Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 40: FEDORA-2024-47dbf2a4de Critical: obs-cef Heap Overflow

fedora
Calendar Grey August 1, 2024
Dist Fedora Esm H88
Important security patch released for Fedora 40 tackling CVE-2023-6349 along with FTBFS remedies for obs-cef.
Security fix for CVE-2023-6349 & FTBFS fixes

Summary

CEF is an embeddable build of Chromium, powered by WebKit (Blink).

This version is a fork by the OBS project designed to be used as

part of the OBS Browser Source plugin.

Update Information:

Security fix for CVE-2023-6349 & FTBFS fixes

Change Log

* Wed Jul 31 2024 Asahi Lina - 5060^cr103.0.5060.134~git20231010.17f8588-6 - Fix CVE-2023-6349 & FTBFS on f40/rawhide * Thu Jul 18 2024 Fedora Release Engineering - 5060^cr103.0.5060.134~git20231010.17f8588-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Thu Jan 25 2024 Fedora Release Engineering - 5060^cr103.0.5060.134~git20231010.17f8588-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Sun Jan 21 2024 Fedora Release Engineering - 5060^cr103.0.5060.134~git20231010.17f8588-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

References


[ 1 ] Bug #2283553 - CVE-2023-6349 libvpx: Heap buffer overflow related to VP9 encoding https://bugzilla.redhat.com/show_bug.cgi?id=2283553

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-47dbf2a4de' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: obs-cef
Product: Fedora 40
Version: 5060^cr103.0.5060.134~git20231010.17f8588
Release: 6.fc40
Summary: OBS fork of the Chromium Embedded Framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here