The following Fedora EPEL 5 Security updates need testing:

    https://admin.fedoraproject.org/updates/rt3-3.6.10-2.el5
    https://admin.fedoraproject.org/updates/cgit-0.9-1.el5
    https://admin.fedoraproject.org/updates/389-admin-1.1.15-1.el5
    https://admin.fedoraproject.org/updates/perl-Mail-Box-2.097-1.el5.1


The following builds have been pushed to Fedora EPEL 5 updates-testing

    cgit-0.9-1.el5
    perl-HTTP-Response-Encoding-0.06-5.el5

Details about builds:


================================================================================
 cgit-0.9-1.el5 (FEDORA-EPEL-2011-2718)
 A fast web interface for git
--------------------------------------------------------------------------------
Update Information:

In addition to closing a DOS vulnerability (thanks to Jim Meyering), this 
upstream feature release adds the following enhancements:

* Support for side-by-side diffs
* Support for repo content in "about" view
* Improved integration with gitolite/gitweb
* Support for git notes in commit/log view
* Support for graph in log view (similar to 'git log --graph')
* Improved handling/display of path filters
* Clients can modify diff view parameters
* Support for directory listings in plain view
* Support for remote branches
* Support for range searches in log view (like 'git log master ^stable)
* Support for expansion of environment vars in certain cgitrc options, which 
can simplify virtual hosting

The release announcement has a more complete changelog:

http://article.gmane.org/gmane.comp.version-control.git/168496

--------------------------------------------------------------------------------
ChangeLog:

* Sun Mar  6 2011 Todd Zullinger <[email protected]> - 0.9-1
- Update to 0.9
- Fixes: CVE-2011-1027
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1027
- Generate and install man page and html docs
- Use libcurl-devel on RHEL >= 6
- Include example filter scripts
- Update example cgitrc
* Tue Feb  8 2011 Fedora Release Engineering <[email protected]> 
- 0.8.2.1-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #680905 - CVE-2011-1027 cgit: invalid hex escape (e.g., %GG) in 
query triggers infinite loop
        https://bugzilla.redhat.com/show_bug.cgi?id=680905
--------------------------------------------------------------------------------


================================================================================
 perl-HTTP-Response-Encoding-0.06-5.el5 (FEDORA-EPEL-2011-2722)
 HTTP::Response::Encoding Perl module
--------------------------------------------------------------------------------
Update Information:

EPEL 5 release.
--------------------------------------------------------------------------------


_______________________________________________
epel-devel-list mailing list
[email protected]
https://www.redhat.com/mailman/listinfo/epel-devel-list

Reply via email to