Wednesday, July 20, 2022

Fedora 37 mass rebuild started

Hi all,

Per the Fedora f37 schedule[1] we have started a mass rebuild
on 2022-07-20 for Fedora f37. We are running this mass rebuild
for the changes listed in:

https://pagure.io/releng/issues?status=Open&tags=mass+rebuild

This mass rebuild will be done in a side tag (f37-rebuild) and merged
when completed.

Failures can be seen
https://kojipkgs.fedoraproject.org/mass-rebuild/f37-failures.html
<https://kojipkgs.fedoraproject.org/mass-rebuild/f37-failures.html>

Things still needing rebuilding
https://kojipkgs.fedoraproject.org/mass-rebuild/f37-need-rebuild.html
<https://kojipkgs.fedoraproject.org/mass-rebuild/f37-need-rebuild.html>

FTBFS (Fails To Build From Source) bugs will be filed shortly after
the mass rebuild is complete.

Please be sure to let releng know if you see any bugs in the
reporting. You can contact releng in #fedora-releng channel on Libera.Chat,
the #releng:fedoraproject.org room on Matrix, or by dropping an email
to our list[2] or filing an issue in pagure[3].

This email template is also in https://pagure.io/releng if you wish to
propose improvements or changes to it.

Regards,

Fedora Release Engineering

[1] https://fedorapeople.org/groups/schedule/f-37/f-37-key-tasks.html
[2] https://lists.fedoraproject.org/admin/lists/rel-eng.lists.fedoraproject.org/
[3] https://pagure.io/releng/

[USN-5528-1] FreeType vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5528-1
July 20, 2022

freetype vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in FreeType.

Software Description:
- freetype: FreeType 2 is a font engine library

Details:

It was discovered that FreeType did not correctly handle certain malformed
font files. If a user were tricked into using a specially crafted font
file, a remote attacker could cause FreeType to crash, or possibly execute
arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
libfreetype6 2.11.1+dfsg-1ubuntu0.1

Ubuntu 20.04 LTS:
libfreetype6 2.10.1-2ubuntu0.2

Ubuntu 18.04 LTS:
libfreetype6 2.8.1-2ubuntu2.2

After a standard system update you need to restart your session to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5528-1
CVE-2022-27404, CVE-2022-27405, CVE-2022-27406, CVE-2022-31782

Package Information:
https://launchpad.net/ubuntu/+source/freetype/2.11.1+dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/freetype/2.10.1-2ubuntu0.2
https://launchpad.net/ubuntu/+source/freetype/2.8.1-2ubuntu2.2

