The following Fedora 12 Security updates need testing: https://admin.fedoraproject.org/updates/bzip2-1.0.6-1.fc12 https://admin.fedoraproject.org/updates/tomcat6-6.0.26-3.fc12 https://admin.fedoraproject.org/updates/freetype-2.3.11-6.fc12 https://admin.fedoraproject.org/updates/openldap-2.4.19-6.fc12 https://admin.fedoraproject.org/updates/horde-3.3.9-1.fc12 https://admin.fedoraproject.org/updates/mailman-2.1.12-10.fc12 https://admin.fedoraproject.org/updates/gnucash-2.2.9-5.fc12 https://admin.fedoraproject.org/updates/seamonkey-2.0.9-1.fc12 https://admin.fedoraproject.org/updates/pidgin-2.7.4-1.fc12 https://admin.fedoraproject.org/updates/gif2png-2.5.1-1202.fc12 https://admin.fedoraproject.org/updates/xpdf-3.02-16.fc12 https://admin.fedoraproject.org/updates/luci-0.22.4-2.0.b9faf868074git.fc12 https://admin.fedoraproject.org/updates/cvs-1.11.23-9.fc12 https://admin.fedoraproject.org/updates/clamav-0.96.3-1200.fc12 https://admin.fedoraproject.org/updates/nss-util-3.12.8-1.fc12,nss-softokn-3.12.8-1.fc12,nss-3.12.8-2.fc12 https://admin.fedoraproject.org/updates/gnome-web-photo-0.9-10.fc12,galeon-2.0.7-26.fc12,xulrunner-1.9.1.14-1.fc12,firefox-3.5.14-1.fc12,gnome-python2-extras-2.25.3-21.fc12,perl-Gtk2-MozEmbed-0.08-6.fc12.16,mozvoikko-1.0-13.fc12 https://admin.fedoraproject.org/updates/bristol-0.40.7-7.fc12 https://admin.fedoraproject.org/updates/pyftpdlib-0.5.2-1.fc12 https://admin.fedoraproject.org/updates/thunderbird-3.0.9-1.fc12,sunbird-1.0-0.25.20090916hg.fc12 https://admin.fedoraproject.org/updates/glibc-2.11.2-3 https://admin.fedoraproject.org/updates/moodle-1.9.10-1.fc12 The following builds have been pushed to Fedora 12 updates-testing etckeeper-0.50-1.fc12 fuse-2.8.5-2.fc12 kobo-0.3.2-1.fc12 moodle-1.9.10-1.fc12 nagios-3.2.3-2.fc12 publican-redhat-2.6-0.fc12 pyftpdlib-0.5.2-1.fc12 qtparted-0.4.5-25.fc12 selinux-policy-3.6.32-125.fc12 tzdata-2010n-1.fc12 Details about builds: ================================================================================ etckeeper-0.50-1.fc12 (FEDORA-2010-16804) Store /etc in a SCM system (git, mercurial, bzr or darcs) -------------------------------------------------------------------------------- Update Information: Update to etckeeper to version 0.50. * Ignore /etc/.initctl. * Do not warn about special files or hardlinks if they are ignored by git. * Set GIT_COMMITTER_EMAIL to root@$hostname to avoid git prompting the user to configure it in .gitconfig. * Deal with strange systems that include the domain name in the hostname, by stripping it. Complete list of changes (including Debian bug numbers) can be found here: http://joey.kitenet.net/code/etckeeper/news/version_0.50/ -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Thomas Moschny <thomas.moschny@xxxxxx> - 0.50-1 - Update to 0.50. - Change %define -> %global. * Fri Sep 17 2010 Thomas Moschny <thomas.moschny@xxxxxx> - 0.49-2 - Adjust minimum required version of GIT. - egg-info files are not created automatically on RHEL5. -------------------------------------------------------------------------------- References: [ 1 ] Bug #646943 - etckeeper-0.50 is available https://bugzilla.redhat.com/show_bug.cgi?id=646943 -------------------------------------------------------------------------------- ================================================================================ fuse-2.8.5-2.fc12 (FEDORA-2010-16833) File System in Userspace (FUSE) utilities -------------------------------------------------------------------------------- Update Information: * Allow mounting FUSE fs into current directory. -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> 2.8.5-2 - Fixed rhbz #622255 * Tue Oct 26 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> 2.8.5-1 - Ver. 2.8.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #622255 - Cannot mount encfs with option allow_root on $HOME https://bugzilla.redhat.com/show_bug.cgi?id=622255 -------------------------------------------------------------------------------- ================================================================================ kobo-0.3.2-1.fc12 (FEDORA-2010-16742) Python modules for tools development -------------------------------------------------------------------------------- Update Information: new upstream version fix xmlrpc transports for py2.5 and 2.6 bump to new upstream version bump to new upstream version bump to new upstream version bump to new upstream version -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Daniel Mach <dmach@xxxxxxxxxx> - 0.3.2-1 - Fix XML-RPC transports to make them work in py2.5 and py2.6. (Daniel Mach) - Automatically scroll the task log window when we're at the bottom of the page. (Daniel Mach) - Show self.* attributes in extended tracebacks. (Daniel Mach) - Compress logs with gzip when a task finishes. (Daniel Mach) - Convert task logs to utf8 (with "replace" option) to prevent raising UnicodeDecodeError during template processing. (Daniel Mach) * Tue Oct 19 2010 Daniel Mach <dmach@xxxxxxxxxx> - 0.3.1-1 - Add help-admin command to display help for admin commands. (Daniel Mach) - Add config parser support for glob matching on dict keys. (Tomas Kopecek) - Implement timeout support in xmlrpc transports. (Daniel Mach) - Improve kobo.xmlrpc.CookieTransport to work with python 2.7 as well. (Daniel Mach) - Add kobo-admin utility. (Martin Bukatovic) - Add missing HttpResponseForbidden import to kobo.hub.views. (Daniel Mach) - Fix bug in "Show only my tasks" search option on Tasks page. (Daniel Mach) -------------------------------------------------------------------------------- ================================================================================ moodle-1.9.10-1.fc12 (FEDORA-2010-16845) A Course Management System -------------------------------------------------------------------------------- Update Information: Fixes security vulnerability in YUI. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 26 2010 Jon Ciesla <limb@xxxxxxxxxxxx> - 1.9.10-1 - New upstream, MSA-10-0017. - htmlpurifier patch upstreamed. -------------------------------------------------------------------------------- References: [ 1 ] Bug #646660 - moodle: XSS vuln in embedded YUI (MSA-10-0017) https://bugzilla.redhat.com/show_bug.cgi?id=646660 -------------------------------------------------------------------------------- ================================================================================ nagios-3.2.3-2.fc12 (FEDORA-2010-16808) Nagios monitors hosts and services and yells if somethings breaks -------------------------------------------------------------------------------- Update Information: * Added accidentally missing patches -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> - 3.2.3-2 - Accidentally forgotten patches added back * Tue Oct 26 2010 Peter Lemenkov <lemenkov@xxxxxxxxx> - 3.2.3-1 - Ver. 3.2.3 - Further cleanups in spec-file * Wed Sep 29 2010 jkeating - 3.2.2-2 - Rebuilt for gcc bug 634757 -------------------------------------------------------------------------------- ================================================================================ publican-redhat-2.6-0.fc12 (FEDORA-2010-16867) Common documentation files for RedHat -------------------------------------------------------------------------------- Update Information: * Wed Oct 27 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.6-0 - Change docs URL to docs.redhat.com per Mike Hideo-Smith <mhideo@xxxxxxxxxx> * Fri Oct 8 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.4-0 - Updated Italian translation Francesco Valente <fvalen@xxxxxxxxxx> - rm fuzzies caused by BZ #628266 previously" -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.6-0 - Change docs URL to docs.redhat.com per Mike Hideo-Smith <mhideo@xxxxxxxxxx> * Fri Oct 15 2010 Jeff Fearn <jfearn@xxxxxxxxxx> 2.5-0 - Remove example override. * Tue Oct 12 2010 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.4-1 - respin to catch English string not replaced in translated languages. -------------------------------------------------------------------------------- ================================================================================ pyftpdlib-0.5.2-1.fc12 (FEDORA-2010-16731) Python FTP server library -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 26 2010 Silas Sewell <silas@xxxxxxxxx> - 0.5.2-1 - Update to 0.5.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #646169 - CVE-2009-5011 pyftpdlib: Race condition in the FTPHandler class https://bugzilla.redhat.com/show_bug.cgi?id=646169 [ 2 ] Bug #646171 - CVE-2009-5012 pyftpdlib: Ability to list the root directory via an FTP session https://bugzilla.redhat.com/show_bug.cgi?id=646171 [ 3 ] Bug #646174 - CVE-2009-5013 pyftpdlib: DoS (memory consumption) by sending a QUIT command during a data transfer https://bugzilla.redhat.com/show_bug.cgi?id=646174 [ 4 ] Bug #646177 - CVE-2010-3494 pyftpdlib: Race condition in the FTPHandler class in ftpserver.py https://bugzilla.redhat.com/show_bug.cgi?id=646177 -------------------------------------------------------------------------------- ================================================================================ qtparted-0.4.5-25.fc12 (FEDORA-2010-16723) Partition Magic clone written in C++ using the Qt toolkit -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Steven Pritchard <steve@xxxxxxxxx> 0.4.5-25 - Patch for "Cannot get parted version" bug (#585263). * Fri Apr 2 2010 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> - 0.4.5-24 - Rebuild for new parted (2.2) * Tue Jan 12 2010 Kevin Kofler <Kevin@xxxxxxxxxxxxxxxx> - 0.4.5-23 - Rebuild for new parted (2.1) -------------------------------------------------------------------------------- References: [ 1 ] Bug #585263 - qtparted fails to start https://bugzilla.redhat.com/show_bug.cgi?id=585263 -------------------------------------------------------------------------------- ================================================================================ selinux-policy-3.6.32-125.fc12 (FEDORA-2010-16756) SELinux policy configuration -------------------------------------------------------------------------------- Update Information: - Allow logwatch to use zz-disk_space logwatch script - Allow radius setrlimit - Allow vpnc to search /root -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.6.32-125 - Allow vpnc to search /root * Tue Oct 26 2010 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.6.32-124 - Allow logwatch to use zz-disk_space logwatch script - Allow radius setrlimit -------------------------------------------------------------------------------- References: [ 1 ] Bug #646110 - SELinux nekar /usr/bin/du "getattr"-Ãtkomst on /usr/share/system-config-services/system-config-services-mechanism.py https://bugzilla.redhat.com/show_bug.cgi?id=646110 [ 2 ] Bug #643240 - SELinux is preventing /usr/sbin/radiusd "setrlimit" access. https://bugzilla.redhat.com/show_bug.cgi?id=643240 [ 3 ] Bug #576991 - openconnect policy problem with users' certificates https://bugzilla.redhat.com/show_bug.cgi?id=576991 -------------------------------------------------------------------------------- ================================================================================ tzdata-2010n-1.fc12 (FEDORA-2010-16825) Timezone data -------------------------------------------------------------------------------- ChangeLog: * Wed Oct 27 2010 Petr Machata <pmachata@xxxxxxxxxx> - 2010n-1 - Upstream 2010l: - Change Cairo's 2010 reversion to DST from the midnight between September 8 and 9 to the midnight between September 9 and 10. - Change Gaza's 2010 return to standard time to the midnight between August 10 and 11. - Bahia de Banderas (Mexican state of Nayarit) changed time zone UTC-7 to new time zone UTC-6 on April 4, 2010 - Upstream 2010m: - Hong Kong didn't observe DST in 1977 - In zone.tab, remove obsolete association of Vostok Station with South Magnetic Pole; add association with Lake Vostok - Upstream 2010n: - Change end of DST in Samoa in 2011 from 2011-04-03 0:00 to 2011-04-03 1:00 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test