This update provides recent git snapshots of os-autoinst and openQA, with the usual slate of bug fixes and changes from upstream. Also, the AMQP plugin is now enabled, as the dependencies have been packaged into Fedora. The update also addresses some potential security issues.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-c404576415 2019-08-11 01:11:43.672603 --------------------------------------------------------------------------------Name : openqa Product : Fedora 30 Version : 4.6 Release : 18.20190716git5bfa647.fc30.2 URL : http://open.qa/ Summary : OS-level automated testing framework Description : openQA is a testing framework that allows you to test GUI applications on one hand and bootloader and kernel on the other. In both cases, it is difficult to script tests and verify the output. Output can be a popup window or it can be an error in early boot even before init is executed. openQA is an automated test tool that makes it possible to test the whole installation process of an operating system. It uses virtual machines to reproduce the process, check the output (both serial console and screen) in every step and send the necessary keystrokes and commands to proceed to the next. openQA can check whether the system can be installed, whether it works properly in 'live' mode, whether applications work or whether the system responds as expected to different installation options and commands. Even more importantly, openQA can run several combinations of tests for every revision of the operating system, reporting the errors detected for each combination of hardware configuration, installation options and variant of the operating system. --------------------------------------------------------------------------------Update Information: This update provides recent git snapshots of os-autoinst and openQA, with the usual slate of bug fixes and changes from upstream. Also, theAMQP plugin is now enabled, as the dependencies have been packaged into Fedora. The update also addresses some potential security issues. --------------------------------------------------------------------------------ChangeLog: * Thu Aug 1 2019 Adam Williamson - 4.6-18.20190716git5bfa647.fc30.2 - Backport PR #2232 (faster and safer markdown rendering) - Allow comments by users again (safe with PR #2232) * Wed Jul 31 2019 Adam Williamson - 4.6-18.20190716git5bfa647.fc30.1 - Only allow operators and admins to post comments (security issue) * Thu Jul 25 2019 Adam Williamson - 4.6-18.20190716git5bfa647 - Backport PR #2213 (fixes vulnerability to maliciously-formed API requests) - Backport PR #2217 (allow passing headers to publish_amqp) * Thu Jul 25 2019 Fedora Release Engineering - 4.6-17.20190716git5bfa647 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Tue Jul 16 2019 Adam Williamson - 4.6-16.20190716git5bfa647 - Update to latest git again, re-sync spec with upstream - Enable AMQP plugin now the dependencies are packaged - Backport some PRs to fix some test failures * Mon Jun 3 2019 Adam Williamson - 4.6-15.20190603git8a35385 - Update to latest git again - Fix update auto restart plugin for upstream changes * Fri May 24 2019 Adam Williamson - 4.6-14.20190522gitab91f31 - Update to latest git again - Drop merged patch --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-c404576415' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This update addresses various security issues in perl-Module-Signature as described below. The default behavior is also changed so as to ignore any MANIFEST.SKIP files unless a "skip" parameter is specified. An updated version of perl-Test-Signature that accounts for the changed default behavior is included in this update. Security issues: * Module::Signature before version 0.75 could be tricked [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5833 2015-04-09 04:58:00 -------------------------------------------------------------------------------- Name : perl-Test-Signature Product : Fedora 21 Version : 1.11 Release : 1.fc21 URL : https://metacpan.org/dist/Test-Signature Summary : Automated SIGNATURE testing Description : Module::Signature allows you to verify that a distribution has not been tampered with. Test::Signature lets that be tested as part of the distribution's test suite. -------------------------------------------------------------------------------- Update Information: This update addresses various security issues in perl-Module-Signature as described below. The default behavior is also changed so as to ignore any MANIFEST.SKIP files unless a "skip" parameter is specified. An updated version of perl-Test-Signature that accounts for the changed default behavior is included in this update. Security issues: * Module::Signature before version 0.75 could be tricked into interpreting the unsigned portion of a SIGNATURE file as the signed portion due to faulty parsing of the PGP signature boundaries. * When verifying the contents of a CPAN module, Module::Signature before version 0.75 ignored some files in the extracted tarball that were not listed in the signature file. This included some files in the t/ directory that would execute automatically during "make test". * Module::Signature before version 0.75 used two argument open() calls to read the files when generatingchecksums from the signed manifest. This allowed embedding arbitrary shell commands into the SIGNATURE file that would execute during the signature verification process. * Module::Signature before version 0.75 has been loading several modules at runtime inside the extracted module directory. Modules like Text::Diff are not guaranteed to be available on all platforms and could be added to a malicious module so that they would load from the '.' path in @INC. -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2015 Paul Howarth - 1.11-1 - Update to 1.11 - Compatibility with Module::Signature 0.75+ - Classify buildreqs by usage - Don't use macros for commands - Avoid clobbering ~/.gnupg for local builds - Make %files list more explicit - Drop %defattr, redundant since rpm 4.4 - Import upstream's GPG key in %prep so we don't need to fetch it from a keyserver when running the signature test * Tue Aug 26 2014 Jitka Plesnikova - 1.10-18 - Perl 5.20 rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1209911 - perl-Module-Signature: unsigned files interpreted as signed in some circumstances https://bugzilla.redhat.com/show_bug.cgi?id=1209911 [ 2 ] Bug #1209915 - perl-Module-Signature: arbitrary code execution during test phase https://bugzilla.redhat.com/show_bug.cgi?id=1209915 [ 3 ] Bug #1209917 - perl-Module-Signature: arbitrary code execution when verifying module signatures https://bugzilla.redhat.com/show_bug.cgi?id=1209917 [ 4 ] Bug #1209918 - perl-Module-Signature: arbitrary modules loading in some circumstances https://bugzilla.redhat.com/show_bug.cgi?id=1209918 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update perl-Test-Signature' at the command line. For more information, refer to "Managing Software with yum", available at . Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.