Fedora 26 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



The following Fedora 26 Security updates need testing:
 Age  URL
  97  https://bodhi.fedoraproject.org/updates/FEDORA-2017-1bf5a0ce01   python-XStatic-jquery-ui-1.12.0.1-2.fc26
  36  https://bodhi.fedoraproject.org/updates/FEDORA-2017-2522df3526   nodejs-brace-expansion-1.1.7-1.fc26
   9  https://bodhi.fedoraproject.org/updates/FEDORA-2017-313712a583   jabberd-2.6.1-1.fc26
   7  https://bodhi.fedoraproject.org/updates/FEDORA-2017-3fb16e3a65   openvas-cli-1.4.5-3.fc26 openvas-gsa-7.0.2-2.fc26 openvas-manager-7.0.2-1.fc26 openvas-scanner-5.1.1-1.fc26 openvas-libraries-9.0.1-1.fc26
   7  https://bodhi.fedoraproject.org/updates/FEDORA-2017-b8bb4b86e2   php-7.1.7-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-d3d38a53f9   knot-2.4.5-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-114e1abf9d   irssi-1.0.4-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-bbe2ee70cd   qt5-qtwebkit-5.212.0-0.5.alpha2.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-661dddc462   groovy18-1.8.9-28.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-e6aaef4475   knot-resolver-1.3.1-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-357f9df699   spatialite-tools-4.3.0-23.fc26 sqlite-3.19.3-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-5112220e59   poppler-0.52.0-4.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-2afe501b36   heimdal-7.4.0-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-015bb3ff87   qemu-2.9.0-2.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-0f75ee2f38   evince-3.24.0-3.fc26


The following Fedora 26 Critical Path updates have yet to be approved:
 Age URL
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2017-73370082fb   garcon-0.6.1-1.fc26
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2017-706c04d233   pcre-8.41-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-357f9df699   spatialite-tools-4.3.0-23.fc26 sqlite-3.19.3-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-ccf0088652   koji-1.13.0-2.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-c2721b7375   selinux-policy-3.13.1-260.1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-bea66311ff   xorg-x11-utils-7.5-23.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-244f799ac9   nss-3.31.0-1.0.fc26 nss-util-3.31.0-1.0.fc26 nss-softokn-3.31.0-1.0.fc26 nspr-4.15.0-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-30f24d8999   vim-8.0.705-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-16b93b066d   brltty-5.5-5.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-654872eda8   lorax-26.9-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2017-45b006e169   efivar-31-1.fc26 efibootmgr-15-1.fc26 dbxtool-7-4.fc26 fwupdate-8-4.fc26 mokutil-0.3.0-5.fc26 pesign-0.112-7.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-c2fa277b08   git-2.13.3-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-f6b14e0e63   supermin-5.1.18-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-1f4b3ceec1   ibus-1.5.16-3.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-aa537fe626   libproxy-0.4.15-2.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-015bb3ff87   qemu-2.9.0-2.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-ad7e5c5657   libvirt-3.2.1-4.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-52ff2e4860   mutter-3.24.3-2.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2017-5112220e59   poppler-0.52.0-4.fc26


The following builds have been pushed to Fedora 26 updates-testing

    cook-2.34-14.fc26
    dbus-sharp-0.15-2.hg2030296.fc26
    distribution-gpg-keys-1.12-1.fc26
    evince-3.24.0-3.fc26
    ghdl-0.34dev-0.20170712git5783528.0.fc26
    git-2.13.3-1.fc26
    git-review-1.25.0-7.fc26
    gnome-abrt-1.2.5-4.fc26
    gnome-shell-extension-media-player-indicator-0-0.13.20170712gitba389fa.fc26
    heimdal-7.4.0-1.fc26
    hotspot-1.0.0-1.fc26
    ibus-1.5.16-3.fc26
    libproxy-0.4.15-2.fc26
    libtaskotron-0.4.23-1.fc26
    libva-1.8.3-1.fc26
    libva-utils-1.8.3-1.fc26
    libvirt-3.2.1-4.fc26
    microcode_ctl-2.1-16.fc26
    mingw-spice-protocol-0.12.13-1.fc26
    mono-zeroconf-0.9.0-19.fc26
    mutter-3.24.3-2.fc26
    nagios-plugins-2.2.1-3git.fc26
    oci-systemd-hook-0.1.8-1.gitd899a8e.fc26
    perl-PAR-Packer-1.036-4.fc26
    php-aws-php-sns-message-validator-1.2.0-1.fc26
    php-phpmyadmin-sql-parser-4.1.9-1.fc26
    poppler-0.52.0-4.fc26
    python-webob-1.7.3-2.fc26
    qemu-2.9.0-2.fc26
    snapd-glib-1.15-1.fc26
    supermin-5.1.18-1.fc26
    uid_wrapper-1.2.2-1.fc26
    wine-2.12-1.fc26

Details about builds:


================================================================================
 cook-2.34-14.fc26 (FEDORA-2017-c15df79a8a)
 File construction tool
--------------------------------------------------------------------------------
Update Information:

This release fixes building documentation.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1307402 - cook: FTBFS in rawhide
        https://bugzilla.redhat.com/show_bug.cgi?id=1307402
--------------------------------------------------------------------------------


================================================================================
 dbus-sharp-0.15-2.hg2030296.fc26 (FEDORA-2017-cc40ade2bd)
 C# bindings for D-Bus
--------------------------------------------------------------------------------
Update Information:

Update dbus-sharp to code which works more reliably and is maintained. Fix mono-
zeroconf bugs (and make it stop using the old broken bundled copy of dbus-
sharp).  These two fixes combined fix banshee.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1469481 - Banshee 2.6.2 crashes on start, not working at all
        https://bugzilla.redhat.com/show_bug.cgi?id=1469481
  [ 2 ] Bug #1408969 - Dbus-sharp needs an update or at least a couple of patches from 0.8.0 included
        https://bugzilla.redhat.com/show_bug.cgi?id=1408969
--------------------------------------------------------------------------------


================================================================================
 distribution-gpg-keys-1.12-1.fc26 (FEDORA-2017-90e4dd5260)
 GPG keys of various Linux distributions
--------------------------------------------------------------------------------
Update Information:

Updated Copr gpg keys.
--------------------------------------------------------------------------------


================================================================================
 evince-3.24.0-3.fc26 (FEDORA-2017-0f75ee2f38)
 Document viewer
--------------------------------------------------------------------------------
Update Information:

- CVE-2017-1000083: Evince command injection vulnerability in CBT handler
(#1468488)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1468488 - CVE-2017-1000083 evince: command injection via filename in tar-compressed comics archive
        https://bugzilla.redhat.com/show_bug.cgi?id=1468488
--------------------------------------------------------------------------------


================================================================================
 ghdl-0.34dev-0.20170712git5783528.0.fc26 (FEDORA-2017-ccc6f98007)
 A VHDL simulator, using the GCC technology
--------------------------------------------------------------------------------
Update Information:

- update to newer git
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1438559 - pyanaconda.payload.PayloadError: Payload error - DNF installation has ended up abruptly: Transaction check error:
        https://bugzilla.redhat.com/show_bug.cgi?id=1438559
  [ 2 ] Bug #1426470 - dnf upgrade produces error messages
        https://bugzilla.redhat.com/show_bug.cgi?id=1426470
--------------------------------------------------------------------------------


================================================================================
 git-2.13.3-1.fc26 (FEDORA-2017-c2fa277b08)
 Fast Version Control System
--------------------------------------------------------------------------------
Update Information:

https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.13.3.t
xt
--------------------------------------------------------------------------------


================================================================================
 git-review-1.25.0-7.fc26 (FEDORA-2017-79b45ffe57)
 A Git helper for integration with Gerrit
--------------------------------------------------------------------------------
Update Information:

Fix crash with no_git_dir under Python 3.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1469831 - [abrt] git-review: cmd.py:1398:_main:UnboundLocalError: local variable 'no_git_dir' referenced before assignment
        https://bugzilla.redhat.com/show_bug.cgi?id=1469831
--------------------------------------------------------------------------------


================================================================================
 gnome-abrt-1.2.5-4.fc26 (FEDORA-2017-3c8fd8b4aa)
 A utility for viewing problems that have occurred with the system
--------------------------------------------------------------------------------
Update Information:

