--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2010-9939
2010-06-15 15:36:01
--------------------------------------------------------------------------------

Name        : selinux-policy
Product     : Fedora 13
Version     : 3.7.19
Release     : 28.fc13
URL         : http://oss.tresys.com/repos/refpolicy/
Summary     : SELinux policy configuration
Description :
SELinux Reference Policy - modular.
Based off of reference policy: Checked out revision  2.20091117

--------------------------------------------------------------------------------
Update Information:

* Mon Jun 14 2010 Miroslav Grepl <[email protected]> 3.7.19-28     - Fixes for
netutils   - Cleanup of aiccu policy   - Add mpd policy  - Allow ftpd ipc_lock
capability   - Allow audisp-remote to getcap and setcap   - Allow iscsid to read
and write raw memory devices  - Fixes for bitlbee policy   - Allow krb5kdc to
write krb5kdc_principal_t file   - Allow hald to send generic signal to dhcp
client   - Fix dev_rw_vhost interface   - Add /var/run/abrt.socket label  -
Fixes for cmirrord policy   - Dontaudit xauth to list inotifyfs filesystem.   -
Allow xserver to translate contexts.   - Allow kdumpgui domain sys_admin
capability   - Allow vpnc to relabelfrom tun_socket   - Allow
prelink_cron_system_t to signal   - Fixes for gitolite   - Allow virt domain to
read symbolic links in device directories  - Add support for /dev/vhost-net   -
Allow psad to read files in /usr   - Allow systat to use nscd socket   - Fixes
for boinc policy
--------------------------------------------------------------------------------
ChangeLog:

* Mon Jun 14 2010 Miroslav Grepl <[email protected]> 3.7.19-28
- Fixes for netutils
- Cleanup of aiccu policy
- Add mpd policy
* Wed Jun  9 2010 Miroslav Grepl <[email protected]> 3.7.19-27
- Allow ftpd ipc_lock capability
- Allow audisp-remote to getcap and setcap
- Allow iscsid to read and write raw memory devices
- Fixes for bitlbee policy
* Wed Jun  9 2010 Miroslav Grepl <[email protected]> 3.7.19-26
- Allow krb5kdc to write krb5kdc_principal_t file
- Allow hald to send generic signal to dhcp client
- Fix dev_rw_vhost interface
- Add /var/run/abrt.socket label
* Tue Jun  8 2010 Miroslav Grepl <[email protected]> 3.7.19-25
- Fixes for cmirrord policy
- Dontaudit xauth to list inotifyfs filesystem.
- Allow xserver to translate contexts.
- Allow kdumpgui domain sys_admin capability
- Allow vpnc to relabelfrom tun_socket
- Allow prelink_cron_system_t to signal
- Fixes for gitolite
- Allow virt domain to read symbolic links in device directories
* Thu Jun  3 2010 Miroslav Grepl <[email protected]> 3.7.19-24
- Add support for /dev/vhost-net
- Allow psad to read files in /usr
- Allow systat to use nscd socket
- Fixes for boinc policy
* Tue Jun  1 2010 Miroslav Grepl <[email protected]> 3.7.19-23
- Add cmirrord policy
- Fixes for accountsd policy
- Fixes for boinc policy
- Allow cups-pdf to set attributes on fonts cache directory
- Allow radiusd to setrlimit
- Allow nscd sys_ptrace capability
* Tue May 25 2010 Dan Walsh <[email protected]> 3.7.19-22
- Allow procmail to execute scripts in the users home dir that are labeled 
home_bin_t
- Fix /var/run/abrtd.lock label
* Mon May 24 2010 Dan Walsh <[email protected]> 3.7.19-21
- Allow login programs to read krb5_home_t
Resolves: 594833
- Add obsoletes for cachefilesfd-selinux package
Resolves: #575084
* Thu May 20 2010 Dan Walsh <[email protected]> 3.7.19-20
- Allow mount to r/w abrt fifo file
- Allow svirt_t to getattr on hugetlbfs
- Allow abrt to create a directory under /var/spool
* Wed May 19 2010 Dan Walsh <[email protected]> 3.7.19-19
- Add labels for /sys
- Allow sshd to getattr on shutdown
- Fixes for munin
- Allow sssd to use the kernel key ring
- Allow tor to send syslog messages
- Allow iptabels to read usr files
- allow policykit to read all domains state
* Thu May 13 2010 Dan Walsh <[email protected]> 3.7.19-17
- Fix path for /var/spool/abrt
- Allow nfs_t as an entrypoint for http_sys_script_t
- Add policy for piranha
- Lots of fixes for sosreport
* Wed May 12 2010 Dan Walsh <[email protected]> 3.7.19-16
- Allow xm_t to read network state and get and set capabilities
- Allow policykit to getattr all processes
- Allow denyhosts to connect to tcp port 9911
- Allow pyranha to use raw ip sockets and ptrace itself
- Allow unconfined_execmem_t and gconfsd mechanism to dbus
- Allow staff to kill ping process
- Add additional MLS rules
* Mon May 10 2010 Dan Walsh <[email protected]> 3.7.19-15
- Allow gdm to edit ~/.gconf dir
Resolves: #590677
- Allow dovecot to create directories in /var/lib/dovecot
Partially resolves 590224
- Allow avahi to dbus chat with NetworkManager
- Fix cobbler labels
- Dontaudit iceauth_t leaks
- fix /var/lib/lxdm file context
- Allow aiccu to use tun tap devices
- Dontaudit shutdown using xserver.log
* Thu May  6 2010 Dan Walsh <[email protected]> 3.7.19-14
- Fixes for sandbox_x_net_t  to match access for sandbox_web_t ++
- Add xdm_etc_t for /etc/gdm directory, allow accountsd to manage this directory
- Add dontaudit interface for bluetooth dbus
- Add chronyd_read_keys, append_keys for initrc_t
- Add log support for ksmtuned
Resolves: #586663
* Thu May  6 2010 Dan Walsh <[email protected]> 3.7.19-13
- Allow boinc to send mail
* Wed May  5 2010 Dan Walsh <[email protected]> 3.7.19-12
- Allow initrc_t to remove dhcpc_state_t
- Fix label on sa-update.cron
- Allow dhcpc to restart chrony initrc
- Don't allow sandbox to send signals to its parent processes
- Fix transition from unconfined_t -> unconfined_mount_t -> rpcd_t
Resolves: #589136
* Mon May  3 2010 Dan Walsh <[email protected]> 3.7.19-11
- Fix location of oddjob_mkhomedir
Resolves: #587385
- fix labeling on /root/.shosts and ~/.shosts
- Allow ipsec_mgmt_t to manage net_conf_t
Resolves: #586760
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #598798 - SELinux is preventing /usr/bin/ksmserver "write" access   
   on /var/run/xdmctl/dmctl-:0/socket.
        https://bugzilla.redhat.com/show_bug.cgi?id=598798
  [ 2 ] Bug #598577 - SELinux is preventing 
/var/lib/boinc/projects/www.worldcommunitygrid.org/wcgrid_beta11_6.13_i686-pc-linux-gnu
 "sigstop" access     .
        https://bugzilla.redhat.com/show_bug.cgi?id=598577
  [ 3 ] Bug #597878 - SELinux is preventing /var/lib/boinc/slots/3/freeze 
"ptrace" access     .
        https://bugzilla.redhat.com/show_bug.cgi?id=597878
  [ 4 ] Bug #597242 - SELinux is preventing /bin/bash "write" access      on 
/var/run/nscd/socket.
        https://bugzilla.redhat.com/show_bug.cgi?id=597242
  [ 5 ] Bug #595835 - selinux breaks nagios
        https://bugzilla.redhat.com/show_bug.cgi?id=595835
  [ 6 ] Bug #599525 - SELinux is preventing /usr/sbin/abrtd "write" access     .
        https://bugzilla.redhat.com/show_bug.cgi?id=599525
  [ 7 ] Bug #601617 - SELinux is preventing /usr/bin/pulseaudio "read" access   
   on 0c50ee6989bbf5811d9f976b0000003e-runtime.
        https://bugzilla.redhat.com/show_bug.cgi?id=601617
  [ 8 ] Bug #600797 - SELinux is preventing /usr/bin/xauth access to a leaked 
inotify file descriptor.
        https://bugzilla.redhat.com/show_bug.cgi?id=600797
  [ 9 ] Bug #600266 - SELinux is preventing /bin/cp "relabelfrom" access      
on /var/lib/dhclient/yp.conf.predhclient.br0.
        https://bugzilla.redhat.com/show_bug.cgi?id=600266
  [ 10 ] Bug #599195 - SELinux is preventing /usr/bin/iceauth access to a 
leaked /tmp/air.mime.BVefuM/temp.flv (deleted) file descriptor.
        https://bugzilla.redhat.com/show_bug.cgi?id=599195
  [ 11 ] Bug #601655 - SELinux is preventing /usr/libexec/dovecot/deliver 
"read" access      on /var/spool/mqueue/dfo58AL71D027807.
        https://bugzilla.redhat.com/show_bug.cgi?id=601655
  [ 12 ] Bug #600651 - gitolite prohibited from authenticating users ssh keys.
        https://bugzilla.redhat.com/show_bug.cgi?id=600651
  [ 13 ] Bug #591514 - SELinux is preventing /bin/bash "signal" access     .
        https://bugzilla.redhat.com/show_bug.cgi?id=591514
  [ 14 ] Bug #601875 - SELinux is preventing 
/usr/lib64/nspluginwrapper/plugin-config "write" access      on 
/usr/lib64/mozilla/plugins-wrapped.
        https://bugzilla.redhat.com/show_bug.cgi?id=601875
  [ 15 ] Bug #602298 - SELinux is preventing /usr/sbin/proftpd "ipc_lock" 
access     .
        https://bugzilla.redhat.com/show_bug.cgi?id=602298
  [ 16 ] Bug #603610 - SELinux is preventing 
/usr/lib64/nspluginwrapper/npconfig "write" access      on 
/usr/lib64/mozilla/plugins-wrapped/nswrapper_64_64.libgnashplugin.so.
        https://bugzilla.redhat.com/show_bug.cgi?id=603610
  [ 17 ] Bug #602821 - aiccu policy is incomplete
        https://bugzilla.redhat.com/show_bug.cgi?id=602821
  [ 18 ] Bug #602453 - SELinux is preventing /usr/libexec/gdm-session-worker 
"getattr" access      on /home/c.cerbo/bin/javaeditline/src/libjavaeditline.so.
        https://bugzilla.redhat.com/show_bug.cgi?id=602453
  [ 19 ] Bug #601559 - SELinux is preventing pulseaudio "read" access      on 
pulse-shm-1776787913.
        https://bugzilla.redhat.com/show_bug.cgi?id=601559
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update selinux-policy' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
[email protected]
https://admin.fedoraproject.org/mailman/listinfo/package-announce

Reply via email to