From: QA Team Robot <qa@altlinux.org> To: sisyphus-cybertalk@lists.altlinux.org Subject: [cyber] I: t7/branch packages: +2! +10 (15273) Date: Sun, 22 May 2016 04:45:45 +0000 Message-ID: <20160522044545.GA24752@gyle.altlinux.org> (raw) 2 ADDED packages firefox-gost - The Mozilla Firefox project is a redesign of Mozilla's browser [143M] * Fri May 20 2016 Andrey Cherepanov <cas@altlinux> 38.7.0-alt0.M70P.1 - New package with support GOST encryption [firefox-gost_patch38.patch] - Build with bundled nss firefox-gost-ru - Russian (RU) Language Pack for Firefox GOST * Fri May 20 2016 Andrey Cherepanov <cas@altlinux> 38.7.0-alt1 - New package for firefox-gost 10 UPDATED packages ImageMagick - An X application for displaying and manipulating images * Wed May 18 2016 Andrey Cherepanov <cas@altlinux> 6.8.4.10-alt3.M70P.1 - Apply security patches from Debian: ImageTragick: The coders EPHEMERAL, URL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT are disabled via policy.xml file, since they are vulnerable to code injection. This mitigates CVE-2016-3714, CVE-2016-3715, CVE-2016-3716, CVE-2016-3717, and CVE-2016-3718. Since ImageMagick reverts to its internal SVG renderer (which uses MVG coder) if Inkscape or RSVG is not used, the option --with-rsvg is included. Closes: 823542. In addition, some other actions were taken with respect to these vulnerabilities: - Drop the PLT/Gnuplot decoder, which was vulnerable to command injection. - Some sanitization for input filenames in http/https delegates is added. - Indirect filename are now authorized by policy. - Indirect reads with label:@ are prevented. - Less secure coders (such as MVG, TEXT, and MSL) require explicit reference in the filename (e.g. mvg:my-graph.mvg). * Thu Apr 25 2013 Fr. Br. George <george@altlinux> 6.8.4.10-alt2.1 alterator-net-openvpn - Alterator module for openvpn connections configuration * Tue Jan 20 2015 Mikhail Efremov <sem@altlinux> 0.8.10-alt1 - Add tmp-dir option to ovpnoptions. - backend: Rename IFACEDIR to IFACESDIR. * Fri Dec 21 2012 Mikhail Efremov <sem@altlinux> 0.8.9-alt1 alterator-openvpn-server - Alterator module for openvpn server configuration * Mon May 16 2016 Mikhail Efremov <sem@altlinux> 0.8.5-alt1 - Fix check for addresses range. * Tue Jan 20 2015 Mikhail Efremov <sem@altlinux> 0.8.4-alt1 - Add tmp-dir option to ovpnoptions. - Rename {,ETCNET_}IFACEDIR to {,ETCNET_}IFACESDIR. * Fri Dec 21 2012 Mikhail Efremov <sem@altlinux> 0.8.3-alt1 perl-Devel-CheckLib - check that a library is available * Sat May 21 2016 Nikolay A. Fetisov <naf@altlinux> 1.07-alt0.M70T.1 - Build for M70T * Sat May 21 2016 Nikolay A. Fetisov <naf@altlinux> 1.07-alt1 - New version * Sat Mar 19 2016 Nikolay A. Fetisov <naf@altlinux> 1.06-alt1 - New version * Mon Sep 28 2015 Nikolay A. Fetisov <naf@altlinux> 1.05-alt1 Note: changelog entry for 1.06-alt0.M70T.1 not found. postgresql9.1 - PostgreSQL client programs and libraries [10M] * Fri May 13 2016 Alexei Takaseev <taf@altlinux> 9.1.22-alt0.M70P.1 - 9.1.22 * Thu Mar 31 2016 Alexei Takaseev <taf@altlinux> 9.1.21-alt0.M70P.1 postgresql9.3 - PostgreSQL client programs and libraries [10M] * Fri May 13 2016 Alexei Takaseev <taf@altlinux> 9.3.13-alt0.M70P.1 - 9.3.13 * Thu Mar 31 2016 Alexei Takaseev <taf@altlinux> 9.3.12-alt0.M70P.1 postgresql9.4 - PostgreSQL client programs and libraries [11M] * Fri May 13 2016 Alexei Takaseev <taf@altlinux> 9.4.8-alt0.M70P.1 - 9.4.8 * Thu Mar 31 2016 Alexei Takaseev <taf@altlinux> 9.4.7-alt0.M70P.1 postgresql9.4-1C - PostgreSQL client programs and libraries (edition for 1C 8.3.3 and later) [11M] * Fri May 13 2016 Alexei Takaseev <taf@altlinux> 9.4.8-alt0.M70P.1 - 9.4.8 * Thu Mar 31 2016 Alexei Takaseev <taf@altlinux> 9.4.7-alt0.M70P.1 postgresql9.5 - PostgreSQL client programs and libraries [11M] * Fri May 13 2016 Alexei Takaseev <taf@altlinux> 9.5.3-alt0.M70P.1 - 9.5.3 * Thu Mar 31 2016 Alexei Takaseev <taf@altlinux> 9.5.2-alt0.M70P.1 zabbix - A network monitor * Thu May 19 2016 Alexei Takaseev <taf@altlinux> 1:3.0.3-alt0.M70P.1 - 3.0.3 * Thu Apr 21 2016 Alexei Takaseev <taf@altlinux> 1:3.0.2-alt0.M70P.1 Total 15273 source packages.
reply other threads:[~2016-05-22 4:45 UTC|newest] Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=20160522044545.GA24752@gyle.altlinux.org \ --to=qa@altlinux.org \ --cc=devel@lists.altlinux.org \ --cc=sisyphus-cybertalk@lists.altlinux.org \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
ALT Linux Sisyphus cybertalk This inbox may be cloned and mirrored by anyone: git clone --mirror http://lore.altlinux.org/sisyphus-cybertalk/0 sisyphus-cybertalk/git/0.git # If you have public-inbox 1.1+ installed, you may # initialize and index your mirror using the following commands: public-inbox-init -V2 sisyphus-cybertalk sisyphus-cybertalk/ http://lore.altlinux.org/sisyphus-cybertalk \ sisyphus-cybertalk@lists.altlinux.org sisyphus-cybertalk@lists.altlinux.ru sisyphus-cybertalk@lists.altlinux.com public-inbox-index sisyphus-cybertalk Example config snippet for mirrors. Newsgroup available over NNTP: nntp://lore.altlinux.org/org.altlinux.lists.sisyphus-cybertalk AGPL code for this site: git clone https://public-inbox.org/public-inbox.git