The following Fedora EPEL 6 Security updates need testing: Age URL 106 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2018-b7556983e8 tomcat-7.0.92-1.el6 29 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-06b243cced guacamole-server-1.0.0-1.el6 10 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-b4ada0648b putty-0.71-1.el6 9 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-62f9745b71 drupal7-7.65-1.el6 7 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2019-13e2a65b5e wordpress-5.1.1-4.el6
The following builds have been pushed to Fedora EPEL 6 updates-testing
bird2-2.0.4-1.el6 ntfs-3g-2017.3.23-11.el6 python-enlighten-1.2.0-1.el6
Details about builds:
================================================================================ bird2-2.0.4-1.el6 (FEDORA-EPEL-2019-759e9f63c8) BIRD Internet Routing Daemon -------------------------------------------------------------------------------- Update Information:
BIRD 2.0.4 (2019-02-27) ======================= * OSPF: Opaque LSAs (RFC 5250) * OSPF: DN-bit handling (RFC 4576) * Preferred route counters are back * Important BGP bugfix * Several bugfixes related to route propagation * some minor bugfixes BIRD 2.0.3 (2019-01-05) ======================= * MRT table dumps (RFC 6396) * BGP Long-lived graceful restart * BGP: Optional import table (Adj-RIB-In) * BGP: Extend 'next hop keep' and 'next hop self' options * BGP: Improved VRF support * OSPF: Authentication trailer for OSPFv3 (RFC 7166) * Babel: New option to randomize router ID * Filter: Custom route attributes * Filter: Support for src accessor to SADR source prefix * Filter: Support for VPN_RD sets * Filter: Make ifname attribute modifiable * Perf: Protocol to measure BIRD performance internally * More verbose error messages in config processing * Log file size limit / log rotation * Many bugfixes Notes ----- Export of routes to RS EBGP (route server) sessions from other sources than RS EBGP sessions was changed that ASN is no longer prepended to BGP_PATH in that case. The change does not affect regular BGP configurations or regular route servers that have only RS EBGP peers. For BGP route servers and route reflectors, the default value of option 'next hop keep' was changed to a more appropriate value. Attributes for OSPF and Babel metrics are no longer reset when exported to these protocols and could be set anywhere in BIRD. As a result, OSPF metric is kept when a route is reannounced between OSPF instances. Also, when route is exported to OSPF with both ospf_metric1 and ospf_metric2 attributes it is now propagated as OSPF-E2 route instead of as OSPF-E1 route. Compiling BIRD with `--enable-debug` no longer automatically activates debug mode (`-d` option) nor local mode (`-l` option). Also, debug mode with output to file (`-D` option) no longer not forces foreground mode (`-f` option). The `configure` script now uses standard option `--runstatedir`, the old option `--with-runtimedir` is deprecated. -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 30 2019 Robert Scheck robert@fedoraproject.org - 2.0.4-1 - Upgrade to 2.0.4 (#1684317) * Fri Jan 18 2019 Robert Scheck robert@fedoraproject.org - 2.0.3-1 - Upgrade to 2.0.3 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1684317 - bird-2.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1684317 --------------------------------------------------------------------------------
================================================================================ ntfs-3g-2017.3.23-11.el6 (FEDORA-EPEL-2019-8d5207833a) Linux NTFS userspace driver -------------------------------------------------------------------------------- Update Information:
Fix for CVE-2019-9755. -------------------------------------------------------------------------------- ChangeLog:
* Fri Mar 29 2019 Tom Callaway spot@fedoraproject.org - 2:2017.3.23-11 - add upstream fix for CVE-2019-9755 * Mon Mar 11 2019 Kamil P��ral kparal@redhat.com - 2:2017.3.23-10 - add Recommends: ntfs-3g-system-compression. That allows people with Windows 10 to read system files. * Fri Feb 1 2019 Fedora Release Engineering releng@fedoraproject.org - 2:2017.3.23-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Jul 16 2018 Richard W.M. Jones rjones@redhat.com - 2:2017.3.23-8 - Fix for ntfsclone crash (RHBZ#1601146). * Fri Jul 13 2018 Fedora Release Engineering releng@fedoraproject.org - 2:2017.3.23-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1691624 - CVE-2019-9755 ntfs-3g: heap-based buffer overflow leads to local root privilege escalation https://bugzilla.redhat.com/show_bug.cgi?id=1691624 --------------------------------------------------------------------------------
================================================================================ python-enlighten-1.2.0-1.el6 (FEDORA-EPEL-2019-d6e1851f7d) Enlighten Progress Bar -------------------------------------------------------------------------------- Update Information:
Update to 1.2.0 -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 30 2019 Avram Lubkin aviso@rockhopper.net - 1.2.0-1 - Update to 1.2.0 * Sat Feb 2 2019 Fedora Release Engineering releng@fedoraproject.org - 1.1.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------
epel-devel@lists.fedoraproject.org