Fedora EPEL 4 updates-testing report

updates at fedoraproject.org updates at fedoraproject.org
Thu Apr 1 21:06:24 UTC 2010


The following builds have been pushed to Fedora EPEL 4 updates-testing

    duplicity-0.6.08b-1.el4
    fetch-crl-2.8.3-1.el4
    globus-gram-job-manager-10.17-1.el4
    perl-Convert-UUlib-1.33-1.el4
    perl-Net-STOMP-Client-0.9-1.el4
    phpPgAdmin-4.2.3-1.el4
    spamass-milter-0.3.1-18.el4

Details about builds:


================================================================================
 duplicity-0.6.08b-1.el4 (FEDORA-EPEL-2010-2503)
 Encrypted bandwidth-efficient backup using rsync algorithm
--------------------------------------------------------------------------------
Update Information:

New in v0.6.08b (2010/03/11)  ----------------------------  Fix bug where
encrypted backup without --gpg-options crashes.  This was a followup issue to
bug 490619 released in 0.6.07.  This is attempt #2 -- not sure what happened to
the patch,  but it did not show up in 0.6-series like it should have.      New
in v0.6.08a (2010/03/11)  ----------------------------  Fix bug where encrypted
backup without --gpg-options crashes.  This was a followup issue to bug 490619
released in 0.6.07.      New in v0.6.08 (2010/03/07)
---------------------------  Bugs closed in this release:     - Need accurate
man page info on use of scp/sftp usage.   - rdiffdir attempts to reference
undefined variables with some command arguments   - TypeError: unsupported
operand type(s) for -: 'NoneType' and 'int'   - TypeError: unsupported operand
type(s) for +: 'NoneType' and 'str'      New in v0.6.07 (2010/02/28)
---------------------------  Bugs closed in this release:     - --tempdir option
doesn't override TMPDIR   - [PATCH] WebDAV backend doesn't work   - re-add scp
backend and make available via command line option   - Use optparse not getopt
- 0.6.06, archive dir: cache desynchronization caused by remove*   - SSHBackend
doesn't handle spaces in path   - "sslerror: The read operation timed out" with
S3   - Don't Warn when there's old backup to delete   - OSError: [Errno 40] Too
many levels of symbolic links   - Allow renaming paths as they are restored
--------------------------------------------------------------------------------
ChangeLog:

* Sun Mar 28 2010 Robert Scheck <robert at fedoraproject.org> 0.6.08b-1
- Upgrade to 0.6.08b
--------------------------------------------------------------------------------


================================================================================
 fetch-crl-2.8.3-1.el4 (FEDORA-EPEL-2010-2499)
 Downloads Certificate Revocation Lists
--------------------------------------------------------------------------------
Update Information:

New version 2.8.3 contains three bug fixes. * Preserve SELinux context for CRL
files if SElinux status program exists and selinux is enabled (RH bug 577403). *
Fix argument parsing on syslog facility specification (RH bug 577387). *
Increase granularity of the RandomWait and allow for 0 in -r option.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Mar 28 2010 Steve Traylen <steve.traylen at cern.ch> - 2.8.3-1
- New upstream 2.8.3
- Removed edg-fetch-crl-2.8.2-getopts.patch and 
  fetch-crl-2.6.6-selinux.patch since both now present in 2.8.3.
* Sat Mar 27 2010 Steve Traylen <steve.traylen at cern.ch> - 2.8.2-2
- Add edg-fetch-crl-2.8.2-getopts.patch for rhbz#577387,
  Jason Smith.
- Add fetch-crl-2.6.6-selinux.patch for rhbz#577403
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #577387 - fetch-crl getopt syslog bug.
        https://bugzilla.redhat.com/show_bug.cgi?id=577387
  [ 2 ] Bug #577403 - fetch-crl doesn't preserve file contexts
        https://bugzilla.redhat.com/show_bug.cgi?id=577403
--------------------------------------------------------------------------------


================================================================================
 globus-gram-job-manager-10.17-1.el4 (FEDORA-EPEL-2010-2511)
 Globus Toolkit - GRAM Jobmanager
--------------------------------------------------------------------------------
Update Information:

The Globus Toolkit is an open source software toolkit used for building Grid
systems and applications. It is being developed by the Globus Alliance and many
others all over the world. A growing number of projects and companies are using
the Globus Toolkit to unlock the potential of grids for their cause.    The
globus-gram-job-manager package contains: GRAM Jobmanager
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #516536 - Review Request: globus-gram-job-manager - Globus Toolkit - GRAM Jobmanager
        https://bugzilla.redhat.com/show_bug.cgi?id=516536
--------------------------------------------------------------------------------


================================================================================
 perl-Convert-UUlib-1.33-1.el4 (FEDORA-EPEL-2010-2517)
 Perl interface to the uulib library
--------------------------------------------------------------------------------
Update Information:

1.33 Wed Oct 28 09:04:38 CET 2009     - handle yEnc files with part end=0 and
total= more gracefully. I wish yEnc had been created by somebody who knows; what
he does; but I doubt he even knows; what he did.      1.32 Wed Sep 16 20:07:13
CEST 2009     - Due to a glitch with CVS, configure lacked executable bits.
(Quickly reported by Anton Berezin).      1.31 Wed Sep 16 09:04:30 CEST 2009
- do not use system-replacements for case-insensitive string functions when
found, as they are broken on too many systems (mostly bsds, as usual, but at
least some versions of GNU/Linux disagree with themselves apparently). Analyzed
by Anton Berezin.      1.3 Sat Aug 29 01:24:35 CEST 2009     - major changes,
new bugs and changes in decoding behaviour are expected (but not intended).   -
major scanning and decoding speed-up (by a factor of 4), by replacing ultra-slow
_FP_gets and improving IsKnownHeader (but fgets is *still* responsible for >50%
if the time).   - new option OPT_AUTOCHECK to disable O(n) UUCheckGlobalList
call after every loadfile, majorly speeds up large decodes (easily by a factor
of 10..100).   - allow "Smerge -1" to call UUCheckGlobalList.   - majorly speed
up part insertion (still O(n), but much faster).   - allow for 1023 octet
headers instead of the standard 255 octet ones.   - support strcasestr,
strcasecmp, strncasecmp for added speed.
--------------------------------------------------------------------------------
ChangeLog:

* Sun Mar 28 2010 Robert Scheck <robert at fedoraproject.org> 1:1.33-1
- Upgrade to 1.33
* Fri Dec  4 2009 Stepan Kasal <skasal at redhat.com> - 1:1.12-2
- rebuild against perl 5.10.1
--------------------------------------------------------------------------------


================================================================================
 perl-Net-STOMP-Client-0.9-1.el4 (FEDORA-EPEL-2010-2490)
 STOMP object oriented client module
--------------------------------------------------------------------------------
ChangeLog:

* Mon Mar 29 2010 Steve Traylen <steve.traylen at cern.ch> - 0.9-1
- New upstream 0.9
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #577880 - The timeout option is not working as expected
        https://bugzilla.redhat.com/show_bug.cgi?id=577880
--------------------------------------------------------------------------------


================================================================================
 phpPgAdmin-4.2.3-1.el4 (FEDORA-EPEL-2010-2508)
 Web-based PostgreSQL administration
--------------------------------------------------------------------------------
Update Information:

This is a bugfix release. Changelog is:    * Fix bug where space as first
character in a bytea column was removed by html renderer  * Check if the given
pg_dumpall / pg_dump paths are correct before using them  * Fix some
transalation files that had bad UTF-8 declaration, rising a warning  * Fix bug
with tables that contain quote in their name  * support PHP 5.3
--------------------------------------------------------------------------------
ChangeLog:

* Mon Mar 29 2010 Devrim Gunduz <devrim at gunduz.org> 4.2.3-1
- Update to 4.2.3
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #574352 - Deprecation warning using phpPgAdmin on php-5.3
        https://bugzilla.redhat.com/show_bug.cgi?id=574352
--------------------------------------------------------------------------------


================================================================================
 spamass-milter-0.3.1-18.el4 (FEDORA-EPEL-2010-2473)
 Milter (mail filter) for spamassassin
--------------------------------------------------------------------------------
Update Information:

This update includes a fix for a problem where if the milter is running using
the "-x" option to expand aliases before passing inbound mail through
SpamAssassin, a malicious client using a carefully-crafted SMTP session could
execute arbitrary code on the mail server. The fix avoids the use of a shell in
the alias expansion and hence there is no longer a problem with having to
sanitize input from the client.    This problem has been assigned CVE-2010-1132,
which is tracked upstream at https://savannah.nongnu.org/bugs/?29136    The
update also contains improved Received-header-generation for message submission
and a fix for a problem where the milter would erroneously log warnings about
the mail server's configuration when the first message from a non-authenticated
client passed through. As part of the fix for this issue, the required milter
macro configuration for the mail server has changed slightly: see the README
file included in the package for details.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Mar 23 2010 Paul Howarth <paul at city-fan.org> 0.3.1-18
- Add patch to get rid of compiler warnings
- Reorder and re-base patches to optimize chances of upstream accepting them
- Improve Received-header patch (#496763) incorporating additional fix from
  upstream update (http://savannah.nongnu.org/bugs/?17178)
* Fri Mar 12 2010 Paul Howarth <paul at city-fan.org> 0.3.1-17
- Update initscript to support running the milter as root, which is needed
  for the -x (expand aliases) option; note that the milter does not run as
  root by default
- Add patch for popen unsanitized input vulnerability
  (#572117, #572119, http://savannah.nongnu.org/bugs/?29136)
- Rebase authuser patch
- Update patch adding auth info to dummy Received-header so that it doesn't
  generate spurious warnings about missing macros (#532266), and update and
  merge the macro documentation patch into this patch
- Document patch usage in spec file
* Tue Aug 11 2009 Paul Howarth <paul at city-fan.org> 0.3.1-16
- Switch to bzipped source tarball
* Sun Jul 26 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> 0.3.1-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
* Fri Apr 24 2009 Paul Howarth <paul at city-fan.org> 0.3.1-14
- Fix Received-header generation (#496763)
- Add authentication info to dummy Received-header (#496769)
- Add option to skip checks for authenticated senders (#437506, #496767)
  (thanks to Habeeb J. Dihu for the reports and patches)
* Wed Mar 18 2009 Paul Howarth <paul at city-fan.org> 0.3.1-13
- Call initscripts directly instead of via /sbin/service and fine-tune scriptlet
  dependencies
- Change sa-milt user's home directory from
  %{_localstatedir}/run/spamass-milter to %{_localstatedir}/lib/spamass-milter
  so as to retain directory contents across a reboot (#489995), and fix the home
  directory of any existing sa-milt account on upgrades
* Fri Feb 27 2009 Paul Howarth <paul at city-fan.org> 0.3.1-12
- Subpackage for postfix is now noarch for Fedora 10 onwards
- Fix scriptlet deps to ensure that sa-milt user exists before we attempt to
  add it to the postfix group
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng at lists.fedoraproject.org> 0.3.1-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
* Fri Feb 13 2009 Paul Howarth <paul at city-fan.org> 0.3.1-10
- Rebuild for shared libmilter in Fedora 11 development
* Thu Jul  3 2008 Paul Howarth <paul at city-fan.org> 0.3.1-9
- Require /usr/sbin/sendmail (for -b/-B/-x options) rather than sendmail pkg
- Make summary and description less Sendmail-specific
- Add patch to support group-writable socket for MTA communication, needed
  to be able to use a Unix-domain socket with Postfix (#452248)
- Add subpackage with group-writable directory for Postfix support
- Tweak initscript to change default options when Postfix socket directory is
  present
- Document additional ENVRCPT macros to provide
* Tue May 20 2008 Paul Howarth <paul at city-fan.org> 0.3.1-8
- Fix initscript failure to start with SELinux in enforcing mode (#447247)
  (needs selinux-policy >= 3.3.1-55 on F9)
* Tue Feb 19 2008 Fedora Release Engineering <rel-eng at fedoraproject.org> 0.3.1-7
- Autorebuild for GCC 4.3
* Mon Feb 18 2008 Paul Howarth <paul at city-fan.org> 0.3.1-6
- Rebuild with gcc 4.3.0 for Fedora 9
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #572117 - SpamAssassin Mail Filter: Arbitrary shell command injection (privilege escalation)
        https://bugzilla.redhat.com/show_bug.cgi?id=572117
--------------------------------------------------------------------------------





More information about the epel-devel-list mailing list