LWN.net Logo

Fedora alert FEDORA-2013-2789 (yum)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 17 Update: yum-3.4.3-31.fc17
Date:  Mon, 18 Mar 2013 02:26:29 +0000
Message-ID:  <20130318022629.27C6421403@bastion01.phx2.fedoraproject.org>
Archive-link:  Article, Thread

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-2789 2013-02-21 04:51:54 -------------------------------------------------------------------------------- Name : yum Product : Fedora 17 Version : 3.4.3 Release : 31.fc17 URL : http://yum.baseurl.org/ Summary : RPM package installer/updater/manager Description : Yum is a utility that can check for and automatically download and install updated RPM packages. Dependencies are obtained and downloaded automatically, prompting the user for permission as necessary. -------------------------------------------------------------------------------- Update Information: Fix a DOS attack (maybe more) by a bad Fedora mirror on repo. metadata. -------------------------------------------------------------------------------- ChangeLog: * Tue Feb 19 2013 James Antill <james at fedoraproject.org> - 3.4.3-32 - Fix non-removal of corrupt metadata files. BZ 908870. * Mon Jan 7 2013 Zdenek Pavlas <zpavlas at redhat.com> - 3.4.3-31 - ui_id: prevent TB on invalid repos with no URLs. BZ 870691. * Mon Nov 12 2012 Zdenek Pavlas <zpavlas at redhat.com> - 3.4.3-30 - update to HEAD as of Oct 16 2012 (just before --downloadonly and yum-cron changes) - Fixes BZ 832166, 826419, 854974, 858632, 856969, 861264, 864018, 864294, 864643, 864717, 864717, 859202. * Tue Aug 28 2012 Zdenek Pavlas <zpavlas at redhat.com> - 3.4.3-29 - update to latest HEAD. - new groups code - lots of bugfixes * Mon Jun 25 2012 Zdenek Pavlas <zpavlas at redhat.com> - 3.4.3-28 - update to latest HEAD. - No async downloading when --cacheonly. BZ 830523. - compare mtime without sub second precision. BZ 831918 - show_lock_owner: report errors if we fail. BZ 745281 - quote uids to keep cachedir ascii-clean. BZ 832195 - A solution to the obsoletes but don't provide problem. BZ 834530 - completion-helper: use the system cachedir * Fri Jun 8 2012 James Antill <james at fedoraproject.org> - 3.4.3-27 - update to latest HEAD. - Fix for ppc64p7 detection. * Thu Jun 7 2012 Zdenek Pavlas <zpavlas at redhat.com> - 3.4.3-26 - update to latest HEAD - more completion helper patches - parallel downloading of packages and metadata - revert a hack that probably caused BZ 829505 * Thu May 31 2012 Zdenek Pavlas <zpavlas at redhat.com> - 3.4.3-25 - backported completion-helper.py patches from HEAD, BZ 809469. * Fri Apr 27 2012 James Antill <james at fedoraproject.org> - 3.4.3-24 - Add code for arm detection. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update yum' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds