The following Fedora 13 Security updates need testing: https://admin.fedoraproject.org/updates/thunderbird-3.1.5-1.fc13,sunbird-1.0-0.29.b2pre.fc13 https://admin.fedoraproject.org/updates/tomcat6-6.0.26-11.fc13 https://admin.fedoraproject.org/updates/perl-libwww-perl-5.837-2.fc13 https://admin.fedoraproject.org/updates/horde-3.3.9-1.fc13 https://admin.fedoraproject.org/updates/mailman-2.1.12-16.fc13 https://admin.fedoraproject.org/updates/luci-0.22.4-2.0.b9faf868074git.fc13 https://admin.fedoraproject.org/updates/xpdf-3.02-16.fc13 https://admin.fedoraproject.org/updates/clamav-0.96.3-1400.fc13 https://admin.fedoraproject.org/updates/gnucash-2.3.15-2.fc13 https://admin.fedoraproject.org/updates/bristol-0.40.7-7.fc13 https://admin.fedoraproject.org/updates/moodle-1.9.10-1.fc13 https://admin.fedoraproject.org/updates/seamonkey-2.0.9-1.fc13 https://admin.fedoraproject.org/updates/pidgin-2.7.4-1.fc13 The following builds have been pushed to Fedora 13 updates-testing EMBOSS-6.2.0-4.fc13 chkconfig-1.3.48-1.fc13 etckeeper-0.50-1.fc13 flies-python-client-0.3.1-1.fc13 flies-python-client-0.3.2-1.fc13 fuse-2.8.5-2.fc13 gajim-0.14.1-1.fc13 gnome-settings-daemon-2.30.1-9.fc13 hosts3d-1.13-1.fc13 httpd-2.2.17-1.fc13.1 ibus-anthy-1.2.4-2.fc13 kobo-0.3.2-1.fc13 moodle-1.9.10-1.fc13 nagios-3.2.3-2.fc13 osmo-0.2.10-2.fc13 publican-redhat-2.6-0.fc13 qtparted-0.4.5-25.fc13 selinux-policy-3.7.19-69.fc13 tzdata-2010n-1.fc13 unuran-1.8.0-1.fc13 Details about builds: ================================================================================ EMBOSS-6.2.0-4.fc13 (FEDORA-2010-16772) The European Molecular Biology Open Software Suite -------------------------------------------------------------------------------- Update Information: Fix doc finding with tfm. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Tom "spot" Callaway <tcallawa@xxxxxxxxxx> - 6.2.0-4 - fix doc finding in tfm (bz 647140) -------------------------------------------------------------------------------- References: [ 1 ] Bug #647140 - tfm fails to find documentation files https://bugzilla.redhat.com/show_bug.cgi?id=647140 -------------------------------------------------------------------------------- ================================================================================ chkconfig-1.3.48-1.fc13 (FEDORA-2010-16713) A system tool for maintaining the /etc/rc*.d hierarchy -------------------------------------------------------------------------------- Update Information: This fixes a couple of bugs in chkconfig's LSB support. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Bill Nottingham <notting@xxxxxxxxxx> 1.3.48-1 - fix install_initd invocation for services that require $local_fs (#632294) * Tue Aug 10 2010 Bill Nottingham <notting@xxxxxxxxxx> 1.3.47-1 - Fix regression introduced in 1.3.45 (#622799) * Wed May 5 2010 Bill Nottingham <notting@xxxxxxxxxx> 1.3.46-1 - translation updates: hu, kn, ko (#589187) -------------------------------------------------------------------------------- References: [ 1 ] Bug #632294 - install_initd fails on Required-Start: $local_fs https://bugzilla.redhat.com/show_bug.cgi?id=632294 [ 2 ] Bug #622799 - Problems with clvmd symlinks when using chkconfig. https://bugzilla.redhat.com/show_bug.cgi?id=622799 -------------------------------------------------------------------------------- ================================================================================ etckeeper-0.50-1.fc13 (FEDORA-2010-16878) Store /etc in a SCM system (git, mercurial, bzr or darcs) -------------------------------------------------------------------------------- Update Information: Update to etckeeper to version 0.50. * Ignore /etc/.initctl. * Do not warn about special files or hardlinks if they are ignored by git. * Set GIT_COMMITTER_EMAIL to root@$hostname to avoid git prompting the user to configure it in .gitconfig. * Deal with strange systems that include the domain name in the hostname, by stripping it. Complete list of changes (including Debian bug numbers) can be found here: http://joey.kitenet.net/code/etckeeper/news/version_0.50/ -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Thomas Moschny <thomas.moschny@xxxxxx> - 0.50-1 - Update to 0.50. - Change %define -> %global. * Fri Sep 17 2010 Thomas Moschny <thomas.moschny@xxxxxx> - 0.49-2 - Adjust minimum required version of GIT. - egg-info files are not created automatically on RHEL5. -------------------------------------------------------------------------------- References: [ 1 ] Bug #646943 - etckeeper-0.50 is available https://bugzilla.redhat.com/show_bug.cgi?id=646943 -------------------------------------------------------------------------------- ================================================================================ flies-python-client-0.3.1-1.fc13 (FEDORA-2010-16853) Python Client for Flies Server -------------------------------------------------------------------------------- Update Information: -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 22 2010 James Ni <jni@xxxxxxxxxx> - 0.3.1-1 - Fix an issue in project creation * Thu Oct 21 2010 James Ni <jni@xxxxxxxxxx> - 0.3.0-1 - Fix the issues in extension support and update translation command * Thu Oct 21 2010 James Ni <jni@xxxxxxxxxx> - 0.2.0-1 - Add extension support and update translation command * Wed Sep 29 2010 James Ni <jni@xxxxxxxxxx> - 0.1.0-1 - Modify the user configuration file and command line options * Wed Sep 8 2010 James Ni <jni@xxxxxxxxxx> - 0.0.6-1 - Try to resolve the dependency of python-setuptools -------------------------------------------------------------------------------- ================================================================================ flies-python-client-0.3.2-1.fc13 (FEDORA-2010-16863) Python Client for Flies Server -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 James Ni <jni@xxxxxxxxxx> - 0.3.2-1 - Fix a typo in project creation * Fri Oct 22 2010 James Ni <jni@xxxxxxxxxx> - 0.3.1-1 - Fix an issue in project creation * Thu Oct 21 2010 James Ni <jni@xxxxxxxxxx> - 0.3.0-1 - Fix the issues in extension support and update translation command * Thu Oct 21 2010 James Ni <jni@xxxxxxxxxx> - 0.2.0-1 - Add extension support and update translation command * Wed Sep 29 2010 James Ni <jni@xxxxxxxxxx> - 0.1.0-1 - Modify the user configuration file and command line options * Wed Sep 8 2010 James Ni <jni@xxxxxxxxxx> - 0.0.6-1 - Try to resolve the dependency of python-setuptools -------------------------------------------------------------------------------- ================================================================================ fuse-2.8.5-2.fc13 (FEDORA-2010-16859) File System in Userspace (FUSE) utilities -------------------------------------------------------------------------------- Update Information: * Allow mounting FUSE fs into current directory. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> 2.8.5-2 - Fixed rhbz #622255 * Tue Oct 26 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> 2.8.5-1 - Ver. 2.8.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #622255 - Cannot mount encfs with option allow_root on $HOME https://bugzilla.redhat.com/show_bug.cgi?id=622255 -------------------------------------------------------------------------------- ================================================================================ gajim-0.14.1-1.fc13 (FEDORA-2010-16806) Jabber client written in PyGTK -------------------------------------------------------------------------------- Update Information: Gajim 0.14.1 is a bugfix release: * Fix changing account name * Fix sending XHTML * Fix some GPG bugs * Minor bugfixes Full list of closed bugs: `http://trac.gajim.org/query?status=closed&milestone=0.14.1` -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 26 2010 Michal Schmidt <mschmidt@xxxxxxxxxx> 0.14.1-1 - Upstream bugfix release. - Dropped merged patches. -------------------------------------------------------------------------------- ================================================================================ gnome-settings-daemon-2.30.1-9.fc13 (FEDORA-2010-16752) The daemon sharing settings from GNOME to GTK+/KDE applications -------------------------------------------------------------------------------- Update Information: This update fixes the status of mouse keys and other accessibility settings when keyboards are plugged in. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Bastien Nocera <bnocera@xxxxxxxxxx> 2.30.1-9 - Apply a11y settings to newly plugged keyboards as well (#647022) -------------------------------------------------------------------------------- References: [ 1 ] Bug #647022 - mousekeys not re-enabled if keyboard is unplugged and plugged back in https://bugzilla.redhat.com/show_bug.cgi?id=647022 -------------------------------------------------------------------------------- ================================================================================ hosts3d-1.13-1.fc13 (FEDORA-2010-16810) 3D real-time network visualiser -------------------------------------------------------------------------------- Update Information: hosts3d-1.13-1.fc13 1.11 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 30 2010 Simon Wesp <cassmodiah@xxxxxxxxxxxxxxxxx> - 1.13-1 - New upstream release * Wed Jul 14 2010 Simon Wesp <cassmodiah@xxxxxxxxxxxxxxxxx> - 1.12-1 - New upstream release * Fri Jul 2 2010 Simon Wesp <cassmodiah@xxxxxxxxxxxxxxxxx> - 1.11-1 - New upstream release * Sun Jun 27 2010 Simon Wesp <cassmodiah@xxxxxxxxxxxxxxxxx> - 1.10-1 - New upstream release * Sat Jun 12 2010 Simon Wesp <cassmodiah@xxxxxxxxxxxxxxxxx> - 1.09-1 - New upstream release * Thu Feb 11 2010 Simon Wesp <cassmodiah@xxxxxxxxxxxxxxxxx> - 1.08-1 - New upstream release -------------------------------------------------------------------------------- ================================================================================ httpd-2.2.17-1.fc13.1 (FEDORA-2010-16832) Apache HTTP Server -------------------------------------------------------------------------------- Update Information: This update contains the latest stable release of Apache httpd. Changes in this update include: * prefork: work around a bug which could cause crashes at process shutdown * mod_reqtimeout: fix handling of timeouts for proxy backend connections * fixes for use of output filters in sub-requests which trigger an internal redirect * mod_ssl: fix for a possible output corruption bug For further details, see http://www.apache.org/dist/httpd/CHANGES_2.2.17 -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Joe Orton <jorton@xxxxxxxxxx> - 2.2.17-1.1 - fix build * Wed Oct 27 2010 Joe Orton <jorton@xxxxxxxxxx> - 2.2.17-1 - update to 2.2.17 * Fri Sep 17 2010 Joe Orton <jorton@xxxxxxxxxx> - 2.2.16-1.1 - add fix for PR 45444 (#634905) * Fri Sep 10 2010 Joe Orton <jorton@xxxxxxxxxx> - 2.2.16-2 - link everything using -z relro and -z now -------------------------------------------------------------------------------- References: [ 1 ] Bug #634905 - SVN OPTIONS / memcpy problem https://bugzilla.redhat.com/show_bug.cgi?id=634905 -------------------------------------------------------------------------------- ================================================================================ ibus-anthy-1.2.4-2.fc13 (FEDORA-2010-16722) The Anthy engine for IBus input platform -------------------------------------------------------------------------------- Update Information: Bug 644771 - ibus-anthy [F7] key cannot work with SEGV -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 26 2010 Takao Fujiwara <tfujiwar@xxxxxxxxxx> - 1.2.4-2 - Updated to 1.2.4 - Resolves #644771 ibus-anthy [F7] key cannot work with SEGV -------------------------------------------------------------------------------- References: [ 1 ] Bug #644771 - ibus-anthy [F7] key cannot work with SEGV https://bugzilla.redhat.com/show_bug.cgi?id=644771 -------------------------------------------------------------------------------- ================================================================================ kobo-0.3.2-1.fc13 (FEDORA-2010-16759) Python modules for tools development -------------------------------------------------------------------------------- Update Information: new upstream version fix xmlrpc transports for py2.5 and 2.6 bump to new upstream version bump to new upstream version bump to new upstream version bump to new upstream version -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Daniel Mach <dmach@xxxxxxxxxx> - 0.3.2-1 - Fix XML-RPC transports to make them work in py2.5 and py2.6. (Daniel Mach) - Automatically scroll the task log window when we're at the bottom of the page. (Daniel Mach) - Show self.* attributes in extended tracebacks. (Daniel Mach) - Compress logs with gzip when a task finishes. (Daniel Mach) - Convert task logs to utf8 (with "replace" option) to prevent raising UnicodeDecodeError during template processing. (Daniel Mach) * Tue Oct 19 2010 Daniel Mach <dmach@xxxxxxxxxx> - 0.3.1-1 - Add help-admin command to display help for admin commands. (Daniel Mach) - Add config parser support for glob matching on dict keys. (Tomas Kopecek) - Implement timeout support in xmlrpc transports. (Daniel Mach) - Improve kobo.xmlrpc.CookieTransport to work with python 2.7 as well. (Daniel Mach) - Add kobo-admin utility. (Martin Bukatovic) - Add missing HttpResponseForbidden import to kobo.hub.views. (Daniel Mach) - Fix bug in "Show only my tasks" search option on Tasks page. (Daniel Mach) -------------------------------------------------------------------------------- ================================================================================ moodle-1.9.10-1.fc13 (FEDORA-2010-16782) A Course Management System -------------------------------------------------------------------------------- Update Information: Fixes security vulnerability in YUI. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 26 2010 Jon Ciesla <limb@xxxxxxxxxxxx> - 1.9.10-1 - New upstream, MSA-10-0017. - htmlpurifier patch upstreamed. -------------------------------------------------------------------------------- References: [ 1 ] Bug #646660 - moodle: XSS vuln in embedded YUI (MSA-10-0017) https://bugzilla.redhat.com/show_bug.cgi?id=646660 -------------------------------------------------------------------------------- ================================================================================ nagios-3.2.3-2.fc13 (FEDORA-2010-16840) Nagios monitors hosts and services and yells if somethings breaks -------------------------------------------------------------------------------- Update Information: * Added accidentally missing patches -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> - 3.2.3-2 - Accidentally forgotten patches added back * Tue Oct 26 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> - 3.2.3-1 - Ver. 3.2.3 - Further cleanups in spec-file * Wed Sep 29 2010 jkeating - 3.2.2-2 - Rebuilt for gcc bug 634757 -------------------------------------------------------------------------------- ================================================================================ osmo-0.2.10-2.fc13 (FEDORA-2010-16799) Personal organizer -------------------------------------------------------------------------------- Update Information: This update brings back the address book, fixes the notification sounds and enables the backup feature. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Christoph Wickert <cwickert@xxxxxxxxxxxxxxxxx> - 0.2.10-2 - BR gtkhtml2-devel for contacts (#644169) - BR libtar for backup feature - Add patch for aplay and require alsa-utils -------------------------------------------------------------------------------- References: [ 1 ] Bug #644169 - No Contact tab https://bugzilla.redhat.com/show_bug.cgi?id=644169 -------------------------------------------------------------------------------- ================================================================================ publican-redhat-2.6-0.fc13 (FEDORA-2010-16748) Common documentation files for RedHat -------------------------------------------------------------------------------- Update Information: * Wed Oct 27 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.6-0 - Change docs URL to docs.redhat.com per Mike Hideo-Smith <mhideo@xxxxxxxxxx> * Fri Oct 8 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.4-0 - Updated Italian translation Francesco Valente <fvalen@xxxxxxxxxx> - rm fuzzies caused by BZ #628266 previously" -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.6-0 - Change docs URL to docs.redhat.com per Mike Hideo-Smith <mhideo@xxxxxxxxxx> -------------------------------------------------------------------------------- ================================================================================ qtparted-0.4.5-25.fc13 (FEDORA-2010-16801) Partition Magic clone written in C++ using the Qt toolkit -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Steven Pritchard <steve@xxxxxxxxx> 0.4.5-25 - Patch for "Cannot get parted version" bug (#585263). * Fri Apr 2 2010 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> - 0.4.5-24 - Rebuild for new parted (2.2) -------------------------------------------------------------------------------- References: [ 1 ] Bug #585263 - qtparted fails to start https://bugzilla.redhat.com/show_bug.cgi?id=585263 -------------------------------------------------------------------------------- ================================================================================ selinux-policy-3.7.19-69.fc13 (FEDORA-2010-16856) SELinux policy configuration -------------------------------------------------------------------------------- Update Information: - Allow system_mail_t to append ~/dead.letter - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles - gpm needs to use the user terminal - Fixes for sandbox policy - Allow chromium-browser to read gnome homedir content - Fix httpd_setrlimit boolean to allow sys_resource capability - Allow lowatch to use zz-disk_space logwatch script - Fix label for ip6tables.save - Allow ssh_t to exec ssh_exec_t -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 26 2010 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.7.19-69 - Dontaudit init leaks * Mon Oct 25 2010 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.7.19-68 - Fix httpd_setrlimit boolean to allow sys_resource capability - Allow lowatch to use zz-disk_space logwatch script - Fix label for ip6tables.save - Allow ssh_t to exec ssh_exec_t * Mon Oct 18 2010 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.7.19-67 - Fixes for sandbox policy - Allow chromium-browser to read gnome homedir content * Wed Oct 13 2010 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.7.19-66 - Allow system_mail_t to append ~/dead.letter - Allow mount to communicate with gfs_controld - Dontaudit hal leaks in setfiles - gpm needs to use the user terminal -------------------------------------------------------------------------------- References: [ 1 ] Bug #641463 - SELinux is preventing /sbin/setfiles "read" access on /var/run/pm-utils/network/dhclient.suspend. https://bugzilla.redhat.com/show_bug.cgi?id=641463 [ 2 ] Bug #641608 - gpm support in mc doesn't work https://bugzilla.redhat.com/show_bug.cgi?id=641608 [ 3 ] Bug #641176 - Selinux does not allow dnsmasq reading /var/run/ppp/resolv.conf file. https://bugzilla.redhat.com/show_bug.cgi?id=641176 [ 4 ] Bug #642330 - SELinux verhindert /bin/login "write" Zugriff on agent.4764. https://bugzilla.redhat.com/show_bug.cgi?id=642330 [ 5 ] Bug #643207 - SELinux is preventing /usr/lib/chromium-browser/chromium-browser "read" access on chromium. https://bugzilla.redhat.com/show_bug.cgi?id=643207 -------------------------------------------------------------------------------- ================================================================================ tzdata-2010n-1.fc13 (FEDORA-2010-16820) Timezone data -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Petr Machata <pmachata@xxxxxxxxxx> - 2010n-1 - Upstream 2010m: - Hong Kong didn't observe DST in 1977 - In zone.tab, remove obsolete association of Vostok Station with South Magnetic Pole; add association with Lake Vostok - Upstream 2010n: - Change end of DST in Samoa in 2011 from 2011-04-03 0:00 to 2011-04-03 1:00 * Mon Aug 16 2010 Petr Machata <pmachata@xxxxxxxxxx> - 2010l-2 - Upstream 2010l: - Change Cairo's 2010 reversion to DST from the midnight between September 8 and 9 to the midnight between September 9 and 10. - Change Gaza's 2010 return to standard time to the midnight between August 10 and 11. - Bahia de Banderas (Mexican state of Nayarit) changed time zone UTC-7 to new time zone UTC-6 on April 4, 2010 -------------------------------------------------------------------------------- ================================================================================ unuran-1.8.0-1.fc13 (FEDORA-2010-16785) Universal Non-Uniform Random number generator -------------------------------------------------------------------------------- Update Information: see NEWS -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Neal Becker <ndbecker2@xxxxxxxxx> - 1.8.0-1 - update to 1.8.0 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test