The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc14 https://admin.fedoraproject.org/updates/socat-1.7.1.3-1.fc14 https://admin.fedoraproject.org/updates/mod_auth_mysql-3.0.0-12.fc14 https://admin.fedoraproject.org/updates/chm2pdf-0.9.1-9.fc14 https://admin.fedoraproject.org/updates/wireshark-1.4.3-1.fc14 https://admin.fedoraproject.org/updates/hplip-3.10.9-14.fc14 https://admin.fedoraproject.org/updates/myproxy-5.3-1.fc14 https://admin.fedoraproject.org/updates/proftpd-1.3.3d-1.fc14 https://admin.fedoraproject.org/updates/tor-0.2.1.29-1400.fc14 https://admin.fedoraproject.org/updates/perl-CGI-Simple-1.113-1.fc14 https://admin.fedoraproject.org/updates/perl-CGI-3.51-1.fc14 https://admin.fedoraproject.org/updates/exim-4.72-2.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/openldap-2.4.23-6.fc14 https://admin.fedoraproject.org/updates/selinux-policy-3.9.7-25.fc14 https://admin.fedoraproject.org/updates/glibc-2.13-1 https://admin.fedoraproject.org/updates/dmidecode-2.11-1.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-geode-2.11.11-2.fc14 The following builds have been pushed to Fedora 14 updates-testing cambozola-0.92-2.fc14 cyrus-imapd-2.3.16-7.fc14 dolphin-connector-1.0-4.fc14 graphviz-2.26.3-1.fc14 groff-1.20.1-3.fc14 openldap-2.4.23-6.fc14 openoffice.org-3.3.0-20.1.fc14 perl-CGI-3.51-1.fc14 perl-CGI-Simple-1.113-1.fc14 perl-Class-Autouse-2.00-1.fc14 perl-Mail-MboxParser-0.55-2.fc14 perl-String-Similarity-1.04-2.fc14 php-phpunit-PHPUnit-3.5.10-1.fc14 php-phpunit-PHPUnit-MockObject-1.0.6-1.fc14 php-phpunit-PHPUnit-Selenium-1.0.2-1.fc14 php-symfony-symfony-1.4.8-2.fc14 publican-jboss-2.4-1.fc14 publican-redhat-2.7-1.fc14 rsibreak-0.11-1.fc14 system-config-printer-1.2.6-3.fc14 systemtap-1.4-2.fc14 tor-0.2.1.29-1400.fc14 xscreensaver-5.12-12.fc14 Details about builds: ================================================================================ cambozola-0.92-2.fc14 (FEDORA-2011-0644) A viewer for multipart jpeg streams -------------------------------------------------------------------------------- Update Information: First release of a viewer for multipart jpeg streams -------------------------------------------------------------------------------- References: [ 1 ] Bug #655496 - Review Request: cambozola - A viewer for multipart jpeg streams https://bugzilla.redhat.com/show_bug.cgi?id=655496 -------------------------------------------------------------------------------- ================================================================================ cyrus-imapd-2.3.16-7.fc14 (FEDORA-2011-0645) A high-performance mail server with IMAP, POP3, NNTP and SIEVE support -------------------------------------------------------------------------------- Update Information: - don't force sync io for all filesystems This only prevents from setting sync io, it does not unset it. So if you have to unset it manually if you use different fs than ext2 for /var : chattr -R -S /var/lib/imap/{user,quota} /var/spool/imap -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Michal Hlavinka <mhlavink@xxxxxxxxxx> - 2.3.16-7 - don't force sync io for all filesystems -------------------------------------------------------------------------------- References: [ 1 ] Bug #665309 - cyrus imapd performance low after upgrade from fedora 12 https://bugzilla.redhat.com/show_bug.cgi?id=665309 -------------------------------------------------------------------------------- ================================================================================ dolphin-connector-1.0-4.fc14 (FEDORA-2011-0652) Simple MySQL C API wrapper for C++ -------------------------------------------------------------------------------- Update Information: Dolphin Connector is a simple MySQL C API wrapper for C++. It is originally designed to be as efficient as is possible, and makes no use of exceptions. -------------------------------------------------------------------------------- References: [ 1 ] Bug #668863 - Review Request: dolphin-connector - Simple MySQL C API wrapper for C++ https://bugzilla.redhat.com/show_bug.cgi?id=668863 -------------------------------------------------------------------------------- ================================================================================ graphviz-2.26.3-1.fc14 (FEDORA-2011-0663) Graph Visualization Tools -------------------------------------------------------------------------------- Update Information: This is a new version of graphviz package that fixes several bugs. For full list of bugs fixed by upstream please see ChangeLog in source package. -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 6 2011 Jaroslav Åkarvada <jskarvad@xxxxxxxxxx> - 2.26.3-1 - New version (#580017) - Fixed gtk plugin program-name (#640671, gtk-progname patch) - Fixed broken links in doc index (#642536, doc-index-fix patch) - Fixed SIGSEGVs on testsuite (#645703, testsuite-sigsegv-fix patch) - Testsuite now do diff check also in case of err output (#645703, rtest-errout-fix patch) - Testsuite enabled on all arches (#645703) - Added urw-fonts to BuildRequires - Compiled with -fno-strict-aliasing - Fixed rpmlint warnings on spec file - Removed unused patches -------------------------------------------------------------------------------- References: [ 1 ] Bug #580017 - graphviz-2.26.