The following Fedora EPEL 7 Security updates need testing:
 Age  URL
  66  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-f005e1b879   
debmirror-2.35-1.el7
   4  https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2021-70fe95babd   
openssl11-1.1.1k-2.el7


The following builds have been pushed to Fedora EPEL 7 updates-testing

    libdxfrw-1.0.1-1.el7
    librecad-2.2.0-0.11.rc2.el7
    ncview-2.1.8-14.el7

Details about builds:


================================================================================
 libdxfrw-1.0.1-1.el7 (FEDORA-EPEL-2021-cd37548bc5)
 Library to read/write DXF files
--------------------------------------------------------------------------------
Update Information:

Update libdxfrw to 1.0.1 (from upstream git). Rebuild librecad against it.  This
fixes CVE-2021-21898, CVE-2021-21899, and CVE-2021-21900.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Nov 22 2021 Tom Callaway <s...@fedoraproject.org> - 1.0.1-1
- rebase to new code home, fixes CVE-2021-21898/21899/21900
* Thu Jul 22 2021 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-19
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Thu May 27 2021 Tom Callaway <s...@fedoraproject.org> - 0.6.3-18
- disable rpath
* Tue Jan 26 2021 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-17
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Thu Dec 31 2020 Tom Callaway <s...@fedoraproject.org> - 0.6.3-16
- more fixes from LibreCAD git
* Wed Nov  4 2020 Tom Callaway <s...@fedoraproject.org> - 0.6.3-15
- add all of the current fixes from LibreCAD git
* Tue Jul 28 2020 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-14
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Wed Jan 29 2020 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Thu Jul 25 2019 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri Feb  1 2019 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Mon Nov 12 2018 Tom Callaway <s...@fedoraproject.org> - 0.6.3-10
- add fix from librecad for CVE-2018-19105
* Fri Jul 13 2018 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Wed Feb  7 2018 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Thu Aug  3 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Mon May 15 2017 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 0.6.3-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_27_Mass_Rebuild
* Fri Feb 10 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Mon Jun  6 2016 Tom Callaway <s...@fedoraproject.org> - 0.6.3-3
- apply changes from LibreCad 2.1.0
* Thu Feb  4 2016 Fedora Release Engineering <rel...@fedoraproject.org> - 
0.6.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Tue Jan 12 2016 Tom Callaway <s...@fedoraproject.org> - 0.6.3-1
- update to 0.6.3
* Fri Sep 11 2015 Tom Callaway <s...@fedoraproject.org> - 0.6.1-1
- update to 0.6.1
* Wed Jun 17 2015 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 0.5.11-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Sat May  2 2015 Kalev Lember <kalevlem...@gmail.com> - 0.5.11-5
- Rebuilt for GCC 5 C++11 ABI change
* Thu Mar 26 2015 Kalev Lember <kalevlem...@gmail.com> - 0.5.11-4
- Rebuilt for GCC 5 ABI change
* Sun Aug 17 2014 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 0.5.11-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2025628 - CVE-2021-21899 librecad: heap out-of-bounds write in 
dwgCompressor:copyCompBytes21
        https://bugzilla.redhat.com/show_bug.cgi?id=2025628
  [ 2 ] Bug #2025631 - CVE-2021-21900 librecad: use-after-free in 
dxfRW:processLType()
        https://bugzilla.redhat.com/show_bug.cgi?id=2025631
  [ 3 ] Bug #2025634 - CVE-2021-21898 librecad: out-of-bounds write in 
dwgCompressor:decompress18()
        https://bugzilla.redhat.com/show_bug.cgi?id=2025634
--------------------------------------------------------------------------------


================================================================================
 librecad-2.2.0-0.11.rc2.el7 (FEDORA-EPEL-2021-cd37548bc5)
 Computer Assisted Design (CAD) Application
--------------------------------------------------------------------------------
Update Information:

Update libdxfrw to 1.0.1 (from upstream git). Rebuild librecad against it.  This
fixes CVE-2021-21898, CVE-2021-21899, and CVE-2021-21900.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Nov 22 2021 Tom Callaway <s...@fedoraproject.org> - 2.2.0-0.11.rc2
- rebuild against new libdxfrw
- rebase to 1d31427
* Thu Jul 22 2021 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.2.0-0.10.rc2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jan 26 2021 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.2.0-0.9.rc2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Thu Dec 31 2020 Tom Callaway <s...@fedoraproject.org> - 2.2.0-0.8.rc2
- update to rc2
* Wed Nov  4 2020 Tom Callaway <s...@fedoraproject.org> - 2.2.0-0.7.rc1
- update to latest git main
* Tue Jul 28 2020 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.2.0-0.6.rc1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Wed Jan 29 2020 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.2.0-0.5.rc1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Thu Jul 25 2019 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.2.0-0.4.rc1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Thu Jun  6 2019 Tom Callaway <s...@fedoraproject.org> - 2.2.0-0.3.rc1
- apply fix for non-unique shared object naming conflicts
* Fri Feb  1 2019 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.2.0-0.2.rc1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Mon Jul 23 2018 Tom Callaway <s...@fedoraproject.org> - 2.2.0-0.1.rc1
- update to 2.2.0-rc1
- add BuildRequires: gcc-c++
* Fri Jul 13 2018 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.0-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Wed Feb  7 2018 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Thu Aug  3 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Feb 10 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Fri Jan 27 2017 Jonathan Wakely <jwak...@redhat.com> - 2.1.0-3
- Rebuilt for Boost 1.63
* Sun Dec 11 2016 Igor Gnatenko <ignate...@redhat.com> - 2.1.0-2
- Rebuild for shapelib SONAME bump
* Mon Jun  6 2016 Tom Callaway <s...@fedoraproject.org> - 2.1.0-1
- update to 2.1.0
* Mon May 16 2016 Tom Callaway <s...@fedoraproject.org> - 2.0.10-1
- update to 2.0.10
* Thu Feb  4 2016 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.0.9-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Fri Jan 15 2016 Jonathan Wakely <jwak...@redhat.com> - 2.0.9-2
- Rebuilt for Boost 1.60
* Tue Jan 12 2016 Tom Callaway <s...@fedoraproject.org> - 2.0.9-1
- update to 2.0.9
* Fri Sep 11 2015 Tom Callaway <s...@fedoraproject.org> - 2.0.8-1
- update to 2.0.8
* Thu Aug 27 2015 Jonathan Wakely <jwak...@redhat.com> - 2.0.7-8
- Rebuilt for Boost 1.59
* Wed Jul 29 2015 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 2.0.7-7
- Rebuilt for https://fedoraproject.org/wiki/Changes/F23Boost159
* Wed Jul 22 2015 David Tardon <dtar...@redhat.com> - 2.0.7-6
- rebuild for Boost 1.58
* Wed Jun 17 2015 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 2.0.7-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Sat May  2 2015 Kalev Lember <kalevlem...@gmail.com> - 2.0.7-4
- Rebuilt for GCC 5 C++11 ABI change
* Thu Mar 26 2015 Richard Hughes <rhug...@redhat.com> - 2.0.7-3
- Add an AppData file for the software center
* Tue Jan 27 2015 Petr Machata <pmach...@redhat.com> - 2.0.7-2
- Rebuild for boost 1.57.0
* Mon Jan  5 2015 Tom Callaway <s...@fedoraproject.org> - 2.0.7-1
- update to 2.0.7
* Wed Nov  5 2014 Tom Callaway <s...@fedoraproject.org> - 2.0.6-1
- update to 2.0.6
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #2025628 - CVE-2021-21899 librecad: heap out-of-bounds write in 
dwgCompressor:copyCompBytes21
        https://bugzilla.redhat.com/show_bug.cgi?id=2025628
  [ 2 ] Bug #2025631 - CVE-2021-21900 librecad: use-after-free in 
dxfRW:processLType()
        https://bugzilla.redhat.com/show_bug.cgi?id=2025631
  [ 3 ] Bug #2025634 - CVE-2021-21898 librecad: out-of-bounds write in 
dwgCompressor:decompress18()
        https://bugzilla.redhat.com/show_bug.cgi?id=2025634
--------------------------------------------------------------------------------


================================================================================
 ncview-2.1.8-14.el7 (FEDORA-EPEL-2021-d2dc3d28aa)
 A visual browser for netCDF format files
--------------------------------------------------------------------------------
Update Information:

Update to 2.1.8
--------------------------------------------------------------------------------
ChangeLog:

* Wed Aug 11 2021 Orion Poplawski <or...@nwra.com> - 2.1.8-14
- Rebuild for netcdf 4.8.0
* Tue Aug 10 2021 Orion Poplawski <or...@nwra.com> - 2.1.8-13
- Rebuild for netcdf 4.8.0
* Thu Jul 22 2021 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jan 26 2021 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Tue Jul 28 2020 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Wed Jan 29 2020 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Thu Jul 25 2019 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Mon Mar 18 2019 Orion Poplawski <or...@nwra.com> - 2.1.8-7
- Rebuild for netcdf 4.6.3
* Fri Feb  1 2019 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Fri Jul 13 2018 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Thu Feb  8 2018 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Thu Aug  3 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.8-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Wed Mar  8 2017 Orion Poplawski <or...@cora.nwra.com> - 2.1.8-1
- Update to 2.1.8
* Fri Feb 10 2017 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.7-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Tue Mar 29 2016 Orion Poplawski <or...@cora.nwra.com> - 2.1.7-1
- Update to 2.1.7
* Mon Mar 28 2016 Orion Poplawski <or...@cora.nwra.com> - 2.1.6-1
- Update to 2.1.6
- Update license to GPLv3
* Thu Feb  4 2016 Fedora Release Engineering <rel...@fedoraproject.org> - 
2.1.5-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Fri Jan 22 2016 Orion Poplawski <or...@cora.nwra.com> - 2.1.5-3
- Rebuild for netcdf 4.4.0
* Wed Jun 17 2015 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 2.1.5-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Wed Mar 18 2015 Orion Poplawski <or...@cora.nwra.com> - 2.1.5-1
- Update to 2.1.5
* Fri Nov 14 2014 Orion Poplawski <or...@cora.nwra.com> - 2.1.4-1
- Update to 2.1.4
* Sat Nov  1 2014 Orion Poplawski <or...@cora.nwra.com> - 2.1.3-1
- Update to 2.1.3
- Cleanup spec
* Sun Aug 17 2014 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 2.1.2-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sat Jun  7 2014 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 2.1.2-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Sat Aug  3 2013 Fedora Release Engineering <rel-...@lists.fedoraproject.org> 
- 2.1.2-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
--------------------------------------------------------------------------------

_______________________________________________
epel-devel mailing list -- epel-devel@lists.fedoraproject.org
To unsubscribe send an email to epel-devel-le...@lists.fedoraproject.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/epel-devel@lists.fedoraproject.org
Do not reply to spam on the list, report it: 
https://pagure.io/fedora-infrastructure

Reply via email to