The following Fedora EPEL 5 Security updates need testing:
https://admin.fedoraproject.org/updates/perl-File-FcntlLock-0.12-1.el5.1,per... https://admin.fedoraproject.org/updates/rt3-3.6.10-2.el5 https://admin.fedoraproject.org/updates/clamav-0.97-9.el5 https://admin.fedoraproject.org/updates/cgit-0.9-1.el5 https://admin.fedoraproject.org/updates/clamav-0.97-5.el5 https://admin.fedoraproject.org/updates/389-admin-1.1.15-1.el5
The following builds have been pushed to Fedora EPEL 5 updates-testing
clamav-0.97-5.el5 clamav-0.97-9.el5 flies-python-client-0.8.1-1.el5 nsd-3.2.7-5.el5 perl-Package-DeprecationManager-0.10-3.el5 znc-0.098-0.3.rc1.el5
Details about builds:
================================================================================ clamav-0.97-5.el5 (FEDORA-EPEL-2011-2792) Anti-virus software -------------------------------------------------------------------------------- ChangeLog:
* Mon Mar 14 2011 Jan-Frode Myklebust janfrode@tanso.net - 0.97-5 - clam-db obsoletes old clamav-data and clamav-data-empty. * Sun Mar 13 2011 Jan-Frode Myklebust janfrode@tanso.net - 0.97-4 - Add back clamd-wrapper to stay compatible with users of old packaging (amavisd-new). * Wed Feb 23 2011 Nick Bebout nb@fedoraproject.org - 0.097-3 - Move db to /var/lib/clamav - Ship empty directory /etc/clamd.d for amavisd-new * Thu Feb 17 2011 Kevin Fenzi kevin@tummy.com - 0.97-2 - Disable llvm. * Tue Feb 8 2011 Kevin Fenzi kevin@tummy.com - 0.97-1 - Update to 0.97 - Fix up for current guidelines. --------------------------------------------------------------------------------
================================================================================ clamav-0.97-9.el5 (FEDORA-EPEL-2011-2806) Anti-virus software -------------------------------------------------------------------------------- Update Information:
https://www.redhat.com/archives/epel-devel-list/2011-March/msg00075.html
-------------------------------------------------------------------------------- ChangeLog:
* Tue Mar 15 2011 Jan-Frode Myklebust janfrode@tanso.net - 0.97-7 - rpm-provide all old package names that are now obsoleted * Mon Mar 14 2011 Jan-Frode Myklebust janfrode@tanso.net - 0.97-6 - clam-db obsoletes old clamav-data-empty. * Sun Mar 13 2011 Jan-Frode Myklebust janfrode@tanso.net - 0.97-4 - Add back clamd-wrapper to stay compatible with users of old packaging (amavisd-new). * Wed Feb 23 2011 Nick Bebout nb@fedoraproject.org - 0.097-3 - Move db to /var/lib/clamav - Ship empty directory /etc/clamd.d for amavisd-new * Thu Feb 17 2011 Kevin Fenzi kevin@tummy.com - 0.97-2 - Disable llvm. * Tue Feb 8 2011 Kevin Fenzi kevin@tummy.com - 0.97-1 - Update to 0.97 - Fix up for current guidelines. -------------------------------------------------------------------------------- References:
[ 1 ] Bug #579370 - Update to newest version 0.96 https://bugzilla.redhat.com/show_bug.cgi?id=579370 [ 2 ] Bug #679793 - CVE-2011-1003 clamav: Double free error by reading VBA project strings [epel-4] https://bugzilla.redhat.com/show_bug.cgi?id=679793 [ 3 ] Bug #538425 - Wrong milter.conf file template in clamav-milter https://bugzilla.redhat.com/show_bug.cgi?id=538425 [ 4 ] Bug #580676 - CVE-2010-0098 CVE-2010-1311 Multiple clamav vulnerabilities [Fedora all] https://bugzilla.redhat.com/show_bug.cgi?id=580676 [ 5 ] Bug #667203 - CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s) [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=667203 [ 6 ] Bug #655636 - clamav-scanner, clamav-scanner-sysvinit in EPEL https://bugzilla.redhat.com/show_bug.cgi?id=655636 [ 7 ] Bug #495502 - 0.95.1 is busted https://bugzilla.redhat.com/show_bug.cgi?id=495502 [ 8 ] Bug #679794 - CVE-2011-1003 clamav: Double free error by reading VBA project strings [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=679794 --------------------------------------------------------------------------------
================================================================================ flies-python-client-0.8.1-1.el5 (FEDORA-EPEL-2011-2795) Python Client for Flies Server -------------------------------------------------------------------------------- ChangeLog:
* Thu Mar 10 2011 James Ni jni@redhat.com - 0.8.1 - Fix bugs(issue 272, issue 274) of retrieve the translation * Mon Mar 7 2011 James Ni jni@redhat.com - 0.8.0 - Stable release * Wed Feb 23 2011 James Ni jni@redhat.com - 0.7.6-1 - Rename the command line option, add a Logger class for better output, set copytrans default value to true, make the extensions to a list of gettext and comment. * Tue Feb 22 2011 James Ni jni@redhat.com - 0.7.4-1 - Fix issue 245:stop processing when type 'n', Add version service, rename the command line option and help info, add InternalServerError * Mon Feb 21 2011 James Ni jni@redhat.com - 0.7.3-1 - Fix issue 244, issue 245, issue 247 and issue 30, add command list for 'flies publican', rewrite the README * Fri Feb 18 2011 James Ni jni@redhat.com - 0.7.2-1 - Rename the gettextutil to publicanutil, Remove the translator from textFlowTarget, Add more help info * Tue Feb 8 2011 Fedora Release Engineering rel-eng@lists.fedoraproject.org - 0.7.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild --------------------------------------------------------------------------------
================================================================================ nsd-3.2.7-5.el5 (FEDORA-EPEL-2011-2798) Fast and lean authoritative DNS Name Server -------------------------------------------------------------------------------- Update Information:
Upgraded to 3.2.7. fix use of NSD_AUTOREBUILD for cron. Add %ghost for /var/run/nsd, fix initscript to properly display ok/failed.
-------------------------------------------------------------------------------- ChangeLog:
* Wed Mar 9 2011 Paul Wouters paul@xelerance.com - 3.2.7-5 - Fix for nsd.init to report OK/FAILED properly (bz#656642) - Use ghost directive for /var/run/nsd (bz#656642) - Remove bogus chowns for /var/*/nsdhm - Fix misnamed variable NSD_AUTORELOAD which should be NSD_AUTOREBUILD * Thu Feb 3 2011 Paul Wouters paul@xelerance.com - 3.2.7-1 - Updated to 3.2.7 - Removed obsolete --enable-nsid * Wed Jan 6 2010 Paul Wouters paul@xelerance.com - 3.2.4-1 - Updated to nsd 3.2.4 * Mon Sep 14 2009 Paul Wouters paul@xelerance.com - 3.2.3-3 - Fix for another redirection error in nsd.cron (Ville Mattila) - Add support for NSD_AUTOREBUILD disabling via /etc/sysconfig/nsd (Ville Mattila) - Fix for checking rebuild with large amount of zones (Ville Mattila) * Mon Aug 17 2009 Paul Wouters paul@xelerance.com - 3.2.3-2 - Updated to 3.2.3 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #656642 - Please Update Spec File to use %ghost on files in /var/run and /var/lock https://bugzilla.redhat.com/show_bug.cgi?id=656642 [ 2 ] Bug #535107 - need to use the new auto-group icon https://bugzilla.redhat.com/show_bug.cgi?id=535107 --------------------------------------------------------------------------------
================================================================================ perl-Package-DeprecationManager-0.10-3.el5 (FEDORA-EPEL-2011-2802) Manage deprecation warnings for your distribution -------------------------------------------------------------------------------- Update Information:
This update, to the current upstream release, addresses issues in 'ignore' handling, which is used to ignore packages in your distribution that can appear on the call stack when a deprecated feature is used. The update also supports the use of regular expressions for the 'ignore' feature. -------------------------------------------------------------------------------- ChangeLog:
* Tue Feb 8 2011 Fedora Release Engineering rel-eng@lists.fedoraproject.org - 0.10-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild * Sat Jan 8 2011 Paul Howarth paul@city-fan.org - 0.10-2 - Update patches for old Test::More and no Test::Requires - perl(Pod::Coverage::TrustPod) now available everywhere except EPEL-4 * Sat Jan 8 2011 Iain Arnell iarnell@gmail.com - 0.10-1 - Update to 0.10: - Test suite uses Test::Fatal instead of Test::Exception * Mon Oct 18 2010 Paul Howarth paul@city-fan.org - 0.09-1 - Update to 0.09: - Added a compilation test * Fri Oct 15 2010 Paul Howarth paul@city-fan.org - 0.08-1 - Update to 0.08: - The use of regular expressions in ignores didn't really work in 0.06 - Added missing deps on List::MoreUtils and Test::Requires - Replaced Test::Warn with Test::Output in the tests - Made the tests actually test what they should be testing - BR: Test::Output rather than Test::Warn - Update patches * Fri Oct 15 2010 Paul Howarth paul@city-fan.org - 0.06-1 - Update to 0.06: - Removed hard dep on Test::Warn for the benefit of Moose - Fixed what looked like a bug in -ignore handling - The -ignore parameter now accepts regexes as well as package names - Update compatibility patches - BR: List::MoreUtils - BR: Test::Requires where possible, patch it out elsewhere --------------------------------------------------------------------------------
================================================================================ znc-0.098-0.3.rc1.el5 (FEDORA-EPEL-2011-2807) An advanced IRC bouncer -------------------------------------------------------------------------------- Update Information:
Upgrade to 0.098-rc1 -------------------------------------------------------------------------------- ChangeLog:
* Sat Mar 12 2011 Nick Bebout nb@fedoraproject.org - 0.098-0.3.rc1 - Update to znc-0.098-rc1 * Wed Mar 2 2011 Nick Bebout nb@fedoraproject.org - 0.098-0.2.beta - Update to znc-0.098-beta --------------------------------------------------------------------------------