Bug 1368412

Summary: borgbackup 1.0.7 is available (contains important security fix)
Product: [Fedora] Fedora Reporter: Felix Schwarz <fschwarz>
Component: borgbackupAssignee: Persona non grata <nobody+366555>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 24CC: fschwarz, nobody+366555
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: borgbackup-1.0.7-1.fc25 borgbackup-1.0.7-1.fc24 borgbackup-1.0.7-1.fc23 borgbackup-1.0.7-1.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-08-29 08:05:49 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Felix Schwarz 2016-08-19 10:16:34 UTC
Current versions of borgbackup contain a security flaw which is fixed in 1.0.7. Currently this is a binary only release (https://github.com/borgbackup/borg/releases/tag/1.0.7bin) to give borg admins a bit of a head start but the full source release is supposed to be released later today.

This ticket is meant as a heads up so we can get the fix into Fedora as soon as possible.

Comment 1 Felix Schwarz 2016-08-20 20:27:35 UTC
borgbackup 1.0.7 is now available: https://pypi.python.org/pypi/borgbackup/1.0.7

More details about the security issue can be found in the changelog:
https://borgbackup.readthedocs.io/en/stable/changes.html#version-1-0-7-2016-08-19

Comment 2 Fedora Update System 2016-08-21 07:32:06 UTC
borgbackup-1.0.7-1.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-f0e09b5124

Comment 3 Fedora Update System 2016-08-21 07:32:12 UTC
borgbackup-1.0.7-1.el7 has been submitted as an update to Fedora EPEL 7. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-f0e09b5124

Comment 4 Fedora Update System 2016-08-21 13:50:36 UTC
borgbackup-1.0.7-1.fc24 has been submitted as an update to Fedora 24. https://bodhi.fedoraproject.org/updates/FEDORA-2016-20014bf2bd

Comment 5 Fedora Update System 2016-08-21 13:51:23 UTC
borgbackup-1.0.7-1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-4820585b11

Comment 6 Fedora Update System 2016-08-21 13:52:02 UTC
borgbackup-1.0.7-1.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2016-f734302c3f

Comment 7 Fedora Update System 2016-08-21 19:52:05 UTC
borgbackup-1.0.7-1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-4820585b11

Comment 8 Fedora Update System 2016-08-21 20:16:59 UTC
borgbackup-1.0.7-1.el7 has been pushed to the Fedora EPEL 7 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-f0e09b5124

Comment 9 Fedora Update System 2016-08-21 20:51:24 UTC
borgbackup-1.0.7-1.fc24 has been pushed to the Fedora 24 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-20014bf2bd

Comment 10 Fedora Update System 2016-08-21 20:52:47 UTC
borgbackup-1.0.7-1.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-f734302c3f

Comment 11 Fedora Update System 2016-08-29 08:05:46 UTC
borgbackup-1.0.7-1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2016-08-29 18:53:16 UTC
borgbackup-1.0.7-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2016-08-29 21:21:22 UTC
borgbackup-1.0.7-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 14 Fedora Update System 2016-09-09 16:50:44 UTC
borgbackup-1.0.7-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.