The following Fedora 25 Security updates need testing: Age URL 239 https://bodhi.fedoraproject.org/updates/FEDORA-2016-d79ba708cb exim-4.87.1-1.fc25 137 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e2d17af41e python-XStatic-jquery-ui-1.12.0.1-4.fc25 77 https://bodhi.fedoraproject.org/updates/FEDORA-2017-5d7498559f nodejs-brace-expansion-1.1.7-1.fc25 36 https://bodhi.fedoraproject.org/updates/FEDORA-2017-86cfcbbae8 libstaroffice-0.0.4-1.fc25 31 https://bodhi.fedoraproject.org/updates/FEDORA-2017-99c0118c0c memcached-1.4.39-1.fc25 27 https://bodhi.fedoraproject.org/updates/FEDORA-2017-2232fe97b4 docker-distribution-2.6.2-1.git48294d9.fc25 21 https://bodhi.fedoraproject.org/updates/FEDORA-2017-be3df4fe14 java-1.8.0-openjdk-aarch32-1.8.0.141-1.170721.fc25 11 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9148fe36b9 postgresql-9.5.8-1.fc25 9 https://bodhi.fedoraproject.org/updates/FEDORA-2017-7e5ac0896e botan-1.10.16-1.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-fa1d8ad61a mercurial-3.8.1-4.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-97eb475d93 cvs-1.11.23-41.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a52a46ba78 xen-4.7.3-2.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-df343b3e09 chromium-60.0.3112.101-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-270ab2baa3 glibc-2.24-10.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a00a087fd4 tomcat-8.0.46-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-98e8569b33 dnsdist-1.2.0-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-2317191f8a taglib-1.11.1-5.fc25 The following Fedora 25 Critical Path updates have yet to be approved: Age URL 81 https://bodhi.fedoraproject.org/updates/FEDORA-2017-613a72e282 lorax-25.22-1.fc25 34 https://bodhi.fedoraproject.org/updates/FEDORA-2017-6b67562744 ca-certificates-2017.2.16-1.0.fc25 16 https://bodhi.fedoraproject.org/updates/FEDORA-2017-226cbd995b libvirt-2.2.1-3.fc25 9 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ba3e72c511 osinfo-db-20170813-1.fc25 9 https://bodhi.fedoraproject.org/updates/FEDORA-2017-67705933e3 glusterfs-3.10.5-1.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-837f04c39a selinux-policy-3.13.1-225.20.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-97eb475d93 cvs-1.11.23-41.fc25 8 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0c6291cd4b pango-1.40.9-1.fc25 7 https://bodhi.fedoraproject.org/updates/FEDORA-2017-bd0324f3e9 p11-kit-0.23.8-1.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ee474bb41c file-5.29-9.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e9a1ddb533 rpm-4.13.0.1-2.fc25 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a52a46ba78 xen-4.7.3-2.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e22c6d53db mariadb-10.1.26-2.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-ed2a089d21 lz4-1.8.0-1.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-270ab2baa3 glibc-2.24-10.fc25 2 https://bodhi.fedoraproject.org/updates/FEDORA-2017-bb07876a1c nspr-4.16.0-1.fc25 nss-3.32.0-1.1.fc25 nss-softokn-3.32.0-1.2.fc25 nss-util-3.32.0-1.0.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-2317191f8a taglib-1.11.1-5.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a6fc26e60e vim-8.0.983-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0442143306 gdk-pixbuf2-2.36.9-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-08a8ae97e7 gnutls-3.5.15-1.fc25 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-66902d17b7 firefox-55.0.2-1.fc25 The following builds have been pushed to Fedora 25 updates-testing COPASI-4.20.158-4.fc25 cacti-1.1.19-1.fc25 cpuid-20170122-5.fc25 distribution-gpg-keys-1.14-1.fc25 dnsdist-1.2.0-1.fc25 engauge-digitizer-10.2-1.fc25 fakechroot-2.19-4.fc25 fedrepo-req-1.5.0-2.fc25 firefox-55.0.2-1.fc25 gdk-pixbuf2-2.36.9-1.fc25 gnutls-3.5.15-1.fc25 gramps-4.2.6-1.fc25 gsequencer-0.9.14-1.fc25 lightdm-gtk-2.0.2-6.fc25 lldpd-0.9.8-1.fc25 mcelog-153-1.fc25 mingw-gdk-pixbuf-2.36.9-1.fc25 mock-1.4.4-1.fc25 notmuch-0.25-1.fc25 nuvola-app-kexp-1.2-1.fc25 nuvola-app-youtube-1.3-1.fc25 perl-CPAN-Perl-Releases-3.32-1.fc25 perl-Module-CoreList-5.20170821-1.fc25 php-horde-Horde-Core-2.30.1-1.fc25 php-nette-tester-2.0.0-1.fc25 php-phpmyadmin-sql-parser-4.1.10-1.fc25 python-cli-helpers-0.2.3-1.fc25 python-subvertpy-0.10.1-1.fc25 python-websockets-3.4-1.fc25 shairport-sync-3.1.1-1.fc25 skopeo-0.1.23-6.git1bbd87f.fc25 syncthing-inotify-0.8.7-4.fc25 taglib-1.11.1-5.fc25 tomcat-8.0.46-1.fc25 variety-0.6.4-4.fc25 vim-8.0.983-1.fc25 zstd-1.3.1-1.fc25 Details about builds: ================================================================================ COPASI-4.20.158-4.fc25 (FEDORA-2017-c6a3e2ecda) Biochemical network simulator -------------------------------------------------------------------------------- Update Information: - Fix Python interpreter -------------------------------------------------------------------------------- ================================================================================ cacti-1.1.19-1.fc25 (FEDORA-2017-2f1ca6beb7) An rrd based graphing tool -------------------------------------------------------------------------------- Update Information: - Update to 1.1.19 Release notes: https://www.cacti.net/release_notes.php?version=1.1.19 -------------------------------------------------------------------------------- ================================================================================ cpuid-20170122-5.fc25 (FEDORA-2017-7c252f57d1) Dumps information about the CPU(s) -------------------------------------------------------------------------------- Update Information: Add cpuinfo2cpuid -------------------------------------------------------------------------------- ================================================================================ distribution-gpg-keys-1.14-1.fc25 (FEDORA-2017-d9f7a93845) GPG keys of various Linux distributions -------------------------------------------------------------------------------- Update Information: * Add Fedora 28 keys * Add several third parties keys (Adobe, Dell, JPackage, CalcForge, VirtualBox, PostgreSQL, Skype, Google, Dropbox, Remi) * Add new Copr's project keys -------------------------------------------------------------------------------- ================================================================================ dnsdist-1.2.0-1.fc25 (FEDORA-2017-98e8569b33) Highly DNS-, DoS- and abuse-aware loadbalancer -------------------------------------------------------------------------------- Update Information: Update to new upstream release 1.2.0 Security fix for CVE-2016-7069 and CVE-2017-7557 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1483870 - CVE-2016-7069 dnsdist: Crafted backend responses can cause a denial of service https://bugzilla.redhat.com/show_bug.cgi?id=1483870 [ 2 ] Bug #1483867 - CVE-2017-7557 dnsdist: Alteration of ACLs via API authentication bypass https://bugzilla.redhat.com/show_bug.cgi?id=1483867 -------------------------------------------------------------------------------- ================================================================================ engauge-digitizer-10.2-1.fc25 (FEDORA-2017-402d0100a0) Convert graphs or map files into numbers -------------------------------------------------------------------------------- Update Information: - Update to 10.2 -------------------------------------------------------------------------------- ================================================================================ fakechroot-2.19-4.fc25 (FEDORA-2017-dbe18d35a5) Gives a fake chroot environment -------------------------------------------------------------------------------- Update Information: Add support for LFS. -------------------------------------------------------------------------------- ================================================================================ fedrepo-req-1.5.0-2.fc25 (FEDORA-2017-5a10270a78) CLI for Fedora package repo requests -------------------------------------------------------------------------------- Update Information: Changes: * Set the user agent string to "fedrepo-req/version" * Add a way to skip Bugzilla ticket validation in fedrepo-req-admin * Explain when a user can't be found in FAS * Don't use the Bugzilla authentication cache on fedrepo-req * Change requirements from "git" to "git-core" ---- Updates to v1.4.0. The client tool is mostly unchanged except that it has a few usability improvements such as having a man page and telling users to read the README if they haven't configured the client tool. The admin tool has a few enhancements and bug fixes that are listed in git. ---- Bumps to version 1.3.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1482575 - fedrepo-req: change requires from git to git-core https://bugzilla.redhat.com/show_bug.cgi?id=1482575 [ 2 ] Bug #1481036 - Requesting new repo errors with meaningless error message https://bugzilla.redhat.com/show_bug.cgi?id=1481036 -------------------------------------------------------------------------------- ================================================================================ firefox-55.0.2-1.fc25 (FEDORA-2017-66902d17b7) Mozilla Firefox Web browser -------------------------------------------------------------------------------- Update Information: - new upstream release (55.0.2) -------------------------------------------------------------------------------- ================================================================================ gdk-pixbuf2-2.36.9-1.fc25 (FEDORA-2017-0442143306) An image loading library -------------------------------------------------------------------------------- Update Information: gdk-pixbuf2 2.36.9 release. * build: meson build improvements * OS X: don't require shared-mime-info (#786167) * gif: fix a coverity warning (#785696) * build: make queryloaders output reproducible (#7835920 * Translation updates -------------------------------------------------------------------------------- ================================================================================ gnutls-3.5.15-1.fc25 (FEDORA-2017-08a8ae97e7) A TLS protocol implementation -------------------------------------------------------------------------------- Update Information: - Update to upstream 3.5.15 release -------------------------------------------------------------------------------- ================================================================================ gramps-4.2.6-1.fc25 (FEDORA-2017-51ceb5152e) Genealogical Research and Analysis Management Programming System -------------------------------------------------------------------------------- Update Information: https://gramps-project.org/introduction-WP/2017/08/gramps-4-2-6-released/ -------------------------------------------------------------------------------- ================================================================================ gsequencer-0.9.14-1.fc25 (FEDORA-2017-30c7767fc0) Advanced Gtk+ Sequencer audio processing engine -------------------------------------------------------------------------------- Update Information: added libpulse dependency -------------------------------------------------------------------------------- ================================================================================ lightdm-gtk-2.0.2-6.fc25 (FEDORA-2017-985f7a1cc6) LightDM GTK Greeter -------------------------------------------------------------------------------- Update Information: - Fix issue with lightdm-autologin-greeter pulled in basic-desktop netinstall -------------------------------------------------------------------------------- References: [ 1 ] Bug #1481192 - Netinstall with only Basic desktop selected failes to start up after reboot https://bugzilla.redhat.com/show_bug.cgi?id=1481192 -------------------------------------------------------------------------------- ================================================================================ lldpd-0.9.8-1.fc25 (FEDORA-2017-0ba7c8b09f) ISC-licensed implementation of LLDP -------------------------------------------------------------------------------- Update Information: Update to 0.9.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1483362 - lldpd-0.9.8 is available https://bugzilla.redhat.com/show_bug.cgi?id=1483362 -------------------------------------------------------------------------------- ================================================================================ mcelog-153-1.fc25 (FEDORA-2017-9994add831) Tool to translate x86-64 CPU Machine Check Exception data -------------------------------------------------------------------------------- Update Information: Update to v153. Fix "16 bytes" issue -------------------------------------------------------------------------------- References: [ 1 ] Bug #1435338 - mcelog: warning: 16 bytes ignored in each record https://bugzilla.redhat.com/show_bug.cgi?id=1435338 -------------------------------------------------------------------------------- ================================================================================ mingw-gdk-pixbuf-2.36.9-1.fc25 (FEDORA-2017-8e3983960b) MinGW Windows GDK Pixbuf library -------------------------------------------------------------------------------- Update Information: MinGW cross compiled gdk-pixbuf 2.36.9 release. -------------------------------------------------------------------------------- ================================================================================ mock-1.4.4-1.fc25 (FEDORA-2017-9a92605b52) Builds packages inside chroots -------------------------------------------------------------------------------- Update Information: * Fedora 27 configs have been added. * /etc/dnf/dnf.conf is used instead of /etc/dnf.conf * /etc/dnf/dnf.conf is populated even when yum is used * Rename group inside of chroot from mockbuild to mock - this will allow you to install mock inside of mock' chroot. -------------------------------------------------------------------------------- ================================================================================ notmuch-0.25-1.fc25 (FEDORA-2017-92d76ee588) System for indexing, searching, and tagging email -------------------------------------------------------------------------------- Update Information: Latest upstream. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1474807 - notmuch-0.25 is available https://bugzilla.redhat.com/show_bug.cgi?id=1474807 -------------------------------------------------------------------------------- ================================================================================ nuvola-app-kexp-1.2-1.fc25 (FEDORA-2017-ea54901e2e) A KEXP live stream plugin for Nuvola Player -------------------------------------------------------------------------------- Update Information: * Fri Jul 28 2017 Martin Gansser <martinkg@xxxxxxxxxxxxxxxxx> - 1.2-1 - initial build -------------------------------------------------------------------------------- ================================================================================ nuvola-app-youtube-1.3-1.fc25 (FEDORA-2017-45d0a27197) YouTube for Nuvola Player 3 -------------------------------------------------------------------------------- Update Information: * Fri Jul 28 2017 Martin Gansser <martinkg@xxxxxxxxxxxxxxxxx> - 1.3-1 - initial build -------------------------------------------------------------------------------- ================================================================================ perl-CPAN-Perl-Releases-3.32-1.fc25 (FEDORA-2017-8b4b3e1443) Mapping Perl releases on CPAN to the location of the tarballs -------------------------------------------------------------------------------- Update Information: Updated to the latest version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1483773 - perl-CPAN-Perl-Releases-3.32 is available https://bugzilla.redhat.com/show_bug.cgi?id=1483773 -------------------------------------------------------------------------------- ================================================================================ perl-Module-CoreList-5.20170821-1.fc25 (FEDORA-2017-3fcf5e8609) What modules are shipped with versions of perl -------------------------------------------------------------------------------- Update Information: This release briings data about Perl 5.27.3. -------------------------------------------------------------------------------- ================================================================================ php-horde-Horde-Core-2.30.1-1.fc25 (FEDORA-2017-11e70a413a) Horde Core Framework libraries -------------------------------------------------------------------------------- Update Information: **Horde_Core 2.30.1** * [mjr] Fix issue that could break ActiveSync sync if object not found. -------------------------------------------------------------------------------- ================================================================================ php-nette-tester-2.0.0-1.fc25 (FEDORA-2017-5b230fb914) An easy-to-use PHP unit testing framework -------------------------------------------------------------------------------- Update Information: Update to 2.0.0 (previous build was a git snapshot) -------------------------------------------------------------------------------- ================================================================================ php-phpmyadmin-sql-parser-4.1.10-1.fc25 (FEDORA-2017-649c11cf8a) A validating SQL lexer and parser with a focus on MySQL dialect -------------------------------------------------------------------------------- Update Information: **Version 4.1.10** - 2017-08-21 * Use custom LoaderException for context loading errors. -------------------------------------------------------------------------------- ================================================================================ python-cli-helpers-0.2.3-1.fc25 (FEDORA-2017-1fb2e16907) Python helpers for common CLI tasks -------------------------------------------------------------------------------- Update Information: New package: python-cli-helpers -------------------------------------------------------------------------------- References: [ 1 ] Bug #1451066 - Review Request: python-cli-helpers - Python helpers for common CLI tasks https://bugzilla.redhat.com/show_bug.cgi?id=1451066 -------------------------------------------------------------------------------- ================================================================================ python-subvertpy-0.10.1-1.fc25 (FEDORA-2017-6820f0c70e) Python bindings for Subversion -------------------------------------------------------------------------------- Update Information: Update URLs -------------------------------------------------------------------------------- ================================================================================ python-websockets-3.4-1.fc25 (FEDORA-2017-de8a446ae1) An implementation of the WebSocket Protocol for python with asyncio -------------------------------------------------------------------------------- Update Information: Update to 3.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1483322 - python-websockets-3.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1483322 -------------------------------------------------------------------------------- ================================================================================ shairport-sync-3.1.1-1.fc25 (FEDORA-2017-ec32afadcc) AirTunes emulator. Multi-Room with Audio Synchronisation -------------------------------------------------------------------------------- Update Information: new backend offering synchronised PulseAudio support. -------------------------------------------------------------------------------- ================================================================================ skopeo-0.1.23-6.git1bbd87f.fc25 (FEDORA-2017-4f9130bffc) Inspect Docker images and repositories on registries -------------------------------------------------------------------------------- Update Information: Fix conflict on name of storage.conf.5. man page, and remove default to "overlay" -------------------------------------------------------------------------------- ================================================================================ syncthing-inotify-0.8.7-4.fc25 (FEDORA-2017-c8197a9286) Syncthing File watcher -------------------------------------------------------------------------------- Update Information: Initial package for fedora. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1431868 - Review Request: syncthing-inotify - Syncthing File watcher https://bugzilla.redhat.com/show_bug.cgi?id=1431868 -------------------------------------------------------------------------------- ================================================================================ taglib-1.11.1-5.fc25 (FEDORA-2017-2317191f8a) Audio Meta-Data Library -------------------------------------------------------------------------------- Update Information: Fix for CVE-2017-12678 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1483959 - CVE-2017-12678 taglib: Incorrect cast in rebuildAggregateFrames function https://bugzilla.redhat.com/show_bug.cgi?id=1483959 -------------------------------------------------------------------------------- ================================================================================ tomcat-8.0.46-1.fc25 (FEDORA-2017-a00a087fd4) Apache Servlet/JSP Engine, RI for Servlet 3.1/JSP 2.3 API -------------------------------------------------------------------------------- Update Information: This update includes a rebase from 8.0.44 up to 8.0.46 which resolves a single CVE along with various other bugs/features: - rh#1480620 CVE-2017-7674 tomcat: Cache Poisoning -------------------------------------------------------------------------------- References: [ 1 ] Bug #1480620 - CVE-2017-7674 tomcat: Cache Poisoning [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1480620 -------------------------------------------------------------------------------- ================================================================================ variety-0.6.4-4.fc25 (FEDORA-2017-fbbcc9af89) Wallpaper changer that automatically downloads wallpapers -------------------------------------------------------------------------------- Update Information: * Mon Aug 21 2017 Martin Gansser <martinkg@xxxxxxxxxxxxxxxxx> - 0.6.4-4 - Add variety-0.6.4-fix_webkit_version.patch - Correct BR webkitgtk3 becomes webkitgtk4 - Add RR pywebkitgtk -------------------------------------------------------------------------------- ================================================================================ vim-8.0.983-1.fc25 (FEDORA-2017-a6fc26e60e) The VIM editor -------------------------------------------------------------------------------- Update Information: The newest upstream commit (fixes guicursor blinking) ---- The newest upstream commit. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1483539 - cursor blink setting broken https://bugzilla.redhat.com/show_bug.cgi?id=1483539 -------------------------------------------------------------------------------- ================================================================================ zstd-1.3.1-1.fc25 (FEDORA-2017-285975e2f4) Zstd compression library -------------------------------------------------------------------------------- Update Information: Latest upstream -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx