The following Fedora EPEL 6 Security updates need testing:
Age URL
616 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7031
python-virtualenv-12.0.7-1.el6
610 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-7168
rubygem-crack-0.3.2-2.el6
500 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-e2b4b5b2fb
mcollective-2.8.4-1.el6
471 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2015-35e240edd9
thttpd-2.25b-24.el6
202 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-8594ed3a53
chicken-4.11.0-3.el6
82 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-e3e50897ac
libbsd-0.8.3-2.el6
66 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-8c6c7bf06e
dbus-sharp-0.7.0-16.el6 dbus-sharp-glib-0.5.0-14.el6 mono-4.2.4-9.el6
32 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-acd2c2af0d
nagios-4.2.4-4.el6
24 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-c3b112eb9e
tomcat-7.0.75-1.el6
14 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-e4e18670f5
drupal7-views-3.15-1.el6
14 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-23896f34bd
munin-2.0.30-5.el6
12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-6f8067610a
GraphicsMagick-1.3.25-6.el6
10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-1e1f31ce42
tor-0.2.9.10-1.el6
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-27a44b4bbf
tcpreplay-4.1.2-3.el6
8 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-50cbc23498
wordpress-4.7.3-1.el6
7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-23481d5e1a
icoutils-0.31.2-1.el6
4 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-1ad70123a8
R-3.3.3-1.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-75190374ce
moodle-2.7.19-1.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-eb18b4839a
mbedtls-2.4.2-1.el6
0 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2017-b1bba0f99d
roundcubemail-1.0.9-2.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
golang-github-beorn7-perks-0-0.10.git4c0e845.el6
golang-github-coreos-pkg-0-0.12.git3ac0863.el6
golang-github-golang-sys-0-0.11.git478fcf5.el6
golang-github-jonboulle-clockwork-0-0.10.git2eee05e.el6
golang-github-mattn-go-runewidth-0-0.5.git737072b.el6
golang-github-russross-blackfriday-1.2-17.el6
golang-github-shurcooL-sanitized_anchor_name-0-0.13.git1dba4b3.el6
golang-github-xiang90-probing-0-0.6.git07dd2e8.el6
mbedtls-2.4.2-1.el6
moodle-2.7.19-1.el6
nedit-5.7-1.el6
roundcubemail-1.0.9-2.el6
Details about builds:
================================================================================
golang-github-beorn7-perks-0-0.10.git4c0e845.el6 (FEDORA-EPEL-2017-a73c1dbde8)
Effective Computation of Things
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 4c0e84591b9aa9e6dcfdf3e020114cd81f89d5f9
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1248633 - Tracker for golang-github-beorn7-perks
https://bugzilla.redhat.com/show_bug.cgi?id=1248633
--------------------------------------------------------------------------------
================================================================================
golang-github-coreos-pkg-0-0.12.git3ac0863.el6 (FEDORA-EPEL-2017-72814742dd)
A collection of go utility packages
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 3ac0863d7acf3bc44daf49afef8919af12f704ef
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1245958 - Review Request: golang-github-coreos-pkg - A collection
of go utility packages
https://bugzilla.redhat.com/show_bug.cgi?id=1245958
--------------------------------------------------------------------------------
================================================================================
golang-github-golang-sys-0-0.11.git478fcf5.el6 (FEDORA-EPEL-2017-24f2f921e7)
Go packages for low-level interaction with the operating system
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 478fcf54317e52ab69f40bb4c7a1520288d7f7ea
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1360748 - update for s390x support
https://bugzilla.redhat.com/show_bug.cgi?id=1360748
--------------------------------------------------------------------------------
================================================================================
golang-github-jonboulle-clockwork-0-0.10.git2eee05e.el6
(FEDORA-EPEL-2017-879cc10773)
A fake clock for golang
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 2eee05ed794112d45db504eb05aa693efd2b8b09
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1250489 - Tracker for golang-github-jonboulle-clockwork
https://bugzilla.redhat.com/show_bug.cgi?id=1250489
--------------------------------------------------------------------------------
================================================================================
golang-github-mattn-go-runewidth-0-0.5.git737072b.el6
(FEDORA-EPEL-2017-f229442d46)
Functions for getting fixed width of the character or string
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 737072b4e32b7a5018b4a7125da8d12de90e8045
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1405690 - Tracker for golang-github-mattn-go-runewidth
https://bugzilla.redhat.com/show_bug.cgi?id=1405690
--------------------------------------------------------------------------------
================================================================================
golang-github-russross-blackfriday-1.2-17.el6 (FEDORA-EPEL-2017-70215e5cd9)
Markdown processor implemented in Go
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 5f33e7b7878355cd2b7e6b8eefc48a5472c69f70
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222338 - Tracker for golang-github-russross-blackfriday
https://bugzilla.redhat.com/show_bug.cgi?id=1222338
--------------------------------------------------------------------------------
================================================================================
golang-github-shurcooL-sanitized_anchor_name-0-0.13.git1dba4b3.el6
(FEDORA-EPEL-2017-0a2dc39090)
Package sanitized_anchor_name provides a func to create sanitized anchor names
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 1dba4b3954bc059efc3991ec364f9f9a35f597d2
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1222336 - Tracker for golang-github-shurcooL-sanitized_anchor_name
https://bugzilla.redhat.com/show_bug.cgi?id=1222336
--------------------------------------------------------------------------------
================================================================================
golang-github-xiang90-probing-0-0.6.git07dd2e8.el6
(FEDORA-EPEL-2017-f466ec7dd2)
Golang project for probing
--------------------------------------------------------------------------------
Update Information:
Bump to upstream 07dd2e8dfe18522e9c447ba95f2fe95262f63bb2 ---- First package
for Fedora
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1432066 - Tracker for golang-github-xiang90-probing
https://bugzilla.redhat.com/show_bug.cgi?id=1432066
[ 2 ] Bug #1262351 - Review Request: golang-github-xiang90-probing - Golang
project for probing
https://bugzilla.redhat.com/show_bug.cgi?id=1262351
--------------------------------------------------------------------------------
================================================================================
mbedtls-2.4.2-1.el6 (FEDORA-EPEL-2017-eb18b4839a)
Light-weight cryptographic and SSL/TLS library
--------------------------------------------------------------------------------
Update Information:
- Update to 2.4.2 - CVE-2017-2784 Release notes: https://tls.mbed.org/tech-
updates/releases/mbedtls-2.4.2-2.1.7-and-1.3.19-released Security notes:
https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security-
advisory-2017-01
--------------------------------------------------------------------------------
================================================================================
moodle-2.7.19-1.el6 (FEDORA-EPEL-2017-75190374ce)
A Course Management System
--------------------------------------------------------------------------------
Update Information:
Multiple CVE fixes.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1336730 - CVE-2016-3729 CVE-2016-3731 CVE-2016-3732 CVE-2016-3733
CVE-2016-3734 moodle: Multiple vulnerabilities fixed in 3.0.4, 2.9.6, 2.8.12
and 2.7.14 [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1336730
[ 2 ] Bug #1319681 - CVE-2016-2151 CVE-2016-2152 CVE-2016-2153 CVE-2016-2154
CVE-2016-2155 CVE-2016-2156 CVE-2016-2157 CVE-2016-2158 CVE-2016-2159
CVE-2016-2190 moodle: multiple security issues fixed in 3.0.3, 2.9.5, 2.8.11,
2.7.13 [epel-6]
https://bugzilla.redhat.com/show_bug.cgi?id=1319681
[ 3 ] Bug #1299361 - CVE-2016-0724 moodle: two enrolment-related web services
don't check course visibility [epel-6]
https://bugzilla.redhat.com/show_bug.cgi?id=1299361
--------------------------------------------------------------------------------
================================================================================
nedit-5.7-1.el6 (FEDORA-EPEL-2017-e7c7b8d010)
A GUI text editor for systems with X
--------------------------------------------------------------------------------
Update Information:
update to 5.7
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1106275 - nedit: FTBFS in rawhide
https://bugzilla.redhat.com/show_bug.cgi?id=1106275
--------------------------------------------------------------------------------
================================================================================
roundcubemail-1.0.9-2.el6 (FEDORA-EPEL-2017-b1bba0f99d)
Round Cube Webmail is a browser-based multilingual IMAP client
--------------------------------------------------------------------------------
Update Information:
Fix for CVE-2016-5103
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1339656 - CVE-2016-5103 roundcubemail: roundcube: XSS
vulnerability in mail content page [epel-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1339656
--------------------------------------------------------------------------------
_______________________________________________
epel-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]