The following Fedora 13 Security updates need testing: https://admin.fedoraproject.org/updates/nbd-2.9.20-1.fc13 https://admin.fedoraproject.org/updates/dbus-1.2.24-2.fc13 https://admin.fedoraproject.org/updates/subversion-1.6.15-1.fc13 https://admin.fedoraproject.org/updates/kernel-2.6.34.8-67.fc13 https://admin.fedoraproject.org/updates/openoffice.org-3.2.0-12.35.fc13 https://admin.fedoraproject.org/updates/dhcp-4.1.2-2.ESV.R1.fc13 https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc13 https://admin.fedoraproject.org/updates/mod_auth_mysql-3.0.0-12.fc13 https://admin.fedoraproject.org/updates/postgresql-8.4.7-1.fc13 https://admin.fedoraproject.org/updates/tor-0.2.1.29-1300.fc13 The following Fedora 13 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/kernel-2.6.34.8-67.fc13 https://admin.fedoraproject.org/updates/selinux-policy-3.7.19-89.fc13 https://admin.fedoraproject.org/updates/system-config-users-1.2.107-1.fc13 https://admin.fedoraproject.org/updates/python-ethtool-0.6-1.fc13 https://admin.fedoraproject.org/updates/livecd-tools-13.1-1.fc13 https://admin.fedoraproject.org/updates/libical-0.46-2.fc13 https://admin.fedoraproject.org/updates/pm-utils-1.2.6.1-4.fc13 https://admin.fedoraproject.org/updates/mash-0.5.20-1.fc13 https://admin.fedoraproject.org/updates/nss-3.12.7-4.fc13,nss-util-3.12.7-2.fc13,nss-softokn-3.12.7-3.fc13,nspr-4.8.6-1.fc13 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-7.fc13 The following builds have been pushed to Fedora 13 updates-testing gnome-chemistry-utils-0.12.6-2.fc13 gnumeric-1.10.13-1.fc13 goffice-0.8.13-1.fc13 kernel-2.6.34.8-67.fc13 python-mpmath-0.17-1.fc13 qbittorrent-2.6.5-1.fc13 Details about builds: ================================================================================ gnome-chemistry-utils-0.12.6-2.fc13 (FEDORA-2011-1122) A set of chemical utilities -------------------------------------------------------------------------------- Update Information: This update syncs goffice and gnumeric with their latest upstream bugfix releases: * ftp://ftp.gnome.org/pub/gnome/sources/goffice/0.8/goffice-0.8.13.news * ftp://ftp.gnome.org/pub/gnome/sources/gnumeric/1.10/gnumeric-1.10.13.news -------------------------------------------------------------------------------- ChangeLog: * Sat Feb 5 2011 Julian Sikorski <belegdol@xxxxxxxxxxxxxxxxx> - 0.12.6-2 - Rebuilt for goffice-0.8.13 and gnumeric-1.10.13 -------------------------------------------------------------------------------- ================================================================================ gnumeric-1.10.13-1.fc13 (FEDORA-2011-1122) Spreadsheet program for GNOME -------------------------------------------------------------------------------- Update Information: This update syncs goffice and gnumeric with their latest upstream bugfix releases: * ftp://ftp.gnome.org/pub/gnome/sources/goffice/0.8/goffice-0.8.13.news * ftp://ftp.gnome.org/pub/gnome/sources/gnumeric/1.10/gnumeric-1.10.13.news -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 3 2011 Julian Sikorski <belegdol@xxxxxxxxxxxxxxxxx> - 1:1.10.13-1 - Updated to 1.10.13 -------------------------------------------------------------------------------- ================================================================================ goffice-0.8.13-1.fc13 (FEDORA-2011-1122) Goffice support libraries -------------------------------------------------------------------------------- Update Information: This update syncs goffice and gnumeric with their latest upstream bugfix releases: * ftp://ftp.gnome.org/pub/gnome/sources/goffice/0.8/goffice-0.8.13.news * ftp://ftp.gnome.org/pub/gnome/sources/gnumeric/1.10/gnumeric-1.10.13.news -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 3 2011 Julian Sikorski <belegdol@xxxxxxxxxxxxxxxxx> - 0.8.13-1 - Updated to 0.8.13 -------------------------------------------------------------------------------- ================================================================================ kernel-2.6.34.8-67.fc13 (FEDORA-2011-1126) The Linux kernel -------------------------------------------------------------------------------- Update Information: Update to kernel 2.6.34.8: http://www.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.34/ChangeLog-2.6.34.8 -------------------------------------------------------------------------------- ChangeLog: * Sat Feb 5 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - Linux 2.6.34.8 - Drop merged patches: 01-compat-make-compat_alloc_user_space-incorporate-the-access_ok-check.patch 02-compat-test-rax-for-the-system-call-number-not-eax.patch 03-compat-retruncate-rax-after-ia32-syscall-entry-tracing.patch aio-check-for-multiplication-overflow-in-do_io_submit.patch cifs-fix-dns-resolver.patch inotify-fix-inotify-oneshot-support.patch inotify-send-IN_UNMOUNT-events.patch irda-correctly-clean-up-self-ias_obj-on-irda_bind-failure.patch keys-fix-bug-in-keyctl-session-to-parent-if-parent-has-no-session-keyring.patch keys-fix-rcu-no-lock-warning-in-keyctl-session-to-parent.patch wireless-extensions-fix-kernel-heap-content-leak.patch pci-msi-remove-unsafe-and-unnecessary-hardware-access.patch pci-msi-restore-read_msi_msg_desc-add-get_cached_msi_msg_desc.patch x86-tsc-sched-recompute-cyc2ns_offset-s-during-resume-from-sleep-states.patch x86-tsc-fix-a-preemption-leak-in-restore_sched_clock_state.patch execve-improve-interactivity-with-large-arguments.patch execve-make-responsive-to-sigkill-with-large-arguments.patch setup_arg_pages-diagnose-excessive-argument-size.patch alsa-seq-oss-fix-double-free-at-error-path-of-snd_seq_oss_open.patch tracing-do-not-allow-llseek-to-set_ftrace_filter.patch sched-00-fix-user-time-incorrectly-accounted-as-system-time-on-32-bit.patch xen-handle-events-as-edge-triggered.patch xen-use-percpu-interrupts-for-ipis-and-virqs.patch sctp-do-not-reset-the-packet-during-sctp_packet_config.patch r8169-fix-dma-allocations.patch skge-quirk-to-4gb-dma.patch depessimize-rds_copy_page_user.patch via-ioctl-prevent-reading-uninit-memory.patch v4l1-fix-32-bit-compat-microcode-loading-translation.patch kvm-fix-fs-gs-reload-oops-with-invalid-ldt.patch alsa-prevent-heap-corruption-in-snd_ctl_new.patch gdth-integer-overflow-in-ioctl.patch - Drop from drm-next patch: d831692 sis-agp: Remove SIS 760, handled by amd64-agp - Drop hunk of quiet-prove_RCU-in-cgroups.patch, now upstream. * Sun Jan 30 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - Copy sunrpc oops fix from F14 * Wed Jan 26 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - TCP networking fixes from 2.6.36.3, including one CVE CVE-2010-4165: possible kernel oops from user MSS - CVE-2011-0521: av7110 negative array offset * Sat Jan 22 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - Security updates CVE-2010-4346: install_special_mapping skips security_file_mmap check CVE-2010-4649: IB/uverbs: Handle large number of entries in poll CQ CVE-2011-0006: ima: fix add LSM rule bug CVE-2010-4648: orinoco: fix TKIP countermeasure behaviour CVE-2010-4650: fuse: verify ioctl retries * Tue Jan 18 2011 Kyle McMartin <kmcmartin@xxxxxxxxxx> - sgruszka: hostap_cs: fix sleeping function called in invalid context (#643758) * Mon Jan 10 2011 Chuck Ebbert <cebbert@xxxxxxxxxx> - CVE-2010-4163 CVE-2010-4668: panic when submitting 0-length I/O requests * Sat Dec 18 2010 Kyle McMartin <kyle@xxxxxxxxxx> - Fix SELinux issues with NFS/btrfs and/or xfsdump. (#662344) * Fri Dec 17 2010 Neil Horman <nhorman@xxxxxxxxxx> - Enhance AF_PACKET to allow non-contiguous buffer alloc (bz 637619) -------------------------------------------------------------------------------- References: [ 1 ] Bug #652508 - CVE-2010-4165 kernel: possible kernel oops from user MSS https://bugzilla.redhat.com/show_bug.cgi?id=652508 [ 2 ] Bug #672398 - CVE-2011-0521 kernel: av7110 negative array offset https://bugzilla.redhat.com/show_bug.cgi?id=672398 [ 3 ] Bug #662189 - CVE-2010-4346 kernel: install_special_mapping skips security_file_mmap check https://bugzilla.redhat.com/show_bug.cgi?id=662189 [ 4 ] Bug #667916 - CVE-2010-4649 kernel: IB/uverbs: Handle large number of entries in poll CQ https://bugzilla.redhat.com/show_bug.cgi?id=667916 [ 5 ] Bug #667912 - CVE-2011-0006 kernel: ima: fix add LSM rule bug https://bugzilla.redhat.com/show_bug.cgi?id=667912 [ 6 ] Bug #667907 - CVE-2010-4648 kernel: orinoco: fix TKIP countermeasure behaviour https://bugzilla.redhat.com/show_bug.cgi?id=667907 [ 7 ] Bug #667892 - CVE-2010-4650 kernel: fuse: verify ioctl retries https://bugzilla.redhat.com/show_bug.cgi?id=667892 [ 8 ] Bug #652957 - CVE-2010-4163 CVE-2010-4668 kernel: panic when submitting certain 0-length I/O requests https://bugzilla.redhat.com/show_bug.cgi?id=652957 -------------------------------------------------------------------------------- ================================================================================ python-mpmath-0.17-1.fc13 (FEDORA-2011-1128) A pure Python library for multiprecision floating-point arithmetic -------------------------------------------------------------------------------- Update Information: Update to 0.17, see changelog at http://mpmath.googlecode.com/svn/trunk/CHANGES. -------------------------------------------------------------------------------- ChangeLog: * Sun Feb 6 2011 Jussi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 0.17-1 - Update to 0.17. -------------------------------------------------------------------------------- References: [ 1 ] Bug #674504 - python-mpmath-0.17 is available https://bugzilla.redhat.com/show_bug.cgi?id=674504 -------------------------------------------------------------------------------- ================================================================================ qbittorrent-2.6.5-1.fc13 (FEDORA-2011-1118) A Bittorrent Client -------------------------------------------------------------------------------- Update Information: * Thu Feb 3 2011 - Christophe Dumez <chris@xxxxxxxxxxxxxxx> - v2.6.5 - BUGFIX: Make sure the progress is not 100% unless the file is complete - BUGFIX: Fix memory leak in HTTP torrent downloader - BUGFIX: Use native file dialogs (by Vladimir Golovnev) - BUGFIX: Fix encoding problem in torrent moving code (by Vladimir Golovnev) - BUGFIX: Performance improvement on ARM - BUGFIX: RSS code rewrite (more cpu/memory efficient) - I18N: Updated Norwegian translation (Tomaso) -------------------------------------------------------------------------------- ChangeLog: * Sat Feb 5 2011 Leigh Scott <leigh123linux@xxxxxxxxxxxxxx> - 1:2.6.5-1 - update to 2.6.5 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test