[USN-5525-1] Apache XML Security for Java vulnerability

-----BEGIN PGP PUBLIC KEY BLOCK-----

xsFNBGLGvrIBEADLhZXSZnoDtKkmUmncBTq46ZmO2noht7GEQKuLW90ybojVJWon
/ZU6B590pev9Nl+lSkGTU7d1ygWtYBxYGxWG1J2gKBjAdI5NlUUQi40ZBrtIK0To
6TX4BxPNZpa0LKIFs2MwxQ0aQRJZeglZcg4/ioQVW7hthEYsF19PDoqS+xygWWT9
OZ1Dml30tUiy65N8L3EHNiwIdmbPDJgDCNiqWZEFcmCDTzL7Kl/DrJ0Iao3F+E58
hy94VcJYQWhHC9esGZ1vlrStfb5/Iz3ExzNgE119apBy1nQ+32D5lDruQq4bhSLM
SV2Bvgo0+xQjOKnsWD15cicxyDQN/K6xtDDDR0t5L99Xga4Z4bAW3QHYVpCvBeeF
FSRJDQKsislThOFByWRUi983Dyq+TkbynV9RUgSR3ocndIDUH3g5jHUS6WHw5cn1
/grmh/6zpsr88cPRvNuK6dUn3Lh8H3XtOMyJWqN5NnAMChBSecxN72lTNc3JAxQA
T1tWDehZCNjSVREVpjPHHmcK9qx7g/mnHIOW8uga+bL8eSFt8v0l99/YO+s+Hukw
isr+fQvjnkcXIB8cUMxYqWGHIPCZwoouoo/PCh7S26h/Lvlhqlai7TWxPGmnknMs
ursvXo2fkg34l0rqc362F2wr7TFejMR0mvrO4O0Inmvl6e3AP3r87cX9nQARAQAB
zS1GYWJpYW4gVG9lcGZlciA8ZmFiaWFuLnRvZXBmZXJAY2Fub25pY2FsLmNvbT7C
wZQEEwEKAD4WIQTZaC2+bCZyBoQEuWcIC8rVC8PpIAUCYsa+sgIbAwUJA8JnAAUL
CQgHAgYVCgkICwIEFgIDAQIeAQIXgAAKCRAIC8rVC8PpIFTDEACBAxSCsN0Ed+W/
WGmGivPul6pTEeY8Bj6KhkQK+AMmWOsFLtuXPW2rpo/lsp07yTi713XalUEo/VgZ
HFgYS/bpf9sjpV8+larOEbpaBqaKurri/s+rXHAs+Md6XA5NIo7rN4Ge5RLblxsL
v8Mn2unNNgohizAFZZdNTjEXgaakjTsvzDjMSoEG92ziB0q6MDrEiiRXz8Z84cD4
MqYthOspzV6v+gvBbG5S0PbuhYJfKdhgASzt5pgsuFEPfoMX0k5PYhlSPLBNOoMt
umTMdRUYFh8GGU0lxw+JmAj6J19LrOdLjVjBpQMi9PVd+3jmrz7JVv2TOxuaLg3V
m/qIAiS6UPHCqbWnDA/dgRRxldas+nvJiHm6NvUcV6US58Te3yLT/m6Ss6GOXxrv
piPZm2ce7gGU8mn58danFnhq8vt57oAmMXOwzzDAfM1WCGt47XmcGOCJRF7UZLdb
+fb74wkzWw7h2lEBpihVqzSrdwwXCDiPEDwH1zrDlQeZF4gfwP/vwTuJoo3f3mAV
CIbp5kswg9d3Hom1mtMRjNF5MzER+WJC27cbRffUyJ6U2hCiWHbNRM6n67wEz9qp
p68039KeqjLZ5LIsLOsl2DY6Nj3eQcGMJkDMCr/kv1/HroreuXkUke8CplfLHx5o
cnqWt26TxuNeGwpf58Qs+Ffu0mo44c7BTQRixr6yARAAuKo4KhmyztqMT/1OCTTm
jbK9ku0oy4exxeTDo/fqiT9wq2nM9aIC0/0pf7kFPGca7avAu0HPJWw5vZ6uRlsS
OMa5QGBGEeLVepnIXfPvXTOaF+6Z81sYftjSe+Nc1P+HjwpporE0xi33cyASY7Bs
o+Sc49kDg7v+Z8nyaGXaj2EVULE7mvMcrpUx+kkjDSDzJR2GXihivSX5eS7+10+c
X6J2G/U2DvSuqZXy0CDVxPn+pbv/WcU42qNe2xT/jkyDIyYQwyia0zrOMvDy8hd8
Oy/6scedu8VdRxcss8Q1R096SfIoYgYUAkIKz4iKM1hC1SrvzRhOmcFgiJWcI6zl
1fnKxb4l+dMXSZJd1gjE44mYL3Y2kivNWbSRUqZ1c1yQJQ+b55d6Ubap8aNahzDS
S4GTLjhp92vsjfNEnE5tvBuqVIwNYMyPBkdRy78obJ6VrDfVNx3eN1j+xpJ5xwy8
mA1wrKxxtFQFBkW2qGZupRscMOxj4f301BOPAPzKx+z5iAXL6JJh5SnmnszJdHy/
Kv5uEExbPL1xg2kPYxRrQOp8ncQ96hHz3ukOYTsSGXhnISiBaUAyO5MPojifyu3s
eueSiM00o4Xe/vO1HfimArqD3pZZTtlIUM/nr/V5bxbyJUWflIFey8bmoWUdqI50
Utw88Pe3os3+c7LQNsetWMMAEQEAAcLBfAQYAQoAJhYhBNloLb5sJnIGhAS5ZwgL
ytULw+kgBQJixr6yAhsMBQkDwmcAAAoJEAgLytULw+kgZCAQAJRD5sSd1qEOaNbh
EPd41UOaZz11oJSVaeRSLCWKte0f9onCC6NlJs/V9YTcrsEqbm0miVEQqGjDGSQj
XO0or/GVoOkoPR4Yg9SIlTN/rPmMx/tG02H4bnkYznxsIzIeYHlzltqNISZS0WYa
MXdkUs/gl6ZLzVuNZogZX5XMNYGnDsYkMdQoTDW5K1WsPl8QAuJnjO1ykbztMdkG
MuQAMlTE4DWEeomVMJLYEiaDOaoCLcbeKs4M2/K3PP0MGrYA9Ag4y6LOVVr+NHHa
KIew8+BBQNDmO4K6/R669sNpDZy80KU1IQxRPpPb0+RWlFxIsT5TccMvvXVtCUq9
9Oi3eOmKgBQoO/X9RZscEWcFR2yEcb0oafvGkSuvUpZeCXpuspAszItk2WV5hC63
I7xxbzwjeroFEpCecK7UyGIzNPus5x9s0pWpuLCxR9oZGjo46aLxBNRYIZbHjcFf
f8c0XVNOz4Khq7ZOjOK4sL84YhkeLUeotbfSYuQF6FWKuIto7jk9CcIfXBSCvWmc
7eRjZFyQJ6Vt5QVlUzyHK53Ownq7BSrl/nzUNKmEnTvS/3379P+jvlqZdCyjG7zV
jtHU29SueLjJCln01r/Xog+FIedsyp/uF5cEc4sqauF4cbyvEjlC+k+LyifNzbhP
QBQxRQ+QjhG3hEo1YimQrQmViRCf
=vcIR
-----END PGP PUBLIC KEY BLOCK-----
==========================================================================
Ubuntu Security Notice USN-5525-1
July 20, 2022

libxml-security-java vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Apache XML Security for Java could be made to expose sensitive information.

Software Description:
- libxml-security-java: Apache XML Security for Java

Details:

It was discovered that Apache XML Security for Java incorrectly passed a
configuration property when creating specific key elements. This allows an
attacker to abuse an XPath Transform to extract sensitive information.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
libxml-security-java 2.0.10-2+deb11u1build0.20.04.1

Ubuntu 18.04 LTS:
libxml-security-java 2.0.10-2~18.04.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5525-1
CVE-2021-40690


Package Information:
https://launchpad.net/ubuntu/+source/libxml-security-java/2.0.10-2+deb11u1build0.20.04.1
https://launchpad.net/ubuntu/+source/libxml-security-java/2.0.10-2~18.04.1

[USN-5527-1] Checkmk vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5527-1
July 20, 2022

check-mk vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Checkmk.

Software Description:
- check-mk: general purpose monitoring plugin for retrieving data

Details:

It was discovered that Checkmk incorrectly handled authentication. An attacker
could possibly use this issue to cause a race condition leading to information
disclosure. (CVE-2017-14955)

It was discovered that Checkmk incorrectly handled certain inputs. An attacker
could use these cross-site scripting issues to inject arbitrary html or
javascript code to obtain sensitive information including user information,
session cookies and valid credentials. (CVE-2017-9781, CVE-2021-36563,
CVE-2021-40906, CVE-2022-24565)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
check-mk-livestatus 1.2.8p16-1ubuntu0.2
check-mk-multisite 1.2.8p16-1ubuntu0.2
check-mk-server 1.2.8p16-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5527-1
CVE-2017-14955, CVE-2017-9781, CVE-2021-36563, CVE-2021-40906,
CVE-2022-24565

Package Information:
https://launchpad.net/ubuntu/+source/check-mk/1.2.8p16-1ubuntu0.2

Tuesday, July 19, 2022

[USN-5526-1] PyJWT vulnerability

==========================================================================
Ubuntu Security Notice USN-5526-1
July 20, 2022

pyjwt vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

PyJWT could allow signature forgery.

Software Description:
- pyjwt: Python 3 implementation of JSON Web Token

Details:

Aapo Oksman discovered that PyJWT incorrectly handled signatures
constructed from SSH public keys. A remote attacker could use this to forge
a JWT signature.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
python3-jwt 2.3.0-1ubuntu0.1

Ubuntu 20.04 LTS:
python3-jwt 1.7.1-2ubuntu2.1

Ubuntu 18.04 LTS:
python-jwt 1.5.3+ds1-1ubuntu0.1
python3-jwt 1.5.3+ds1-1ubuntu0.1

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5526-1
CVE-2022-29217

Package Information:
https://launchpad.net/ubuntu/+source/pyjwt/2.3.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/pyjwt/1.7.1-2ubuntu2.1
https://launchpad.net/ubuntu/+source/pyjwt/1.5.3+ds1-1ubuntu0.1

Upcoming F37 schedule dates

It's me again with some more schedule reminders

* 2022-07-19 (TODAY!) — F37 Self-Contained Change proposals due
* 2022-07-20 (TOMORROW) — Mass rebuild begins
* 2022-07-26 — Software string freeze
* 2022-08-09 — F37 branches from Rawhide, Change complete (testable) deadline

More schedule details are available at
https://fedorapeople.org/groups/schedule/f-37/f-37-key-tasks.html

--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

[USN-5524-1] HarfBuzz vulnerability

==========================================================================
Ubuntu Security Notice USN-5524-1
July 19, 2022

harfbuzz vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

HarfBuzz could be made to crash if it opened specially crafted data.

Software Description:
- harfbuzz: OpenType text shaping engine

Details:

It was discovered that HarfBuzz incorrectly handled certain glyph sizes. A
remote attacker could use this issue to cause HarfBuzz to crash, resulting
in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
libharfbuzz0b 2.7.4-1ubuntu3.1

Ubuntu 20.04 LTS:
libharfbuzz0b 2.6.4-1ubuntu4.2

After a standard system update you need to restart your session to make all
the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5524-1
CVE-2022-33068

Package Information:
https://launchpad.net/ubuntu/+source/harfbuzz/2.7.4-1ubuntu3.1
https://launchpad.net/ubuntu/+source/harfbuzz/2.6.4-1ubuntu4.2

List of long term FTBFS packages to be retired in August

Dear maintainers.

Based on the current fail to build from source policy, the following packages
will be retired from Fedora 37 approximately one week before branching (August
2022).

Policy:
https://docs.fedoraproject.org/en-US/fesco/Fails_to_build_from_source_Fails_to_install/

The packages in rawhide were not successfully built at least since Fedora 35.

This report is based on dist tags.

Packages collected via:
https://github.com/hroncok/fedora-report-ftbfs-retirements/blob/master/ftbfs-retirements.ipynb

If you see a package that was built, please let me know.
If you see a package that should be exempted from the process, please let me
know and we can work together to get a FESCo approval for that.

If you see a package that can be rebuilt, please do so.

Package (co)maintainers
============================================================================
golang-grpc-go4 eclipseo, go-sig, jchaloup
klamav kkofler
koffice-kivio kkofler, rdieter
lancer willb
php-aws-sdk3 lcts
php-pimple lcts
recorder ddd
rubygem-bundler_ext jaruga, ruby-packagers-sig, vondruch
rubygem-coffee-rails jaruga, ruby-packagers-sig, vondruch
rubygem-image_processing pvalena
rubygem-minitest-reporters pvalena
rubygem-sprockets-rails jaruga, pvalena, ruby-packagers-sig
tinygo go-sig, qulogic
uom-parent lberk, mgoodwin, nathans
xs petersen


The following packages require above mentioned packages:
Depending on: golang-grpc-go4 (1)
golang-x-build (maintained by: eclipseo, go-sig, jchaloup)
golang-x-build-0-0.19.20201229git0a4bf69.fc35.src requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34
golang-x-build-devel-0-0.19.20201229git0a4bf69.fc35.noarch requires
golang(grpc.go4.org) = 0-0.9.20180421git11d0a25.fc34,
golang(grpc.go4.org/codes) = 0-0.9.20180421git11d0a25.fc34

