The following Fedora 13 Security updates need testing: https://admin.fedoraproject.org/updates/tor-0.2.1.29-1300.fc13 https://admin.fedoraproject.org/updates/kdelibs-4.5.5-2.fc13 https://admin.fedoraproject.org/updates/mediawiki-1.16.4-57.fc13 https://admin.fedoraproject.org/updates/libmodplug-0.8.7-3.fc13 https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc13 https://admin.fedoraproject.org/updates/perl-Mojolicious-0.999925-3.fc13 https://admin.fedoraproject.org/updates/perl-5.10.1-123.fc13 https://admin.fedoraproject.org/updates/openldap-2.4.21-12.fc13 https://admin.fedoraproject.org/updates/dhcp-4.1.2-4.ESV.R2.fc13 https://admin.fedoraproject.org/updates/seamonkey-2.0.13-1.fc13 https://admin.fedoraproject.org/updates/kdenetwork-4.5.5-2.fc13 https://admin.fedoraproject.org/updates/libcgroup-0.35.1-5.fc13 https://admin.fedoraproject.org/updates/libtiff-3.9.5-1.fc13 https://admin.fedoraproject.org/updates/python-feedparser-5.0.1-1.fc13 https://admin.fedoraproject.org/updates/libvirt-0.8.2-6.fc13 https://admin.fedoraproject.org/updates/xorg-x11-server-utils-7.4-17.fc13 https://admin.fedoraproject.org/updates/krb5-1.7.1-19.fc13 https://admin.fedoraproject.org/updates/ikiwiki-3.20100815.7-1.fc13 https://admin.fedoraproject.org/updates/tmux-1.4-3.fc13 https://admin.fedoraproject.org/updates/fail2ban-0.8.4-27.fc13 The following Fedora 13 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/python-ethtool-0.7-2.fc13 https://admin.fedoraproject.org/updates/libtiff-3.9.5-1.fc13 https://admin.fedoraproject.org/updates/pygtk2-2.17.0-8.fc13 https://admin.fedoraproject.org/updates/dosfstools-3.0.9-5.fc13 https://admin.fedoraproject.org/updates/tzdata-2011d-3.fc13 https://admin.fedoraproject.org/updates/policycoreutils-2.0.83-33.8.fc13 https://admin.fedoraproject.org/updates/libimobiledevice-1.0.6-1.fc13 https://admin.fedoraproject.org/updates/usbmuxd-1.0.7-1.fc13 https://admin.fedoraproject.org/updates/fuse-2.8.5-5.fc13 https://admin.fedoraproject.org/updates/libcgroup-0.35.1-5.fc13 https://admin.fedoraproject.org/updates/openldap-2.4.21-12.fc13 https://admin.fedoraproject.org/updates/livecd-tools-13.2-1.fc13 https://admin.fedoraproject.org/updates/lua-5.1.4-7.fc13 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-7.fc13 https://admin.fedoraproject.org/updates/lldpad-0.9.26-2.fc13 The following builds have been pushed to Fedora 13 updates-testing fail2ban-0.8.4-27.fc13 libburn-1.0.6-1.fc13 mfiler3-4.2.7-2.fc13 perl-Mojolicious-0.999925-3.fc13 perl-Test-CheckManifest-1.24-1.fc13 saphire-1.4.0-1.fc13 Details about builds: ================================================================================ fail2ban-0.8.4-27.fc13 (FEDORA-2011-5151) Ban IPs that make too many password failures -------------------------------------------------------------------------------- Update Information: fail2ban used predictable /tmp files which a local user can allocate before fail2ban does. All tmp files have been moved to /var/lib/fail2ban. This also helps with selinux policies. Another security related fix is that fail2ban defaulted to gamin which conflicts with selinux, so users had to typically choose between fail2ban and selinux. fail2ban now defaults to inotify (thanks to Jonathan Underwood). There are also some minor bugs fixed: * tmpfiles.d support for tmpfs /var/run * example mail domains changed to normalized example.com. -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 9 2011 Axel Thimm <Axel.Thimm@xxxxxxxxxx> - 0.8.4-27 - Move tmp files to /var/lib (suggested by Phil Anderson). - Enable inotify support (by Jonathan Underwood). - Fixes RH bugs #669966, #669965, #551895, #552947, #658849, #656584. -------------------------------------------------------------------------------- References: [ 1 ] Bug #669966 - fail2ban can't work with tmp files https://bugzilla.redhat.com/show_bug.cgi?id=669966 [ 2 ] Bug #669965 - unsafe use of /tmp https://bugzilla.redhat.com/show_bug.cgi?id=669965 [ 3 ] Bug #551895 - RFE: Add patch to enable inotify support https://bugzilla.redhat.com/show_bug.cgi?id=551895 [ 4 ] Bug #552947 - RFE: conform fail2ban example email sending domains to RFC 2606 https://bugzilla.redhat.com/show_bug.cgi?id=552947 [ 5 ] Bug #658849 - Please change fail2ban to not use gam_server https://bugzilla.redhat.com/show_bug.cgi?id=658849 [ 6 ] Bug #656584 - Please Update Spec File to use %ghost on files in /var/run and /var/lock https://bugzilla.redhat.com/show_bug.cgi?id=656584 -------------------------------------------------------------------------------- ================================================================================ libburn-1.0.6-1.fc13 (FEDORA-2011-5511) Library for reading, mastering and writing optical discs -------------------------------------------------------------------------------- Update Information: Changes towards previous version 1.0.4: * Burning DVD-R DAO with 2 kB size granularity rather than 32 kB * New API call burn_allow_drive_role_4() Changes towards previous version 1.0.2: * Bug fix: Read-only file descriptors were classified as write-only pseudo drives -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 17 2011 Robert Scheck <robert@xxxxxxxxxxxxxxxxx> 1.0.6-1 - Update to upstream 1.0.6 * Mon Feb 28 2011 Honza Horak <hhorak@xxxxxxxxxx> - 1.0.2-1 - Update to upstream 1.0.2 * Thu Feb 17 2011 Honza Horak <hhorak@xxxxxxxxxx> - 1.0.0-1 - Update to upstream 1.0.0 * Mon Feb 7 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.8.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Thu Apr 22 2010 Nikola Pajkovsky <npajkovs@xxxxxxxxxx> - 0.8.0-1 - Update to upstream 0.8.0 -------------------------------------------------------------------------------- ================================================================================ mfiler3-4.2.7-2.fc13 (FEDORA-2011-5510) Two pane file manager under UNIX console -------------------------------------------------------------------------------- Update Information: Update saphire to 1.4.0 Also saphire / mfiler3 will use less instead of lv for Japanese help page. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 14 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxx> - 4.2.7-2 - Fix compilation error with saphire 1.4.0 (and actually fix symbol error) - Prefer less over lv for help pager -------------------------------------------------------------------------------- ================================================================================ perl-Mojolicious-0.999925-3.fc13 (FEDORA-2011-5505) A next generation web framework for Perl -------------------------------------------------------------------------------- Update Information: Security bugfix attempt http://blog.kraih.com/mojolicious-116-emergency-release-please-upgr -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 17 2011 Yanko Kaneti <yaneti@xxxxxxxxxxx> 0.999925-3 - Security bugfix attempt. -------------------------------------------------------------------------------- ================================================================================ perl-Test-CheckManifest-1.24-1.fc13 (FEDORA-2011-5499) Check if your Manifest matches your distro -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 17 2011 Ralf CorsÃpius <corsepiu@xxxxxxxxxxxxxxxxx> 1.24-1 - Upstream update. -------------------------------------------------------------------------------- ================================================================================ saphire-1.4.0-1.fc13 (FEDORA-2011-5510) Yet another shell -------------------------------------------------------------------------------- Update Information: Update saphire to 1.4.0 Also saphire / mfiler3 will use less instead of lv for Japanese help page. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 13 2011 Mamoru Tasaka <mtasaka@xxxxxxxxxxxxxxxxx> - 1.4.0-1 - 1.4.0 - Prefer less over lv for help pager -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test