Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

openSUSE: 2023:0096-1 Critical: Liferea Remote Code Execution

opensuse
Calendar Grey April 27, 2023
Dist Opensuse Esm H88
Important openSUSE Security Patch for liferea addresses a remote code execution vulnerability identified as CVE-2023-1350.
An update that solves one vulnerability and has one errata is now available

Description

liferea was updated to version 1.14.1:

+ Fix CVE-2023-1350 - Remote code execution on feed enrichment

(boo#1209190).

Update to version 1.14.0:

+ New 'Reader mode' preference that allows stripping all web content

+ Implement support for Webkits Intelligent Tracking Protection

+ New progress bar when loading websites

+ Youtube videos from media:video can be embedded now with a click on the

video preview picture.

+ Changes to UserAgent handling: same UA is now used for both feed

fetching and internal browsing.

+ New view mode 'Automatic' which switches between 'Normal' and 'Wide'

mode based on the window proportions.

+ Liferea now supports the new GTK dark theme logic, where in the

GTK/GNOME preferences you define wether you "prefer" dark mode or light

mode

+ Favicon discovery improvements: now detects all types of Apple Touch

Icons, MS Tile Images and Safari Mask Icons

+ Increase size of stored favicons to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-96=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

liferea-1.14.1-bp154.2.3.1

liferea-debuginfo-1.14.1-bp154.2.3.1

liferea-debugsource-1.14.1-bp154.2.3.1

- openSUSE Backports SLE-15-SP4 (noarch):

liferea-lang-1.14.1-bp154.2.3.1

References

https://www.suse.com/security/cve/CVE-2023-1350.html

https://bugzilla.suse.com/1193579

https://bugzilla.suse.com/1209190

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0096-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here