Depending on: rubygem-image_processing (28)
rubygem-activestorage (maintained by: ruby-packagers-sig, vondruch)
rubygem-activestorage-7.0.2.3-1.fc37.src requires rubygem(image_processing) =
1.11.0

rubygem-actionmailbox (maintained by: pvalena)
rubygem-actionmailbox-7.0.2.3-1.fc37.noarch requires rubygem(activestorage) =
7.0.2.3
rubygem-actionmailbox-7.0.2.3-1.fc37.src requires rubygem(activestorage) =
7.0.2.3

rubygem-actiontext (maintained by: pvalena)
rubygem-actiontext-7.0.2.3-1.fc37.noarch requires rubygem(activestorage) =
7.0.2.3
rubygem-actiontext-7.0.2.3-1.fc37.src requires rubygem(activestorage) = 7.0.2.3

rubygem-rails (maintained by: jstribny, kanarip, mmorsi, mtasaka, pvalena,
ruby-packagers-sig, sseago, tdawson, vondruch)
rubygem-rails-1:7.0.2.3-1.fc37.noarch requires rubygem(activestorage) = 7.0.2.3

rubygem-railties (maintained by: mmorsi, pvalena, tdawson, vondruch)
rubygem-railties-7.0.2.3-1.fc37.src requires rubygem(activestorage) = 7.0.2.3

rubygem-rspec-rails (maintained by: clalance, vondruch)
rubygem-rspec-rails-5.1.1-1.fc37.src requires rubygem(actionmailbox) = 7.0.2.3

rubygem-apipie-rails (maintained by: ruby-packagers-sig, vondruch)
rubygem-apipie-rails-0.5.18-5.fc36.noarch requires rubygem(rails) = 7.0.2.3

rubygem-declarative_authorization (maintained by: mcpierce)
rubygem-declarative_authorization-0.5.7-17.fc36.noarch requires
rubygem(rails) = 7.0.2.3

rubygem-importmap-rails (maintained by: pvalena)
rubygem-importmap-rails-1.0.3-1.fc37.src requires rubygem(rails) = 7.0.2.3

rubygem-sass-rails (maintained by: ruby-packagers-sig, tdawson, vondruch)
rubygem-sass-rails-6.0.0-4.fc36.src requires rubygem(rails) = 7.0.2.3

rubygem-shoulda (maintained by: stahnma, tdawson)
rubygem-shoulda-3.6.0-10.fc36.src requires rubygem(rails) = 7.0.2.3

rubygem-shoulda-context (maintained by: tdawson, vondruch)
rubygem-shoulda-context-1.2.2-11.fc36.src requires rubygem(rails) = 7.0.2.3

rubygem-shoulda-matchers (maintained by: vondruch)
rubygem-shoulda-matchers-4.5.1-3.fc36.src requires rubygem(rails) = 7.0.2.3

rubygem-actionpack (maintained by: jaruga, jstribny, kanarip, mmorsi, pvalena,
ruby-packagers-sig, sseago, vondruch)
rubygem-actionpack-1:7.0.2.3-1.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-actionview (maintained by: jaruga, pvalena, ruby-packagers-sig)
rubygem-actionview-7.0.2.3-1.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-activemodel (maintained by: jstribny, mmorsi, pvalena, tdawson, vondruch)
rubygem-activemodel-7.0.2.3-1.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-ammeter (maintained by: jstribny, ruby-packagers-sig, vondruch)
rubygem-ammeter-1.1.5-2.fc36.noarch requires rubygem(railties) = 7.0.2.3
rubygem-ammeter-1.1.5-2.fc36.src requires rubygem(railties) = 7.0.2.3

rubygem-font-awesome-rails (maintained by: abradshaw, ckyriakidou, evgeni,
fale, snecker)
rubygem-font-awesome-rails-4.7.0.8-1.fc37.noarch requires rubygem(railties) =
7.0.2.3
rubygem-font-awesome-rails-4.7.0.8-1.fc37.src requires rubygem(railties) =
7.0.2.3

rubygem-generator_spec (maintained by: ilgrad)
rubygem-generator_spec-0.9.4-11.fc36.noarch requires rubygem(railties) = 7.0.2.3
rubygem-generator_spec-0.9.4-11.fc36.src requires rubygem(railties) = 7.0.2.3

rubygem-globalid (maintained by: jaruga, pvalena, ruby-packagers-sig)
rubygem-globalid-1.0.0-2.fc36.src requires rubygem(railties) = 7.0.2.3

rubygem-haml (maintained by: kanarip, pvalena)
rubygem-haml-5.2.2-2.fc36.src requires rubygem(railties) = 7.0.2.3

rubygem-jbuilder (maintained by: pvalena, vondruch)
rubygem-jbuilder-2.11.5-1.fc37.src requires rubygem(railties) = 7.0.2.3

rubygem-jquery-rails (maintained by: jstribny, tdawson, vondruch)
rubygem-jquery-rails-4.4.0-2.fc36.noarch requires rubygem(railties) = 7.0.2.3

rubygem-rails-controller-testing (maintained by: valtri)
rubygem-rails-controller-testing-1.0.5-5.fc36.src requires rubygem(railties)
= 7.0.2.3

rubygem-sass-twitter-bootstrap (maintained by: tdawson)
rubygem-sass-twitter-bootstrap-2.3.0-15.fc36.noarch requires
rubygem(railties) = 7.0.2.3

rubygem-sassc-rails (maintained by: pvalena)
rubygem-sassc-rails-2.1.2-4.fc36.noarch requires rubygem(railties) = 7.0.2.3
rubygem-sassc-rails-2.1.2-4.fc36.src requires rubygem(railties) = 7.0.2.3

rubygem-slim (maintained by: vondruch)
rubygem-slim-4.1.0-5.fc36.src requires rubygem(railties) = 7.0.2.3

rubygem-web-console (maintained by: jaruga, ruby-packagers-sig, vondruch)
rubygem-web-console-4.1.0-4.fc36.noarch requires rubygem(railties) = 7.0.2.3
rubygem-web-console-4.1.0-4.fc36.src requires rubygem(railties) = 7.0.2.3

Too many dependencies for rubygem-image_processing, not all listed here


Affected (co)maintainers (directly and indirectly):
abradshaw: rubygem-image_processing
ckyriakidou: rubygem-image_processing
clalance: rubygem-image_processing
ddd: recorder
eclipseo: golang-grpc-go4
evgeni: rubygem-image_processing
fale: rubygem-image_processing
go-sig: tinygo, golang-grpc-go4
ilgrad: rubygem-image_processing
jaruga: rubygem-coffee-rails, rubygem-bundler_ext, rubygem-image_processing,
rubygem-sprockets-rails
jchaloup: golang-grpc-go4
jstribny: rubygem-image_processing
kanarip: rubygem-image_processing
kkofler: klamav, koffice-kivio
lberk: uom-parent
lcts: php-aws-sdk3, php-pimple
mcpierce: rubygem-image_processing
mgoodwin: uom-parent
mmorsi: rubygem-image_processing
mtasaka: rubygem-image_processing
nathans: uom-parent
petersen: xs
pvalena: rubygem-image_processing, rubygem-minitest-reporters,
rubygem-sprockets-rails
qulogic: tinygo
rdieter: koffice-kivio
ruby-packagers-sig: rubygem-coffee-rails, rubygem-bundler_ext,
rubygem-image_processing, rubygem-sprockets-rails
snecker: rubygem-image_processing
sseago: rubygem-image_processing
stahnma: rubygem-image_processing
tdawson: rubygem-image_processing
valtri: rubygem-image_processing
vondruch: rubygem-coffee-rails, rubygem-bundler_ext, rubygem-image_processing
willb: lancer

--
Miro Hrončok
--
Phone: +420777974800
IRC: mhroncok
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

[USN-5523-1] LibTIFF vulnerabilities

==========================================================================
Ubuntu Security Notice USN-5523-1
July 19, 2022

tiff vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 ESM
- Ubuntu 14.04 ESM

Summary:

Several security issues were fixed in LibTIFF.

Software Description:
- tiff: Tag Image File Format (TIFF) library

Details:

It was discovered that LibTIFF was not properly performing checks to
guarantee that allocated memory space existed, which could lead to a
NULL pointer dereference via a specially crafted file. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2022-0907, CVE-2022-0908)

It was discovered that LibTIFF was not properly performing checks to
avoid division calculations where the denominator value was zero,
which could lead to an undefined behavior situation via a specially
crafted file. An attacker could possibly use this issue to cause a
denial of service. (CVE-2022-0909)

It was discovered that LibTIFF was not properly performing bounds
checks, which could lead to an out-of-bounds read via a specially
crafted file. An attacker could possibly use this issue to cause a
denial of service or to expose sensitive information. (CVE-2022-0924)

It was discovered that LibTIFF was not properly performing the
calculation of data that would eventually be used as a reference for
bounds checking operations, which could lead to an out-of-bounds
read via a specially crafted file. An attacker could possibly use
this issue to cause a denial of service or to expose sensitive
information. (CVE-2020-19131)

It was discovered that LibTIFF was not properly terminating a
function execution when processing incorrect data, which could lead
to an out-of-bounds read via a specially crafted file. An attacker
could possibly use this issue to cause a denial of service or to
expose sensitive information. (CVE-2020-19144)

It was discovered that LibTIFF was not properly performing checks
when setting the value for data later used as reference during memory
access, which could lead to an out-of-bounds read via a specially
crafted file. An attacker could possibly use this issue to cause a
denial of service or to expose sensitive information.
(CVE-2022-22844)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 ESM:
  libtiff-opengl                  4.0.6-1ubuntu0.8+esm2
  libtiff-tools                   4.0.6-1ubuntu0.8+esm2
  libtiff5                        4.0.6-1ubuntu0.8+esm2
  libtiffxx5                      4.0.6-1ubuntu0.8+esm2

Ubuntu 14.04 ESM:
  libtiff-opengl                  4.0.3-7ubuntu0.11+esm2
  libtiff-tools                   4.0.3-7ubuntu0.11+esm2
  libtiff5                        4.0.3-7ubuntu0.11+esm2
  libtiffxx5                      4.0.3-7ubuntu0.11+esm2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5523-1
  CVE-2020-19131, CVE-2020-19144, CVE-2022-0907, CVE-2022-0908,
  CVE-2022-0909, CVE-2022-0924, CVE-2022-22844

Monday, July 18, 2022

Ubuntu 21.10 (Impish Indri) End of Life reached on July 14 2022

This is a follow-up to the End of Life warning sent earlier to confirm
that as of July 14, 2022, Ubuntu 21.10 is no longer supported. No more
package updates will be accepted to 21.10, and it will be archived to
old-releases.ubuntu.com in the coming weeks.

The original End of Life warning follows, with upgrade instructions:

Ubuntu announced its 21.10 (Impish Indri) release almost 9 months
ago, on October 14, 2021, and its support period is now nearing its
end. Ubuntu 21.10 will reach end of life on July 14, 2022.

At that time, Ubuntu Security Notices will no longer include
information or updated packages for Ubuntu 21.10.

The supported upgrade path from Ubuntu 21.10 is via Ubuntu 22.04 LTS.
Instructions and caveats for the upgrade may be found at:

https://help.ubuntu.com/community/JammyUpgrades

Ubuntu 22.04 LTS continues to be actively supported with security
updates and select high-impact bug fixes. Announcements of security
updates for Ubuntu releases are sent to the ubuntu-security-announce
mailing list, information about which may be found at:

https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

Since its launch in October 2004 Ubuntu has become one of the most
highly regarded Linux distributions with millions of users in homes,
schools, businesses and governments around the world. Ubuntu is Open
Source software, costs nothing to download, and users are free to
customise or alter their software in order to meet their needs.

On behalf of the Ubuntu Release Team,
--
Brian Murray

F37 proposal: Mumble 1.4 (Self-Contained Change proposal)

https://fedoraproject.org/wiki/Changes/Mumble1.4

This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.

== Summary ==

Update the Mumble voice chat application from 1.3 to 1.4.

== Owner ==

* Name: [[User:carlwgeorge| Carl George]]
* Email: carl@redhat.com


== Detailed Description ==

Earlier this year the Mumble project released a new major version. The full
list of new features can be found in the
[https://www.mumble.info/blog/mumble-1.4.230/ upstream release notes].

This change also involves several notable packaging changes.

* Enable the native PipeWire audio backend
* Rename the Mumble server package from murmur to mumble-server, per
upstream preference
* Relocate Mumble server configuration file from
/etc/murmur/murmur.ini to /etc/murmur.ini, per upstream preference

== Feedback ==

== Benefit to Fedora ==

Mumble is a popular voice chat application. It is commonly used for gaming and
podcasts. Updating the Fedora package to the latest upstream version ensures
that Fedora Linux continues to be an attractive operating system for those
communities.

== Scope ==

* Proposal owners:
** Build version 1.4.x in carlwgeorge/mumble copr
** Test copr packages
** Build version 1.4.x in appropriate Fedora branches

* Other developers: N/A (not needed for this Change)

* Release engineering: N/A (not needed for this Change)

* Policies and guidelines: N/A (not needed for this Change)

* Trademark approval: N/A (not needed for this Change)

== Upgrade/compatibility impact ==

The Mumble developers prefer distributions to name the server package
mumble-server. Currently this is named murmur in Fedora. This change renames
the server package to align with upstream. The required provides/obsoletes
will be added per the packaging guidelines.

The Mumble developers prefer the server configuration file to be
/etc/murmur.ini. Currently this file is /etc/murmur/murmur.ini in Fedora.
This change relocates that file in an RPM scriptlet to align with upstream.
The old path will become a compatibility symlink to the new path.

== How To Test ==

As Mumble is voice chat software, to test this change you will need a
microphone and headphones/speakers. The carlwgeorge/mumble copr repository
contains the updated packages. Install the mumble package to test the client.
Install the mumble-server package to test the server. If you have other Mumble
servers you routinely connect to, connect to them with the updated mumble
package. If you are familiar with setting up a Mumble server, set one up with
the existing 1.3.x packages and then update to the 1.4.x packages. Verify that
the server configuration file gets relocated as described in this change.

== User Experience ==

Users will have the 1.4.x version of Mumble available, with all the
upstream features that provides.

== Dependencies ==

N/A

== Contingency Plan ==

* Contingency mechanism: revert to Mumble 1.3 with an epoch
* Contingency deadline: beta freeze
* Blocks release? no

== Documentation ==

* https://www.mumble.info/blog/mumble-1.4.230/

== Release Notes ==

Mumble 1.4 is available in Fedora 37.


--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure

F37 proposal: Emacs 28 (Self-Contained Change proposal)

https://fedoraproject.org/wiki/Changes/Emacs_28

This document represents a proposed Change. As part of the Changes
process, proposals are publicly announced in order to receive
community feedback. This proposal will only be implemented if approved
by the Fedora Engineering Steering Committee.

== Summary ==

Update GNU Emacs to 28.1 release. This release includes a wide variety
of new features, including native compilation of Lisp files.

== Owner ==

* Name: [[User:Bhavin192| Bhavin Gandhi]]
* Email: bhavin192@fedoraproject.org


== Detailed Description ==

The Emacs package will be updated to 28.1 release of GNU Emacs. This
will have native compilation feature enabled, and will package
additional natively compiled Lisp files.


== Benefit to Fedora ==

This major version of Emacs has bugfixes and new features which also
improve the overall speed of Emacs.

== Scope ==

* Proposal owners: Upgrade the Emacs package to 28.1
* Other developers: N/A
* Release engineering: N/A (not needed for this Change)
* Policies and guidelines: N/A (not needed for this Change)
* Trademark approval: N/A (not needed for this Change)
* Alignment with Objectives: N/A

== Upgrade/compatibility impact ==

Users might see some warnings while their installed Emacs packages get
natively compiled after first launch post the upgrade. These warnings
won't break any functionality, though the users are encouraged to
update their Emacs packages.

== How To Test ==

# Run dnf update emacs
# Open Emacs and check if inbuilt functionalities and packages work as indented.

== User Experience ==

https://www.gnu.org/software/emacs/#Releases

* Lisp files are natively compiled, this results in speed improvements
for most of the functionalities
* Much improved display of Emoji and Emoji sequences
* New system for documenting groups of functions

== Dependencies ==
N/A

== Contingency Plan ==

* Contingency mechanism: (What to do? Who will do it?) N/A (not a
System Wide Change)
* Contingency deadline: N/A (not a System Wide Change)
* Blocks release? N/A (not a System Wide Change), No

== Documentation ==
* https://www.gnu.org/software/emacs/news/NEWS.28.1
* https://src.fedoraproject.org/rpms/emacs/pull-request/12

== Release Notes ==
The upstream release notes are available at
https://www.gnu.org/software/emacs/news/NEWS.28.1

These can also be accessed from within Emacs by doing `C-h n`.


--
Ben Cotton
He / Him / His
Fedora Program Manager
Red Hat
TZ=America/Indiana/Indianapolis
_______________________________________________
devel-announce mailing list -- devel-announce@lists.fedoraproject.org
To unsubscribe send an email to devel-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel-announce@lists.fedoraproject.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure