The following Fedora 14 Security updates need testing: https://admin.fedoraproject.org/updates/tomcat6-6.0.26-20.fc14 https://admin.fedoraproject.org/updates/mingw32-openssl-1.0.0a-2.fc14 https://admin.fedoraproject.org/updates/wireshark-1.4.6-1.fc14 https://admin.fedoraproject.org/updates/couchdb-1.0.2-1.fc14 https://admin.fedoraproject.org/updates/tor-0.2.1.29-1400.fc14 https://admin.fedoraproject.org/updates/kdenetwork-4.6.2-2.fc14 https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc14 https://admin.fedoraproject.org/updates/avahi-0.6.27-6.fc14 https://admin.fedoraproject.org/updates/mingw32-libtiff-3.9.5-1.fc14 https://admin.fedoraproject.org/updates/polkit-0.98-5.fc14 https://admin.fedoraproject.org/updates/SimGear-2.0.0-5.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 https://admin.fedoraproject.org/updates/mediawiki-1.16.4-58.fc14 https://admin.fedoraproject.org/updates/asterisk-1.6.2.17.3-1.fc14 The following Fedora 14 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/kernel-2.6.35.12-90.fc14 https://admin.fedoraproject.org/updates/tar-1.23-9.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-qxl-0.0.21-3.fc14 https://admin.fedoraproject.org/updates/evolution-exchange-2.32.3-1.fc14,evolution-data-server-2.32.3-1.fc14,evolution-2.32.3-1.fc14 https://admin.fedoraproject.org/updates/audit-2.1.1-1.fc14 https://admin.fedoraproject.org/updates/polkit-0.98-5.fc14 https://admin.fedoraproject.org/updates/pygtk2-2.17.0-9.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-nouveau-0.0.16-14.20101010git8c8f15c.fc14 https://admin.fedoraproject.org/updates/dosfstools-3.0.9-6.fc14 https://admin.fedoraproject.org/updates/libimobiledevice-1.0.6-1.fc14 https://admin.fedoraproject.org/updates/libconcord-0.23-5.fc14,udev-161-9.fc14,concordance-0.23-2.fc14 https://admin.fedoraproject.org/updates/usbmuxd-1.0.7-1.fc14 https://admin.fedoraproject.org/updates/openldap-2.4.23-10.fc14 https://admin.fedoraproject.org/updates/avahi-0.6.27-6.fc14 https://admin.fedoraproject.org/updates/xorg-x11-drv-geode-2.11.11-4.fc14 The following builds have been pushed to Fedora 14 updates-testing clamtk-4.32-1.fc14 gausssum-2.2.5-1.fc14 gnomad2-2.9.4-8.fc14 libprojectM-2.0.1-10.fc14 mingw32-libtiff-3.9.5-1.fc14 rpmlint-1.2-1.fc14 rubygem-daemon_controller-0.2.6-1.fc14 rubygem-file-tail-1.0.5-3.fc14 rubygem-spruz-0.2.5-3.fc14 sugar-0.92.1-2.fc14 sugar-artwork-0.92.0-1.fc14 sugar-base-0.92.0-1.fc14 Details about builds: ================================================================================ clamtk-4.32-1.fc14 (FEDORA-2011-5963) Easy to use graphical user interface for Clam anti virus -------------------------------------------------------------------------------- Update Information: Update to 4.32. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Dave M. <dave.nerd@xxxxxxxxx> - 4.32-1 - Updated to release 4.32. * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 4.31-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ gausssum-2.2.5-1.fc14 (FEDORA-2011-5949) A GUI application for analysis of output of quantum computations -------------------------------------------------------------------------------- Update Information: Minor bugfix update to 2.2.5. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Jussi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 2.2.5-1 - Update to 2.2.5. * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.2.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #698588 - gausssum-2.2.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=698588 -------------------------------------------------------------------------------- ================================================================================ gnomad2-2.9.4-8.fc14 (FEDORA-2011-5948) A GNOME 2.0 client for the Creative Jukeboxes and Dell DJs -------------------------------------------------------------------------------- Update Information: Remove HAL dependency. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Linus Walleij <triad@xxxxxxxxx> 2.9.4-8 - Drop HAL dependencies and build without HAL * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.9.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #677070 - [abrt] gnomad2-2.9.4-5.fc14: __strlen_sse2_bsf: Process /usr/bin/gnomad2 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=677070 [ 2 ] Bug #684317 - [abrt] gnomad2-2.9.4-5.fc14: __libc_message: Process /usr/bin/gnomad2 was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=684317 [ 3 ] Bug #692056 - [abrt] gnomad2-2.9.4-6.fc14: NJB_Get_Disk_Usage: Process /usr/bin/gnomad2 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=692056 [ 4 ] Bug #692605 - [abrt] gnomad2-2.9.4-6.fc14: strcmp: Process /usr/bin/gnomad2 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=692605 [ 5 ] Bug #692614 - [abrt] gnomad2-2.9.4-6.fc14: __libc_free: Process /usr/bin/gnomad2 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=692614 [ 6 ] Bug #698866 - [abrt] gnomad2-2.9.4-6.fc14: __libc_message: Process /usr/bin/gnomad2 was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=698866 [ 7 ] Bug #663955 - [abrt] gnomad2-2.9.4-5.fc14: __libc_message: Process /usr/bin/gnomad2 was killed by signal 6 (SIGABRT) https://bugzilla.redhat.com/show_bug.cgi?id=663955 [ 8 ] Bug #666282 - [abrt] gnomad2-2.9.4-5.fc14: free: Process /usr/bin/gnomad2 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=666282 -------------------------------------------------------------------------------- ================================================================================ libprojectM-2.0.1-10.fc14 (FEDORA-2011-5961) The libraries for the projectM music visualization plugin -------------------------------------------------------------------------------- Update Information: Fix fonts patch. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Jameson Pugh <imntreal@xxxxxxxxx> - 2.0.1-10 - Fixed fonts patch -------------------------------------------------------------------------------- References: [ 1 ] Bug #698381 - [abrt] audacious-2.4.4-2.fc14: FTSize::CharSize: Process /usr/bin/audacious2 was killed by signal 11 (SIGSEGV) https://bugzilla.redhat.com/show_bug.cgi?id=698381 -------------------------------------------------------------------------------- ================================================================================ mingw32-libtiff-3.9.5-1.fc14 (FEDORA-2011-5962) MinGW Windows port of the LibTIFF library -------------------------------------------------------------------------------- Update Information: Update MinGW Windows cross-compiled libtiff to 3.9.5, incorporating most of our previous patches. Includes a fix for CVE-2011-1167: A flaw was reported in libtiff's thunder decoder. The thunder decoder assumes 4bits per pixel, but if a file has bitpersample set to a smaller value, or defaulted (1) then the allocated strip buffer will be too small, and a heap-based buffer overlow may occur. This could be used to crash an application linked to libtiff, or execute arbitrary code with the privileges of the application opening a malicious TIFF file. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Kalev Lember <kalev@xxxxxxxxxxxx> - 3.9.5-1 - Update to 3.9.5 - Fixes CVE-2011-1167 (#689575) - Dropped the patches from Fedora native libtiff package which are all now incorporated in 3.9.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #689575 - CVE-2011-1167 libtiff: heap-based buffer overflow in thunder decoder (ZDI-CAN-1004) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=689575 -------------------------------------------------------------------------------- ================================================================================ rpmlint-1.2-1.fc14 (FEDORA-2011-5951) Tool for checking common errors in RPM packages -------------------------------------------------------------------------------- Update Information: Update rpmlint to 1.2, fixes a number of open bugs. Also filter out files-attr-not-set check except on EL4. For changes from 1.1 to 1.2, see: http://rpmlint.zarb.org/cgi-bin/trac.cgi/log/trunk?stop_rev=1834&rev=1859&verbose=on -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 24 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.2-1 - update to 1.2 - filter away files-attr-not-set for all targets except EL-4 (bz694579) * Thu Mar 3 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.1-3 - apply upstream fix for source url aborts (bz 680781) * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Fri Feb 4 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.1-1 - update to 1.1 * Tue Dec 7 2010 Tom "spot" Callaway <tcallawa@xxxxxxxxxx> - 1.0-3 - fix typo in changelog - % comment out item in changelog - simplify el4/el5 config files (thanks to Ville SkyttÃ) -------------------------------------------------------------------------------- References: [ 1 ] Bug #637712 - RFE: rpmlint should check for address of FSF in files containing GPL license https://bugzilla.redhat.com/show_bug.cgi?id=637712 [ 2 ] Bug #657593 - traceback when version contains only epoch https://bugzilla.redhat.com/show_bug.cgi?id=657593 [ 3 ] Bug #675360 - rpmlint complain about private-shared-object-provides only on x86_64 https://bugzilla.redhat.com/show_bug.cgi?id=675360 [ 4 ] Bug #694090 - python-bytecode-inconsistent-mtime checking is wrongly done on soft links https://bugzilla.redhat.com/show_bug.cgi?id=694090 [ 5 ] Bug #696749 - PATCH: Run undefined-non-weak-symbols through c++filt to improve readability. https://bugzilla.redhat.com/show_bug.cgi?id=696749 -------------------------------------------------------------------------------- ================================================================================ rubygem-daemon_controller-0.2.6-1.fc14 (FEDORA-2011-5950) A library for implementing daemon management capabilities -------------------------------------------------------------------------------- References: [ 1 ] Bug #697780 - Review Request: rubygem-daemon_controller - A library for implementing daemon management capabilities https://bugzilla.redhat.com/show_bug.cgi?id=697780 -------------------------------------------------------------------------------- ================================================================================ rubygem-file-tail-1.0.5-3.fc14 (FEDORA-2011-5959) File::Tail for Ruby -------------------------------------------------------------------------------- References: [ 1 ] Bug #697779 - Review Request: rubygem-file-tail - File::Tail for Ruby https://bugzilla.redhat.com/show_bug.cgi?id=697779 -------------------------------------------------------------------------------- ================================================================================ rubygem-spruz-0.2.5-3.fc14 (FEDORA-2011-5954) Useful tools library in Ruby -------------------------------------------------------------------------------- References: [ 1 ] Bug #697767 - Review Request: rubygem-spruz - Useful tools library in Ruby https://bugzilla.redhat.com/show_bug.cgi?id=697767 -------------------------------------------------------------------------------- ================================================================================ sugar-0.92.1-2.fc14 (FEDORA-2011-5957) Constructionist learning platform -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.92.1-2 - Fix the sugar desktop icon in emulator * Thu Apr 14 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.92.1-1 - 0.92.1 release * Tue Mar 1 2011 Simon Schampijer <simon@xxxxxxxxxx> - 0.92.0-2 - added upower (battery status indicator) and ConsoleKit (logged users information) as runtime dependencies * Mon Feb 28 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.92.0-1 - 0.92.0 release * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.90.3-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ sugar-artwork-0.92.0-1.fc14 (FEDORA-2011-5957) Artwork for Sugar look-and-feel -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 28 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.92.0-1 - 0.92.0 stable release * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.90.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Sat Jan 29 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.90.0-2 - bump build -------------------------------------------------------------------------------- ================================================================================ sugar-base-0.92.0-1.fc14 (FEDORA-2011-5957) Base Sugar library -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 28 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.92.0-1 - 0.92.0 stable release * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 0.90.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Sat Jan 29 2011 Peter Robinson <pbrobinson@xxxxxxxxx> - 0.90.1-2 - bump build -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test