Fedora 26 updates-testing report

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]


The following Fedora 26 Security updates need testing:
 Age  URL
 245  https://bodhi.fedoraproject.org/updates/FEDORA-2017-ccb5c8d1e7   docker-distribution-2.6.2-1.git48294d9.fc26
  77  https://bodhi.fedoraproject.org/updates/FEDORA-2018-66b885ae3c   keycloak-httpd-client-install-0.8-1.fc26
  64  https://bodhi.fedoraproject.org/updates/FEDORA-2018-4f8a78a5ef   squid-4.0.23-1.fc26
  39  https://bodhi.fedoraproject.org/updates/FEDORA-2018-db5041e661   bro-2.5.3-1.fc26
  26  https://bodhi.fedoraproject.org/updates/FEDORA-2018-c967cee830   dovecot-2.2.34-1.fc26
  22  https://bodhi.fedoraproject.org/updates/FEDORA-2018-122ea355a7   memcached-1.4.39-2.fc26
  15  https://bodhi.fedoraproject.org/updates/FEDORA-2018-505e83d30e   webkitgtk4-2.20.0-1.fc26
  12  https://bodhi.fedoraproject.org/updates/FEDORA-2018-c1769746da   python-paramiko-2.2.3-1.fc26
  11  https://bodhi.fedoraproject.org/updates/FEDORA-2018-e03a17fa61   mosquitto-1.4.15-1.fc26
   9  https://bodhi.fedoraproject.org/updates/FEDORA-2018-a233dae4ab   tomcat-8.0.50-1.fc26
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2018-5673d070df   ImageMagick- rubygem-rmagick-2.16.0-15.fc26
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2018-010396b4a2   chromium-65.0.3325.181-1.fc26
   5  https://bodhi.fedoraproject.org/updates/FEDORA-2018-43541091ab   libvncserver-0.9.11-3.fc26
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2018-6f2df5ab6c   librelp-1.2.15-1.fc26
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2018-331af74020   gd-2.2.5-2.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-d5aa3e1d90   bchunk-1.2.2-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-c71dd2e199   php-7.1.16-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-a61baabbac   firefox-59.0.2-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-7649fef814   thunderbird-52.7.0-1.fc26

