Re: Moving Mozilla to Seamonkey

2006-07-27 Thread Marc Deslauriers
On Thu, 2006-07-27 at 15:11 -0600, Stephen John Smoogen wrote: I think it might be a good idea to evaluate a change of Firefox/Thunderbird/Mozilla to the latest tree set. This would mean changing Mozilla to Seamonkey, and moving Firefox/Thunderbird to 1.5.x series. I know this is a big

Re: Moving Mozilla to Seamonkey

2006-07-27 Thread Marc Deslauriers
On Fri, 2006-07-28 at 03:42 +0530, Rahul wrote: In general, IMO, Fedora Legacy errata policy should be to bump up to the newer upstream version on ancillary packages and backport fixes to only libraries or software that have other visible major dependencies and externally defined

[FLSA-2006:175040] Updated php packages fix security issues

2006-07-27 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated php packages fix security issues Advisory ID: FLSA:175040 Issue date:2006-07-27 Product: Red Hat Linux, Fedora Core Keywords:

Re: Squirrelmail 1.4.7 security fixes

2006-07-24 Thread Marc Deslauriers
On Mon, 2006-07-24 at 10:39 +0200, Nils Breunese (Lemonbit Internet) wrote: I see squirrelmail 1.4.7 fixes several security issues (see http:// www.squirrelmail.org/changelog.php), but I couldn't find any bugs related to these in bugzilla. I'm not a bugzilla wizard however, so I didn't

[FLSA-2006:189137-1] Updated mozilla packages fix security issues

2006-06-06 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mozilla packages fix security issues Advisory ID:FLSA:189137-1 Issue date: 2006-06-06 Product:Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:189137-2] Updated firefox package fixes security issues

2006-06-06 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated firefox package fixes security issues Advisory ID:FLSA:189137-2 Issue date: 2006-06-06 Product:Fedora Core Keywords: Bugfix, Security

[FLSA-2006:190777] Updated X.org packages fix security issue

2006-06-06 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated X.org packages fix security issue Advisory ID: FLSA:190777 Issue date:2006-06-06 Product: Fedora Core Keywords: Bugfix CVE

[FLSA-2006:190884] Updated squirrelmail package fixes security issues

2006-06-06 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated squirrelmail package fixes security issues Advisory ID: FLSA:190884 Issue date:2006-06-06 Product: Red Hat Linux, Fedora Core

Re: Fedora products, to upgrade rather than backport?

2006-05-15 Thread Marc Deslauriers
On Mon, 2006-05-15 at 15:20 -0400, Jesse Keating wrote: So in the RHL space, the choice was clear. Backport whenever possible. However the Fedora landscape is different. Upstream Core does not do backporting, they more often than not version upgrade to resolve security issues. Why should

Fedora Legacy Test Update Notification: mozilla

2006-05-15 Thread Marc Deslauriers
are advised to upgrade to these updated packages containing Mozilla version 1.7.13 which corrects these issues. - Changelogs rh7.3: * Sat Apr 22 2006 Marc Deslauriers [EMAIL PROTECTED] 37:1.7.13-0.73.1.legacy - Updated to 1.7.13

Fedora Legacy Test Update Notification: firefox

2006-05-15 Thread Marc Deslauriers
. - Changelogs fc3: * Wed Apr 19 2006 Marc Deslauriers [EMAIL PROTECTED] 0:1.0.8-1.1.fc3.1.legacy - Update to firefox 1.0.8 - This update can be downloaded from: http

[FLSA-2006:152898] Updated emacs packages fix a security issue

2006-05-12 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated emacs packages fix a security issue Advisory ID: FLSA:152898 Issue date:2006-05-12 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:152904] Updated ncpfs package fixes security issues

2006-05-12 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated ncpfs package fixes security issues Advisory ID: FLSA:152904 Issue date:2006-05-12 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:152923] Updated xloadimage package fixes security issues

2006-05-12 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated xloadimage package fixes security issues Advisory ID: FLSA:152923 Issue date:2006-05-12 Product: Red Hat Linux, Fedora Core

[FLSA-2006:185355] Updated gnupg package fixes security issues

2006-05-12 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gnupg package fixes security issues Advisory ID: FLSA:185355 Issue date:2006-05-12 Product: Red Hat Linux, Fedora Core Keywords:

Fedora Legacy Test Update Notification: tetex

2006-04-26 Thread Marc Deslauriers
to these issues. - Changelogs rh73: * Tue Apr 25 2006 Marc Deslauriers [EMAIL PROTECTED] 1.0.7-47.5.legacy - Added tetex tetex-latex and tetex-dvips to BuildPreReq! * Fri Apr 21 2006 Marc Deslauriers [EMAIL PROTECTED] 1.0.7-47.4.legacy - Added

Fedora Legacy Test Update Notification: emacs

2006-04-26 Thread Marc Deslauriers
- Fedora Legacy Test Update Notification FEDORALEGACY-2006-152898 Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152898 2006-04-26 - Name:

Re: [Updated] [FLSA-2006:186277] Updated sendmail packages fix security issue

2006-04-05 Thread Marc Deslauriers
On Wed, 2006-04-05 at 12:50 -0400, Adam Gibson wrote: One thing I noticed after the latest yum update of sendmail from the previous update is that alternatives is broken for /etc/pam.d/smtp for the sendmail package. Sendmail used to create /etc/pam.d/smtp.sendmail which alternatives would

[FLSA-2006:152873] Updated xine package fixes security issues

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated xine package fixes security issues Advisory ID: FLSA:152873 Issue date:2006-04-04 Product: Red Hat Linux 7.3 Keywords:

[FLSA-2006:152896] Updated mod_python package fixes a security issue

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mod_python package fixes a security issue Advisory ID: FLSA:152896 Issue date:2006-04-04 Product: Red Hat Linux, Fedora Core

[FLSA-2006:156290] Updated cyrus-imapd packages fix security issues

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated cyrus-imapd packages fix security issues Advisory ID: FLSA:156290 Issue date:2006-04-04 Product: Fedora Core Keywords:

[FLSA-2006:170411] Updated imap packages fix security issue

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated imap packages fix security issue Advisory ID: FLSA:170411 Issue date:2006-04-04 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:183571-1] Updated tar package fixes security issue

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated tar package fixes security issue Advisory ID: FLSA:183571-1 Issue date:2006-04-04 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:184074] Updated pine package fixes security issue

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated pine package fixes security issue Advisory ID: FLSA:184074 Issue date:2006-04-04 Product: Red Hat Linux Keywords: Bugfix,

[FLSA-2006:184098] Updated libc-client packages fixes security issue

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated libc-client packages fixes security issue Advisory ID: FLSA:184098 Issue date:2006-04-04 Product: Fedora Core 2 Keywords:

[Updated] [FLSA-2006:186277] Updated sendmail packages fix security issue

2006-04-04 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated sendmail packages fix security issue Advisory ID: FLSA:186277 Issue date:2006-04-04 Product: Red Hat Linux, Fedora Core Keywords:

[UPDATED] Fedora Legacy Test Update Notification: gnupg

2006-04-01 Thread Marc Deslauriers
. - Changelogs rh73: * Sat Apr 01 2006 Marc Deslauriers [EMAIL PROTECTED] 1.0.7-13.3.legacy - Added missing texinfo to BuildPrereq * Thu Mar 23 2006 Marc Deslauriers [EMAIL PROTECTED] 1.0.7-13.2.legacy - Added missing openldap

Fedora Legacy Test Update Notification: ncpfs

2006-03-28 Thread Marc Deslauriers
backported fixes for these issues. - Changelogs rh73: * Fri Mar 10 2006 Marc Deslauriers [EMAIL PROTECTED] 2.2.0.18-6.1.legacy - fixed getuid security bug CVE-2005-0013 rh9: * Fri Mar 10 2006 Marc Deslauriers [EMAIL PROTECTED