* New translations: Friulian, Kazakh, Norwegian Nynorsk. * Translation updates:
Dutch, Finnish, Marathi.
--------------------------------------------------------------------------------


================================================================================
 gnome-shell-extension-media-player-indicator-0-0.13.20170712gitba389fa.fc26 (FEDORA-2017-3bdba210d8)
 Control MPRIS2 capable media players: Rhythmbox, Banshee, Clementine and more
--------------------------------------------------------------------------------
Update Information:

Update to 0-0.13.20170712gitba389fa
--------------------------------------------------------------------------------


================================================================================
 heimdal-7.4.0-1.fc26 (FEDORA-2017-2afe501b36)
 A Kerberos 5 implementation without export restrictions
--------------------------------------------------------------------------------
Update Information:

Update to 7.4.0 GA release (CVE-2017-11103)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1469998 - CVE-2017-11103 heimdal: krb5: Metadata taken from the unauthenticated plaintext [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1469998
--------------------------------------------------------------------------------


================================================================================
 hotspot-1.0.0-1.fc26 (FEDORA-2017-ef275a5084)
 The Linux perf GUI for performance analysis
--------------------------------------------------------------------------------
Update Information:

A standalone GUI for performance data. Attempting to provide a UI like
KCachegrind around Linux perf.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1469396 - Review Request: hotspot - The Linux perf GUI for performance analysis
        https://bugzilla.redhat.com/show_bug.cgi?id=1469396
--------------------------------------------------------------------------------


================================================================================
 ibus-1.5.16-3.fc26 (FEDORA-2017-1f4b3ceec1)
 Intelligent Input Bus for Linux OS
--------------------------------------------------------------------------------
Update Information:

This version uses HarfBuzz directly without Pango cell calculations to render
emoji variants.
--------------------------------------------------------------------------------


================================================================================
 libproxy-0.4.15-2.fc26 (FEDORA-2017-aa537fe626)
 A library handling all the details of proxy configuration
--------------------------------------------------------------------------------
Update Information:

Fix crash when using PAC files
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1459779 - [abrt] glib-networking: JS_AbortIfWrongThread(): glib-pacrunner killed by signal 11
        https://bugzilla.redhat.com/show_bug.cgi?id=1459779
--------------------------------------------------------------------------------


================================================================================
 libtaskotron-0.4.23-1.fc26 (FEDORA-2017-0e2dc8ea61)
 Taskotron Support Library
--------------------------------------------------------------------------------
Update Information:

- documentation improvements - DNF_REPO item type removed - default task
artifact now points to artifacts root dir instead of task log - fix rpm deps
handling via dnf on Fedora 26 (but only support package names   and filepaths as
deps in task formulas)
--------------------------------------------------------------------------------


================================================================================
 libva-1.8.3-1.fc26 (FEDORA-2017-c204245777)
 Video Acceleration (VA) API for Linux
--------------------------------------------------------------------------------
Update Information:

libva: -Set verbosity level between {0, 1, 2} by setting the variable
LIBVA_MESSAGING_LEVEL  in /etc/libva.conf or by setting the environment variable
LIBVA_MESSAGING_LEVEL.  libva-utils: - putsurface: include wayland-client.h
instead of wayland-server.h  - avcenc: add AUD NAL unit at the beginning of pic
- avcenc: enable direct_spatial_mv_pred_flag for B frame - avcenc: add the frame
number as the command line input parameter
--------------------------------------------------------------------------------


================================================================================
 libva-utils-1.8.3-1.fc26 (FEDORA-2017-c204245777)
 Tools for VAAPI (including vainfo)
--------------------------------------------------------------------------------
Update Information:

libva: -Set verbosity level between {0, 1, 2} by setting the variable
LIBVA_MESSAGING_LEVEL  in /etc/libva.conf or by setting the environment variable
LIBVA_MESSAGING_LEVEL.  libva-utils: - putsurface: include wayland-client.h
instead of wayland-server.h  - avcenc: add AUD NAL unit at the beginning of pic
- avcenc: enable direct_spatial_mv_pred_flag for B frame - avcenc: add the frame
number as the command line input parameter
--------------------------------------------------------------------------------


================================================================================
 libvirt-3.2.1-4.fc26 (FEDORA-2017-ad7e5c5657)
 Library providing a simple virtualization API
--------------------------------------------------------------------------------
Update Information:

* Fix resuming qemu VMs suspended before libvirt 3.2.0 * Fix issues with AMD CPU
models, and some others
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1468043 - Backport "Use more data for comparing CPUs" commit series to work correctly with qemu 2.9.0+
        https://bugzilla.redhat.com/show_bug.cgi?id=1468043
--------------------------------------------------------------------------------


================================================================================
 microcode_ctl-2.1-16.fc26 (FEDORA-2017-f26055c5ce)
 Tool to transform and deploy CPU microcode update for x86
--------------------------------------------------------------------------------
Update Information:

Update to upstream 2.1-13. 20170707
--------------------------------------------------------------------------------


================================================================================
 mingw-spice-protocol-0.12.13-1.fc26 (FEDORA-2017-512b86a8eb)
 Spice protocol header files
--------------------------------------------------------------------------------
Update Information:

new version
--------------------------------------------------------------------------------


================================================================================
 mono-zeroconf-0.9.0-19.fc26 (FEDORA-2017-cc40ade2bd)
 Mono.Zeroconf networking library
--------------------------------------------------------------------------------
Update Information:

Update dbus-sharp to code which works more reliably and is maintained. Fix mono-
zeroconf bugs (and make it stop using the old broken bundled copy of dbus-
sharp).  These two fixes combined fix banshee.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1469481 - Banshee 2.6.2 crashes on start, not working at all
        https://bugzilla.redhat.com/show_bug.cgi?id=1469481
  [ 2 ] Bug #1408969 - Dbus-sharp needs an update or at least a couple of patches from 0.8.0 included
        https://bugzilla.redhat.com/show_bug.cgi?id=1408969
--------------------------------------------------------------------------------


================================================================================
 mutter-3.24.3-2.fc26 (FEDORA-2017-52ff2e4860)
 Window and compositing manager based on Clutter
--------------------------------------------------------------------------------
Update Information:

Don't crash when moving between non-adjacent monitors
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1465122 - [abrt] gnome-shell: update_move(): gnome-shell killed by signal 11
        https://bugzilla.redhat.com/show_bug.cgi?id=1465122
--------------------------------------------------------------------------------


================================================================================
 nagios-plugins-2.2.1-3git.fc26 (FEDORA-2017-a5f81422dc)
 Host/service/network monitoring program plugins for Nagios
--------------------------------------------------------------------------------
Update Information:

Updated patches to fix check_http problems  ----  Update to git for 20170703
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1052740 - SELinux is preventing check_log via NRPE from read and open var_log_t files
        https://bugzilla.redhat.com/show_bug.cgi?id=1052740
  [ 2 ] Bug #1204683 - check_ide_smart cannot be started by nrpe
        https://bugzilla.redhat.com/show_bug.cgi?id=1204683
  [ 3 ] Bug #1210380 - SELinux prevents check_mailq from executing postfix when run via NRPE
        https://bugzilla.redhat.com/show_bug.cgi?id=1210380
  [ 4 ] Bug #1256848 - nagios-plugins-log has incorrect paths to egrep/tail (EL6)
        https://bugzilla.redhat.com/show_bug.cgi?id=1256848
  [ 5 ] Bug #1423008 - nagios-plugins-2.2.1 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1423008
  [ 6 ] Bug #1427925 - check_http 2.2.0-4 fails if Transfer-Encoding ends the header
        https://bugzilla.redhat.com/show_bug.cgi?id=1427925
  [ 7 ] Bug #1463674 - check_http segfaults once Location header terminates with additional 0x0a and is last header line
        https://bugzilla.redhat.com/show_bug.cgi?id=1463674
  [ 8 ] Bug #1465784 - nagios http plugin is old and buggy
        https://bugzilla.redhat.com/show_bug.cgi?id=1465784
--------------------------------------------------------------------------------


================================================================================
 oci-systemd-hook-0.1.8-1.gitd899a8e.fc26 (FEDORA-2017-c653be291e)
 OCI systemd hook for docker
--------------------------------------------------------------------------------
Update Information:

Allow users to selectively disable oci-systemd-hook
--------------------------------------------------------------------------------
ChangeLog:

