The following Fedora 13 Security updates need testing: https://admin.fedoraproject.org/updates/tor-0.2.1.29-1300.fc13 https://admin.fedoraproject.org/updates/mingw32-openssl-1.0.0-0.7.beta4.fc13 https://admin.fedoraproject.org/updates/SimGear-2.0.0-5.fc13 https://admin.fedoraproject.org/updates/libmodplug-0.8.7-3.fc13 https://admin.fedoraproject.org/updates/feh-1.10.1-1.fc13 https://admin.fedoraproject.org/updates/openldap-2.4.21-12.fc13 https://admin.fedoraproject.org/updates/wireshark-1.2.16-1.fc13 https://admin.fedoraproject.org/updates/mingw32-libtiff-3.9.5-1.fc13 https://admin.fedoraproject.org/updates/libcgroup-0.35.1-5.fc13 https://admin.fedoraproject.org/updates/libtiff-3.9.5-1.fc13 https://admin.fedoraproject.org/updates/polkit-0.96-2.fc13 https://admin.fedoraproject.org/updates/xorg-x11-server-utils-7.4-17.fc13 https://admin.fedoraproject.org/updates/mediawiki-1.16.4-58.fc13 https://admin.fedoraproject.org/updates/asterisk-1.6.2.17.3-1.fc13 The following Fedora 13 Critical Path updates have yet to be approved: https://admin.fedoraproject.org/updates/NetworkManager-0.8.4-1.fc13 https://admin.fedoraproject.org/updates/polkit-0.96-2.fc13 https://admin.fedoraproject.org/updates/xorg-x11-drv-penmount-1.4.1-2.fc13 https://admin.fedoraproject.org/updates/python-ethtool-0.7-2.fc13 https://admin.fedoraproject.org/updates/libtiff-3.9.5-1.fc13 https://admin.fedoraproject.org/updates/pygtk2-2.17.0-9.fc13 https://admin.fedoraproject.org/updates/dosfstools-3.0.9-5.fc13 https://admin.fedoraproject.org/updates/libimobiledevice-1.0.6-1.fc13 https://admin.fedoraproject.org/updates/usbmuxd-1.0.7-1.fc13 https://admin.fedoraproject.org/updates/fuse-2.8.5-5.fc13 https://admin.fedoraproject.org/updates/libcgroup-0.35.1-5.fc13 https://admin.fedoraproject.org/updates/openldap-2.4.21-12.fc13 https://admin.fedoraproject.org/updates/livecd-tools-13.2-1.fc13 https://admin.fedoraproject.org/updates/lua-5.1.4-7.fc13 https://admin.fedoraproject.org/updates/xorg-x11-drv-openchrome-0.2.904-7.fc13 https://admin.fedoraproject.org/updates/lldpad-0.9.26-2.fc13 The following builds have been pushed to Fedora 13 updates-testing clamtk-4.32-1.fc13 gausssum-2.2.5-1.fc13 mingw32-libtiff-3.9.5-1.fc13 rpmlint-1.2-1.fc13 rubygem-daemon_controller-0.2.6-1.fc13 rubygem-file-tail-1.0.5-3.fc13 rubygem-spruz-0.2.5-3.fc13 Details about builds: ================================================================================ clamtk-4.32-1.fc13 (FEDORA-2011-5956) Easy to use graphical user interface for Clam anti virus -------------------------------------------------------------------------------- Update Information: Update to 4.32. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Dave M. <dave.nerd@xxxxxxxxx> - 4.32-1 - Updated to release 4.32. * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 4.31-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild -------------------------------------------------------------------------------- ================================================================================ gausssum-2.2.5-1.fc13 (FEDORA-2011-5947) A GUI application for analysis of output of quantum computations -------------------------------------------------------------------------------- Update Information: Minor bugfix update to 2.2.5. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Jussi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 2.2.5-1 - Update to 2.2.5. * Tue Feb 8 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 2.2.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Fri Aug 6 2010 Jussi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 2.2.4-1 - Update to 2.2.4. * Wed Jul 21 2010 David Malcolm <dmalcolm@xxxxxxxxxx> - 2.2.3-2 - Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild * Fri Feb 19 2010 Jussi Lehtola <jussilehtola@xxxxxxxxxxxxxxxxx> - 2.2.3-1 - Update to 2.2.3. -------------------------------------------------------------------------------- References: [ 1 ] Bug #698588 - gausssum-2.2.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=698588 -------------------------------------------------------------------------------- ================================================================================ mingw32-libtiff-3.9.5-1.fc13 (FEDORA-2011-5955) MinGW Windows port of the LibTIFF library -------------------------------------------------------------------------------- Update Information: Update MinGW Windows cross-compiled libtiff to 3.9.5, incorporating most of our previous patches. Includes a fix for CVE-2011-1167: A flaw was reported in libtiff's thunder decoder. The thunder decoder assumes 4bits per pixel, but if a file has bitpersample set to a smaller value, or defaulted (1) then the allocated strip buffer will be too small, and a heap-based buffer overlow may occur. This could be used to crash an application linked to libtiff, or execute arbitrary code with the privileges of the application opening a malicious TIFF file. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 25 2011 Kalev Lember <kalev@xxxxxxxxxxxx> - 3.9.5-1 - Update to 3.9.5 - Fixes CVE-2011-1167 (#689575) - Dropped the patches from Fedora native libtiff package which are all now incorporated in 3.9.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #689575 - CVE-2011-1167 libtiff: heap-based buffer overflow in thunder decoder (ZDI-CAN-1004) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=689575 -------------------------------------------------------------------------------- ================================================================================ rpmlint-1.2-1.fc13 (FEDORA-2011-5952) Tool for checking common errors in RPM packages -------------------------------------------------------------------------------- Update Information: Update rpmlint to 1.2, fixes a number of open bugs. Also filter out files-attr-not-set check except on EL4. For changes from 1.1 to 1.2, see: http://rpmlint.zarb.org/cgi-bin/trac.cgi/log/trunk?stop_rev=1834&rev=1859&verbose=on -------------------------------------------------------------------------------- ChangeLog: * Sun Apr 24 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.2-1 - update to 1.2 - filter away files-attr-not-set for all targets except EL-4 (bz694579) * Thu Mar 3 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.1-3 - apply upstream fix for source url aborts (bz 680781) * Wed Feb 9 2011 Fedora Release Engineering <rel-eng@xxxxxxxxxxxxxxxxxxxxxxx> - 1.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Fri Feb 4 2011 Tom Callaway <spot@xxxxxxxxxxxxxxxxx> - 1.1-1 - update to 1.1 * Tue Dec 7 2010 Tom "spot" Callaway <tcallawa@xxxxxxxxxx> - 1.0-3 - fix typo in changelog - % comment out item in changelog - simplify el4/el5 config files (thanks to Ville SkyttÃ) -------------------------------------------------------------------------------- References: [ 1 ] Bug #637712 - RFE: rpmlint should check for address of FSF in files containing GPL license https://bugzilla.redhat.com/show_bug.cgi?id=637712 [ 2 ] Bug #657593 - traceback when version contains only epoch https://bugzilla.redhat.com/show_bug.cgi?id=657593 [ 3 ] Bug #675360 - rpmlint complain about private-shared-object-provides only on x86_64 https://bugzilla.redhat.com/show_bug.cgi?id=675360 [ 4 ] Bug #694090 - python-bytecode-inconsistent-mtime checking is wrongly done on soft links https://bugzilla.redhat.com/show_bug.cgi?id=694090 [ 5 ] Bug #696749 - PATCH: Run undefined-non-weak-symbols through c++filt to improve readability. https://bugzilla.redhat.com/show_bug.cgi?id=696749 -------------------------------------------------------------------------------- ================================================================================ rubygem-daemon_controller-0.2.6-1.fc13 (FEDORA-2011-5960) A library for implementing daemon management capabilities -------------------------------------------------------------------------------- References: [ 1 ] Bug #697780 - Review Request: rubygem-daemon_controller - A library for implementing daemon management capabilities https://bugzilla.redhat.com/show_bug.cgi?id=697780 -------------------------------------------------------------------------------- ================================================================================ rubygem-file-tail-1.0.5-3.fc13 (FEDORA-2011-5953) File::Tail for Ruby -------------------------------------------------------------------------------- References: [ 1 ] Bug #697779 - Review Request: rubygem-file-tail - File::Tail for Ruby https://bugzilla.redhat.com/show_bug.cgi?id=697779 -------------------------------------------------------------------------------- ================================================================================ rubygem-spruz-0.2.5-3.fc13 (FEDORA-2011-5958) Useful tools library in Ruby -------------------------------------------------------------------------------- References: [ 1 ] Bug #697767 - Review Request: rubygem-spruz - Useful tools library in Ruby https://bugzilla.redhat.com/show_bug.cgi?id=697767 -------------------------------------------------------------------------------- -- test mailing list test@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe: https://admin.fedoraproject.org/mailman/listinfo/test