The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/asterisk-1.6.2.16.1-1.fc14 https://admin.fedoraproject.org/updates/util-linux-ng-2.18-4.8.fc14 https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc14 https://admin.fedoraproject.org/updates/socat-1.7.1.3-1.fc14 https://admin.fedoraproject.org/updates/mod_auth_mysql-3.0.0-12.fc14 https://admin.fedoraproject.org/updates/postgresql-8.4.7-1.fc14 https://admin.fedoraproject.org/updates/tor-0.2.1.29-1400.fc14 https://admin.fedoraproject.org/updates/exim-4.72-2.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/hunspell-1.2.12-4.fc14 https://admin.fedoraproject.org/updates/selinux-policy-3.9.7-28.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-8.fc14 https://admin.fedoraproject.org/updates/pinentry-0.8.1-1.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-ati-6.13.1-0.4.20100705git37b348059.fc14 https://admin.fedoraproject.org/updates/python-ethtool-0.6-1.fc14 https://admin.fedoraproject.org/updates/perl-5.12.3-141.fc14 https://admin.fedoraproject.org/updates/nss-3.12.9-2.fc14 https://admin.fedoraproject.org/updates/dmidecode-2.11-1.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-geode-2.11.11-2.fc14 The following builds have been pushed to Fedora 14 updates-testing apache-commons-daemon-1.0.2-5.fc14 bangarang-2.0-1.fc14 evolution-rss-0.2.3-1.fc14 extrema-4.4.5-2.fc14 hunspell-1.2.12-4.fc14 ksh-20110131-1.fc14 openchange-0.9-11.fc14 openldap-2.4.23-8.fc14 qtcurve-gtk2-1.8.5-1.fc14 qtcurve-kde4-1.8.4-1.fc14 rubygem-flexmock-0.8.11-2.fc14 rubygem-hoe-2.9.0-1.fc14 selinux-policy-3.9.7-28.fc14 webacula-5.0.3-1.fc14 xguest-1.0.9-3.fc14 Details about builds: ================================================================================ apache-commons-daemon-1.0.2-5.fc14 (FEDORA-2011-1004) Defines API to support an alternative invocation mechanism -------------------------------------------------------------------------------- Update Information: This update fixes bug #669259 where jsvc crashed with SIGSEGV when no LD_LIBRARY_PATH was specified. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 1 2011 Stanislav Ochotnicky <sochotnicky@xxxxxxxxxx> - 1.0.2-5 - Fix bug 669259 (execve warning segfault) -------------------------------------------------------------------------------- References: [ 1 ] Bug #669259 - jsvc runtime crash when using jvm https://bugzilla.redhat.com/show_bug.cgi?id=669259 -------------------------------------------------------------------------------- ================================================================================ bangarang-2.0-1.fc14 (FEDORA-2011-0996) Media player with nepomuk support -------------------------------------------------------------------------------- Update Information: New Info View that provides helpful information about your media when you need it and integrated metadata editing and drilling. Info fetchers to help lookup additional media information for Artists, Movies, TV Shows, Actors, etc. Support for Audio and Video feeds Organize and browse media using (nepomuk) tags. Improved DVD support including support for subtitles, chapters, audio channels and angles. Embedded and external subtitle support Improved audio and video settings Bookmarks support Revamped Files and Folders support MPRIS and system tray support Shortcuts support and moreâ -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Thomas Janssen <thomasj@xxxxxxxxxxxxxxxxx> 2.0-1 - 2.0 release -------------------------------------------------------------------------------- ================================================================================ evolution-rss-0.2.3-1.fc14 (FEDORA-2011-0998) Evolution RSS Reader -------------------------------------------------------------------------------- Update Information: Update to 0.2.3, fix some blocker bugs. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 31 2011 Lucian Langa <cooly@xxxxxxxxxxxx> - 1:0.2.3-1 - new upstream release -------------------------------------------------------------------------------- References: [ 1 ] Bug #670758 - [abrt] Segfault when importing new feed https://bugzilla.redhat.com/show_bug.cgi?id=670758 -------------------------------------------------------------------------------- ================================================================================ extrema-4.4.5-2.fc14 (FEDORA-2011-0995) Extrema is a powerful visualization and data analysis tool -------------------------------------------------------------------------------- Update Information: Update to latest upstream release extrema 4.4.5. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 31 2011 Terje Rosten <terje.rosten@xxxxxxx> - 4.4.5-2 - Add patch to build with gcc 4.6 * Sun Jan 30 2011 Terje Rosten <terje.rosten@xxxxxxx> - 4.4.5-1 - 4.4.5 -------------------------------------------------------------------------------- ================================================================================ hunspell-1.2.12-4.fc14 (FEDORA-2011-1000) A spell checker and morphological analyzer library -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 CaolÃn McNamara <caolanm@xxxxxxxxxx> - 1.2.12-4 - Resolves: rhbz#673799 French spellchecking crash -------------------------------------------------------------------------------- References: [ 1 ] Bug #673799 - [abrt][fr] AffixMgr::suffix_check killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=673799 -------------------------------------------------------------------------------- ================================================================================ ksh-20110131-1.fc14 (FEDORA-2011-0484) The Original ATT Korn Shell -------------------------------------------------------------------------------- Update Information: - updated to 2011-01-27 - fixed crash caused by wrong wctrans_t size -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Michal Hlavinka <mhlavink@xxxxxxxxxx> - 20110131-1 - ksh updated to 2011-01-31 * Fri Jan 28 2011 Michal Hlavinka <mhlavink@xxxxxxxxxx> - 20110127-1 - ksh updated to 2011-01-27 * Thu Jan 20 2011 Michal Hlavinka <mhlavink@xxxxxxxxxx> - 20110118-1 - ksh updated to 2011-01-18 * Mon Jan 17 2011 Michal Hlavinka <mhlavink@xxxxxxxxxx> - 20110104-1 - ksh updated to 2011-01-04 -------------------------------------------------------------------------------- References: [ 1 ] Bug #667670 - [abrt] ksh-20110104-1.fc15: towctrans: Process /bin/ksh was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=667670 [ 2 ] Bug #664106 - Regression in ksh-20101212 https://bugzilla.redhat.com/show_bug.cgi?id=664106 -------------------------------------------------------------------------------- ================================================================================ openchange-0.9-11.fc14 (FEDORA-2011-0997) Provides access to Microsoft Exchange servers using native protocols -------------------------------------------------------------------------------- Update Information: Fixes error when trying to send a message through evolution-mapi: Error while Sending message. ModifyRecipients: MAPI error ecRpcFormat (0x4b6) occurred -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Milan Crha <mcrha@xxxxxxxxxx> - 0.9-11 - Add patch for message sending, found by Gianluca Cecchi (RH bug #674034) * Thu Dec 16 2010 Matthew Barnes <mbarnes@xxxxxxxxxx> - 0.9-10 - Re-fix man-pages file conflict (RH bug #654729). -------------------------------------------------------------------------------- References: [ 1 ] Bug #674034 - unable to send e-mail with exchange-mapi account in evolution https://bugzilla.redhat.com/show_bug.cgi?id=674034 -------------------------------------------------------------------------------- ================================================================================ openldap-2.4.23-8.fc14 (FEDORA-2011-1007) LDAP support libraries -------------------------------------------------------------------------------- Update Information: - initscript: slaptest with '-u' to skip database opening (#667768) - fix: verification of self issued certificates (#657984) - removed slurpd options from sysconfig/ldap -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 2.4.23-8 - fix update: openldap can't use TLS after a fork() (#636956) * Tue Jan 25 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 2.4.23-7 - fix: openldap can't use TLS after a fork() (#636956) - fix: openldap-server upgrade gets stuck when the database is damaged (#664433) * Thu Jan 20 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 2.4.23-6 - fix: some server certificates refused with inadequate type error (#668899) - fix: default encryption strength dropped in switch to using NSS (#669446) * Thu Jan 6 2011 Jan Vcelak <jvcelak@xxxxxxxxxx> 2.4.23-5 - initscript: slaptest with '-u' to skip database opening (#667768) - removed slurpd options from sysconfig/ldap - fix: verification of self issued certificates (#657984) -------------------------------------------------------------------------------- References: [ 1 ] Bug #636956 - openldap can't use TLS after a fork() https://bugzilla.redhat.com/show_bug.cgi?id=636956 [ 2 ] Bug #664433 - openldap-server upgrade gets stuck when the database is damaged https://bugzilla.redhat.com/show_bug.cgi?id=664433 [ 3 ] Bug #669446 - Default encryption strength dropped in switch to using NSS https://bugzilla.redhat.com/show_bug.cgi?id=669446 [ 4 ] Bug #668899 - some server certificates refused with inadequate type error https://bugzilla.redhat.com/show_bug.cgi?id=668899 [ 5 ] Bug #667768 - Init script is working wrong if database recovery is needed https://bugzilla.redhat.com/show_bug.cgi?id=667768 [ 6 ] Bug #657984 - openldap does not trust certs with Basic Constraint ext. with CA == FALSE https://bugzilla.redhat.com/show_bug.cgi?id=657984 -------------------------------------------------------------------------------- ================================================================================ qtcurve-gtk2-1.8.5-1.fc14 (FEDORA-2011-1011) This is a set of widget styles for Gtk2 based apps -------------------------------------------------------------------------------- Update Information: KDE4: Fix saving of custom alpha values. Fix crash upon exit - due to double free. Fix import of ZIP qtcurve files. Fix display of background images, etc, in embedded preview. Fix QMake compile - thanks, once again, to Hugues Delorme. When hiding shortcuts, only show these if widget is enabled. Don't draw titlebar button frame for menu button if this is where the window icon is to be. This was already the case for circular buttons,but not for square buttons. If drawing sunken background behind titlebar buttons, need to reduce size of square buttons. This already happens for circular buttons. Don't draw sunken background around icon based menu button, if it is the only button on the left/right. Draw menubar and statusbar kwin toggle buttons square if using square titlebar buttons. Draw box around checked Libre/Open Office menu checkboxes. Ukrainian translation - thanks to Yuri Chornoivan Slight drawing fix for square scrollviews. When compiled against KDE, react to style changes. Slightly clean-up code. GTK2: Fix compilation against Gtk2 older than 2.20 Remove some Gtk3 hacks. Dont draw frame when shadow is set to NONE. Use correct shade for highlighted menuitems when not using the highlight colour, and the popup is shaded. If using custom menu colours, when drawing selected menuitems always draw as such - even if not using the highlight colour. Fix issues with image based backgrounds. Don't start drag on widget tab labels. Don't remove mouse over colour for pressed combo buttons. Use gtk_rc_parse_string to hide shortcuts, and not GtkSettings Fix KDE style non-editable combos which have has-frame set to FALSE. Better fix for problems with Pidgin's tabs and window dragging. Fix crash when using background gradients/images and built using 'Release' build type. Fix titles in GIMP's preferences dialog. Improve window drag code to take care of GtkPizza, and other, widgets. Use Gdk window to determine offsets when drawing background gradients. Use SHADOW_IN for treeviews. Fix background gradients in scrollviews. When drawing background gradients, use the background colour of the top-level widget's style. Fix slight glitch with striped scrollbar sliders. Hacky fix for tabs in Thunderbird main window. Better detection of toolbar buttons in Thunderbird. Slightly clean-up code. Can only use KDE-style non-editable combo popup if also using glow focus - as Gtk2 modifes the focus rect. Don't recolour checks/radios in listviews when row is selected. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Thomas Janssen <thomasj@xxxxxxxxxxxxxxxxx> 1.8.5-1 - update to 1.8.5 -------------------------------------------------------------------------------- ================================================================================ qtcurve-kde4-1.8.4-1.fc14 (FEDORA-2011-1011) This is a set of widget styles for Qt4/KDE4 based apps -------------------------------------------------------------------------------- Update Information: KDE4: Fix saving of custom alpha values. Fix crash upon exit - due to double free. Fix import of ZIP qtcurve files. Fix display of background images, etc, in embedded preview. Fix QMake compile - thanks, once again, to Hugues Delorme. When hiding shortcuts, only show these if widget is enabled. Don't draw titlebar button frame for menu button if this is where the window icon is to be. This was already the case for circular buttons,but not for square buttons. If drawing sunken background behind titlebar buttons, need to reduce size of square buttons. This already happens for circular buttons. Don't draw sunken background around icon based menu button, if it is the only button on the left/right. Draw menubar and statusbar kwin toggle buttons square if using square titlebar buttons. Draw box around checked Libre/Open Office menu checkboxes. Ukrainian translation - thanks to Yuri Chornoivan Slight drawing fix for square scrollviews. When compiled against KDE, react to style changes. Slightly clean-up code. GTK2: Fix compilation against Gtk2 older than 2.20 Remove some Gtk3 hacks. Dont draw frame when shadow is set to NONE. Use correct shade for highlighted menuitems when not using the highlight colour, and the popup is shaded. If using custom menu colours, when drawing selected menuitems always draw as such - even if not using the highlight colour. Fix issues with image based backgrounds. Don't start drag on widget tab labels. Don't remove mouse over colour for pressed combo buttons. Use gtk_rc_parse_string to hide shortcuts, and not GtkSettings Fix KDE style non-editable combos which have has-frame set to FALSE. Better fix for problems with Pidgin's tabs and window dragging. Fix crash when using background gradients/images and built using 'Release' build type. Fix titles in GIMP's preferences dialog. Improve window drag code to take care of GtkPizza, and other, widgets. Use Gdk window to determine offsets when drawing background gradients. Use SHADOW_IN for treeviews. Fix background gradients in scrollviews. When drawing background gradients, use the background colour of the top-level widget's style. Fix slight glitch with striped scrollbar sliders. Hacky fix for tabs in Thunderbird main window. Better detection of toolbar buttons in Thunderbird. Slightly clean-up code. Can only use KDE-style non-editable combo popup if also using glow focus - as Gtk2 modifes the focus rect. Don't recolour checks/radios in listviews when row is selected. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Thomas Janssen <thomasj@xxxxxxxxxxxxxxxxx> 1.8.4-1 - update to 1.8.4 -------------------------------------------------------------------------------- ================================================================================ rubygem-flexmock-0.8.11-2.fc14 (FEDORA-2011-1013) Mock object library for ruby -------------------------------------------------------------------------------- Update Information: Currently the main package contains a Provides containing typo. This new rpm will fix this issue. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxxxx> - 2.9.0-1 - Fix typo Provides on main package (bug 674413) -------------------------------------------------------------------------------- References: [ 1 ] Bug #674413 - rubygem-flexmock doesn't provide rubygem(flexmock) https://bugzilla.redhat.com/show_bug.cgi?id=674413 -------------------------------------------------------------------------------- ================================================================================ rubygem-hoe-2.9.0-1.fc14 (FEDORA-2011-1005) Hoe is a simple rake/rubygems helper for project Rakefiles -------------------------------------------------------------------------------- Update Information: New version 2.9.0 is released. -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxxxx> - 2.9.0-1 - 2.9.0 -------------------------------------------------------------------------------- ================================================================================ selinux-policy-3.9.7-28.fc14 (FEDORA-2011-1002) SELinux policy configuration -------------------------------------------------------------------------------- Update Information: - Make sandbox to work - Fix httpd_selinux man page to refer to httpd_sys_rw_content_t - Allow awstats to read squid logs - Allow dirsrv to send syslog messages - ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Fix keyboardd interface - Add execmem_exec_t label for gimp - Allow nagios plugin to read /proc/meminfo - Fix label for /usr/lib/debug - Add label for /usr/lib/bjlib - Fixes for confined users - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite -------------------------------------------------------------------------------- ChangeLog: * Wed Feb 2 2011 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.9.7-28 - Make sandbox to work - Fix httpd_selinux man page to refer to httpd_sys_rw_content_t - Allow awstats to read squid logs - Allow dirsrv to send syslog messages * Tue Feb 1 2011 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.9.7-27 - ricci_modclusterd_t needs to bind to rpc ports 500-1023 - Fix keyboardd interface * Thu Jan 27 2011 Miroslav Grepl <mgrepl@xxxxxxxxxx> 3.9.7-26 - Add execmem_exec_t label for gimp - Allow nagios plugin to read /proc/meminfo - Fix label for /usr/lib/debug - Add label for /usr/lib/bjlib - Fixes for confined users - Change oracle_port_t to oracledb_port_t to prevent conflict with satellite -------------------------------------------------------------------------------- References: [ 1 ] Bug #671170 - SELinux is preventing /usr/local/bin/cnijnetprn from 'write' accesses on the file /usr/lib/bjlib/cnnet.ini. https://bugzilla.redhat.com/show_bug.cgi?id=671170 [ 2 ] Bug #672798 - SELinux is preventing /usr/sbin/smartd from 'ioctl' accesses on the blk_file /dev/sdc. https://bugzilla.redhat.com/show_bug.cgi?id=672798 [ 3 ] Bug #651221 - filespec_add: conflicting specifications (getconf) https://bugzilla.redhat.com/show_bug.cgi?id=651221 [ 4 ] Bug #671067 - SELinux is preventing /bin/loadkeys from 'open' accesses on the fifo_file Unknown. https://bugzilla.redhat.com/show_bug.cgi?id=671067 [ 5 ] Bug #665203 - SELinux is preventing /sbin/iscsid from using the 'sys_ptrace' capabilities. https://bugzilla.redhat.com/show_bug.cgi?id=665203 [ 6 ] Bug #673405 - SELinux is preventing /usr/sbin/hddtemp from 'read' accesses on the blk_file sdf. https://bugzilla.redhat.com/show_bug.cgi?id=673405 [ 7 ] Bug #671444 - SELinux errors when slapi-nis plugin enables nis listener https://bugzilla.redhat.com/show_bug.cgi?id=671444 [ 8 ] Bug #673846 - SELinux is preventing /usr/bin/python from 'search' accesses on the directory /root/.local. https://bugzilla.redhat.com/show_bug.cgi?id=673846 [ 9 ] Bug #674415 - Update man page re: httpd_sys_rw_content_t https://bugzilla.redhat.com/show_bug.cgi?id=674415 [ 10 ] Bug #673728 - SELinux is preventing /usr/bin/perl from 'getattr' accesses on the file /var/log/squid/access.log. https://bugzilla.redhat.com/show_bug.cgi?id=673728 [ 11 ] Bug #673224 - Sandboxes don't start after recent upgrade https://bugzilla.redhat.com/show_bug.cgi?id=673224 -------------------------------------------------------------------------------- ================================================================================ webacula-5.0.3-1.fc14 (FEDORA-2011-0994) Web interface of a Bacula backup system -------------------------------------------------------------------------------- Update Information: Fix bug #3151906 -- "Single" files missing from "Select Files for Restore" -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 24 2011 Yuri Timofeev <tim4dev@xxxxxxxxx> 5.0.3-1 - Version 5.0.3 -------------------------------------------------------------------------------- ================================================================================ xguest-1.0.9-3.fc14 (FEDORA-2011-1003) Creates xguest user as a locked down user -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 1 2011 Dan Walsh <dwalsh@xxxxxxxxxx> - 1.0.9-3 - Fix boolean handling in the post install -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test