- doc Remove documentation for future option faked sys - build Don't use dev srandom on OpenBSD - Do not use C99 feature - g10 Fix regexp sanitization - g10 Push compress filter only if compressed - gpg Sanitize diagnostic with the original file name [CVE-2018-12020]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-4ef71d3525 2018-06-15 15:48:22.929912 --------------------------------------------------------------------------------Name : gnupg Product : Fedora 28 Version : 1.4.22 Release : 7.fc28 URL : http://www.gnupg.org/ Summary : A GNU utility for secure communication and data storage Description : GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide). --------------------------------------------------------------------------------Update Information: - doc Remove documentation for future option faked sys - build Don't use dev srandom on OpenBSD - Do not use C99 feature - g10 Fix regexp sanitization - g10 Push compress filter only if compressed - gpg Sanitize diagnostic with the original file name [CVE-2018-12020] --------------------------------------------------------------------------------ChangeLog: * Fri Jun 8 2018 Brian C. Lane - 1.4.22-7 - doc Remove documentation for future option faked sys - build Don't use dev srandom on OpenBSD - Do not use C99 feature - g10 Fix regexp sanitization - g10 Push compress filter only if compressed - gpg Sanitize diagnostic with the original file name [CVE-2018-12020] --------------------------------------------------------------------------------This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-4ef71d3525' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update to 2.13. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10884 2015-06-29 21:04:53 -------------------------------------------------------------------------------- Name : s3ql Product : Fedora 21 Version : 2.13 Release : 1.fc21 URL : Summary : Full-Featured File System for Online Data Storage Description : S3QL is a file system that stores all its data online using storage services like Google Storage, Amazon S3 or OpenStack. S3QL effectively provides a hard disk of dynamic, infinite capacity that can be accessed from any computer with Internet access. S3QL is a standard conforming, full featured UNIX file system that is conceptually indistinguishable from any local file system. Furthermore, S3QL has additional features like compression, encryption, data de-duplication, immutable trees and snapshotting which make it especially suitable for on-line backup and archival. S3QL is designed to favor simplicity and elegance over performance and feature- creep. Care has been taken to make the source code as readable and serviceable as possible. Solid error detection and error handling have been included from the very first line, and S3QL comes with extensive automated test cases for all its components. == Features =* Transparency. Conceptually, S3QL is indistinguishable from a local file system. For example, it supports hardlinks, symlinks, standard unix permissions, extended attributes and file sizes up to 2 TB. * Dynamic Size. The size of an S3QL file system grows and shrinks dynamically as required. * Compression. Before storage, all data may compressed with the LZMA, bzip2 or deflate (gzip) algorithm. * Encryption. After compression (but before upload), all data can AES encrypted with a 256 bit key. An additional SHA256 HMAC checksum is used to protect the data against manipulation. * Data De-duplication. If several files have identical contents, the redundant data will be stored only once. Thisworks across all files stored in the file system, and also if only some parts of the files are identical while other parts differ. * Immutable Trees. Directory trees can be made immutable, so that their contents can no longer be changed in any way whatsoever. This can be used to ensure that backups can not be modified after they have been made. * Copy-on-Write/Snapshotting. S3QL can replicate entire directory trees without using any additional storage space. Only if one of the copies is modified, the part of the data that has been modified will take up additional storage space. This can be used to create intelligent snapshots that preserve the state of a directory at different points in time using a minimum amount of space. * High Performance independent of network latency. All operations that do not write or read file contents (like creating directories or moving, renaming, and changing permissions of files and directories) are very fast because they are carried out without any network transactions. S3QL achieves this by saving the entire file and directory structure in a database. This database is locally cached and the remote copy updated asynchronously. * Support for low bandwidth connections. S3QL splits file contents into smaller blocks and caches blocks locally. This minimizes both the number of network transactions required for reading and writing data, and the amount of data that has to be transferred when only parts of a file are read or written. -------------------------------------------------------------------------------- Update Information: Update to 2.13 -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 29 2015 Marcel Wysocki - 2.13-1 - Update to 2.13 * Fri Jun 19 2015 Fedora Release Engineering - 2.9-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1134677 - CVE-2014-0485 s3ql: code execution due to unsafepickle() usage [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1134677 [ 2 ] Bug #1182213 - [abrt] s3ql: pkg_resources.py:567:resolve:pkg_resources.DistributionNotFound: requests https://bugzilla.redhat.com/show_bug.cgi?id=1182213 [ 3 ] Bug #1124493 - s3ql-2.13 is available https://bugzilla.redhat.com/show_bug.cgi?id=1124493 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update s3ql' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
This is a re-issue of the testing update, this time signed with the testing key. Sorry for the multiple-releases.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-336 2006-04-19 ---------------------------------------------------------------------Product : Fedora Core 5 Name : gnupg Version : 1.4.3 Release : 2 Summary : A GNU utility for secure communication and data storage. Description : GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide). ---------------------------------------------------------------------Update Information: This is a re-issue of the testing update, this time signed with the testing key. Sorry for the multiple-releases. ---------------------------------------------------------------------* Tue Apr 11 2006 Nalin Dahyabhai - 1.4.3-2 - apply patch from David Shaw to try multiple defaults if the the photo-viewer option isn't set (fixes #187880) ---------------------------------------------------------------------This update can be downloaded from: 9da4e798eadd6f80069aa8fb4976b3812e393b13 SRPMS/gnupg-1.4.3-2.src.rpm 93f8b864103868a058242e341b39401b4218854a ppc/gnupg-1.4.3-2.ppc.rpm a327f807ba3eb730d00aac21a78ed30a038cc057 ppc/debug/gnupg-debuginfo-1.4.3-2.ppc.rpm 77ab12741224c39326bc74238731d6c8dc5e8a3d x86_64/gnupg-1.4.3-2.x86_64.rpm 041a4b804e2e146673b937dd3f0e8763173a1b7b x86_64/debug/gnupg-debuginfo-1.4.3-2.x86_64.rpm 48b48555ec4b4a8f23687d95dd13096dca1546ac i386/gnupg-1.4.3-2.i386.rpm 3888ee92e2e7790a44172e345d23ae8fd23e9296 i386/debug/gnupg-debuginfo-1.4.3-2.i386.rpm Thisupdate can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.