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=580017 [ 2 ] Bug #640671 - Missing program name in DotEdit: Help -> About https://bugzilla.redhat.com/show_bug.cgi?id=640671 [ 3 ] Bug #642536 - Broken links in HTML documentation https://bugzilla.redhat.com/show_bug.cgi?id=642536 [ 4 ] Bug #645703 - Enable and fix testsuite in graphviz https://bugzilla.redhat.com/show_bug.cgi?id=645703 [ 5 ] Bug #507982 - Doxygen causes slightly different images on i386 and x86_64 https://bugzilla.redhat.com/show_bug.cgi?id=507982 -------------------------------------------------------------------------------- ================================================================================ groff-1.20.1-3.fc14 (FEDORA-2011-0641) A document formatting system -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 1.20.1-3 - fix: bad character definition error on some manual pages (#665535) - fix: sigabrt in troff when raising error from make_node (#670580) - fix: a few manual pages typos -------------------------------------------------------------------------------- References: [ 1 ] Bug #665535 - /usr/share/groff/1.20.1/tmac/doc.tmac:3375: bad character definition https://bugzilla.redhat.com/show_bug.cgi?id=665535 [ 2 ] Bug #670580 - [abrt] groff-1.20.1-2.fc14: assertion_failed: Process /usr/bin/troff was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=670580 -------------------------------------------------------------------------------- ================================================================================ openldap-2.4.23-6.fc14 (FEDORA-2011-0651) LDAP support libraries -------------------------------------------------------------------------------- Update Information: - initscript: slaptest with '-u' to skip database opening (#667768) - fix: verification of self issued certificates (#657984) - removed slurpd options from sysconfig/ldap -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 20 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 2.4.23-6 - fix: some server certificates refused with inadequate type error (#668899) - fix: default encryption strength dropped in switch to using NSS (#669446) * Thu Jan 6 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 2.4.23-5 - initscript: slaptest with '-u' to skip database opening (#667768) - removed slurpd options from sysconfig/ldap - fix: verification of self issued certificates (#657984) -------------------------------------------------------------------------------- References: [ 1 ] Bug #669446 - Default encryption strength dropped in switch to using NSS https://bugzilla.redhat.com/show_bug.cgi?id=669446 [ 2 ] Bug #668899 - some server certificates refused with inadequate type error https://bugzilla.redhat.com/show_bug.cgi?id=668899 [ 3 ] Bug #667768 - Init script is working wrong if database recovery is needed https://bugzilla.redhat.com/show_bug.cgi?id=667768 [ 4 ] Bug #657984 - openldap does not trust certs with Basic Constraint ext. with CA == FALSE https://bugzilla.redhat.com/show_bug.cgi?id=657984 -------------------------------------------------------------------------------- ================================================================================ openoffice.org-3.3.0-20.1.fc14 (FEDORA-2011-0632) OpenOffice.org comprehensive office suite -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 19 2011 CaolÃn McNamara <caolanm@xxxxxxxxxx>- 1:3.3.0-20.1 - Resolves: rhbz#668349 Backport replace libegg with gtkStatusicon - latest milestone -------------------------------------------------------------------------------- References: [ 1 ] Bug #668349 - OpenOffice.org icon background should be transparent https://bugzilla.redhat.com/show_bug.cgi?id=668349 -------------------------------------------------------------------------------- ================================================================================ perl-CGI-3.51-1.fc14 (FEDORA-2011-0640) Handle Common Gateway Interface requests and responses -------------------------------------------------------------------------------- Update Information: Update to version 3.51, extending the fix for CVE-2010-2761. -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 20 2011 Marcela MaÅlÃÅovà <mmaslano@xxxxxxxxxx> 3.51-1 - update to fix CVE-2010-2761 -------------------------------------------------------------------------------- References: [ 1 ] Bug #657950 - perl-5.12.2/CGI-3.50 security update https://bugzilla.redhat.com/show_bug.cgi?id=657950 -------------------------------------------------------------------------------- ================================================================================ perl-CGI-Simple-1.113-1.fc14 (FEDORA-2011-0653) Simple totally OO CGI interface that is CGI.pm compliant -------------------------------------------------------------------------------- Update Information: Update to 1.113 and apply additional patch to resolve CVE-2010-4410. Fix boundary to use randomized value as opposed to hardcoded value. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.113-1 - Update to 1.113, apply additional patch to fully resolve CVE-2010-4411 * Wed Dec 1 2010 Tom "spot" Callaway <tcallawa@xxxxxxxxxx> - 1.112-2 - patch for randomizing boundary (bz 658973) -------------------------------------------------------------------------------- References: [ 1 ] Bug #658976 - perl-CGI, perl-CGI-Simple: CVE-2010-2761 -- hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, CVE-2010-4410 -- CRLF injection vulnerability in the header function https://bugzilla.redhat.com/show_bug.cgi?id=658976 [ 2 ] Bug #658970 - perl-CGI-Simple: CRLF injection vulnerability via a crafted URL https://bugzilla.redhat.com/show_bug.cgi?id=658970 -------------------------------------------------------------------------------- ================================================================================ perl-Class-Autouse-2.00-1.fc14 (FEDORA-2011-0661) Run-time class loading on first method call -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Ralf CorsÃpius <corsepiu@xxxxxxxxxxxxxxxxx> - 2.00-1 - Upstream update. - Adjust BR:'s. - Add %bcond_with xt_tests. -------------------------------------------------------------------------------- ================================================================================ perl-Mail-MboxParser-0.55-2.fc14 (FEDORA-2011-0639) Read-only access to UNIX-mailboxes -------------------------------------------------------------------------------- Update Information: This package is requirement for dspam (mentioned in bug). Details about package: http://search.cpan.org/~vparseval/Mail-MboxParser-0.55/MboxParser.pm -------------------------------------------------------------------------------- References: [ 1 ] Bug #622502 - dspam_train requires Mail::MboxParser, but it isn't listed as a dependency https://bugzilla.redhat.com/show_bug.cgi?id=622502 -------------------------------------------------------------------------------- ================================================================================ perl-String-Similarity-1.04-2.fc14 (FEDORA-2011-0638) Calculates the similarity of two strings -------------------------------------------------------------------------------- ================================================================================ php-phpunit-PHPUnit-3.5.10-1.fc14 (FEDORA-2011-0360) Regression testing framework for unit tests -------------------------------------------------------------------------------- Update Information: Upstream Changelog: PHPUnit 3.5.10 -------------- * Fixed GH-71: `PHPUnit_Framework_TestSuite::addTestFile()` has problems identifying the correct test suite. * Fixed GH-120: Printer class does not handle "file does not exist" problems correctly. * Fixed GH-125: Work around [PHP bug #47987](http://bugs.php.net/bug.php?id=47987). PHPUnit 3.5.9 ------------- * Fixed GH-17: Process Isolation breaks for global objects that implement the `Serializable` interface. * Fixed GH-64: `./` added to path to test when using PHPUnit on Windows terminal. * Fixed GH-104: Bootstrap must be relative to the current directory. PHPUnit 3.5.8 ------------- * Fixed GH-84: If no assertions are made the code should not be marked as covered. * Fixed GH-115: Make most of the attributes in `PHPUnit_Framework_TestCase` private. PHPUnit 3.5.7 ------------- * Implemented GH-103: Improved handling of deprecated PHPUnit features. * Fixed GH-100: `assertSame()` does not give useful output on misordered arrays. * Fixed GH-105: Backup of static attributes causes memory exhaustion. * The TextUI test runner now prints the normal progress output in verbose mode. PHPUnit_Selenium 1.0.2 ---------------------- * Updated for PHPUnit 3.5.8. PHPUnit_MockObject 1.0.6 ------------------------ * Fixed GH-35: Mocking undeclared methods impossible since 1.0.4. PHPUnit_MockObject 1.0.5 ------------------------ * Fixed GH-34: Mocking methods with variable parameter count impossible since 1.0.4. PHPUnit_MockObject 1.0.4 ------------------------ * Fixed GH-3: `returnCallback()` does not work for parameters that are passed by reference. Changelog, Readme and License are now provided in the package documentation. -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 20 2011 Remi Collet <Fedora@xxxxxxxxxxxxxxxxx> - 3.5.10-1 - Version 3.5.10 (stable) - API 3.5.7 (stable) * Tue Jan 18 2011 Remi Collet <Fedora@xxxxxxxxxxxxxxxxx> - 3.5.9-1 - Version 3.5.9 (stable) - API 3.5.7 (stable) * Tue Jan 11 2011 Remi Collet <Fedora@xxxxxxxxxxxxxxxxx> - 3.5.7-1 - Version 3.5.7 (stable) - API 3.5.7 (stable) - README, CHANGELOG and LICENSE are now in the tarball -------------------------------------------------------------------------------- ================================================================================ php-phpunit-PHPUnit-MockObject-1.0.6-1.fc14 (FEDORA-2011-0360) Mock Object library for PHPUnit -------------------------------------------------------------------------------- Update Information: Upstream Changelog: PHPUnit 3.5.10 -------------- * Fixed GH-71: `PHPUnit_Framework_TestSuite::addTestFile()` has problems identifying the correct test suite. * Fixed GH-120: Printer class does not handle "file does not exist" problems correctly. * Fixed GH-125: Work around [PHP bug #47987](http://bugs.php.net/bug.php?id=47987). PHPUnit 3.5.9 ------------- * Fixed GH-17: Process Isolation breaks for global objects that implement the `Serializable` interface. * Fixed GH-64: `./` added to path to test when using PHPUnit on Windows terminal. * Fixed GH-104: Bootstrap must be relative to the current directory. PHPUnit 3.5.8 ------------- * Fixed GH-84: If no assertions are made the code should not be marked as covered. * Fixed GH-115: Make most of the attributes in `PHPUnit_Framework_TestCase` private. PHPUnit 3.5.7 ------------- * Implemented GH-103: Improved handling of deprecated PHPUnit features. * Fixed GH-100: `assertSame()` does not give useful output on misordered arrays. * Fixed GH-105: Backup of static attributes causes memory exhaustion. * The TextUI test runner now prints the normal progress output in verbose mode. PHPUnit_Selenium 1.0.2 ---------------------- * Updated for PHPUnit 3.5.8. PHPUnit_MockObject 1.0.6 ------------------------ * Fixed GH-35: Mocking undeclared methods impossible since 1.0.4. PHPUnit_MockObject 1.0.5 ------------------------ * Fixed GH-34: Mocking methods with variable parameter count impossible since 1.0.4. PHPUnit_MockObject 1.0.4 ------------------------ * Fixed GH-3: `returnCallback()` does not work for parameters that are passed by reference. Changelog, Readme and License are now provided in the package documentation. -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 18 2011 Remi Collet <Fedora@xxxxxxxxxxxxxxxxx> - 1.0.6-1 - Version 1.0.6 (stable) - API 1.0.4 (stable) * Tue Jan 18 2011 Remi Collet <Fedora@xxxxxxxxxxxxxxxxx> - 1.0.5-1 - Version 1.0.5 (stable) - API 1.0.4 (stable) - CHANGELOG and LICENSE are now in the tarball -------------------------------------------------------------------------------- ================================================================================ php-phpunit-PHPUnit-Selenium-1.0.2-1.fc14 (FEDORA-2011-0360) Selenium RC integration for PHPUnit -------------------------------------------------------------------------------- Update Information: Upstream Changelog: PHPUnit 3.5.10 -------------- * Fixed GH-71: `PHPUnit_Framework_TestSuite::addTestFile()` has problems identifying the correct test suite. * Fixed GH-120: Printer class does not handle "file does not exist" problems correctly. * Fixed GH-125: Work around [PHP bug #47987](http://bugs.php.net/bug.php?id=47987). PHPUnit 3.5.9 ------------- * Fixed GH-17: Process Isolation breaks for global objects that implement the `Serializable` interface. * Fixed GH-64: `./` added to path to test when using PHPUnit on Windows terminal. * Fixed GH-104: Bootstrap must be relative to the current directory. PHPUnit 3.5.8 ------------- * Fixed GH-84: If no assertions are made the code should not be marked as covered. * Fixed GH-115: Make most of the attributes in `PHPUnit_Framework_TestCase` private. PHPUnit 3.5.7 ------------- * Implemented GH-103: Improved handling of deprecated PHPUnit features. * Fixed GH-100: `assertSame()` does not give useful output on misordered arrays. * Fixed GH-105: Backup of static attributes causes memory exhaustion. * The TextUI test runner now prints the normal progress output in verbose mode. PHPUnit_Selenium 1.0.2 ---------------------- * Updated for PHPUnit 3.5.8. PHPUnit_MockObject 1.0.6 ------------------------ * Fixed GH-35: Mocking undeclared methods impossible since 1.0.4. PHPUnit_MockObject 1.0.5 ------------------------ * Fixed GH-34: Mocking methods with variable parameter count impossible since 1.0.4. PHPUnit_MockObject 1.0.4 ------------------------ * Fixed GH-3: `returnCallback()` does not work for parameters that are passed by reference. Changelog, Readme and License are now provided in the package documentation. -------------------------------------------------------------------------------- ChangeLog: * Tue Jan 18 2011 Remi Collet <Fedora@xxxxxxxxxxxxxxxxx> - 1.0.2-1 - Version 1.0.2 (stable) - API 1.0.0 (stable) - CHANGELOG and LICENSE are now in the tarball -------------------------------------------------------------------------------- ================================================================================ php-symfony-symfony-1.4.8-2.fc14 (FEDORA-2011-0648) Open-Source PHP Web Framework -------------------------------------------------------------------------------- Update Information: initial import of symfony 1.4.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #517191 - Review Request: php-symfony-symfony - Open-Source PHP Web Framework https://bugzilla.redhat.com/show_bug.cgi?id=517191 -------------------------------------------------------------------------------- ================================================================================ publican-jboss-2.4-1.fc14 (FEDORA-2011-0656) Common documentation files for JBoss -------------------------------------------------------------------------------- Update Information: Remove max_image_width -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.4-1 - remove max_image_width -------------------------------------------------------------------------------- ================================================================================ publican-redhat-2.7-1.fc14 (FEDORA-2011-0633) Common documentation files for RedHat -------------------------------------------------------------------------------- Update Information: Removes max_image_width restriction -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 19 2011 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.7-1 - correct Requires: and BuildRequires: * Wed Jan 19 2011 RÃdiger Landmann <r.landmann@xxxxxxxxxx> 2.7-0 - rm max_image_width override per BZ#662584 -------------------------------------------------------------------------------- References: [ 1 ] Bug #662584 - RedHat brand restricts images to 444px https://bugzilla.redhat.com/show_bug.cgi?id=662584 -------------------------------------------------------------------------------- ================================================================================ rsibreak-0.11-1.fc14 (FEDORA-2011-0655) A small utility which bothers you at certain intervals -------------------------------------------------------------------------------- Update Information: Fixes a lot of bugs from older RSIBreak versions, especially working with multiple screens was completely broken, buggy screenshots from the system tray, make the timers work for Qt=>4.4, etc. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Tom Albers <toma@xxxxxxx> - 0.11-1 - New upstream version -------------------------------------------------------------------------------- References: [ 1 ] Bug #631223 - FTBFS rsibreak-0.10-3.fc14 https://bugzilla.redhat.com/show_bug.cgi?id=631223 -------------------------------------------------------------------------------- ================================================================================ system-config-printer-1.2.6-3.fc14 (FEDORA-2011-0513) A printer administration tool -------------------------------------------------------------------------------- Update Information: New upstream release that fixes several bugs. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Jiri Popelka <jpopelka@xxxxxxxxxx> 1.2.6-3 - Fixed driver selection when there are duplicate PPDs available. (#667571) - Grabbing focus for editing breaks it (bug #650995). * Tue Jan 18 2011 Jiri Popelka <jpopelka@xxxxxxxxxx> 1.2.6-2 - Allow %, ( and ) characters in dnssd URI (bug #669820). * Mon Jan 17 2011 Jiri Popelka <jpopelka@xxxxxxxxxx> 1.2.6-1 - 1.2.6: - Remove reference to current printer on exit (bug #556548). - Handle cups.Connection() failure in PrinterURIIndexr (bug #648014). - Block unwanted characters when editing queue name (bug #658550). - Initialise D-Bus threading in timedops module (bug #662047). - many other fixes -------------------------------------------------------------------------------- References: [ 1 ] Bug #648014 - [abrt] system-config-printer-1.2.4-1.fc13: jobviewer.py:125:_map_printer:RuntimeError: failed to connect to server https://bugzilla.redhat.com/show_bug.cgi?id=648014 [ 2 ] Bug #650995 - [Compiz] Unable to rename printer https://bugzilla.redhat.com/show_bug.cgi?id=650995 [ 3 ] Bug #658550 - Spaces in printer name get removed https://bugzilla.redhat.com/show_bug.cgi?id=658550 [ 4 ] Bug #662047 - troubleshooter uses D-Bus from two threads https://bugzilla.redhat.com/show_bug.cgi?id=662047 [ 5 ] Bug #667571 - Did something change my CUPS driver from Postscript to pxlmono? https://bugzilla.redhat.com/show_bug.cgi?id=667571 [ 6 ] Bug #668127 - [abrt] system-config-printer-1.2.5-8.fc14: system-config-printer.py:5634:entry_changed:UnicodeDecodeError: 'utf8' codec can't decode byte 0xaa in position 52: invalid start byte https://bugzilla.redhat.com/show_bug.cgi?id=668127 [ 7 ] Bug #669820 - dnssd unable to resolve URI for HP network printer https://bugzilla.redhat.com/show_bug.cgi?id=669820 -------------------------------------------------------------------------------- ================================================================================ systemtap-1.4-2.fc14 (FEDORA-2011-0657) Instrumentation System -------------------------------------------------------------------------------- Update Information: Updates to upstream release 1.4, plus subsequent <sys/sdt.h> fixes -------------------------------------------------------------------------------- ChangeLog: * Wed Jan 19 2011 Stan Cox <scox@xxxxxxxxxx> - 1.4-2 - sdt fixes * Mon Jan 17 2011 Frank Ch. Eigler <fche@xxxxxxxxxx> - 1.4-1 - Upstream release. * Tue Dec 7 2010 Dan HorÃk <dan[at]danny.cz> - 1.3-4 - publican now needs a versioned BR (see /usr/bin/publican for details) -------------------------------------------------------------------------------- References: [ 1 ] Bug #670646 - Markers using %rbx register incorrectly masked to low byte https://bugzilla.redhat.com/show_bug.cgi?id=670646 -------------------------------------------------------------------------------- ================================================================================ tor-0.2.1.29-1400.fc14 (FEDORA-2011-0642) Anonymizing overlay network for TCP (The onion router) -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 17 2011 Enrico Scholz <enrico.scholz@xxxxxxxxxxxxxxxxxxxxxxxxx> - 0.2.1.29-1400 - updated to 0.2.1.29 (SECURITY) - CVE-2011-0427: heap overflow bug, potential remote code execution -------------------------------------------------------------------------------- References: [ 1 ] Bug #671259 - CVE-2011-0015 CVE-2011-0016 CVE-2011-0427 CVE-2011-0490 CVE-2011-0491 CVE-2011-0492 CVE-2011-0493 tor: multiple security flaws fixed in 0.2.1.29 https://bugzilla.redhat.com/show_bug.cgi?id=671259 -------------------------------------------------------------------------------- ================================================================================ xscreensaver-5.12-12.fc14 (FEDORA-2011-0643) X screen saver and locker -------------------------------------------------------------------------------- Update Information: It is found that currently webcollage and vidwhacker don't show any pictures on root window. This new rpm will fix this issue. -base subpackage installs scripts which are only used by hacks included in -{gl-}extras subpackages and actually not needed in -base subpackage, and the scripts add unwanted perl dependency on -base subpackage. This new package will remove unneeded dependency from -base subpackage. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 21 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxxxx> - 1:5.12-12 - Make webcollage work again (for newer gdk-pixbuf) - Fix vidwhacker also * Tue Jan 11 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxxxx> - 1:5.12-10 - From F-14+ (not for F-13), kill perl dependency on -base, move hack related files to -extras-base (bug 668427) -------------------------------------------------------------------------------- References: [ 1 ] Bug #668427 - dependency to perl from base package https://bugzilla.redhat.com/show_bug.cgi?id=668427 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test