-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-9538 2013-05-29 17:25:27 --------------------------------------------------------------------------------
Name : bzr Product : Fedora 19 Version : 2.5.1 Release : 11.fc19 URL : http://www.bazaar-vcs.org/ Summary : Friendly distributed version control system Description : Bazaar is a distributed revision control system that is powerful, friendly, and scalable. It is the successor of Baz-1.x which, in turn, was a user-friendly reimplementation of GNU Arch. -------------------------------------------------------------------------------- Update Information: * Fixes CVE-2013-2099, maliciously crafted SSL certificate can cause a denial of service. * Builds the C extensions from the Cython source instead of the pregenerated C files. * Build without strict-aliasing on Fedora versions which have a bug in the python distutils module. * Install the localization files * (F17-only) Update from upstream 2.5.0 to 2.5.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #963260 - CVE-2013-2098 CVE-2013-2099 python: ssl.match_hostname() DoS via certificates with specially crafted hostname wildcard patterns https://bugzilla.redhat.com/show_bug.cgi?id=963260 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bzr' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
