The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/perl-IO-Socket-SSL-1.37-1.fc14 https://admin.fedoraproject.org/updates/libwmf-0.2.8.4-27.fc14 https://admin.fedoraproject.org/updates/seamonkey-2.0.11-1.fc14 https://admin.fedoraproject.org/updates/eclipse-3.6.1-6.1.fc14 https://admin.fedoraproject.org/updates/git-1.7.3.4-1.fc14 https://admin.fedoraproject.org/updates/drupal-views-6.x.2.12-1.fc14 https://admin.fedoraproject.org/updates/collectd-4.9.4-1.fc14 https://admin.fedoraproject.org/updates/php-5.3.4-1.fc14.1,php-eaccelerator-0.9.6.1-3.fc14,maniadrive-1.2-23.fc14 https://admin.fedoraproject.org/updates/ImageMagick-6.6.4.1-15.fc14 https://admin.fedoraproject.org/updates/perl-CGI-Simple-1.112-2.fc14 https://admin.fedoraproject.org/updates/exim-4.72-2.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/koji-1.6.0-1.fc14 https://admin.fedoraproject.org/updates/kernel-2.6.35.10-68.fc14 https://admin.fedoraproject.org/updates/selinux-policy-3.9.7-18.fc14 https://admin.fedoraproject.org/updates/cronie-1.4.5-4.fc14 https://admin.fedoraproject.org/updates/python-decorator-3.2.1-1.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-geode-2.11.10-1.fc14 The following builds have been pushed to Fedora 14 updates-testing alienarena-7.50-1.fc14 alienarena-data-20101216-1.fc14 cciss_vol_status-1.09-1.fc14 fuse-emulator-1.0.0-1.fc14 fuse-emulator-utils-1.0.0-1.fc14 ghc-failure-0.1.0.1-1.fc14 ghc-neither-0.1.0-1.fc14 koji-1.6.0-1.fc14 libspectrum-1.0.0-1.fc14 perl-DateTime-Format-HTTP-0.40-1.fc14 perl-IO-Socket-SSL-1.37-1.fc14 perl-common-sense-3.3-1.fc14 python-migrate0.5-0.5.3-7.fc14 rhythmbox-0.13.2-1.fc14 root-5.28.00-1.fc14 rubygem-boxgrinder-build-fedora-os-plugin-0.0.5-1.fc14 springlobby-0.118-1.fc14 tomcatjss-2.0.0-1.fc14 xmlstarlet-1.0.3-1.fc14 xrootd-3.0.0-1.fc14 zbar-0.10-6.fc14 Details about builds: ================================================================================ alienarena-7.50-1.fc14 (FEDORA-2010-19060) Multiplayer retro sci-fi deathmatch game -------------------------------------------------------------------------------- Update Information: Update Alien Arena to 2011 (7.50). Major 7.50 features: 1. Ragdoll physics using the Open Dynamics Physics Engine 2. Implementation of AutoTools 3. Extensive re-write of in-game IRC client 4. Two brand new maps - Annihilation and Neptune 5. Player models and skins updated 6. Fixed LOD meshes for all player models 7. Added alphamasking to ppl lit BSP surfaces 8. Fixed dodge-chaining exploit 9. Extensive code cleanup in many areas 10. Faster particle rendering 11. Updated MacPorts build 12. Fixed bugs with exiting vehicles 13. TTF fonts for console and game messages 14. Fixed issues with colored names and kick/ban routines 15. Reworked auto-bot kick and auto team balancing 16. Fixed and cleaned up various rscript issues 17. Option to replace vehicle consoles with 2D HUDS 18. Listen servers automatically passworded 19. Fixed OpenAL segfaults when no devices are defined 20. Fixed precaching of base player models and their weapon models for much smoother gameplay 21. New music added for various maps 22. Fixed server issues with intermissions, and player names 23. Revamp of dm-babel 24. Updated/improved various shaders 25. Streamlining of several bsp surface renderer functions -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 16 2010 Tom "spot" Callaway <tcallawa@xxxxxxxxxx> - 7.50-1 - update to 7.50 - fix ode NAN issue -------------------------------------------------------------------------------- ================================================================================ alienarena-data-20101216-1.fc14 (FEDORA-2010-19060) Data files for Alien Arena 2011 -------------------------------------------------------------------------------- Update Information: Update Alien Arena to 2011 (7.50). Major 7.50 features: 1. Ragdoll physics using the Open Dynamics Physics Engine 2. Implementation of AutoTools 3. Extensive re-write of in-game IRC client 4. Two brand new maps - Annihilation and Neptune 5. Player models and skins updated 6. Fixed LOD meshes for all player models 7. Added alphamasking to ppl lit BSP surfaces 8. Fixed dodge-chaining exploit 9. Extensive code cleanup in many areas 10. Faster particle rendering 11. Updated MacPorts build 12. Fixed bugs with exiting vehicles 13. TTF fonts for console and game messages 14. Fixed issues with colored names and kick/ban routines 15. Reworked auto-bot kick and auto team balancing 16. Fixed and cleaned up various rscript issues 17. Option to replace vehicle consoles with 2D HUDS 18. Listen servers automatically passworded 19. Fixed OpenAL segfaults when no devices are defined 20. Fixed precaching of base player models and their weapon models for much smoother gameplay 21. New music added for various maps 22. Fixed server issues with intermissions, and player names 23. Revamp of dm-babel 24. Updated/improved various shaders 25. Streamlining of several bsp surface renderer functions -------------------------------------------------------------------------------- ChangeLog: * Thu Dec 16 2010 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> 20101216-1 - update to 20101216 (7.50) -------------------------------------------------------------------------------- ================================================================================ cciss_vol_status-1.09-1.fc14 (FEDORA-2010-19061) Show status of logical drives attached to HP Smartarray controllers -------------------------------------------------------------------------------- Update Information: Changes since 1.06 include reporting failed physical drive serial numbers, connector, box and bay, as well as optionally reporting S.M.A.R.T. predictive failures. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Joshua Roys <roysjosh@xxxxxxxxx> - 1.09-1 - update to new release -------------------------------------------------------------------------------- ================================================================================ fuse-emulator-1.0.0-1.fc14 (FEDORA-2010-19050) The Free UNIX Spectrum Emulator -------------------------------------------------------------------------------- Update Information: New upstream release. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Lucian Langa <cooly@xxxxxxxxxxxx> - 1.0.0-1 - new upstream release -------------------------------------------------------------------------------- ================================================================================ fuse-emulator-utils-1.0.0-1.fc14 (FEDORA-2010-19050) Additional utils for the Fuse spectrum emulator -------------------------------------------------------------------------------- Update Information: New upstream release. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Lucian Langa <cooly@xxxxxxxxxxxx> - 1.0.0-1 - update patch0 - new upstream release -------------------------------------------------------------------------------- ================================================================================ ghc-failure-0.1.0.1-1.fc14 (FEDORA-2010-18830) A simple type class for success/failure computations -------------------------------------------------------------------------------- Update Information: A simple type class for success/failure computations. =============== The standard Either datatype suffers from a lack of monad and applicative instances. To make matters worse, the mtl and transformers packages provide orphan instances which conflict with each other, as well as defining a transformer version which has an usually unnecessary superclass constraint. Besides these annoyances, there is another issue: there exist two reasonable definitions of the Applicative instance for Either: one the holds onto only the first Left value, or one that appends all Left values together via a Monoid instance. The former is compatible with the monad instance, while the latter is not. This package defines three datatypes, some helpers functions and instances. The data types are AEither, MEither and MEitherT. AEither provides an Applicative instance which appends Left values, MEither provides the monadic definition, and MEitherT is a monad transformer. -------------------------------------------------------------------------------- References: [ 1 ] Bug #630283 - Review Request: ghc-neither - Either with monad and applicative instances https://bugzilla.redhat.com/show_bug.cgi?id=630283 [ 2 ] Bug #630223 - Review Request: ghc-failure - A simple type class for success/failure computations https://bugzilla.redhat.com/show_bug.cgi?id=630223 -------------------------------------------------------------------------------- ================================================================================ ghc-neither-0.1.0-1.fc14 (FEDORA-2010-18830) Either with monad and applicative instances -------------------------------------------------------------------------------- Update Information: A simple type class for success/failure computations. =============== The standard Either datatype suffers from a lack of monad and applicative instances. To make matters worse, the mtl and transformers packages provide orphan instances which conflict with each other, as well as defining a transformer version which has an usually unnecessary superclass constraint. Besides these annoyances, there is another issue: there exist two reasonable definitions of the Applicative instance for Either: one the holds onto only the first Left value, or one that appends all Left values together via a Monoid instance. The former is compatible with the monad instance, while the latter is not. This package defines three datatypes, some helpers functions and instances. The data types are AEither, MEither and MEitherT. AEither provides an Applicative instance which appends Left values, MEither provides the monadic definition, and MEitherT is a monad transformer. -------------------------------------------------------------------------------- References: [ 1 ] Bug #630283 - Review Request: ghc-neither - Either with monad and applicative instances https://bugzilla.redhat.com/show_bug.cgi?id=630283 [ 2 ] Bug #630223 - Review Request: ghc-failure - A simple type class for success/failure computations https://bugzilla.redhat.com/show_bug.cgi?id=630223 -------------------------------------------------------------------------------- ================================================================================ koji-1.6.0-1.fc14 (FEDORA-2010-19055) Build system tools -------------------------------------------------------------------------------- Update Information: Update to koji 1.6.0 -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Dennis Gilmore <dennis@xxxxxxxx> - 1.6.0-1 - update to 1.6.0 * Wed Dec 1 2010 Dennis Gilmore <dennis@xxxxxxxx> - 1.5.0-1 - update to 1.5.0 -------------------------------------------------------------------------------- ================================================================================ libspectrum-1.0.0-1.fc14 (FEDORA-2010-19050) A library for reading spectrum emulator file formats -------------------------------------------------------------------------------- Update Information: New upstream release. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Lucian Langa <cooly@xxxxxxxxxxxx> - 1.0.0-1 - new upstream release -------------------------------------------------------------------------------- ================================================================================ perl-DateTime-Format-HTTP-0.40-1.fc14 (FEDORA-2010-19059) HTTP protocol date conversion routines -------------------------------------------------------------------------------- Update Information: This update fixes [RT#62332](https://rt.cpan.org/Public/Bug/Display.html?id=62332): format_isoz now actually changes the time zone. -------------------------------------------------------------------------------- ChangeLog: * Sat Dec 18 2010 Iain Arnell <iarnell@xxxxxxxxx> 0.40-1 - update to latest upstream version - clean up spec for modern rpmbuild - PERL_INSTALL_ROOT -> DESTDIR - fix up crlf in docs * Thu Dec 16 2010 Marcela Maslanova <mmaslano@xxxxxxxxxx> - 0.38-6 - 661697 rebuild for fixing problems with vendorach/lib -------------------------------------------------------------------------------- ================================================================================ perl-IO-Socket-SSL-1.37-1.fc14 (FEDORA-2010-19058) Perl library for transparent SSL -------------------------------------------------------------------------------- Update Information: This update fixes a problem whereby IO::Socket::SSL fell back to the "VERIFY_NONE" verification mode if another verification mode was defined but no valid ca_file or ca_path was provided. The updated version throws an error in that situation rather than proceeding with the connection despite being unable to verify the certificate(s) as requested. This issue was originally reported at http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=606058 -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 10 2010 Paul Howarth <paul@xxxxxxxxxxxx> - 1.37-1 - Update to 1.37 - don't complain about invalid certificate locations if user explicitly set SSL_ca_path and SSL_ca_file to undef: assume that user knows what they are doing and will work around the problems themselves (CPAN RT#63741) * Thu Dec 9 2010 Paul Howarth <paul@xxxxxxxxxxxx> - 1.36-1 - Update to 1.36 - update documentation for SSL_verify_callback based on CPAN RT#63743 and CPAN RT#63740 * Mon Dec 6 2010 Paul Howarth <paul@xxxxxxxxxxxx> - 1.35-1 - Update to 1.35 (addresses CVE-2010-4334) - if verify_mode is not VERIFY_NONE and the ca_file/ca_path cannot be verified as valid, it will no longer fall back to VERIFY_NONE but throw an error (http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=606058) * Tue Nov 2 2010 Paul Howarth <paul@xxxxxxxxxxxx> - 1.34-1 - Update to 1.34 - schema http for certificate verification changed to wildcards_in_cn=1 - if upgrading socket from inet to ssl fails due to handshake problems, the socket gets downgraded back again but is still open (CPAN RT#61466) - deprecate kill_socket: just use close() -------------------------------------------------------------------------------- References: [ 1 ] Bug #660847 - CVE-2010-4334 perl-IO-Socket-SSL: ignores user request for peer verification https://bugzilla.redhat.com/show_bug.cgi?id=660847 -------------------------------------------------------------------------------- ================================================================================ perl-common-sense-3.3-1.fc14 (FEDORA-2010-19049) "Common sense" Perl defaults -------------------------------------------------------------------------------- Update Information: This update removes a number of warnings: * removed "exiting" category * removed "substr" warning * removed "parenthesis" warning -------------------------------------------------------------------------------- ChangeLog: * Sat Dec 18 2010 Iain Arnell <iarnell@xxxxxxxxx> 3.3-1 - update to latest upstream version - clean up spec for modern rpmbuild * Wed Dec 15 2010 Marcela Maslanova <mmaslano@xxxxxxxxxx> - 3.0-3 - 661697 rebuild for fixing problems with vendorach/lib -------------------------------------------------------------------------------- ================================================================================ python-migrate0.5-0.5.3-7.fc14 (FEDORA-2010-19063) Schema migration tools for SQLAlchemy -------------------------------------------------------------------------------- Update Information: version 0.5.3 of python-migrate packaged for projects that depends on 0.5.x branch -------------------------------------------------------------------------------- ================================================================================ rhythmbox-0.13.2-1.fc14 (FEDORA-2010-19046) Music Management Application -------------------------------------------------------------------------------- Update Information: This update adds the following features. * Much improved Last.fm (and Libre.fm) plugin * New podcast sub-sources showing newly posted and recently downloaded episodes * Various fixes for iPod support And also contains a lot of bug fixes. See http://ftp.gnome.org/pub/GNOME/sources/rhythmbox/0.13/rhythmbox-0.13.2.news for details and attribution. -------------------------------------------------------------------------------- ChangeLog: * Mon Nov 1 2010 Bastien Nocera <bnocera@xxxxxxxxxx> 0.13.2-1 - Update to 0.13.2 -------------------------------------------------------------------------------- ================================================================================ root-5.28.00-1.fc14 (FEDORA-2010-19048) Numerical data analysis framework -------------------------------------------------------------------------------- Update Information: New root release 5.28.00 * New package root-genetic containing a genetic minimization module for root * New package root-graf-fitsio for using the Flexible Image Transport System (FITS) data format in root * The default for streaming the content of STL containers was changed from object-wise to member-wise * For the complete set of release notes see http://root.cern.ch/root/v528/Version528.news.html New xrootd release 3.0.0 * This version includes the FUSE (filesystem in user space) xrootd mount tool -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 15 2010 Mattias Ellert <mattias.ellert@xxxxxxxxxxxx> - 5.28.00-1 - Update to 5.28.00 - Drop patches fixed upstream: root-linker-scripts.patch, root-dpm-rfio.patch, root-missing-explicit-link.patch, root-split-latex.patch, root-cern-filename.patch, root-make-3.82.patch, root-fonttype-combobox-dtor.patch - New sub-packages: root-genetic, root-graf-fitsio, root-hist-factory, root-proof-pq2 - Make root-io a separate package again - the circular dependency with the root-core package was resolved upstream -------------------------------------------------------------------------------- ================================================================================ rubygem-boxgrinder-build-fedora-os-plugin-0.0.5-1.fc14 (FEDORA-2010-19042) Fedora Operating System Plugin -------------------------------------------------------------------------------- References: [ 1 ] Bug #652406 - Review Request: rubygem-boxgrinder-build-fedora-os-plugin - BoxGrinder files required to build appliances with Fedora OS https://bugzilla.redhat.com/show_bug.cgi?id=652406 -------------------------------------------------------------------------------- ================================================================================ springlobby-0.118-1.fc14 (FEDORA-2010-19039) A lobby client for the spring RTS game engine -------------------------------------------------------------------------------- Update Information: - version 118b (w/ GTK fix). - BT download should work now. -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Gilboa Davara <gilboad [at] gmail [dot] com> - 0.118-1 - version 0.118 (w/ GTK fix) - BT download should work now. * Thu Nov 18 2010 Gilboa Davara <gilboad [at] gmail [dot] com> - 