Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 32 FEDORA-2021-bdaf015218 Moderate: QtWebEngine Fix

fedora
Calendar Grey February 1, 2021
Dist Fedora Esm H88
This patch resolves several vulnerabilities found in QtWebEngine and kf5-messagelib for Fedora 32.
This update rebases QtWebEngine to the latest Qt 5 release, 5.15.2, fixing dozens of security issues

Summary

KDE Message libraries.

This update rebases QtWebEngine to the latest Qt 5 release, 5.15.2, fixing

dozens of security issues. (The same version is already shipped on Fedora 33 and

Rawhide.) The included kf5-messagelib update backports a fix for compatibility

with QtWebEngine 5.15.x. The Chromium version has been updated to

83.0.4103.122, with backported security fixes from Chromium up to version

86.0.4240.183. That fixes dozens of security issues compared to 5.14.2. This

version also adds the Qt PDF module, a Qt wrapper around PDFium. This is a

separate library and cannot cause backwards compatibility issues. In addition,

several bugs have been fixed, see the Changes files: *

https://code.qt.io/cgit/qt/qtwebengine.git/tree/dist/changes-5.15.0?h=5.15 *

https://code.qt.io/cgit/qt/qtwebengine.git/tree/dist/changes-5.15.1?h=5.15 *

https://code.qt.io/cgit/qt/qtwebengine.git/tree/dist/changes-5.15.2?h=5.15

Behavior Changes since 5.14.2: * XSS Auditing has been removed, and the

XSSAuditingEnabled setting no longer has any effect. * [QTBUG-79864] The viz

display compositor is now used by default on all platforms, but can be disabled

with --disable-viz-display-compositor. * The network layer integration has been

rewritten to use Chromium's network service, and now runs in a separate

sandboxed process by default. * [QTBUG-83656] CTRL+mouse wheel page zoom fixed,

and now works by default.

* Fri Jan 29 2021 Kevin Kofler - 19.12.2-2

- Backport fix for loading headers w/ QtWebEngine 5.15 from 20.04.2 (kde#422746)

- Add missing BuildRequires: cmake(Qca-qt5)

su -c 'dnf upgrade --advisory FEDORA-2021-bdaf015218' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 32
Version: 19.12.2
Release: 2.fc32
URL: Summary : KDE Message libraries

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here