The following Fedora EPEL 6 Security updates need testing:
 Age  URL
 1082  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2012-5620/bugzilla-3.4.14-2.el6
 147  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-4008/cross-binutils-2.23.51.0.3-1.el6.1
 135  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2014-4242/facter-1.6.18-8.el6
  41  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-0864/nodejs-0.10.36-3.el6,libuv-0.10.34-1.el6,v8-3.14.5.10-17.el6
  20  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1317/mongodb-2.4.13-1.el6
  19  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1346/drupal6-6.35-1.el6
  14  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1404/tor-0.2.5.11-1.el6
  14  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1376/owncloud-7.0.5-2.el6
   8  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1501/strongswan-5.3.0-1.el6
   8  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1530/drupal7-webform-4.7-1.el6
   6  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1552/mediawiki119-1.19.24-1.el6
   3  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1592/arj-3.10.22-22.el6
   3  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-1599/perl-DBD-Firebird-1.19-1.el6
   0  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5739/perl-Test-Signature-1.11-1.el6,perl-Module-Signature-0.78-1.el6
   0  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5707/chrony-1.31.1-1.el6
   0  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5720/zarafa-7.1.12-1.el6
   0  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5702/torque-4.2.10-1.el6
   0  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5690/php-pecl-zendopcache-7.0.4-2.el6
   0  
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2015-5684/knot-1.6.3-1.el6


The following builds have been pushed to Fedora EPEL 6 updates-testing

    collectl-4.0.0-1.el6
    perl-MCE-1.606-1.el6
    perl-Module-Signature-0.78-1.el6
    perl-Test-Signature-1.11-1.el6
    python-bugzilla-1.2.0-1.el6
    qpid-proton-0.9-3.el6
    rubygem-qpid_proton-0.9.0-1.el6
    vertica-python-0.3.5-1.el6

Details about builds:


================================================================================
 collectl-4.0.0-1.el6 (FEDORA-EPEL-2015-5730)
 A utility to collect various Linux performance data
--------------------------------------------------------------------------------
Update Information:

- update to upstream version 4.0.0
- upstream changelog at http://collectl.sourceforge.net/Releases.html

--------------------------------------------------------------------------------
ChangeLog:

* Thu Apr  9 2015 Dan Horák <dan[at]danny.cz> - 4.0.0-1
- upgrade to upstream version 4.0.0 (#1201069)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1201069 - collectl-4.0.0.src is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1201069
--------------------------------------------------------------------------------


================================================================================
 perl-MCE-1.606-1.el6 (FEDORA-EPEL-2015-5727)
 Many-core Engine for Perl providing parallel processing capabilities
--------------------------------------------------------------------------------
Update Information:

A new version of MCE is available. See 
http://search.cpan.org/src/MARIOROY/MCE-1.606/CHANGES for details on changes in 
this release.
A new version of MCE is available. See 
http://cpansearch.perl.org/src/MARIOROY/MCE-1.605/CHANGES for details on 
changes in this release.
A new version of MCE is available. See 
http://cpansearch.perl.org/src/MARIOROY/MCE-1.604/CHANGES for summary of 
changes for this release.
--------------------------------------------------------------------------------
ChangeLog:

* Thu Apr  9 2015 Petr Šabata <con...@redhat.com> - 1.606-1
- 1.606 bump
* Wed Apr  8 2015 Petr Šabata <con...@redhat.com> - 1.605-1
- 1.605 bump
* Mon Mar 23 2015 Petr Šabata <con...@redhat.com> - 1.604-1
- 1.604 bump
* Wed Feb 11 2015 Petr Pisar <ppi...@redhat.com> - 1.600-3
- Move mce_grep tool into a separate sub-package
* Tue Feb 10 2015 Petr Pisar <ppi...@redhat.com> - 1.600-2
- Correct dependencies
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1210119 - perl-MCE-1.606 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1210119
  [ 2 ] Bug #1209148 - perl-MCE-1.605 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1209148
  [ 3 ] Bug #1204474 - perl-MCE-1.604 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1204474
--------------------------------------------------------------------------------


================================================================================
 perl-Module-Signature-0.78-1.el6 (FEDORA-EPEL-2015-5739)
 CPAN signature management utilities and modules
--------------------------------------------------------------------------------
Update Information:

This update addresses various security issues in perl-Module-Signature as 
described below. The default behavior is also changed so as to ignore any 
MANIFEST.SKIP files unless a "skip" parameter is specified. An updated version 
of perl-Test-Signature that accounts for the changed default behavior is 
included in this update.

Security issues:

 * Module::Signature before version 0.75 could be tricked into interpreting the 
unsigned portion of a SIGNATURE file as the signed portion due to faulty 
parsing of the PGP signature boundaries.

 * When verifying the contents of a CPAN module, Module::Signature before 
version 0.75 ignored some files in the extracted tarball that were not listed 
in the signature file. This included some files in the t/ directory that would 
execute
automatically during "make test".

 * Module::Signature before version 0.75 used two argument open() calls to read 
the files when generating checksums from the signed manifest. This allowed 
embedding arbitrary shell commands into the SIGNATURE file that would execute 
during the signature verification process.

 * Module::Signature before version 0.75 has been loading several modules at 
runtime inside the extracted module directory. Modules like Text::Diff are not 
guaranteed to be available on all platforms and could be added to a malicious
module so that they would load from the '.' path in @INC.

--------------------------------------------------------------------------------
ChangeLog:

* Thu Apr  9 2015 Paul Howarth <p...@city-fan.org> - 0.78-1
- Update to 0.78
  - Fix verify() use from cpanm and CPAN.pm
* Wed Apr  8 2015 Paul Howarth <p...@city-fan.org> - 0.77-1
- Update to 0.77
  - Include the latest public keys of PAUSE, ANDK and AUDREYT
  - Clarify scripts/cpansign copyright to CC0 (#965126, CPAN RT#85466)
* Wed Apr  8 2015 Paul Howarth <p...@city-fan.org> - 0.76-1
- Update to 0.76
  - Fix signature tests by defaulting to verify(skip=>1) when
    $ENV{TEST_SIGNATURE} is true
* Tue Apr  7 2015 Paul Howarth <p...@city-fan.org> - 0.75-1
- Update to 0.75
  - Fix GPG signature parsing logic
  - MANIFEST.SKIP is no longer consulted unless --skip is given
  - Properly use open() modes to avoid injection attacks
  - More protection of @INC from relative paths
- Don't try to run the signature test, which needs the network
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1209911 - perl-Module-Signature: unsigned files interpreted as 
signed in some circumstances
        https://bugzilla.redhat.com/show_bug.cgi?id=1209911
  [ 2 ] Bug #1209915 - perl-Module-Signature: arbitrary code execution during 
test phase
        https://bugzilla.redhat.com/show_bug.cgi?id=1209915
  [ 3 ] Bug #1209917 - perl-Module-Signature: arbitrary code execution when 
verifying module signatures
        https://bugzilla.redhat.com/show_bug.cgi?id=1209917
  [ 4 ] Bug #1209918 - perl-Module-Signature: arbitrary modules loading in some 
circumstances
        https://bugzilla.redhat.com/show_bug.cgi?id=1209918
--------------------------------------------------------------------------------


================================================================================
 perl-Test-Signature-1.11-1.el6 (FEDORA-EPEL-2015-5739)
 Automated SIGNATURE testing
--------------------------------------------------------------------------------
Update Information:

This update addresses various security issues in perl-Module-Signature as 
described below. The default behavior is also changed so as to ignore any 
MANIFEST.SKIP files unless a "skip" parameter is specified. An updated version 
of perl-Test-Signature that accounts for the changed default behavior is 
included in this update.

Security issues:

 * Module::Signature before version 0.75 could be tricked into interpreting the 
unsigned portion of a SIGNATURE file as the signed portion due to faulty 
parsing of the PGP signature boundaries.

 * When verifying the contents of a CPAN module, Module::Signature before 
version 0.75 ignored some files in the extracted tarball that were not listed 
in the signature file. This included some files in the t/ directory that would 
execute
automatically during "make test".

 * Module::Signature before version 0.75 used two argument open() calls to read 
the files when generating checksums from the signed manifest. This allowed 
embedding arbitrary shell commands into the SIGNATURE file that would execute 
during the signature verification process.

 * Module::Signature before version 0.75 has been loading several modules at 
runtime inside the extracted module directory. Modules like Text::Diff are not 
guaranteed to be available on all platforms and could be added to a malicious
module so that they would load from the '.' path in @INC.

--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr  8 2015 Paul Howarth <p...@city-fan.org> - 1.11-1
- Update to 1.11
  - Compatibility with Module::Signature 0.75+
- Classify buildreqs by usage
- Don't use macros for commands
- Avoid clobbering ~/.gnupg for local builds
- Make %files list more explicit
- Drop %defattr, redundant since rpm 4.4
- Import upstream's GPG key in %prep so we don't need to fetch it from a
  keyserver when running the signature test
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1209911 - perl-Module-Signature: unsigned files interpreted as 
signed in some circumstances
        https://bugzilla.redhat.com/show_bug.cgi?id=1209911
  [ 2 ] Bug #1209915 - perl-Module-Signature: arbitrary code execution during 
test phase
        https://bugzilla.redhat.com/show_bug.cgi?id=1209915
  [ 3 ] Bug #1209917 - perl-Module-Signature: arbitrary code execution when 
verifying module signatures
        https://bugzilla.redhat.com/show_bug.cgi?id=1209917
  [ 4 ] Bug #1209918 - perl-Module-Signature: arbitrary modules loading in some 
circumstances
        https://bugzilla.redhat.com/show_bug.cgi?id=1209918
--------------------------------------------------------------------------------


================================================================================
 python-bugzilla-1.2.0-1.el6 (FEDORA-EPEL-2015-5735)
 A python library and tool for interacting with Bugzilla
--------------------------------------------------------------------------------
Update Information:

* Rebased to version 1.2.0
* Add bugzilla new/query/modify --field flag (Arun Babu Neelicattu)
* API support for ExternalBugs (Arun Babu Neelicattu, Brian Bouterse)
* Add new/modify --alias support (Adam Williamson)
* Bugzilla.logged_in now returns live state (Arun Babu Neelicattu)
* Fix getbugs API with latest Bugzilla releases
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr  8 2015 Cole Robinson <crobi...@redhat.com> - 1.2.0-1
- Rebased to version 1.2.0
- Add bugzilla new/query/modify --field flag (Arun Babu Neelicattu)
- API support for ExternalBugs (Arun Babu Neelicattu, Brian Bouterse)
- Add new/modify --alias support (Adam Williamson)
- Bugzilla.logged_in now returns live state (Arun Babu Neelicattu)
- Fix getbugs API with latest Bugzilla releases
--------------------------------------------------------------------------------


================================================================================
 qpid-proton-0.9-3.el6 (FEDORA-EPEL-2015-5741)
 A high performance, lightweight messaging library
--------------------------------------------------------------------------------
Update Information:

Added a global excludes macro to fix EL6 issues with example Perl modules.
Marked the examples in -c-devel as doc.
Rebased on Proton 0.9.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr  8 2015 Darryl L. Pierce <dpie...@redhat.com> - 0.9-3
- Added a global excludes macro to fix EL6 issues with example Perl modules.
* Wed Apr  8 2015 Darryl L. Pierce <dpie...@redhat.com> - 0.9-2
- Marked the examples in -c-devel as doc.
- Turned off the executable flag on all files under examples.
* Mon Apr  6 2015 Darryl L. Pierce <dpie...@redhat.com> - 0.9-1
- Rebased on Proton 0.9.
- Removed the proton binary from qpid-proton-c.
- Added the perl-qpid-proton subpackage.
--------------------------------------------------------------------------------


================================================================================
 rubygem-qpid_proton-0.9.0-1.el6 (FEDORA-EPEL-2015-5734)
 Ruby language bindings for the Qpid Proton messaging framework
--------------------------------------------------------------------------------
Update Information:

Rebased on qpid_proton 0.9.0.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Apr  7 2015 Darryl L. Pierce <dpie...@redhat.com> - 0.9-1
- Rebased on qpid_proton 0.9.0.
- Added dependency on rubygem(json).
* Fri Jan 16 2015 Vít Ondruch <vondr...@redhat.com> - 0.8-2
- Rebuilt for https://fedoraproject.org/wiki/Changes/Ruby_2.2
--------------------------------------------------------------------------------


================================================================================
 vertica-python-0.3.5-1.el6 (FEDORA-EPEL-2015-5737)
 A native Python adapter for the Vertica database
--------------------------------------------------------------------------------
Update Information:

update to version 0.3.5
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr  8 2015 Jakub Jedelsky <jakub.jedel...@gmail.com> - 0.3.5-1
- update to version 0.3.5
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1209692 - vertica-python-v0.3.5 is available
        https://bugzilla.redhat.com/show_bug.cgi?id=1209692
--------------------------------------------------------------------------------

_______________________________________________
epel-devel mailing list
epel-de...@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/epel-devel

Reply via email to