Fedora Legacy Test Update Notification: fetchmail

2006-03-28 Thread Marc Deslauriers
for POP3 buffer overflow - CAN-2005-2355 (#164512) rh9: * Thu Mar 23 2006 Marc Deslauriers [EMAIL PROTECTED] 6.2.0-3.4.legacy - Added missing e2fsprogs-devel to BuildPrereq * Sat Mar 11 2006 Donald Maner [EMAIL PROTECTED] 6.2.0-3.2.legacy - add patch for CAN-2003-0792 (#164512) - add patch for CAN

Fedora Legacy Test Update Notification: gnupg

2006-03-28 Thread Marc Deslauriers
. - Changelogs rh73: * Thu Mar 23 2006 Marc Deslauriers [EMAIL PROTECTED] 1.0.7-13.2.legacy - Added missing openldap-devel and zlib-devel to BuildPrereq * Wed Mar 15 2006 Donald Maner [EMAIL PROTECTED] 1.0.7-13.1.legacy - add patch from Werner Koch to error out on ambiguous armored

[UPDATED] Fedora Legacy Test Update Notification: sendmail

2006-03-28 Thread Marc Deslauriers
. - Changelogs rh73: * Sat Mar 25 2006 Marc Deslauriers [EMAIL PROTECTED] 8.12.11-4.22.10.legacy - Added hesiod-devel to BuildRequires - Reverted to previous alternatives files - Removed new triggers - Modified instructions in sendmail.mc * Wed Mar 22 2006

Re: New sendmail and missing /usr/lib/sendmail

2006-03-27 Thread Marc Deslauriers
On Sun, 2006-03-26 at 23:48 -0600, Mike McCarty wrote: Ah, now we get down to the nitty gritty of the desire to hasten the process of going from a Test state to a Release state. Hopefully, those who in past have seen no need to maintain a policy of no package can move from Test state to

Re: New sendmail and missing /usr/lib/sendmail

2006-03-27 Thread Marc Deslauriers
On Mon, 2006-03-27 at 10:47 -0800, Jesse Keating wrote: These issues should be resolved in the newer packages in updates-testing. They're not in updates-testing yet. They're still awaiting PUBLISH votes in bugzilla. https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186277 Marc.

Re: sendmail upgrade issues

2006-03-26 Thread Marc Deslauriers
On Sun, 2006-03-26 at 01:38 -0600, Eric Rostetter wrote: This is fixed in the package awaiting QA. I never received an email about any such package... I didn't know I had to send you one. :) Look here: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=186277 Marc. signature.asc

Re: RH 9.0: AUTH LOGIN issue with latest sendmail patch

2006-03-25 Thread Marc Deslauriers
On Sat, 2006-03-25 at 08:52 -0600, Mike Klinke wrote: There seem to be three missing links on RH9 and FC1: /usr/lib/sendmail - /etc/alternatives/mta-sendmail /usr/share/man/man8/sendmail.8.gz - /etc/alternatives/mta-sendmailman /etc/pam.d/smtp -

[FLEA-2006:173091-1] Updated glibc packages add daylight savings rule enhancements

2006-03-23 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated glibc packages add daylight savings rule enhancements Advisory ID: FLEA:173091-1 Issue date:2006-03-23 Product:

[FLEA-2006:173091-2] Updated tzdata package adds daylight savings rule enhancements

2006-03-23 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated tzdata package adds daylight savings rule enhancements Advisory ID: FLEA:173091-2 Issue date:2006-03-23 Product:

[FLEA-2006:173091-1] Updated glibc packages add daylight savings rule enhancements

2006-03-23 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated glibc packages add daylight savings rule enhancements Advisory ID: FLEA:173091-1 Issue date:2006-03-23 Product:

[FLEA-2006:173091-2] Updated tzdata package adds daylight savings rule enhancements

2006-03-23 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated tzdata package adds daylight savings rule enhancements Advisory ID: FLEA:173091-2 Issue date:2006-03-23 Product:

Re: US-CERT Technical Cyber Security Alert TA06-081A -- Sendmail Race Condition Vulnerability (fwd)

2006-03-23 Thread Marc Deslauriers
On Wed, 2006-03-22 at 10:29 -0800, Kenneth Porter wrote: For those of us accepting mail from outside on pre-FC4 Fedora, are any updates in the pipe to address this? Packages have been created and QA'd. They will be pushed to updates-testing soon. You may follow progress here:

[FLSA-2006:173274] Updated gdk-pixbuf packages fix security issues

2006-03-16 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gdk-pixbuf packages fix security issues Advisory ID: FLSA:173274 Issue date:2006-03-16 Product: Red Hat Linux, Fedora Core

[FLSA-2006:175404] Updated xpdf package fixes security issues

2006-03-16 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated xpdf package fixes security issues Advisory ID: FLSA:175404 Issue date:2006-03-16 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:178606] Updated kdelibs packages fix security issues

2006-03-16 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated kdelibs packages fix security issues Advisory ID: FLSA:178606 Issue date:2006-03-16 Product: Red Hat Linux, Fedora Core Keywords:

Fedora Legacy Server Outage

2006-03-16 Thread Marc Deslauriers
As we sent out today's security advisories, one of our servers experienced an outage before completely syncing to the mirrors. As a result, the updates repository contains missing packages. This situation should be corrected shortly. I apologize for any problems this may cause. Marc.

Fedora Legacy Test Update Notification: mod_python

2006-03-15 Thread Marc Deslauriers
- Fedora Legacy Test Update Notification FEDORALEGACY-2006-152896 Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152896 2006-03-15 - Name:

Fedora Legacy Test Update Notification: tcpdump

2006-03-15 Thread Marc Deslauriers
security patches and are not vulnerable to these issues. - Changelogs rh9: * Sat Jun 11 2005 Marc Deslauriers [EMAIL PROTECTED] 14:3.7.2-7.9.4.legacy - fix for Multiple DoS issues in tcpdump (CAN-2005-1280, CAN-2005-1279, CAN-2005-1278

Fedora Legacy Test Update Notification: cyrus-imapd

2006-03-15 Thread Marc Deslauriers
these issues. - Changelogs fc2: * Mon Mar 06 2006 Marc Deslauriers [EMAIL PROTECTED] 2.2.12-1.1.fc2.1.legacy - Update to 2.2.12 to fix CVE-2005-0546. The only difference between 2.2.10 and 2.2.12 was the security fix, so upgrading

Fedora Legacy Test Update Notification: imap

2006-03-15 Thread Marc Deslauriers
. - Changelogs rh73: * Mon Mar 06 2006 Marc Deslauriers [EMAIL PROTECTED] 2001a-10.3.legacy - Replaced CVE-2005-2933 patch with the one from RHEL21 for consistency's sake * Wed Oct 12 2005 Ville Herva [EMAIL PROTECTED] 2001a-10.2.legacy - Added security patch for CAN-2005-2933 rh9: * Mon Mar 06 2006

Fedora Legacy Test Update Notification: tar (rh73, rh9, fc1, fc2)

2006-03-15 Thread Marc Deslauriers
CVE-2005-1918 to this issue. Users of tar should upgrade to this updated package, which contains a replacement backported patch to correct this issue. - Changelogs rh73: * Tue Mar 07 2006 Marc Deslauriers [EMAIL PROTECTED] 1.13.25

Fedora Legacy Test Update Notification: pine

2006-03-15 Thread Marc Deslauriers
the name CVE-2003-0297 to this issue. Users of Pine are advised to upgrade to these erratum packages which contain a backported patch to correct this issue. - Changelogs rh73: * Wed Mar 08 2006 Marc Deslauriers [EMAIL PROTECTED

Fedora Legacy Test Update Notification: libc-client

2006-03-15 Thread Marc Deslauriers
of libc-client should upgrade to these updated packages, which contain a backported patch that resolves this issue. - Changelogs fc2: * Tue Mar 07 2006 Marc Deslauriers [EMAIL PROTECTED] 2002e-5.1.legacy - apply fix for CVE-2005-2933

[FLSA-2006:168516] Updated pcre packages fix a security issue

2006-03-07 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated pcre packages fix a security issue Advisory ID: FLSA:168516 Issue date:2006-03-07 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:176751] Updated gpdf package fixes security issues

2006-03-07 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gpdf package fixes security issues Advisory ID: FLSA:176751 Issue date:2006-03-07 Product: Fedora Core Keywords: Bugfix

[UPDATED] Fedora Legacy Test Update Notification: kernel (fc1)

2006-03-05 Thread Marc Deslauriers
. - Changelogs fc1: * Fri Mar 03 2006 Marc Deslauriers [EMAIL PROTECTED] 2.4.22-1.2199.8.legacy.nptl - Fixed the broken CVE-2005-0749 patch that was causing unstability * Fri Feb 17 2006 Marc Deslauriers [EMAIL PROTECTED] 2.4.22-1.2199.7.legacy.nptl - Added patch for CVE-2002

Re: Rebuild exisitng errata for x86_64?

2006-03-04 Thread Marc Deslauriers
On Sat, 2006-03-04 at 01:58 -0600, Eric Rostetter wrote: In any case, I think we should _at least_ release all FC3 packages for x86_64. In other words, we shouldn't release new FC3 x86_64 without releasing also the older FC3 x86_64, for consistency. So far, all FC3 updates have had x86_64

Fedora Legacy Test Update Notification: glibc

2006-03-01 Thread Marc Deslauriers
. - Changelogs rh73: * Mon Feb 20 2006 Marc Deslauriers [EMAIL PROTECTED] 2.2.4-44.legacy.8 - Bring timezone info up to version 2006a * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 2.2.4-44.legacy.7 - Bring timezone info up to version 2005m rh9: * Tue

Fedora Legacy Test Update Notification: tzdata

2006-03-01 Thread Marc Deslauriers
. - Changelogs fc1: * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 2005r-3.fc1.1.legacy - Rebuilt as a Fedora Legacy update to Fedora Core 1 fc2: * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 2005r-3.fc2.1.legacy - Rebuilt as a Fedora Legacy update to Fedora Core 2

[FLSA-2006:175818] Updated udev packages fix a security issue

2006-02-27 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated udev packages fix a security issue Advisory ID: FLSA:175818 Issue date:2006-02-27 Product: Fedora Core Keywords: Bugfix

[FLSA-2006:177326] Updated mod_auth_pgsql package fixes security issue

2006-02-27 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mod_auth_pgsql package fixes security issue Advisory ID: FLSA:177326 Issue date:2006-02-27 Product: Fedora Core Keywords:

[FLSA-2006:177694] Updated auth_ldap package fixes security issue

2006-02-27 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated auth_ldap package fixes security issue Advisory ID: FLSA:177694 Issue date:2006-02-27 Product: Red Hat Linux Keywords:

[FLSA-2006:181014] Updated gnutls packages fix a security issue

2006-02-27 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gnutls packages fix a security issue Advisory ID: FLSA:181014 Issue date:2006-02-27 Product: Fedora Core Keywords: Bugfix

Fedora Legacy Test Update Notification: pcre

2006-02-26 Thread Marc Deslauriers
-2005-2491 rh9: * Sun Feb 19 2006 Marc Deslauriers [EMAIL PROTECTED] 3.9-10.1.legacy - Added patch for CVE-2005-2491 fc1: * Sat Feb 25 2006 Marc Deslauriers [EMAIL PROTECTED] 4.4-1.2.legacy - Added pcre-devel to BuildPrereq * Sun Feb 19 2006 Marc Deslauriers [EMAIL PROTECTED] 4.4-1.1.legacy

Fedora Legacy Test Update Notification: xpdf

2006-02-26 Thread Marc Deslauriers
. - Changelogs rh73: * Mon Feb 20 2006 Marc Deslauriers [EMAIL PROTECTED] 1.00-7.6.legacy - Added better patch for CVE-2004-0888 * Sun Feb 19 2006 Marc Deslauriers [EMAIL PROTECTED] 1.00-7.5.legacy - Added patch for CVE-2005-3193 rh9: * Sun Feb 19 2006 Marc Deslauriers

Fedora Legacy Test Update Notification: udev

2006-02-26 Thread Marc Deslauriers
to these updated packages, which contain a backported patch and are not vulnerable to this issue. - Changelogs fc2: * Sun Feb 26 2006 Marc Deslauriers [EMAIL PROTECTED] 024-6.2.legacy - Added missing glib2-devel to BuildRequires * Sun

[FLSA-2006:138098] Updated nfs-utils package fixes security issues

2006-02-25 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated nfs-utils package fixes security issues Advisory ID: FLSA:138098 Issue date:2006-02-25 Product: Red Hat Linux, Fedora Core

[FLSA-2006:158543] Updated gaim package fixes security issues

2006-02-25 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gaim package fixes security issues Advisory ID: FLSA:158543 Issue date:2006-02-25 Products: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:176731] Updated perl packages fix security issue

2006-02-25 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated perl packages fix security issue Advisory ID: FLSA:176731 Issue date:2006-02-25 Product: Red Hat Linux, Fedora Core Keywords:

Fedora Legacy Test Update Notification: gdk-pixbuf

2006-02-23 Thread Marc Deslauriers
to these issues. - Changelogs rh73: * Sun Feb 19 2006 Marc Deslauriers [EMAIL PROTECTED] - 1:0.22.0-7.73.4.legacy - Prevent another integer overflow in the xpm loader (CVE-2005-2976) - Prevent an infinite loop in the xpm loader (CVE-2005

Fedora Legacy Test Update Notification: libungif

2006-02-23 Thread Marc Deslauriers
and CVE-2005-3350 to these issues. All users of libungif are advised to upgrade to these updated packages, which contain backported patches that resolve these issues. - Changelogs rh73: * Wed Feb 22 2006 Marc Deslauriers [EMAIL

[FLSA-2006:180036-1] Updated mozilla packages fix security issues

2006-02-23 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mozilla packages fix security issues Advisory ID: FLSA:180036-1 Issue date:2006-02-23 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:180036-2] Updated firefox package fixes security issues

2006-02-23 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated firefox package fixes security issues Advisory ID: FLSA:180036-2 Issue date:2006-02-23 Product: Fedora Core Keywords:

Re: x86_64 Packages missing

2006-02-22 Thread Marc Deslauriers
On Wed, 2006-02-22 at 13:07 +0100, Klaus Steinberger wrote: Hello, in the last Advisories (e.g. [FLSA-2006:175406]) also x86_64 Packages were mentioned, but they are missing from the updates Repository, they are just in updates-testing. Were they missed or is that intentional? the

Re: Fedora Legacy Test Update Notification: gpdf

2006-02-22 Thread Marc Deslauriers
On Wed, 2006-02-22 at 09:57 -0700, Michal Jaegermann wrote: On Mon, Feb 20, 2006 at 07:58:41PM -0500, Marc Deslauriers wrote: - Fedora Legacy Test Update Notification FEDORALEGACY-2006-176751 fedora/3/updates

Fedora Legacy Test Update Notification: kernel (rh73 and rh9)

2006-02-20 Thread Marc Deslauriers
their kernels to the packages associated with their machine architectures and configurations as listed in this erratum. - Changelogs rh73: * Sat Feb 04 2006 Marc Deslauriers [EMAIL PROTECTED] 2.4.20-45.9.legacy - Removed CVE-2005-3044

Fedora Legacy Test Update Notification: kernel (fc1)

2006-02-20 Thread Marc Deslauriers
) All users are advised to upgrade their kernels to the packages associated with their machine architectures and configurations as listed in this erratum. - Changelogs fc1: * Fri Feb 17 2006 Marc Deslauriers [EMAIL PROTECTED

Fedora Legacy Test Update Notification: kernel (fc2)

2006-02-20 Thread Marc Deslauriers
. - Changelogs fc2: * Fri Feb 10 2006 Marc Deslauriers [EMAIL PROTECTED] 2.6.10-2.3.legacy_FC2 - Added patches for: CVE-2002-2185 (IGMP DoS) CVE-2005-3805 (POSIX timer cleanup handling on exit locking problem) CVE-2005-3807

Fedora Legacy Test Update Notification: kernel (fc3)

2006-02-20 Thread Marc Deslauriers
to upgrade their kernels to the packages associated with their machine architectures and configurations as listed in this erratum. - Changelogs fc3: * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 2.6.12-2.3.legacy_FC3 - Corrected

Fedora Legacy Test Update Notification: gpdf

2006-02-20 Thread Marc Deslauriers
: * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 0.110-1.5.legacy - Use better patch for CVE-2004-0888 (from RHEL3 xpdf) - Add patch for CVE-2005-3193 fc2: * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 2.8.2-4.1.1.legacy - Rebuilt as Fedora Legacy security update for Fedora Core 2

Fedora Legacy Test Update Notification: perl-DBI

2006-02-20 Thread Marc Deslauriers
to this erratum package which disables the temporary PID file unless configured. - Changelogs rh73: * Sat Feb 18 2006 Marc Deslauriers [EMAIL PROTECTED] 1.21-1.1.legacy - Added fix for CVE-2005-0077 rh9: * Sat Feb 18 2006 Marc

[FLSA-2006:152809] Updated squid package fixes security issues

2006-02-18 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated squid package fixes security issues Advisory ID: FLSA:152809 Issue date:2006-02-18 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:168935] Updated openssh packages fix security issues

2006-02-18 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated openssh packages fix security issues Advisory ID: FLSA:168935 Issue date:2006-02-18 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:175406] Updated Apache httpd packages fix security issues

2006-02-18 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated Apache httpd packages fix security issues Advisory ID: FLSA:175406 Issue date:2006-02-18 Product: Red Hat Linux, Fedora Core

Fedora Legacy Test Update Notification: sudo

2006-02-17 Thread Marc Deslauriers
of sudo should update to this updated package, which contains a backported patch and is not vulnerable to this issue. - Changelogs rh73: * Mon Feb 13 2006 Marc Deslauriers [EMAIL PROTECTED] 1.6.5p2-2.3.legacy - Fix CVE-2005-1993 sudo

Fedora Legacy Test Update Notification: XFree86

2006-02-17 Thread Marc Deslauriers
of XFree86 should upgrade to these updated packages, which contain backported patches and are not vulnerable to these issues. - Changelogs rh73: * Sun Feb 12 2006 Marc Deslauriers [EMAIL PROTECTED] 4.2.1-16.73.31.legacy - Add XFree86

Fedora Legacy Test Update Notification: xorg-x11

2006-02-17 Thread Marc Deslauriers
. - Changelogs fc2: * Sun Feb 12 2006 Marc Deslauriers [EMAIL PROTECTED] 6.7.0-14.1.legacy - Add XFree86-4.3.0-security-CAN-2005-2495.patch to fix various integer overflows. - This update can be downloaded from: http

Fedora Legacy Test Update Notification: postgresql

2006-02-12 Thread Marc Deslauriers
: * Sat Feb 11 2006 Marc Deslauriers [EMAIL PROTECTED] 7.3.10-0.90.1.legacy - Update to PostgreSQL 7.3.10 (fixes CVE-2005-1409 and CVE-2005-1410) fc1: * Sat Feb 11 2006 Marc Deslauriers [EMAIL PROTECTED] 7.3.10-1.1.legacy - Rebuilt as Fedora Legacy security update for Fedore Core 1 - Added missing

Fedora Legacy Test Update Notification: gnutls

2006-02-12 Thread Marc Deslauriers
a backported patch from the GNU TLS maintainers to correct this issue. - Changelogs fc3: * Sun Feb 12 2006 Marc Deslauriers [EMAIL PROTECTED] 1.0.20-3.1.3.legacy - Added missing zlib-devel to BuildPrereq * Sat Feb 11 2006 Marc

Re: no mandatory QA testing at all [Re: crazy thought about how to ease QA testing]

2006-02-11 Thread Marc Deslauriers
On Fri, 2006-02-10 at 22:00 -0800, Jesse Keating wrote: On Sat, 2006-02-11 at 07:32 +0200, Pekka Savola wrote: I agree that this would complicate the process further. I have proposed something simpler, and still do: 1) every package, even without any VERIFY QA votes at all, will be

[UPDATED] Fedora Legacy Test Update Notification: httpd

2006-02-11 Thread Marc Deslauriers
Deslauriers [EMAIL PROTECTED] 1.3.27-9.legacy - mod_imap: add security fix for XSS issue (CVE-2005-3352) rh9: * Sun Jan 22 2006 Marc Deslauriers [EMAIL PROTECTED] 2.0.40-21.21.legacy - mod_ssl: add security fix for HTTP-on-SSL-port handling (CVE-2005-3357) - mod_imap: add security fix for XSS issue

Fedora Legacy Test Update Notification: nfs-utils

2006-02-11 Thread Marc Deslauriers
- Fedora Legacy Test Update Notification FEDORALEGACY-2006-138098 https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=138098 2006-02-11 - Name:

Fedora Legacy Test Update Notification: openssh

2006-02-11 Thread Marc Deslauriers
: * Mon Jan 23 2006 Marc Deslauriers [EMAIL PROTECTED] 3.1p1-14.3.legacy - use fork+exec instead of system in scp - CVE-2006-0225 rh9: * Mon Jan 23 2006 Marc Deslauriers [EMAIL PROTECTED] 3.5p1-11.4.legacy - use fork+exec instead of system in scp - CVE-2006-0225 * Sun Jan 22 2006 Marc Deslauriers

Fedora Legacy Test Update Notification: mozilla

2006-02-11 Thread Marc Deslauriers
are advised to upgrade to these updated packages, which contain backported patches to correct these issues. - Changelogs rh7.3: * Sun Feb 05 2006 Marc Deslauriers [EMAIL PROTECTED] 37:1.7.12-0.73.3.legacy - Fix CVE-2005-4134, CVE-2006

Fedora Legacy Test Update Notification: perl

2006-02-08 Thread Marc Deslauriers
- Fedora Legacy Test Update Notification FEDORALEGACY-2006-176731 Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=176731 2006-02-08 - Name:

Fedora Legacy Test Update Notification: gaim

2006-01-24 Thread Marc Deslauriers
and is not vulnerable to these issues. - 7.3 changelog: * Wed Jan 18 2006 Marc Deslauriers [EMAIL PROTECTED] 1.5.0-0.73.1.legacy - Updated to 1.5.0 to fix security issues - Added CVS backport patches from FC4 * Mon May 23 2005 Marc

Re: slapper worm

2006-01-23 Thread Marc Deslauriers
On Tue, 2006-01-24 at 06:32 +1000, Michael Mansour wrote: I'm using: perl-5.8.3-17.4.legacy httpd-2.0.51-1.9.legacy openssl-0.9.7a-33.13.legacy Are there any updates FL can do to any of the packages to fix/block slapper from an FC1 machine? What version of php are you running? Marc.

Fedora Legacy Test Update Notification: mod_auth_pgsql

2006-01-19 Thread Marc Deslauriers
- Fedora Legacy Test Update Notification FEDORALEGACY-2006-177326 Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=177326 2006-01-19 - Name:

[FLSA-2006:167803] Updated mysql packages fix security issues

2006-01-10 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mysql packages fix security issues Advisory ID: FLSA:167803 Issue date:2006-01-10 Product: Red Hat Linux, Fedora Core Keywords:

Fedora Legacy Test Update Notification: perl

2006-01-09 Thread Marc Deslauriers
- Fedora Legacy Test Update Notification FEDORALEGACY-2005-152845 Bugzilla https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=152845 2006-01-09 - Name:

[FLSA-2006:136323] Updated gettext package fixes security issues

2006-01-09 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gettext package fixes security issues Advisory ID: FLSA:136323 Issue date:2006-01-09 Product: Red Hat Linux, Fedora Core Keywords:

[FLSA-2006:152803] Updated lesstif packages fix security issues

2006-01-09 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated lesstif packages fix security issues Advisory ID: FLSA:152803 Issue date:2006-01-09 Product: Red Hat Linux, Fedora Core Keywords:

  1   2   >