It appears at a quick glance that both entries marking freetype-1.5 vulnerable are typo's that should refer to freetype2 instead... freetype-lib-1.5 which is included by the freetype-1.5 metapackage has never been marked vulnerable. As for gdb6, the patch is here: https://bugzilla.redhat.com/show_bug.cgi?id=204841 I don't know if I can do anything about it before the freeze ends... family obligations popped up for today... not sure how long they will take. - Tim