id=1469093 -------------------------------------------------------------------------------- ================================================================================ rpkg-1.49-6.fc25 (FEDORA-2017-cc3aa68a6f) Python library for interacting with rpm+git -------------------------------------------------------------------------------- Update Information: Use python2-koji instead of koji -------------------------------------------------------------------------------- References: [ 1 ] Bug #1468836 - ImportError: No module named koji https://bugzilla.redhat.com/show_bug.cgi?id=1468836 -------------------------------------------------------------------------------- ================================================================================ rpy-2.8.6-1.fc25 (FEDORA-2017-4acde45111) Python interface to the R language -------------------------------------------------------------------------------- Update Information: Update to R 3.4.1. This contains several significant bugfixes introduced in 3.4.0, so updating is strongly recommended. Full release notes are here: https://cran.r-project.org/doc/manuals/r-release/NEWS.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1456452 - rpy-2.8.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1456452 -------------------------------------------------------------------------------- ================================================================================ rubygem-diffy-3.2.0-1.1.fc25 (FEDORA-2017-d7ee29e6ad) A convenient way to diff string in ruby -------------------------------------------------------------------------------- Update Information: new update -------------------------------------------------------------------------------- ================================================================================ rust-srpm-macros-4-2.fc25 (FEDORA-2017-925eed2733) RPM macros for building Rust source packages -------------------------------------------------------------------------------- Update Information: Rust-packaging related packages -------------------------------------------------------------------------------- ================================================================================ screen-4.6.1-1.fc25 (FEDORA-2017-041c266c46) A screen manager that supports multiple logins on one terminal -------------------------------------------------------------------------------- Update Information: Rebase to the latest upstream version 4.6.0 Changes: * Update Unicode wide tables to 9.0 * Support more serial speeds * Improved namespaces support * Migrate from fifos to sockets * Start viewing scrollback at first line of output * problems with starting session in some cases * parallel make install * segfault when querying info on nonUTF locale -------------------------------------------------------------------------------- References: [ 1 ] Bug #1466080 - screen-4.6.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1466080 [ 2 ] Bug #1469323 - screen-4.6.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1469323 -------------------------------------------------------------------------------- ================================================================================ tracer-0.6.13-1.fc25 (FEDORA-2017-0e8d47812d) Finds outdated running applications in your system -------------------------------------------------------------------------------- Update Information: Features: - report reboot for new kernels (#83) - Get daemon names from dbus (#82) - bash completion support - Use ID_LIKE in /etc/os-release (#81) Bugfixes: - Fixes #85 - Always respect app type defines - Fixes #84 - ignore flag is now respected - Fixes #20 - print executable in interactive mode - Fixes #56 - Add Ubunut support - Fixes #76 - polkitd service can be restarted - Fixes #73 - add support for Oracle Linux - Fixes #66 - reconise postfix process correctly - Fixes #68 - recognised SSH sessions correctly -------------------------------------------------------------------------------- References: [ 1 ] Bug #1469282 - tracer-common should require python3-argcomplete https://bugzilla.redhat.com/show_bug.cgi?id=1469282 -------------------------------------------------------------------------------- ================================================================================ vim-8.0.705-1.fc25 (FEDORA-2017-9075f30365) The VIM editor -------------------------------------------------------------------------------- Update Information: The newest upstream commit. -------------------------------------------------------------------------------- ================================================================================ xen-4.7.3-1.fc25 (FEDORA-2017-ddd2aa1a04) Xen is a virtual machine monitor -------------------------------------------------------------------------------- Update Information: update to xen-4.7.3 -------------------------------------------------------------------------------- ================================================================================ xiphos-4.0.5-2.fc25 (FEDORA-2017-70aed6762a) Bible study and research tool -------------------------------------------------------------------------------- Update Information: Fix post install scripts for upgrades -------------------------------------------------------------------------------- References: [ 1 ] Bug #1448623 - GUI broken & Error with RPM Script https://bugzilla.redhat.com/show_bug.cgi?id=1448623 -------------------------------------------------------------------------------- ================================================================================ xoreos-tools-0.0.4-2.fc25 (FEDORA-2017-ce142c9640) Tools to help the development of xoreos -------------------------------------------------------------------------------- Update Information: Tools to aid in the development of xoreos -------------------------------------------------------------------------------- References: [ 1 ] Bug #1465588 - Review Request: xoreos-tools - Tools to help the development of xoreos https://bugzilla.redhat.com/show_bug.cgi?id=1465588 -------------------------------------------------------------------------------- ================================================================================ yash-2.45-1.fc25 (FEDORA-2017-4f36a90573) Yet Another SHell -------------------------------------------------------------------------------- Update Information: New version 2.45 is released -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx