[cyber] I: Sisyphus-20210128 packages: +2! -2 +26 (17789)

QA Team Robot qa на altlinux.org
Чт Янв 28 03:15:24 MSK 2021


	2 ADDED packages

python3-module-aiokafka - asyncio client for kafka
* Wed Jan 27 2021 Grigory Ustinov <grenka на altlinux> 0.7.0-alt1
- Build new version for python3 only.
* Sat Jun 01 2019 Vitaly Lipatov <lav на altlinux> 0.5.1-alt1

python3-module-parted - Python bindings for libparted
* Wed Jan 27 2021 Grigory Ustinov <grenka на altlinux> 3.11.7-alt1
- Automatically updated to 3.11.7.
- Drop python2 support.
* Thu Mar 22 2018 Aleksei Nikiforov <darktemplar на altlinux> 3.11.1-alt1.1

	2 REMOVED packages

python-module-aiokafka	0.5.1-alt1
python-module-parted	3.11.1-alt1.1

	26 UPDATED packages

aqemu - QEMU GUI written in Qt5
* Wed Jan 27 2021 Leontiy Volodin <lvol на altlinux> 1:0.9.4-alt1
- 0.9.4 version (more stable).
* Fri Jan 15 2021 Leontiy Volodin <lvol на altlinux> 0.9.6-alt0.1.git34ca8ce

atf-rockchip - ARM Trusted Firmware
* Tue Jan 26 2021 Sergey Bolshakov <sbolshakov на altlinux> 2.4-alt1
- 2.4 released
* Thu Jul 02 2020 Sergey Bolshakov <sbolshakov на altlinux> 2.3-alt1

atf-sunxi - ARM Trusted Firmware
* Tue Jan 26 2021 Sergey Bolshakov <sbolshakov на altlinux> 2.4-alt1
- 2.4 released
* Thu Jul 02 2020 Sergey Bolshakov <sbolshakov на altlinux> 2.3-alt1

blender - 3D modeling, animation, rendering and post-production 	[42M]
* Wed Jan 27 2021 Aleksei Nikiforov <darktemplar на altlinux> 2.91.2-alt2
- Updated runtime dependencies.
* Fri Jan 22 2021 Aleksei Nikiforov <darktemplar на altlinux> 2.91.2-alt1

ca-certificates - Common CA :Certificates
* Wed Jan 27 2021 Alexey Gladkov <legion на altlinux> 2021.01.27-alt1
- mozilla: sync with nss-3.61.
* Thu Oct 22 2020 Alexey Gladkov <legion на altlinux> 2020.10.22-alt1

firefox - The Mozilla Firefox project is a redesign of Mozilla's browser	[380M]
* Tue Jan 26 2021 Alexey Gladkov <legion на altlinux> 85.0-alt1
- New release (85.0).
- Security fixes:
  + CVE-2021-23953: Cross-origin information leakage via redirected PDF requests
  + CVE-2021-23954: Type confusion when using logical assignment operators in JavaScript switch statements
  + CVE-2021-23955: Clickjacking across tabs through misusing requestPointerLock
  + CVE-2021-23956: File picker dialog could have been used to disclose a complete directory
  + CVE-2021-23957: Iframe sandbox could have been bypassed on Android via the intent URL scheme
  + CVE-2021-23958: Screen sharing permission leaked across tabs
  + CVE-2021-23959: Cross-Site Scripting in error pages on Firefox for Android
  + CVE-2021-23960: Use-after-poison for incorrectly redeclared JavaScript variables during GC
  + CVE-2021-23961: More internal network hosts could have been probed by a malicious webpage
  + CVE-2021-23962: Use-after-poison in <code>nsTreeBodyFrame::RowCountChanged</code>
  + CVE-2021-23963: Permission prompt inaccessible after asking for additional permissions
  + CVE-2021-23964: Memory safety bugs fixed in Firefox 85 and Firefox ESR 78.7
  + CVE-2021-23965: Memory safety bugs fixed in Firefox 85
* Wed Jan 06 2021 Alexey Gladkov <legion на altlinux> 84.0.2-alt1

libbytesize - A library for working with sizes in bytes
* Wed Jan 27 2021 Yuri N. Sedunov <aris на altlinux> 2.5-alt1
- 2.5
* Sat Aug 01 2020 Yuri N. Sedunov <aris на altlinux> 2.4-alt1