--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1404450 - unable to disable oci-systemd-hook on Atomic Host
        https://bugzilla.redhat.com/show_bug.cgi?id=1404450
--------------------------------------------------------------------------------


================================================================================
 perl-PAR-Packer-1.036-4.fc26 (FEDORA-2017-bf212e0247)
 PAR Packager
--------------------------------------------------------------------------------
Update Information:

This release adds a dependency on the same Perl version perl-PAR-Packer was
built against this how PAR::Packer is implemented.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1470542 - PAR::Packer requires the same perl version it was built against
        https://bugzilla.redhat.com/show_bug.cgi?id=1470542
--------------------------------------------------------------------------------


================================================================================
 php-aws-php-sns-message-validator-1.2.0-1.fc26 (FEDORA-2017-a59dc4e85e)
 Amazon SNS message validation
--------------------------------------------------------------------------------
Update Information:

## 1.2.0  * Adds support for creating an instance of `Aws\Sns\Message` from a
PSR-7 Request or ServerRequest.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1470413 - php-aws-php-sns-message-validator-1.2.0 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1470413
--------------------------------------------------------------------------------


================================================================================
 php-phpmyadmin-sql-parser-4.1.9-1.fc26 (FEDORA-2017-59e6aeae0b)
 A validating SQL lexer and parser with a focus on MySQL dialect
--------------------------------------------------------------------------------
Update Information:

**Version 4.1.9** - 2017-07-12  * Various code cleanups. * Improved error
handling of several invalid statements.   ----  **Version 4.1.8** - 2017-07-09
* Fixed parsing SQL comment at the end of query. * Improved handing of non utf-8
strings. * Added query flag for SET queries.
--------------------------------------------------------------------------------


================================================================================
 poppler-0.52.0-4.fc26 (FEDORA-2017-5112220e59)
 PDF rendering library
--------------------------------------------------------------------------------
Update Information:

* various flaws: CVE-2017-7515 CVE-2017-9775 CVE-2017-9776 CVE-2017-9865  ----
* CVE-2017-9406 CVE-2017-9408 various memory leak flaws
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1459067 - CVE-2017-7515 CVE-2017-9775 CVE-2017-9776 CVE-2017-9865 poppler: various flaws [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1459067
  [ 2 ] Bug #1458703 - CVE-2017-9406 CVE-2017-9408 poppler: various flaws [fedora-all]
        https://bugzilla.redhat.com/show_bug.cgi?id=1458703
--------------------------------------------------------------------------------


================================================================================
 python-webob-1.7.3-2.fc26 (FEDORA-2017-7ecdab7184)
 WSGI request and response object
--------------------------------------------------------------------------------
Update Information:

* Update to [1.7.3](https://pypi.python.org/pypi/WebOb/1.7.3). * Provide
python2-webob. * Depend on python2- versions of nose and setuptools. * Mark the
license with the license macro.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1466976 - python-webob-1.7.3 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1466976
--------------------------------------------------------------------------------


================================================================================
 qemu-2.9.0-2.fc26 (FEDORA-2017-015bb3ff87)
 QEMU is a FAST! processor emulator
--------------------------------------------------------------------------------
Update Information:

* CVE-2017-8112: vmw_pvscsi: infinite loop in pvscsi_log2 (bz #1445622) *
CVE-2017-8309: audio: host memory lekage via capture buffer (bz #1446520) *
CVE-2017-8379: input: host memory lekage via keyboard events (bz #1446560) *
CVE-2017-8380: scsi: megasas: out-of-bounds read in megasas_mmio_write (bz
#1446578) * CVE-2017-7493: 9pfs: guest privilege escalation in virtfs mapped-
file mode (bz #1451711) * CVE-2017-9503: megasas: null pointer dereference while
processing megasas command (bz #1459478) * CVE-2017-10806: usb-redirect: stack
buffer overflow in debug logging (bz #1468497) * CVE-2017-9524: nbd: segfault
due to client non-negotiation (bz #1460172) * CVE-2017-10664: qemu-nbd: server
breaks with SIGPIPE upon client abort (bz #1466192)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1445621 - CVE-2017-8112 Qemu: scsi: vmw_pvscsi: infinite loop in pvscsi_log2
        https://bugzilla.redhat.com/show_bug.cgi?id=1445621
  [ 2 ] Bug #1446517 - CVE-2017-8309 Qemu: audio: host memory leakage via capture buffer
        https://bugzilla.redhat.com/show_bug.cgi?id=1446517
  [ 3 ] Bug #1446547 - CVE-2017-8379 Qemu: input: host memory lekage via keyboard events
        https://bugzilla.redhat.com/show_bug.cgi?id=1446547
  [ 4 ] Bug #1446577 - CVE-2017-8380 Qemu: scsi: megasas: out-of-bounds read in megasas_mmio_write
        https://bugzilla.redhat.com/show_bug.cgi?id=1446577
  [ 5 ] Bug #1451709 - CVE-2017-7493 Qemu: 9pfs: guest privilege escalation in virtfs mapped-file mode
        https://bugzilla.redhat.com/show_bug.cgi?id=1451709
  [ 6 ] Bug #1459477 - CVE-2017-9503 Qemu: scsi: megasas: null pointer dereference while processing megasas command
        https://bugzilla.redhat.com/show_bug.cgi?id=1459477
  [ 7 ] Bug #1468496 - CVE-2017-10806 Qemu: usb-redirect: stack buffer overflow in debug logging
        https://bugzilla.redhat.com/show_bug.cgi?id=1468496
  [ 8 ] Bug #1460170 - CVE-2017-9524 Qemu: nbd: segmentation fault due to client non-negotiation
        https://bugzilla.redhat.com/show_bug.cgi?id=1460170
  [ 9 ] Bug #1466190 - CVE-2017-10664 Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort
        https://bugzilla.redhat.com/show_bug.cgi?id=1466190
--------------------------------------------------------------------------------


================================================================================
 snapd-glib-1.15-1.fc26 (FEDORA-2017-8ba37dcc1c)
 Library providing a GLib interface to snapd
--------------------------------------------------------------------------------
Update Information:

Update to snapd-glib v1.15.  Overview of changes since v1.13:   From v1.15:  *
Marked `snapd_system_information_get_confinement` as stable * Correctly stop
requests if cancelled  From v1.14:  * New API:     -
`snapd_app_get_desktop_file`     - `snapd_snap_get_title`     -
`snapd_system_information_get_confinement` (unstable) * Don't timeout waiting
for snapd * Add version defines so can do conditional compilation on new
features  * Fix compilation with PolKit >= 0.114  * Fix snapd-qt compilation in
clang  * Fix snapd-qt compilation on systems that use different versions of MOC
* snapd-qt improvements to better match best practice  * Include enum headers in
`snapd-glib.h`  * Fix compile warnings using clang  * Documentation improvements
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1468236 - snapd-glib-1.15 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1468236
--------------------------------------------------------------------------------


================================================================================
 supermin-5.1.18-1.fc26 (FEDORA-2017-f6b14e0e63)
 Tool for creating supermin appliances
--------------------------------------------------------------------------------
Update Information:

New upstream release 5.1.18.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1470157 - symbolic links are broken
        https://bugzilla.redhat.com/show_bug.cgi?id=1470157
--------------------------------------------------------------------------------


================================================================================
 uid_wrapper-1.2.2-1.fc26 (FEDORA-2017-c3b36bdb3f)
 A wrapper for privilege separation
--------------------------------------------------------------------------------
Update Information:

Update to version 1.2.2
--------------------------------------------------------------------------------


================================================================================
 wine-2.12-1.fc26 (FEDORA-2017-9f85c0d2d8)
 A compatibility layer for windows applications
--------------------------------------------------------------------------------
Update Information:

Wine  - Audio driver for Android.   - Some performance improvements with async
I/O.   - More RegEdit file parser improvements.   - Beginnings for MSI user
interface support.   - Various bug fixes.  Wine-staging   - Support for depth
bias / depth clamping in D3D11. - Support for copying between resources with
compatible DXGI formats. - Use OpenGL core context when necessary. - Various
smaller bug fixes and improvements.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1468794 - wine-2.12 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1468794
--------------------------------------------------------------------------------
_______________________________________________
test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx




[Index of Archives]     [Fedora Desktop]     [Fedora SELinux]     [Photo Sharing]     [Yosemite Forum]     [KDE Users]

  Powered by Linux