The following Fedora 28 Security updates need testing: Age URL 261 https://bodhi.fedoraproject.org/updates/FEDORA-2018-d510cfd7eb jgraphx-3.6.0.0-6.fc28 210 https://bodhi.fedoraproject.org/updates/FEDORA-2018-d7aeaa74da nodejs-brace-expansion-1.1.11-1.fc28 209 https://bodhi.fedoraproject.org/updates/FEDORA-2018-bc073fdc1a nodejs-atob-2.1.1-1.fc28 202 https://bodhi.fedoraproject.org/updates/FEDORA-2018-9dd3f7c013 unrtf-0.21.9-8.fc28 170 https://bodhi.fedoraproject.org/updates/FEDORA-2018-28e9841baf docker-latest-1.13.1-37.git9cb56fd.fc28 85 https://bodhi.fedoraproject.org/updates/FEDORA-2018-cc4b7af297 xerces-c27-2.7.0-28.fc28 42 https://bodhi.fedoraproject.org/updates/FEDORA-2018-aadd3c2790 mupdf-1.14.0-6.fc28 37 https://bodhi.fedoraproject.org/updates/FEDORA-2018-997a9e3e1f xen-4.10.2-4.fc28 37 https://bodhi.fedoraproject.org/updates/FEDORA-2018-aa3752ac3c nginx-1.14.1-1.fc28 28 https://bodhi.fedoraproject.org/updates/FEDORA-2018-b60fdc1998 net-snmp-5.8-3.fc28 28 https://bodhi.fedoraproject.org/updates/FEDORA-2018-70fe6a4d75 nagios-4.4.2-3.fc28 23 https://bodhi.fedoraproject.org/updates/FEDORA-2018-dbcb80405c nbdkit-1.4.4-1.fc28 16 https://bodhi.fedoraproject.org/updates/FEDORA-2018-cc86ef9e22 squid-4.4-1.fc28 13 https://bodhi.fedoraproject.org/updates/FEDORA-2018-2abadd4469 haproxy-1.8.15-1.fc28 13 https://bodhi.fedoraproject.org/updates/FEDORA-2018-b18f9dd65b tomcat-8.5.35-1.fc28 9 https://bodhi.fedoraproject.org/updates/FEDORA-2018-67e98d4b7a python-lxml-4.2.5-1.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-e69d2aaa60 wordpress-5.0.2-1.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-50e3877b63 php-pear-1.10.7-2.fc28 4 https://bodhi.fedoraproject.org/updates/FEDORA-2018-27f957ae8e terminology-1.3.2-1.fc28 0 https://bodhi.fedoraproject.org/updates/FEDORA-2018-276a5f97b6 beep-1.3-24.fc28
The following Fedora 28 Critical Path updates have yet to be approved: Age URL 37 https://bodhi.fedoraproject.org/updates/FEDORA-2018-997a9e3e1f xen-4.10.2-4.fc28 31 https://bodhi.fedoraproject.org/updates/FEDORA-2018-fdc6d449e5 pungi-4.1.31-1.fc28 31 https://bodhi.fedoraproject.org/updates/FEDORA-2018-63e2c74a11 python-productmd-1.18-1.fc28 30 https://bodhi.fedoraproject.org/updates/FEDORA-2018-3222e7c914 radvd-2.17-11.fc28 28 https://bodhi.fedoraproject.org/updates/FEDORA-2018-c86898e4a7 gdb-8.1.1-4.fc28 28 https://bodhi.fedoraproject.org/updates/FEDORA-2018-b60fdc1998 net-snmp-5.8-3.fc28 25 https://bodhi.fedoraproject.org/updates/FEDORA-2018-12c54ca4bf gjs-1.52.5-1.fc28 16 https://bodhi.fedoraproject.org/updates/FEDORA-2018-9f541b469b nfs-utils-2.3.3-1.rc2.fc28 15 https://bodhi.fedoraproject.org/updates/FEDORA-2018-9963fc558e efivar-37-1.fc28 12 https://bodhi.fedoraproject.org/updates/FEDORA-2018-816dbc3486 osinfo-db-20181214-1.fc28 9 https://bodhi.fedoraproject.org/updates/FEDORA-2018-67e98d4b7a python-lxml-4.2.5-1.fc28 9 https://bodhi.fedoraproject.org/updates/FEDORA-2018-db7152a500 flatpak-1.0.6-4.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-fe07b3a436 breeze-icon-theme-5.53.0-1.fc28 extra-cmake-modules-5.53.0-1.fc28 kf5-5.53.0-1.fc28 kf5-attica-5.53.0-1.fc28 kf5-baloo-5.53.0-1.fc28 kf5-bluez-qt-5.53.0-1.fc28 kf5-frameworkintegration-5.53.0-2.fc28 kf5-kactivities-5.53.0-1.fc28 kf5-kactivities-stats-5.53.0-1.fc28 kf5-kapidox-5.53.0-1.fc28 kf5-karchive-5.53.0-1.fc28 kf5-kauth-5.53.0-1.fc28 kf5-kbookmarks-5.53.0-1.fc28 kf5-kcmutils-5.53.0-1.fc28 kf5-kcodecs-5.53.0-1.fc28 kf5-kcompletion-5.53.0-1.fc28 kf5-kconfig-5.53.0-1.fc28 kf5-kconfigwidgets-5.53.0-1.fc28 kf5-kcoreaddons-5.53.0-1.fc28 kf5-kcrash-5.53.0-1.fc28 kf5-kdbusaddons-5.53.0-1.fc28 kf5-kdeclarative-5.53.0-2.fc28 kf5-kded-5.53.0-1.fc28 kf5-kdelibs4support-5.53.0-1.fc28 kf5-kdesignerplugin-5.53.0-1.fc28 kf5-kdesu-5.53.0-1.fc28 kf5-kdewebkit-5.53.0-1.fc28 kf5-kdnssd-5.53.0-1.fc28 kf5-kdoctools-5.53.0-1.fc28 kf5-kemoticons-5.53.0-1.fc28 kf5-kfilemetadata-5.53.0-1.fc28 kf5-kglobalaccel-5.53.0-1.fc28 kf5-kguiad dons-5.53.0-1.fc28 kf5-kholidays-5.53.0-1.fc28 kf5-khtml-5.53.0-1.fc28 kf5-ki18n-5.53.0-1.fc28 kf5-kiconthemes-5.53.0-1.fc28 kf5-kidletime-5.53.0-1.fc28 kf5-kimageformats-5.53.0-1.fc28 kf5-kinit-5.53.0-1.fc28 kf5-kio-5.53.0-1.fc28 kf5-kirigami2-5.53.0-1.fc28 kf5-kitemmodels-5.53.0-1.fc28 kf5-kitemviews-5.53.0-1.fc28 kf5-kjobwidgets-5.53.0-1.fc28 kf5-kjs-5.53.0-1.fc28 kf5-kjsembed-5.53.0-1.fc28 kf5-kmediaplayer-5.53.0-1.fc28 kf5-knewstuff-5.53.0-1.fc28 kf5-knotifications-5.53.0-1.fc28 kf5-knotifyconfig-5.53.0-1.fc28 kf5-kpackage-5.53.0-1.fc28 kf5-kparts-5.53.0-1.fc28 kf5-kpeople-5.53.0-1.fc28 kf5-kplotting-5.53.0-1.fc28 kf5-kpty-5.53.0-1.fc28 kf5-kross-5.53.0-1.fc28 kf5-krunner-5.53.0-1.fc28 kf5-kservice-5.53.0-1.fc28 kf5-ktexteditor-5.53.0-1.fc28 kf5-ktextwidgets-5.53.0-1.fc28 kf5-kunitconversion-5.53.0-1.fc28 kf5-kwallet-5.53.0-1.fc28 kf5-kwayland-5.53.0-2.fc28 kf5-kwidgetsaddons-5.53.0-1.fc28 kf5-kwindowsystem-5.53.0-1.fc28 kf5-kxmlgui-5.53.0-2.fc28 kf5-kxmlrpcclient-5.53.0-1.fc28 kf5-modemmanager-qt-5.53.0-1.fc28 kf5-networkmanager-qt-5.53.0-1.fc28 kf5-plasma-5.53.0-1.fc28 kf5-prison-5.53.0-1.fc28 kf5-purpose-5.53.0-1.fc28 kf5-solid-5.53.0-1.fc28 kf5-sonnet-5.53.0-1.fc28 kf5-syndication-5.53.0-1.fc28 kf5-syntax-highlighting-5.53.0-1.fc28 kf5-threadweaver-5.53.0-1.fc28 oxygen-icon-theme-5.53.0-1.fc28 qqc2-desktop-style-5.53.0-1.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-bfd076926b redhat-rpm-config-110-1.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-7d88c302b7 linux-firmware-20181219-89.git0f22c852.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-d81ade974c glib2-2.56.4-1.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-43c225890a libfm-1.3.1-1.fc28 pcmanfm-1.3.1-1.fc28 7 https://bodhi.fedoraproject.org/updates/FEDORA-2018-4dddcb3e5e highlight-3.48-1.fc28 6 https://bodhi.fedoraproject.org/updates/FEDORA-2018-e6538e58ce ceph-12.2.10-1.fc28
The following builds have been pushed to Fedora 28 updates-testing
0ad-0.0.23b-1.fc28 0ad-data-0.0.23b-1.fc28 Random123-1.09-7.fc28 darktable-2.6.0-2.fc28 gnome-chemistry-utils-0.14.17-15.fc28 gnumeric-1.12.44-1.fc28 goffice-0.10.44-1.fc28 kernel-4.19.12-200.fc28 kernel-headers-4.19.12-200.fc28 krb5-1.16.1-23.fc28 krename-5.0.60-1.fc28 libxmlb-0.1.5-1.fc28 lutris-0.4.23-5.fc28 python-subliminal-2.0.5-8.fc28 qdigidoc-4.2.0-4.fc28 strace-4.26-1.fc28 supertux-0.6.0-1.fc28 tcpreplay-4.3.1-1.fc28 xpad-5.3.0-1.fc28 zchunk-1.0.2-1.fc28
Details about builds:
================================================================================ 0ad-0.0.23b-1.fc28 (FEDORA-2018-217ca7e714) Cross-Platform RTS Game of Ancient Warfare -------------------------------------------------------------------------------- Update Information:
Update to 0.0.23b -------------------------------------------------------------------------------- ChangeLog:
* Thu Dec 27 2018 Pete Walter pwalter@fedoraproject.org - 0.0.23b-1 - Update to 0.0.23b * Thu Jul 12 2018 Fedora Release Engineering releng@fedoraproject.org - 0.0.23-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Tue Jul 10 2018 Pete Walter pwalter@fedoraproject.org - 0.0.23-2 - Rebuild for ICU 62 --------------------------------------------------------------------------------
================================================================================ 0ad-data-0.0.23b-1.fc28 (FEDORA-2018-217ca7e714) The Data Files for 0 AD -------------------------------------------------------------------------------- Update Information:
Update to 0.0.23b -------------------------------------------------------------------------------- ChangeLog:
* Thu Dec 27 2018 Pete Walter pwalter@fedoraproject.org - 0.0.23b-1 - Update to 0.0.23b * Thu Jul 12 2018 Fedora Release Engineering releng@fedoraproject.org - 0.0.23-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ Random123-1.09-7.fc28 (FEDORA-2018-0d7b48dcdb) Library of random number generators -------------------------------------------------------------------------------- Update Information:
* Enable aarch64 support -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Ankur Sinha <ankursinha AT fedoraproject DOT org> - 1.09-7 - Add aarch64 patch * Thu Jul 12 2018 Fedora Release Engineering releng@fedoraproject.org - 1.09-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ darktable-2.6.0-2.fc28 (FEDORA-2018-e3d6cf76aa) Utility to organize and develop raw images -------------------------------------------------------------------------------- Update Information:
2.6.0 release -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Germano Massullo germano@germanomassullo.org - 2.6.0-2 - changed cmake and clang minimum version requirement * Fri Dec 28 2018 Pete Walter pwalter@fedoraproject.org - 2.6.0-1 - Update to 2.6.0 - Enable ppc64le build (#1660807) * Wed Jul 18 2018 Germano Massullo germano.massullo@gmail.com - 2.4.4-3 - added noise tools and basecurve tools subpackages * Thu Jul 12 2018 Fedora Release Engineering releng@fedoraproject.org - 2.4.4-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1660807 - enable ppc64le when updating to 2.6 https://bugzilla.redhat.com/show_bug.cgi?id=1660807 [ 2 ] Bug #1613439 - [abrt] darktable: __libc_sigaction(): darktable killed by SIGABRT https://bugzilla.redhat.com/show_bug.cgi?id=1613439 --------------------------------------------------------------------------------
================================================================================ gnome-chemistry-utils-0.14.17-15.fc28 (FEDORA-2018-e4180311ab) A set of chemical utilities -------------------------------------------------------------------------------- Update Information:
An update to the latest gnumeric and goffice releases: * http://gnumeric.org/announcements/1.12/gnumeric-1.12.43.html * http://gnumeric.org/announcements/1.12/gnumeric-1.12.44.html -------------------------------------------------------------------------------- ChangeLog:
* Tue Dec 25 2018 Julian Sikorski belegdol@fedoraproject.org - 0.14.17-15 - Rebuild for gnumeric-1.12.44 --------------------------------------------------------------------------------
================================================================================ gnumeric-1.12.44-1.fc28 (FEDORA-2018-e4180311ab) Spreadsheet program for GNOME -------------------------------------------------------------------------------- Update Information:
An update to the latest gnumeric and goffice releases: * http://gnumeric.org/announcements/1.12/gnumeric-1.12.43.html * http://gnumeric.org/announcements/1.12/gnumeric-1.12.44.html -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 24 2018 Julian Sikorski belegdol@fedoraproject.org - 1:1.12.44-1 - Update to 1.12.44 - Drop included patches --------------------------------------------------------------------------------
================================================================================ goffice-0.10.44-1.fc28 (FEDORA-2018-e4180311ab) G Office support libraries -------------------------------------------------------------------------------- Update Information:
An update to the latest gnumeric and goffice releases: * http://gnumeric.org/announcements/1.12/gnumeric-1.12.43.html * http://gnumeric.org/announcements/1.12/gnumeric-1.12.44.html -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 24 2018 Julian Sikorski belegdol@fedoraproject.org - 0.10.44-1 - Update to 0.10.44 --------------------------------------------------------------------------------
================================================================================ kernel-4.19.12-200.fc28 (FEDORA-2018-cfc5245d6e) The Linux kernel -------------------------------------------------------------------------------- Update Information:
The v4.19.12 stable update contains important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog:
* Mon Dec 24 2018 Peter Robinson pbrobinson@fedoraproject.org 4.19.12-200 - Linux v4.19.12 - Another fix for issue affecting Raspberry Pi 3-series WiFi (rhbz 1652093) * Thu Dec 20 2018 Jeremy Cline jcline@redhat.com - 4.19.11-200 - Linux v4.19.11 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1652093 - kernel 4.19.2-301 does not create wifi device on upgrade on raspberry pi 3b https://bugzilla.redhat.com/show_bug.cgi?id=1652093 --------------------------------------------------------------------------------
================================================================================ kernel-headers-4.19.12-200.fc28 (FEDORA-2018-cfc5245d6e) Header files for the Linux kernel for use by glibc -------------------------------------------------------------------------------- Update Information:
The v4.19.12 stable update contains important fixes across the tree. -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Jeremy Cline jcline@redhat.com - 4.19.12-200 - Linux v4.19.12 * Thu Dec 20 2018 Jeremy Cline jcline@redhat.com - 4.19.11-200 - Linux v4.19.11 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1652093 - kernel 4.19.2-301 does not create wifi device on upgrade on raspberry pi 3b https://bugzilla.redhat.com/show_bug.cgi?id=1652093 --------------------------------------------------------------------------------
================================================================================ krb5-1.16.1-23.fc28 (FEDORA-2018-3f302fce3c) The Kerberos network authentication system -------------------------------------------------------------------------------- Update Information:
This update re-disables a patch which was added in -20, found to cause problems for FreeIPA, and disabled in -21. The recent -22 update re-enabled that patch (possibly unintentionally, as this is not mentioned in the changelog), and it was immediately reported by [two](https://bugzilla.redhat.com/show_bug.cgi?id=1633089#c50) [testers](https://bugzilla.redhat.com/show_bug.cgi?id=1622760#c19) - and also by openQA update tests - that FreeIPA was having problems again. So, it seems wise to disable it once more. ---- Fix low-severity CVE-2018-20217 (an authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request.) -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Adam Williamson awilliam@redhat.com - 1.16.1-23 - Disable patch from -20 again (rharwood re-enabled it in -22, and it immediately broke FreeIPA again) * Thu Dec 20 2018 Robbie Harwood rharwood@redhat.com - 1.16.1-22 - Remove incorrect KDC assertion (CVE-2018-20217) --------------------------------------------------------------------------------
================================================================================ krename-5.0.60-1.fc28 (FEDORA-2018-7f371dbb81) Powerful batch file renamer -------------------------------------------------------------------------------- Update Information:
Switch to use Qt5/KF5. -------------------------------------------------------------------------------- ChangeLog:
* Thu Dec 27 2018 Vasiliy Glazov Vasiliy N. Glazov vascom2@gmail.com 5.0.60-1 - Initial release with KF5 * Fri Jul 13 2018 Fedora Release Engineering releng@fedoraproject.org - 4.0.9-27 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Wed Jul 11 2018 Sandro Mani manisandro@gmail.com - 4.0.9-26 - Rebuild (podofo) --------------------------------------------------------------------------------
================================================================================ libxmlb-0.1.5-1.fc28 (FEDORA-2018-4d3b99b28a) Library for querying compressed XML metadata -------------------------------------------------------------------------------- Update Information:
- New upstream release - Add xb_builder_node_export() for gnome-software - Ignore calls to xb_silo_query_build_index() with no results - Lazy load the stemmer when required --------------------------------------------------------------------------------
================================================================================ lutris-0.4.23-5.fc28 (FEDORA-2018-4865f440a3) Install and play any video game easily -------------------------------------------------------------------------------- Update Information:
Changing the format of those previously added dependencies so that they work -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Christopher King bunnyapocalypse@protonmail.com - 0.4.23-5 - Changing the format of those previously added dependencies so that they work * Thu Dec 20 2018 Christopher King bunnyapocalypse@protonmail.com - 0.4.23-4 - Adding some mesa depends to make Lutris work on more systems more reliably * Fri Nov 16 2018 Christopher King bunnyapocalypse@protonmail.com - 0.4.23-3 - Turns out that I hadn't actually made a mistake, reverting most of the changes * Thu Nov 15 2018 Christopher King bunnyapocalypse@protonmail.com - 0.4.23-2 - Updating this spec to actually install the appdata file -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1661236 - Missing 32-bit Mesa/Vulkan dependencies https://bugzilla.redhat.com/show_bug.cgi?id=1661236 --------------------------------------------------------------------------------
================================================================================ python-subliminal-2.0.5-8.fc28 (FEDORA-2018-9c1d431d24) Python library to search and download subtitles -------------------------------------------------------------------------------- Update Information:
Enable python dependency generator -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Juan Orti Alcaine jorti@fedoraproject.org - 2.0.5-8 - Enable python dependency generator * Sat Jul 14 2018 Fedora Release Engineering releng@fedoraproject.org - 2.0.5-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Tue Jun 19 2018 Miro Hron��ok mhroncok@redhat.com - 2.0.5-6 - Rebuilt for Python 3.7 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1662371 - Package fail to start (Library missing?) https://bugzilla.redhat.com/show_bug.cgi?id=1662371 --------------------------------------------------------------------------------
================================================================================ qdigidoc-4.2.0-4.fc28 (FEDORA-2018-76a3587d35) Estonian digital signature and encryption application -------------------------------------------------------------------------------- Update Information:
4.2 release Obsoletes qesteidutil -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Germano Massullo germano@germanomassullo.org - 4.2.0-4 - added Provides: qesteidutil * Tue Dec 11 2018 Germano Massullo germano@germanomassullo.org - 4.2.0-3 - adding obsoletes: qesteidutil for F30 * Tue Dec 4 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.2.0-2 - Add proper provides and obsoletes * Tue Dec 4 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.2.0-1 - Upstream release 4.2.0 * Mon Nov 19 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.1.0-1 - Upstream release 4.1.0 * Thu Oct 4 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.0.0-4 - Use the officially provided zip pack - Update static resource files * Mon Jun 25 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.0.0-3 - Add instructions on how to obtain the tarball - Re-pack the sources tarball with ones obtained from VCS. * Mon Jun 18 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.0.0-2 - Add a patch for sanbox compilation * Wed Jun 13 2018 Dmitri Smirnov dmitri@smirnov.ee - 4.0.0-1 - Update sources to the 4.0.0 release - Add a patch to workaround the Qt 5.11 compatibility * Sun Jun 3 2018 Dmitri Smirnov dmitri@smirnov.ee - 0.6.0-3 - Update sources to the latest one * Thu May 3 2018 Dmitri Smirnov dmitri@smirnov.ee - 0.6.0-2 - Remove filetype bindings and icons to avoid conflict with DigiDoc3 * Tue May 1 2018 Dmitri Smirnov dmitri@smirnov.ee - 0.6.0-1 - Initial packaging of 0.6.0 beta -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1606031 - qdigidoc: FTBFS in Fedora rawhide https://bugzilla.redhat.com/show_bug.cgi?id=1606031 [ 2 ] Bug #1658238 - Fix sandbox patch https://bugzilla.redhat.com/show_bug.cgi?id=1658238 --------------------------------------------------------------------------------
================================================================================ strace-4.26-1.fc28 (FEDORA-2018-1a4ec1ea2e) Tracks and displays system calls associated with a running process -------------------------------------------------------------------------------- Update Information:
v4.25 -> v4.26. -------------------------------------------------------------------------------- ChangeLog:
* Thu Dec 27 2018 Dmitry V. Levin ldv@altlinux.org - 4.26-1 - v4.25 -> v4.26. * Tue Oct 30 2018 Dmitry V. Levin ldv@altlinux.org - 4.25-1 - v4.24 -> v4.25. --------------------------------------------------------------------------------
================================================================================ supertux-0.6.0-1.fc28 (FEDORA-2018-b6203108cc) Jump'n run like game -------------------------------------------------------------------------------- Update Information:
Update to 0.6.0 -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Pete Walter pwalter@fedoraproject.org - 0.6.0-1 - Update to 0.6.0 - Drop opengl-game-wrapper.sh use - Update URL - Spec file cleanup - Remove ExcludeArch: ppc64le * Thu Aug 23 2018 Nicolas Chauvet kwizart@gmail.com - 0.5.1-13 - Rebuilt for glew 2.1.0 * Sat Jul 14 2018 Fedora Release Engineering releng@fedoraproject.org - 0.5.1-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ tcpreplay-4.3.1-1.fc28 (FEDORA-2018-166b220ff1) Replay captured network traffic -------------------------------------------------------------------------------- Update Information:
This release (4.3.1) contains bug fixes only: - Fix checkspell detected typos (#531) - Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: - Fix maxOS TOS checksum failure (#524) - TCP sequence edits seeding (#514) - Fix issues identifed by Codacy (#493) - CVE-2018-18408 use-after-free in post_args (#489) - CVE-2018-18407 heap-buffer-overflow csum_replace4 (#488) - CVE-2018-17974 heap- buffer-overflow dlt_en10mb_encode (#486) - CVE-2018-17580 heap-buffer-overflow fast_edit_packet (#485) - CVE-2018-17582 heap-buffer-overflow in get_next_packet (#484) - Out-of-tree build (#482) - CVE-2018-13112 heap-buffer-overflow in get_l2len (#477 dup #408) - Closing stdin on pipe (#479) - Second pcap file hangs on multiplier option (#472) - Jumbo frame support for fragroute option (#466) - TCP sequence edit ACK corruption (#451) - TCP sequence number edit initial SYN packet should have zero ACK (#450) - Travis CI build fails due to new build images (#432) - Upgrade libopts to 5.18.12 to address version build issues (#430) - Add ability to change tcp SEQ/ACK numbers (#425) - Hang using loop and netmap options (#424) - tcpprep -S not working for large cache files (#423) - Unable to tcprewrite range of ports with --portmap (#422) - --maxsleep broken for values less than 1000 (#421) - -T flag breaks traffic replay timing (#419) - Respect 2nd packet timing (#418) - Avoid non-blocking behaviour when using STDIN (#416) - pcap containing >1020 packets produces invalid cache file (#415) - manpage typos (#413) - Fails to open tap0 on Zephyr (#411) - Heap- buffer-overflow in get_l2protocol (#410) - Heap-buffer-overflow in packet2tree (#409) - Heap-buffer-overflow in get_l2len (#408) - Heap-buffer-overflow in flow_decode (#407) - Rewrite zero IP total length field to match the actual packet length (#406) - Stack-buffer-overflow in tcpcapinfo (#405) - tcpprep --include option does not exclude (#404) - Negative-size-param memset in dlt_radiotap_get_80211 (#402) - tcpeplay --verbose option not working (#398) - Fix replay when using --with-testnic (#178) -------------------------------------------------------------------------------- ChangeLog:
* Sat Dec 29 2018 Bojan Smojver <bojan@rexursive com> - 4.3.1-1 - bump up to 4.3.1 * Sat Jul 14 2018 Fedora Release Engineering releng@fedoraproject.org - 4.2.5-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri Mar 9 2018 Bojan Smojver <bojan@rexursive com> - 4.2.5-5 - add gcc build requirement -------------------------------------------------------------------------------- References:
[ 1 ] Bug #1636599 - CVE-2018-17974 tcpreplay: heap-based buffer over-read in dlt_en10mb_encode in plugins/dlt_en10mb/en10mb.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1636599 [ 2 ] Bug #1635043 - CVE-2018-17582 tcpreplay: heap-based buffer over-read in the get_next_packet() in send_packets.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1635043 [ 3 ] Bug #1635040 - CVE-2018-17580 tcpreplay: heap-based buffer over-read in fast_edit_packet() in file send_packets.c [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1635040 [ 4 ] Bug #1646410 - CVE-2018-18408 tcpreplay: use-after-free in post_args function in tcpbridge.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1646410 [ 5 ] Bug #1646404 - CVE-2018-18407 tcpreplay: tcpreplay: heap-based buffer over-read in csum_replace4 function in incremental_checksum.h [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1646404 [ 6 ] Bug #1636600 - CVE-2018-17974 tcpreplay: heap-based buffer over-read in dlt_en10mb_encode in plugins/dlt_en10mb/en10mb.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1636600 [ 7 ] Bug #1635042 - CVE-2018-17582 tcpreplay: heap-based buffer over-read in the get_next_packet() in send_packets.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1635042 [ 8 ] Bug #1635039 - CVE-2018-17580 tcpreplay: heap-based buffer over-read in fast_edit_packet() in file send_packets.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1635039 --------------------------------------------------------------------------------
================================================================================ xpad-5.3.0-1.fc28 (FEDORA-2018-1047078bc8) Sticky notepad for GTK -------------------------------------------------------------------------------- Update Information:
Update to 5.3.0 with various bugfixes. -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Kevin Fenzi kevin@scrye.com - 5.3.0-1 - Update to 5.3.0 --------------------------------------------------------------------------------
================================================================================ zchunk-1.0.2-1.fc28 (FEDORA-2018-f1d4b9be8d) Compressed file format that allows easy deltas -------------------------------------------------------------------------------- Update Information:
Add tests for validating new chunk matching code ---- Use hash table for finding identical chunks, speeding up process considerably ---- 1.0 release with ABI/API stability guarantee -------------------------------------------------------------------------------- ChangeLog:
* Fri Dec 28 2018 Jonathan Dieter jdieter@gmail.com - 1.0.2-1 - Use hash table for finding identical chunks, speeding up process considerably - Add test case to verify that identical chunk checking is working * Sat Dec 22 2018 Jonathan Dieter jdieter@gmail.com - 1.0.0-1 - 1.0 release. API/ABI stability is now guaranteed --------------------------------------------------------------------------------