The following Fedora 26 Critical Path updates have yet to be approved:
 Age URL
  42  https://bodhi.fedoraproject.org/updates/FEDORA-2018-ddd1e5c30a   iproute-4.14.1-5.fc26
  22  https://bodhi.fedoraproject.org/updates/FEDORA-2018-6b73fc22f3   breeze-icon-theme-5.44.0-1.fc26 extra-cmake-modules-5.44.0-1.fc26 kf5-5.44.0-1.fc26 kf5-attica-5.44.0-1.fc26 kf5-baloo-5.44.0-1.fc26 kf5-bluez-qt-5.44.0-1.fc26 kf5-frameworkintegration-5.44.0-1.fc26 kf5-kactivities-5.44.0-1.fc26 kf5-kactivities-stats-5.44.0-1.fc26 kf5-kapidox-5.44.0-1.fc26 kf5-karchive-5.44.0-1.fc26 kf5-kauth-5.44.0-1.fc26 kf5-kbookmarks-5.44.0-1.fc26 kf5-kcmutils-5.44.0-1.fc26 kf5-kcodecs-5.44.0-1.fc26 kf5-kcompletion-5.44.0-1.fc26 kf5-kconfig-5.44.0-1.fc26 kf5-kconfigwidgets-5.44.0-1.fc26 kf5-kcoreaddons-5.44.0-2.fc26 kf5-kcrash-5.44.0-1.fc26 kf5-kdbusaddons-5.44.0-1.fc26 kf5-kdeclarative-5.44.0-1.fc26 kf5-kded-5.44.0-1.fc26 kf5-kdelibs4support-5.44.0-1.fc26 kf5-kdesignerplugin-5.44.0-1.fc26 kf5-kdesu-5.44.0-1.fc26 kf5-kdewebkit-5.44.0-1.fc26 kf5-kdnssd-5.44.0-1.fc26 kf5-kdoctools-5.44.0-1.fc26 kf5-kemoticons-5.44.0-1.fc26 kf5-kfilemetadata-5.44.0-1.fc26 kf5-kglobalaccel-5.44.0-1.fc26 kf5-kguiad
 dons-5.44.0-1.fc26 kf5-khtml-5.44.0-1.fc26 kf5-ki18n-5.44.0-1.fc26 kf5-kiconthemes-5.44.0-1.fc26 kf5-kidletime-5.44.0-1.fc26 kf5-kimageformats-5.44.0-1.fc26 kf5-kinit-5.44.0-1.fc26 kf5-kio-5.44.0-2.fc26 kf5-kirigami2-5.44.0-1.fc26 kf5-kitemmodels-5.44.0-1.fc26 kf5-kitemviews-5.44.0-1.fc26 kf5-kjobwidgets-5.44.0-1.fc26 kf5-kjs-5.44.0-1.fc26 kf5-kjsembed-5.44.0-1.fc26 kf5-kmediaplayer-5.44.0-1.fc26 kf5-knewstuff-5.44.0-1.fc26 kf5-knotifications-5.44.0-1.fc26 kf5-knotifyconfig-5.44.0-1.fc26 kf5-kpackage-5.44.0-1.fc26 kf5-kparts-5.44.0-1.fc26 kf5-kpeople-5.44.0-1.fc26 kf5-kplotting-5.44.0-1.fc26 kf5-kpty-5.44.0-1.fc26 kf5-kross-5.44.0-1.fc26 kf5-krunner-5.44.0-1.fc26 kf5-kservice-5.44.0-1.fc26 kf5-ktexteditor-5.44.0-1.fc26 kf5-ktextwidgets-5.44.0-1.fc26 kf5-kunitconversion-5.44.0-1.fc26 kf5-kwallet-5.44.0-1.fc26 kf5-kwayland-5.44.0-1.fc26 kf5-kwidgetsaddons-5.44.0-1.fc26 kf5-kwindowsystem-5.44.0-1.fc26 kf5-kxmlgui-5.44.0-1.fc26 kf5-kxmlrpcclient-5.44.0-1.fc26 kf5-modemmanager-qt-5.44.0-
 1.fc26 kf5-networkmanager-qt-5.44.0-1.fc26 kf5-plasma-5.44.0-1.fc26 kf5-prison-5.44.0-1.fc26 kf5-purpose-5.44.0-1.fc26 kf5-solid-5.44.0-1.fc26 kf5-sonnet-5.44.0-1.fc26 kf5-syntax-highlighting-5.44.0-1.fc26 kf5-threadweaver-5.44.0-1.fc26 oxygen-icon-theme-5.44.0-1.fc26 qqc2-desktop-style-5.44.0-1.fc26
  15  https://bodhi.fedoraproject.org/updates/FEDORA-2018-505e83d30e   webkitgtk4-2.20.0-1.fc26
   8  https://bodhi.fedoraproject.org/updates/FEDORA-2018-a37f6f92f7   pcre-8.42-1.fc26
   8  https://bodhi.fedoraproject.org/updates/FEDORA-2018-0ecf7675fc   xfce4-settings-4.12.3-1.fc26
   6  https://bodhi.fedoraproject.org/updates/FEDORA-2018-98ca353528   libdrm-2.4.91-1.fc26
   3  https://bodhi.fedoraproject.org/updates/FEDORA-2018-ab61ad2e1b   osinfo-db-20180325-1.fc26
   1  https://bodhi.fedoraproject.org/updates/FEDORA-2018-a5ea01b3ea   kernel-4.15.13-200.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-005f7a449e   enca-1.19-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-d4cacdf9bc   rpm-4.13.1-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-7649fef814   thunderbird-52.7.0-1.fc26
   0  https://bodhi.fedoraproject.org/updates/FEDORA-2018-a61baabbac   firefox-59.0.2-1.fc26

The following builds have been pushed to Fedora 26 updates-testing


Details about builds:

 R-Rmpfr-0.7.0-1.fc26 (FEDORA-2018-eeabc4f99b)
 R MPFR - Multiple Precision Floating-Point Reliable
Update Information:

Initial package of Rmpfr for R

  [ 1 ] Bug #1561356 - Review Request: R-Rmpfr - R MPFR - Multiple Precision Floating-Point Reliable

 R-corpus-0.10.0-1.fc26 (FEDORA-2018-ee714daef5)
 Text Corpus Analysis
Update Information:

Initial package of corpus for R

  [ 1 ] Bug #1561334 - Review Request: R-corpus - Text Corpus Analysis

 R-getPass-0.2.2-1.fc26 (FEDORA-2018-cb0a34efde)
 Masked User Input
Update Information:

Initial package of getPass for R

  [ 1 ] Bug #1561306 - Review Request: R-getPass - Masked User Input

 aime-8.20180223-1.fc26 (FEDORA-2018-4438800a2b)
 An application embeddable programming language interpreter
Update Information:

- Updated to new 8.20180223 upstream version, fixes rhbz #1548775

  [ 1 ] Bug #1548775 - aime-8.20180223 is available

 babl-0.1.44-1.fc26 (FEDORA-2018-4467ee6e99)
 A dynamic, any to any, pixel format conversion library
Update Information:

Upstream bugfix and enhancement releases.  For details, see the respective
upstream changelogs:

 cmake-3.11.0-1.fc26 (FEDORA-2018-926e88d126)
 Cross-platform make system
Update Information:

- New upstream release

  [ 1 ] Bug #1551147 - cmake -E cmake_autogen crashing (probably due to build with GCC 8)
  [ 2 ] Bug #1536233 - cmake-3.11.0 is available

 drupal7-7.58-1.fc26 (FEDORA-2018-d8269e4262)
 An open-source content-management platform
Update Information:

- https://www.drupal.org/SA-CORE-2018-002 - https://www.drupal.org/SA-

  [ 1 ] Bug #1548190 - drupal7: drupal: JavaScript cross-site scripting in checkPlain function [fedora-all]
  [ 2 ] Bug #1547793 - drupal7-7.57 is available
  [ 3 ] Bug #1548324 - CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [epel-all]
  [ 4 ] Bug #1548201 - drupal7: drupal: External link injection on 404 pages when linking to the current page [epel-all]
  [ 5 ] Bug #1548197 - drupal7: drupal: jQuery vulnerability with untrusted domains requests via Ajax [epel-all]
  [ 6 ] Bug #1548195 - drupal7: drupal: Private file access bypass in Drupal private file system [epel-all]
  [ 7 ] Bug #1561801 - drupal7-7.58 is available
  [ 8 ] Bug #1548191 - drupal7: drupal: JavaScript cross-site scripting in checkPlain function [epel-all]
  [ 9 ] Bug #1548326 - CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal7: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]
  [ 10 ] Bug #1548202 - drupal7: drupal: External link injection on 404 pages when linking to the current page [fedora-all]
  [ 11 ] Bug #1548198 - drupal7: drupal: jQuery vulnerability with untrusted domains requests via Ajax [fedora-all]
  [ 12 ] Bug #1548194 - drupal7: drupal: Private file access bypass in Drupal private file system [fedora-all]

 drupal8-8.3.9-1.fc26 (FEDORA-2018-922cc2fbaa)
 An open source content management platform
Update Information:

* [8.3.9](https://www.drupal.org/project/drupal/releases/8.3.9)     * [SA-
CORE-2018-002 (CVE-2018-7600)](https://www.drupal.org/SA-CORE-2018-002) *
[8.3.8](https://www.drupal.org/project/drupal/releases/8.3.8)     * [SA-
CORE-2018-001 (CVE-2017-6926 / CVE-2017-6927 / CVE-2017-6930 /

  [ 1 ] Bug #1561855 - CVE-2018-7600 drupal8: drupal: Unsanitized requests allow remote attackers to execute arbitrary code [fedora-all]
  [ 2 ] Bug #1548325 - CVE-2017-6926 CVE-2017-6927 CVE-2017-6928 CVE-2017-6929 CVE-2017-6930 CVE-2017-6931 CVE-2017-6932 drupal8: drupal: Multiple vulnerabilities fixed in 7.57 and 8.4.5 (SA-CORE-2018-001) [fedora-all]
  [ 3 ] Bug #1548192 - drupal8: drupal: JavaScript cross-site scripting in checkPlain function [fedora-all]
  [ 4 ] Bug #1548188 - drupal8: drupal: Comment reply form allows access to restricted content [fedora-all]

 gegl03-0.3.30-1.fc26 (FEDORA-2018-4467ee6e99)
 Graph based image processing framework
Update Information:

Upstream bugfix and enhancement releases.  For details, see the respective
upstream changelogs:

 gnome-boxes-3.24.1-3.fc26 (FEDORA-2018-14246218d4)
 A simple GNOME 3 application to access remote or virtual systems
Update Information:

Avoid crashing when unable to connect to libvirt session, maintaining at least
the remote viewer capabilities.

  [ 1 ] Bug #1441170 - [abrt] gnome-boxes: boxes_app_setup_default_source_co(): gnome-boxes killed by signal 6

 mame-0.196-1.fc26 (FEDORA-2018-30fa0dbb8c)
 Multiple Arcade Machine Emulator
Update Information:

An update to the latest mame release:  * http://mamedev.org/?p=455

 mariadb-10.1.32-1.fc26 (FEDORA-2018-02c0e3725e)
 A community developed branch of MySQL
Update Information:

**MariaDB 10.1.32**  Release notes:
https://mariadb.com/kb/en/library/mariadb-10132-release-notes/  Bugs solved:
Jemalloc issue on aarch64 (solved in jemalloc package)
https://bugzilla.redhat.com/show_bug.cgi?id=1545539   CVEs fixed:
CVE-2018-2562, CVE-2018-2622, CVE-2018-2640,     CVE-2018-2665, CVE-2018-2668,

  [ 1 ] Bug #1548039 - mariadb-10.1.31 is available

 nodejs-6.14.0-1.fc26 (FEDORA-2018-e672eaf4df)
 JavaScript runtime
Update Information:


  [ 1 ] Bug #1562027 - CVE-2018-7158 CVE-2018-7159 CVE-2018-7160 nodejs: various flaws [fedora-all]

 passwd-0.80-1.fc26 (FEDORA-2018-58a96b7680)
 An utility for setting or changing passwords using PAM
Update Information:

Update to **passwd-0.80**

  [ 1 ] Bug #1293929 - passwd man page is incomplete

 pcp-4.0.1-1.fc26 (FEDORA-2018-a88bef9929)
 System-level performance monitoring and performance management
Update Information:

Enhancement and bugfix update. Major changes include a revamp of the archive log
management, more frequent compression by default and updates to related
utilities. Addition of a cron driven daily report to the pcp-zeroconf package
(like sa2(1)), and dependencies to also install the pcp-doc package (for man
pages) and pcp-system-tools package which includes pmrep(1) and other monitoring
utilities. Many pmrep(1) bug fixes and new configuration entries. Updates to the
prometheus PMDA for control metrics, scalability improvements, support for URL
config request headers and response filtering. The postgreSQL PMDA now supports
up to version 9.6, will reconnect automatically if the DB connection is lost,
and other improvements. Updates to many other PMDAs, including the new BCC PMDA.
SELinux updates for a variety of AVC denials, and new SELinux rules for
pmdagluster and numad_t. Many new bug fixes and enhancements to libpcp and
libpcp_pmda including service discovery API extensions. Performance improvments
to pmwebd and support for etag headers. Improvements to pmmgr service discovery.
Build fixes for Windows/mingw and many other build, infrastructure and
documentation updates.

  [ 1 ] Bug #1558708 - selinux blocks pmdagluster
  [ 2 ] Bug #1529915 - pmcd binding only to localhost:44321 by default

 perl-Perl-Tidy-Sweetened-1.14-1.fc26 (FEDORA-2018-bb6f917f6c)
 Tweaks to Perl::Tidy to support some syntactic sugar
Update Information:

This release adds support for closing side comments and for Kavorka's basic

  [ 1 ] Bug #1561814 - perl-Perl-Tidy-Sweetened-1.14 is available

 publicsuffix-list-20180328-1.fc26 (FEDORA-2018-803beecbda)
 Cross-vendor public domain suffix database
Update Information:

Recent revision - 20180328

 rho-0.0.33-1.fc26 (FEDORA-2018-d4a1b7ae4b)
 An SSH system profiler
Update Information:

# Testing Rho  To set up Rho, you create profiles that control how to run each
scan. - Authentication profiles contain user credentials for a user with
sufficient authority to complete the scan (for example, a root user or one with
root-level access obtained through -sudo privilege escalation). - Network
profiles contain network identifiers (for example, a hostname, IP address, or
range of IP addresses) and the authentication profiles to be used for a scan.
Complete the following steps, repeating them as necessary to access all parts of
your environment that you want to scan: 1. Create at least one authentication
profile with root-level access to Rho: ``` rho auth add --name auth_name
--username root_name(--sshkeyfile key_file | --password) ```  a. At the Rho
vault password prompt, create a new Rho vault password. This password is
required to access the encrypted Rho data, such as authentication and network
profiles, scan data, and other information.  b. If you did not use the
sshkeyfile option to provide an SSH key for the username value, enter the
password of the user with root-level access at the connection password prompt.
For example, for an authentication profile where the authentication profile name
is roothost1, the user with root-level access is root, and the SSH key for the
user is in the path ~/.ssh/id_rsa, you would enter the following command: ```
rho auth add --name roothost1 --username root --sshkeyfile ~/.ssh/id_rsa ``` You
can also use the sudo-password option to create an authentication profile for a
user with root-level access who requires a password to obtain this privilege.
You can use the sudo-password option with either the sshkeyfile or the password
option. For example, for an authentication profile where the authentication
profile name is sudouser1, the user with root-level access is sysadmin, and the
access is obtained through the password option, you would enter the following
command: ``` rho auth add --name sudouser1 --username sysadmin --password
--sudo-password ```  After you enter this command, you are prompted to enter two
passwords. First, you would enter the connection password for the username user,
and then you would enter the password for the sudo command.  2. Create at least
one network profile that specifies one or more network identifiers, such as a
host name, an IP address, a list of IP addresses, or an IP range, and one or
more authentication profiles to be used for the scan: ``` rho profile add --name
profile_name --hosts host_name_or_file --auth auth_name ```  For example, for a
network profile where the name of the network profile is mynetwork, the network
to be scanned is the subnet, and the authentication profiles that
are used to run the scan are roothost1 and roothost2, you would enter the
following command: ``` rho profile add --name mynetwork --hosts 192.0.2.[1:254]
--auth roothost1 roothost2 ```  You can also use a file to pass in the network
identifiers. If you use a file to enter multiple network identifiers, such as
multiple individual IP addresses, enter each on a single line. For example, for
a network profile where the path to this file is /home/user1/hosts_file, you
would enter the following command: ``` rho profile add --name mynetwork --hosts
/home/user1/hosts_file --auth roothost1 roothost2 ```  # Running a scan Run the
scan by using the scan command, specifying a network profile for the profile
option and a location to store the output as a file in the comma-separated
variables (CSV) format for the reportfile option: ``` rho scan --profile
profile_name --reportfile filename.csv ``` For example, if you want to use the
network profile mynetwork and save the report as mynetwork_scan1.csv, you would
enter the following command: ``` rho scan --profile mynetwork --reportfile
mynetwork_scan1.csv ```

 starcal-3.0.7-1.fc26 (FEDORA-2018-b738729760)
 A full-featured international calendar written in Python
Update Information:

New version with updated calendar special days for year 1397 (jalali)

  [ 1 ] Bug #1558008 - starcal-3.0.7 is available

 tzdata-2018d-1.fc26 (FEDORA-2018-29e01a0027)
 Timezone data
Update Information:

    Resolves: #1560131     - Rebase to tzdata-2018d:       - DST for Asia/Gaza
and Asia/Hebron has changed from March 31 to March 24.       - Antarctica/Casey
station changed to UTC+8 on March 11.

  [ 1 ] Bug #1560131 - tzdata-2018d is available

 xfce4-terminal- (FEDORA-2018-0f98904e5d)
 Terminal Emulator for the Xfce Desktop environment
Update Information:

bugfix update; version
test mailing list -- test@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to test-leave@xxxxxxxxxxxxxxxxxxxxxxx

[Index of Archives]     [Fedora Desktop]     [Fedora SELinux]     [Photo Sharing]     [Yosemite Forum]     [KDE Users]

  Powered by Linux