0.116-1 - version 0.116 (w/ GTK fix) * Wed Sep 29 2010 jkeating - 0.101-2 - Rebuilt for gcc bug 634757 * Wed Sep 15 2010 Aurelien Bompard <abompard@xxxxxxxxxxxxxxxxx> - 0.101-1 - version 0.101 -------------------------------------------------------------------------------- References: [ 1 ] Bug #663422 - [abrt] springlobby-0.116-1.fc14: Process /usr/bin/springlobby was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=663422 [ 2 ] Bug #633472 - [abrt] springlobby-0.95-1.fc13: x86_fallback_frame_state: Process /usr/bin/springlobby was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=633472 [ 3 ] Bug #642633 - [abrt] springlobby-0.95-1.fc13: raise: Process /usr/bin/springlobby was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=642633 [ 4 ] Bug #654840 - RFE: Please upgrade to .116. (patch attached). https://bugzilla.redhat.com/show_bug.cgi?id=654840 [ 5 ] Bug #629961 - [abrt] springlobby-0.95-1.fc13: raise: Process /usr/bin/springlobby was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=629961 [ 6 ] Bug #636374 - [abrt] springlobby-0.95-1.fc13: Process /usr/bin/springlobby was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=636374 [ 7 ] Bug #653174 - [abrt] springlobby-0.95-1.fc13: raise: Process /usr/bin/springlobby was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=653174 -------------------------------------------------------------------------------- ================================================================================ tomcatjss-2.0.0-1.fc14 (FEDORA-2010-19040) JSSE implementation using JSS for Tomcat -------------------------------------------------------------------------------- Update Information: use tomcat6 for tomcatjss -------------------------------------------------------------------------------- References: [ 1 ] Bug #658188 - remove remaining references to tomcat5 https://bugzilla.redhat.com/show_bug.cgi?id=658188 -------------------------------------------------------------------------------- ================================================================================ xmlstarlet-1.0.3-1.fc14 (FEDORA-2010-19045) Command Line XML Toolkit -------------------------------------------------------------------------------- Update Information: This update to upstream 1.0.3 fixes numerous bugs. More detailed information is available at: http://sourceforge.net/projects/xmlstar/files/xmlstarlet/1.0.3/ -------------------------------------------------------------------------------- ChangeLog: * Fri Dec 17 2010 Paul W. Frields <stickster@xxxxxxxxx> - 1.0.3-1 - Update to new upstream 1.0.3 - Add %check section for validation testing * Mon Nov 1 2010 Paul W. Frields <stickster@xxxxxxxxx> - 1.0.2-1 - Update to new upstream 1.0.2 * Sun Jan 10 2010 Paul W. Frields <stickster@xxxxxxxxx> - 1.0.1-9 - Correct source URL -------------------------------------------------------------------------------- References: [ 1 ] Bug #648185 - xmlstarlet-1.0.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=648185 -------------------------------------------------------------------------------- ================================================================================ xrootd-3.0.0-1.fc14 (FEDORA-2010-19048) Extended ROOT file server -------------------------------------------------------------------------------- Update Information: New root release 5.28.00 * New package root-genetic containing a genetic minimization module for root * New package root-graf-fitsio for using the Flexible Image Transport System (FITS) data format in root * The default for streaming the content of STL containers was changed from object-wise to member-wise * For the complete set of release notes see http://root.cern.ch/root/v528/Version528.news.html New xrootd release 3.0.0 * This version includes the FUSE (filesystem in user space) xrootd mount tool -------------------------------------------------------------------------------- ================================================================================ zbar-0.10-6.fc14 (FEDORA-2010-19064) Bar code reader -------------------------------------------------------------------------------- Update Information: Update it to the newest version available at zbar git directory; Use libv4l to communicate with video devices. -------------------------------------------------------------------------------- ChangeLog: * Sun Dec 5 2010 mchehab - 0.10-6 - Update it to the newest version available at zbar git directory - Use libv4l to communicate with video devices -------------------------------------------------------------------------------- References: [ 1 ] Bug #660172 - [RFE] Update package to use latest upstream and libv4l https://bugzilla.redhat.com/show_bug.cgi?id=660172 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test