libofx - The OFX parser library
* Wed Jan 27 2021 Andrey Cherepanov <cas на altlinux> 0.10.1-alt1
- New version.
- Mention previous CVE.
* Mon Jan 04 2021 Andrey Cherepanov <cas на altlinux> 0.10.0-alt1

libsigrokdecode - sigrok -- signal analysis software suite
* Wed Jan 27 2021 Grigory Ustinov <grenka на altlinux> 0.5.3-alt2
- Add patch for building with python3.9.
* Thu Feb 06 2020 Grigory Ustinov <grenka на altlinux> 0.5.3-alt1

libxml2 - The library for manipulating XML files
* Wed Jan 27 2021 Grigory Ustinov <grenka на altlinux> 1:2.9.10-alt5
- Add patch for python3.9 support.
* Fri Nov 06 2020 Aleksei Nikiforov <darktemplar на altlinux> 1:2.9.10-alt4

mount-tray - udisks based removable device mounter
* Wed Jan 27 2021 Dmitriy Khanzhin <jinn на altlinux> 1.2.5-alt7
- Use tray icon in png format (ALT #39566)
- Restore patch
- Remove [Build]Requires no longer needed
* Thu Jan 07 2021 Dmitriy Khanzhin <jinn на altlinux> 1.2.5-alt6

nagios - Services and network monitoring system
* Wed Jan 27 2021 Paul Wolneykien <manowar на altlinux> 3.0.6-alt15
- Fixes:
  + CVE-2017-12847 Kill arbitrary processes by leveraging access to PID file.
- Don't install the PID file.
* Wed Jan 27 2021 Paul Wolneykien <manowar на altlinux> 3.0.6-alt14
- Fixes:
  + CVE-2016-8641 Privilege escalation via symbolic links.
  + CVE-2016-9566 Gaining root privileges via a symlink attack on the log file.
  + CVE-2014-1878 Possible segfault in cmd.cgi.
* Wed May 13 2020 Paul Wolneykien <manowar на altlinux> 3.0.6-alt13

nss - Netscape Network Security Services(NSS)                   	[60M]
* Wed Jan 27 2021 Alexey Gladkov <legion на altlinux> 3.61.0-alt1
- New version (3.61).
- Certificate Authority Changes:
  + Add CN=NAVER Global Root Certification Authority
  + Remove CN=GeoTrust Global CA
  + Remove CN=GeoTrust Primary Certification Authority
  + Remove CN=GeoTrust Primary Certification Authority - G3
  + Remove CN=GeoTrust Universal CA
  + Remove CN=GeoTrust Universal CA 2
  + Remove CN=VeriSign Class 3 Public Primary Certification Authority - G4
  + Remove CN=VeriSign Class 3 Public Primary Certification Authority - G5
  + Remove CN=thawte Primary Root CA
  + Remove CN=thawte Primary Root CA - G2
  + Remove CN=thawte Primary Root CA - G3
* Sat Dec 26 2020 Alexey Gladkov <legion на altlinux> 3.59.1-alt1

openqa - OS-level automated testing framework
* Fri Jan 22 2021 Alexandr Antonov <aas на altlinux> 4.5.1528009330.e68ebe2b-alt18
- update to current version
* Tue Dec 08 2020 Alexandr Antonov <aas на altlinux> 4.5.1528009330.e68ebe2b-alt17

os-autoinst - OS-level test automation                          	[20M]
* Fri Jan 22 2021 Alexandr Antonov <aas на altlinux> 4.5.1527308405.8b586d5-alt18
- update to current version
* Wed Dec 02 2020 Alexandr Antonov <aas на altlinux> 4.5.1527308405.8b586d5-alt17

perl-Source-Repository-Mass - Source-Repository-Mass - Perl extension for converting SRPM and spec files
* Wed Jan 27 2021 Igor Vlasenko <viy на altlinux> 0.438-alt1
- new version
* Sat Jan 16 2021 Igor Vlasenko <viy на altlinux> 0.437-alt1

restic - Fast, secure, efficient backup program                 	[13M]
* Sun Nov 08 2020 Mikhail Gordeev <obirvalger на altlinux> 0.11.0-alt1
- Update to v0.11.0.
* Sun Mar 15 2020 Vitaly Chikunov <vt на altlinux> 0.9.6-alt1

sudo - Allows command execution as another user
* Wed Jan 27 2021 Evgeny Sinelnikov <sin на altlinux> 1:1.9.5p2-alt1
- Update to latest security release (fixes: CVE-2021-3156) (closes: 39615)
- Added sudo-python package with Sudo Python Plugin API
- Added sudo-logsrvd package with High-performance log server
* Fri Nov 13 2020 Evgeny Sinelnikov <sin на altlinux> 1:1.9.3p1-alt1
- Update to latest release
- Enable python policy support
* Sun Aug 30 2020 Evgeny Sinelnikov <sin на altlinux> 1:1.9.2-alt1
- Update to latest release of the sudo 1.9 (Fixes: CVE-2019-19232, CVE-2019-19234)
- Added sudo event and I/O log server
- Added send sudo I/O log to log server utility
- Added selinux support
- Added native audit support
* Sun Aug 30 2020 Evgeny Sinelnikov <sin на altlinux> 1:1.8.31p2-alt1

telepathy-glib - Telepathy framework - GLib connection manager library
* Wed Jan 27 2021 Yuri N. Sedunov <aris на altlinux> 0.24.2-alt1
- 0.24.2
- enabled %check, gtk-doc
- fixed License tag
* Fri Apr 05 2019 Yuri N. Sedunov <aris на altlinux> 0.24.1-alt3.2

thunderbird - Thunderbird is Mozilla's e-mail client            	[367M]
* Wed Jan 27 2021 Andrey Cherepanov <cas на altlinux> 78.7.0-alt1
- New version (78.7.0).
- Security fixes:
  + CVE-2021-23953 Cross-origin information leakage via redirected PDF requests
  + CVE-2021-23954 Type confusion when using logical assignment operators in JavaScript switch statements
  + CVE-2020-15685 IMAP Response Injection when using STARTTLS
  + CVE-2020-26976 HTTPS pages could have been intercepted by a registered service worker when they should not have been
  + CVE-2021-23960 Use-after-poison for incorrectly redeclared JavaScript variables during GC
  + CVE-2021-23964 Memory safety bugs fixed in Thunderbird 78.7
* Tue Jan 12 2021 Andrey Cherepanov <cas на altlinux> 78.6.1-alt1

u-boot-meson - Das U-Boot                                       	[14M]
* Wed Jan 27 2021 Sergey Bolshakov <sbolshakov на altlinux> 2021.01-alt1
- 2021.01 released
* Tue Oct 06 2020 Sergey Bolshakov <sbolshakov на altlinux> 2020.10-alt1

u-boot-qemu - Das U-Boot                                        	[14M]
* Tue Jan 26 2021 Sergey Bolshakov <sbolshakov на altlinux> 2021.01-alt1
- 2021.01 released
* Tue Oct 06 2020 Sergey Bolshakov <sbolshakov на altlinux> 2020.10-alt1

u-boot-rockchip - Das U-Boot                                    	[14M]
* Wed Jan 27 2021 Sergey Bolshakov <sbolshakov на altlinux> 2021.01-alt1
- 2021.01 released
* Tue Oct 06 2020 Sergey Bolshakov <sbolshakov на altlinux> 2020.10-alt1

u-boot-rpi3 - Das U-Boot                                        	[14M]
* Wed Jan 27 2021 Sergey Bolshakov <sbolshakov на altlinux> 2021.01-alt1
- 2021.01 released
* Tue Oct 06 2020 Sergey Bolshakov <sbolshakov на altlinux> 2020.10-alt1

u-boot-sunxi - Das U-Boot                                       	[14M]
* Wed Jan 27 2021 Sergey Bolshakov <sbolshakov на altlinux> 2021.01-alt1
- 2021.01 released
* Tue Oct 06 2020 Sergey Bolshakov <sbolshakov на altlinux> 2020.10-alt1

xfce4-panel - Panel for Xfce
* Wed Jan 27 2021 Mikhail Efremov <sem на altlinux> 4.16.1-alt1
- Updated to 4.16.1.
* Wed Dec 23 2020 Mikhail Efremov <sem на altlinux> 4.16.0-alt1

Total 17789 source packages.


Подробная информация о списке рассылки Sisyphus-cybertalk