The following Fedora 27 Security updates need testing: Age URL 26 https://bodhi.fedoraproject.org/updates/FEDORA-2017-d270e932a3 nagios-4.3.4-3.fc27 12 https://bodhi.fedoraproject.org/updates/FEDORA-2017-7106a157f5 dnsmasq-2.77-9.fc27 12 https://bodhi.fedoraproject.org/updates/FEDORA-2017-523f6a613d botan-1.10.17-1.fc27 12 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e8179c06fd curl-7.55.1-6.fc27 12 https://bodhi.fedoraproject.org/updates/FEDORA-2017-67f13dd1e1 mingw-taglib-1.11.1-4.fc27 7 https://bodhi.fedoraproject.org/updates/FEDORA-2017-899c5f6a86 nodejs-forwarded-0.1.2-1.fc27 6 https://bodhi.fedoraproject.org/updates/FEDORA-2017-025ff38ac9 poppler-0.57.0-5.fc27 5 https://bodhi.fedoraproject.org/updates/FEDORA-2017-cbb8db2be6 libXfont2-2.0.2-1.fc27 5 https://bodhi.fedoraproject.org/updates/FEDORA-2017-39c5f8cd7e sssd-1.15.3-5.fc27 5 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9fd430dba0 wireshark-2.4.2-1.fc27 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-0b90d8bb68 thunderbird-52.4.0-2.fc27 4 https://bodhi.fedoraproject.org/updates/FEDORA-2017-e1dc7351db kernel-4.13.6-300.fc27 1 https://bodhi.fedoraproject.org/updates/FEDORA-2017-a1f0519599 git-annex-6.20170925-1.fc27 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-19c9fc71f9 cacti-1.1.26-1.fc27 0 https://bodhi.fedoraproject.org/updates/FEDORA-2017-9b3e2904bf lucene-6.1.0-6.fc27 The following builds have been pushed to Fedora 27 updates-testing adobe-source-sans-pro-fonts-2.020-1.fc27 astrometry-0.72-4.fc27 beakerlib-1.17-2.fc27 cacti-1.1.26-1.fc27 cargo-0.22.0-1.fc27 dfu-programmer-0.7.2-1.fc27 docker-1.13.1-33.git790e958.fc27 fusioninventory-agent-2.3.21-3.fc27 gocomplete-0-0.2.20170908git88e5976.fc27 golang-github-jefferai-jsonx-0-0.1.20160722git9cc31c3.fc27 golang-github-pquerna-otp-1.0.0-1.fc27 golang-github-templexxx-cpufeat-0-0.1.20170927.git3794dfb.fc27 libnitrokey-3.1-1.fc27 lollypop-0.9.304-1.fc27 lucene-6.1.0-6.fc27 magic-8.2.38-1.fc27 mathicgb-1.0-12.20170606.gitbd634c8.fc27 nitrokey-app-1.2-0.2.beta.3.fc27 nss-softokn-3.33.0-1.1.fc27 nvidia-query-resource-opengl-1.0.0-2.fc27 perl-Dancer2-0.205002-1.fc27 perl-Math-Base85-0.4-1.fc27 perl-Sys-Path-0.16-1.fc27 pyotherside-1.5.3-1.fc27 python-astroML-0.3-16.fc27 python-btchip-0.1.21-4.fc27 python-enlighten-1.0.6-1.fc27 python-events-0.2.1-1.fc27 python-nectar-1.5.6-1.fc27 rust-1.21.0-1.fc27 sayonara-0.9.3-5.git20171018.fc27 skopeo-0.1.24-6.dev.git28d4e08.fc27 socket_wrapper-1.1.8-4.fc27 sugar-physics-32.1-3.fc27 valgrind-3.13.0-9.fc27 xrootd-4.7.0-3.fc27 zabbix-3.0.12-1.fc27 Details about builds: ================================================================================ adobe-source-sans-pro-fonts-2.020-1.fc27 (FEDORA-2017-2d76a9b93a) A set of OpenType fonts designed for user interfaces -------------------------------------------------------------------------------- Update Information: This update provides the latest version of the Adobe Source Sans Pro fonts. It includes support for Greek and Cyrillic languages, amongst many features. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1503250 - Outdated package https://bugzilla.redhat.com/show_bug.cgi?id=1503250 -------------------------------------------------------------------------------- ================================================================================ astrometry-0.72-4.fc27 (FEDORA-2017-85b8f8bd95) Blind astrometric calibration of arbitrary astronomical images -------------------------------------------------------------------------------- Update Information: Added 4204-4219 index files. ---- Added 2MASS data files -------------------------------------------------------------------------------- ================================================================================ beakerlib-1.17-2.fc27 (FEDORA-2017-a826acf5fd) A shell-level integration testing library -------------------------------------------------------------------------------- Update Information: - completely reworked getting rpms - bstor.py rewritten in pure bash - some doc fixes - completely rewritten journal - extended test suite - support for XSL transformation of journal.xml - provided xunit.xsl - libraries are now searched also in /usr/share/beakerlib-libraries -------------------------------------------------------------------------------- ================================================================================ cacti-1.1.26-1.fc27 (FEDORA-2017-19c9fc71f9) An rrd based graphing tool -------------------------------------------------------------------------------- Update Information: - Update to 1.1.26 - CVE-2017-15194 Release notes: https://www.cacti.net/release_notes.php?version=1.1.26 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1500456 - CVE-2017-15194 cacti: XSS in the URI / refresh page in include/global_session.php https://bugzilla.redhat.com/show_bug.cgi?id=1500456 -------------------------------------------------------------------------------- ================================================================================ cargo-0.22.0-1.fc27 (FEDORA-2017-46923a510b) Rust's package manager and build tool -------------------------------------------------------------------------------- Update Information: New versions of Rust and Cargo -- see the release notes for [1.21](https://blog .rust-lang.org/2017/10/12/Rust-1.21.html). -------------------------------------------------------------------------------- ================================================================================ dfu-programmer-0.7.2-1.fc27 (FEDORA-2017-174d06b397) A Device Firmware Update based USB programmer for Atmel chips -------------------------------------------------------------------------------- Update Information: Update to 0.7.2 -------------------------------------------------------------------------------- ================================================================================ docker-1.13.1-33.git790e958.fc27 (FEDORA-2017-3da8ad596a) Automates deployment of containerized applications -------------------------------------------------------------------------------- Update Information: move rhel secrets info from docker to skopeo-containers ---- Add override kernel check. ---- built commit 28d4e08 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1479003 - skopeo-containers file conflict with inn https://bugzilla.redhat.com/show_bug.cgi?id=1479003 [ 2 ] Bug #1478843 - Package version 0.1.23-2.git1bbd87f has a file conflict with inn https://bugzilla.redhat.com/show_bug.cgi?id=1478843 -------------------------------------------------------------------------------- ================================================================================ fusioninventory-agent-2.3.21-3.fc27 (FEDORA-2017-e3b8f5f127) FusionInventory agent -------------------------------------------------------------------------------- Update Information: Do not provides perl(setup); BZ #1485919 - thanks to E. Seyman -------------------------------------------------------------------------------- References: [ 1 ] Bug #1485919 - Do not provide "perl(setup)" https://bugzilla.redhat.com/show_bug.cgi?id=1485919 -------------------------------------------------------------------------------- ================================================================================ gocomplete-0-0.2.20170908git88e5976.fc27 (FEDORA-2017-d316ece212) A tool for bash writing bash completion in Go (Golang) -------------------------------------------------------------------------------- Update Information: Fix unit-test/devel dependency issue. -------------------------------------------------------------------------------- ================================================================================ golang-github-jefferai-jsonx-0-0.1.20160722git9cc31c3.fc27 (FEDORA-2017-ab551d924f) Go (golang) library to transform JSON into JSONx -------------------------------------------------------------------------------- Update Information: First package for Fedora -------------------------------------------------------------------------------- References: [ 1 ] Bug #1430135 - Review Request: golang-github-jefferai-jsonx - Go (golang) library to transform JSON into JSONx https://bugzilla.redhat.com/show_bug.cgi?id=1430135 -------------------------------------------------------------------------------- ================================================================================ golang-github-pquerna-otp-1.0.0-1.fc27 (FEDORA-2017-99b9b0f37c) TOTP Library for Go (Golang) -------------------------------------------------------------------------------- Update Information: First package for Fedora -------------------------------------------------------------------------------- References: [ 1 ] Bug #1501002 - Review Request: golang-github-pquerna-otp - TOTP Library for Go (Golang) https://bugzilla.redhat.com/show_bug.cgi?id=1501002 -------------------------------------------------------------------------------- ================================================================================ golang-github-templexxx-cpufeat-0-0.1.20170927.git3794dfb.fc27 (FEDORA-2017-d9d91cd0eb) Implementation of internal/cpu in Go -------------------------------------------------------------------------------- Update Information: Initial package for fedora. Needed for updating golang-github- templexxx-{reedsolomon,xor}. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1503026 - Review Request: golang-github-templexxx-cpufeat - Implementation of internal/cpu in Go https://bugzilla.redhat.com/show_bug.cgi?id=1503026 -------------------------------------------------------------------------------- ================================================================================ libnitrokey-3.1-1.fc27 (FEDORA-2017-8b014cf697) Communicate with Nitrokey stick devices in a clean and easy manner -------------------------------------------------------------------------------- Update Information: Update nitrokey-app to latest beta release and libnitrokey to latest stable. -------------------------------------------------------------------------------- ================================================================================ lollypop-0.9.304-1.fc27 (FEDORA-2017-045461c4cc) Music player for GNOME -------------------------------------------------------------------------------- Update Information: Update to 0.9.304 -------------------------------------------------------------------------------- ================================================================================ lucene-6.1.0-6.fc27 (FEDORA-2017-9b3e2904bf) High-performance, full-featured text search engine -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-12629 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1501529 - CVE-2017-12629 Solr: Code execution via entity expansion https://bugzilla.redhat.com/show_bug.cgi?id=1501529 -------------------------------------------------------------------------------- ================================================================================ magic-8.2.38-1.fc27 (FEDORA-2017-bd501fbd01) A very capable VLSI layout tool -------------------------------------------------------------------------------- Update Information: New version 8.2.38 is released. -------------------------------------------------------------------------------- ================================================================================ mathicgb-1.0-12.20170606.gitbd634c8.fc27 (FEDORA-2017-451c90b5ae) Groebner basis computations -------------------------------------------------------------------------------- Update Information: This update removes an unnecessary dependency on gtest from the mgb binary. -------------------------------------------------------------------------------- ================================================================================ nitrokey-app-1.2-0.2.beta.3.fc27 (FEDORA-2017-8b014cf697) Nitrokey's Application -------------------------------------------------------------------------------- Update Information: Update nitrokey-app to latest beta release and libnitrokey to latest stable. -------------------------------------------------------------------------------- ================================================================================ nss-softokn-3.33.0-1.1.fc27 (FEDORA-2017-88eb0ae252) Network Security Services Softoken Module -------------------------------------------------------------------------------- Update Information: This update prevents issues on half-upgraded system with nss-softokn-freebl >= 3.33, by adding versioned dependency on nspr/nss-util: https://lists.fedoraproje ct.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx/message/NJHY3HPELUQB5ESEBWA6K KWSL6PXYBIM/ -------------------------------------------------------------------------------- ================================================================================ nvidia-query-resource-opengl-1.0.0-2.fc27 (FEDORA-2017-d72706c981) Querying OpenGL resource usage of applications using the NVIDIA OpenGL driver -------------------------------------------------------------------------------- Update Information: Querying OpenGL resource usage of applications using the NVIDIA OpenGL driver -------------------------------------------------------------------------------- ================================================================================ perl-Dancer2-0.205002-1.fc27 (FEDORA-2017-5272105eff) Lightweight yet powerful web application framework -------------------------------------------------------------------------------- Update Information: Updated to the latest version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1503367 - perl-Dancer2-0.205002 is available https://bugzilla.redhat.com/show_bug.cgi?id=1503367 -------------------------------------------------------------------------------- ================================================================================ perl-Math-Base85-0.4-1.fc27 (FEDORA-2017-63f9b40927) Perl extension for base 85 numbers, as referenced by RFC 1924 -------------------------------------------------------------------------------- Update Information: Updated to the latest version -------------------------------------------------------------------------------- ================================================================================ perl-Sys-Path-0.16-1.fc27 (FEDORA-2017-33132292fb) Supply autoconf style installation directories -------------------------------------------------------------------------------- Update Information: Updated to the latest version -------------------------------------------------------------------------------- ================================================================================ pyotherside-1.5.3-1.fc27 (FEDORA-2017-9d38319194) Asynchronous Python 3 Bindings for Qt 5 -------------------------------------------------------------------------------- Update Information: Updated to 1.5.3 -------------------------------------------------------------------------------- ================================================================================ python-astroML-0.3-16.fc27 (FEDORA-2017-b97b1e8305) Python tools for machine learning and data mining in Astronomy -------------------------------------------------------------------------------- Update Information: Added a weak dependency (Recommends) on healpy, which is an optional dependency of astroML. -------------------------------------------------------------------------------- ================================================================================ python-btchip-0.1.21-4.fc27 (FEDORA-2017-130804af0c) Python communication library for Ledger Hardware Wallet products -------------------------------------------------------------------------------- Update Information: - Add python-mnemonic dependency for BIP39 support during dongle setup - New sub-package: python3-btchip (upstream added py3 support) (#1499686) - New sub- package: python-btchip-common - current for the btchip udev rules - Add udev rules (20-hw1.rules) for automatic device recognition - Fix summary mistake in common package ---- - Add python-mnemonic dependency for BIP39 support during dongle setup - New sub-package: python3-btchip (upstream added py3 support) (#1499686) - New sub-package: python-btchip-common - current for the btchip udev rules - Add udev rules (20-hw1.rules) for automatic device recognition -------------------------------------------------------------------------------- References: [ 1 ] Bug #1499686 - Please add also python3-btchip in python-btchip https://bugzilla.redhat.com/show_bug.cgi?id=1499686 -------------------------------------------------------------------------------- ================================================================================ python-enlighten-1.0.6-1.fc27 (FEDORA-2017-81868e4554) Enlighten Progress Bar -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1502091 - Review Request: python-enlighten - Enlighten Progress Bar https://bugzilla.redhat.com/show_bug.cgi?id=1502091 -------------------------------------------------------------------------------- ================================================================================ python-events-0.2.1-1.fc27 (FEDORA-2017-8fc9424a56) Bringing the elegance of C# EventHanlder to Python -------------------------------------------------------------------------------- Update Information: Initial package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1389311 - Review Request: python-events - Bringing the elegance of C# EventHanlder to Python https://bugzilla.redhat.com/show_bug.cgi?id=1389311 -------------------------------------------------------------------------------- ================================================================================ python-nectar-1.5.6-1.fc27 (FEDORA-2017-162e43887e) A download library that separates workflow from implementation details -------------------------------------------------------------------------------- Update Information: New release of package -------------------------------------------------------------------------------- ================================================================================ rust-1.21.0-1.fc27 (FEDORA-2017-46923a510b) The Rust Programming Language -------------------------------------------------------------------------------- Update Information: New versions of Rust and Cargo -- see the release notes for [1.21](https://blog .rust-lang.org/2017/10/12/Rust-1.21.html). -------------------------------------------------------------------------------- ================================================================================ sayonara-0.9.3-5.git20171018.fc27 (FEDORA-2017-e564ac74df) A lightweight Qt Audio player -------------------------------------------------------------------------------- Update Information: Update to 0.9.3-5.git20171018 -------------------------------------------------------------------------------- ================================================================================ skopeo-0.1.24-6.dev.git28d4e08.fc27 (FEDORA-2017-3da8ad596a) Inspect Docker images and repositories on registries -------------------------------------------------------------------------------- Update Information: move rhel secrets info from docker to skopeo-containers ---- Add override kernel check. ---- built commit 28d4e08 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1479003 - skopeo-containers file conflict with inn https://bugzilla.redhat.com/show_bug.cgi?id=1479003 [ 2 ] Bug #1478843 - Package version 0.1.23-2.git1bbd87f has a file conflict with inn https://bugzilla.redhat.com/show_bug.cgi?id=1478843 -------------------------------------------------------------------------------- ================================================================================ socket_wrapper-1.1.8-4.fc27 (FEDORA-2017-6b6aa9f9cb) A library passing all socket communications through Unix sockets -------------------------------------------------------------------------------- Update Information: Update to version 1.1.8 -------------------------------------------------------------------------------- ================================================================================ sugar-physics-32.1-3.fc27 (FEDORA-2017-8642981c6b) A physical world simulator and playground for Sugar -------------------------------------------------------------------------------- Update Information: Use system version of Box2D and not the bundled one. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1446934 - Failure to import Box2D in Sugar Physics https://bugzilla.redhat.com/show_bug.cgi?id=1446934 -------------------------------------------------------------------------------- ================================================================================ valgrind-3.13.0-9.fc27 (FEDORA-2017-2db47fddfd) Tool for finding memory management bugs in programs -------------------------------------------------------------------------------- Update Information: Fix xml log output to socket. PPC64 instruction fixes. Implement static TLS code for more platforms. Suppress ld.so _dl_runtime_resolve_avx_slow conditional jump warning. -------------------------------------------------------------------------------- ================================================================================ xrootd-4.7.0-3.fc27 (FEDORA-2017-d9876ffbd5) Extended ROOT file server -------------------------------------------------------------------------------- Update Information: Add two library symlinks to xrootd-private-devel. -------------------------------------------------------------------------------- ================================================================================ zabbix-3.0.12-1.fc27 (FEDORA-2017-287c8e56e0) Open-source monitoring solution for your IT infrastructure -------------------------------------------------------------------------------- Update Information: https://www.zabbix.com/rn3.0.12 -------------------------------------------------------------------------------- _______________________________________________ test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx