Update to freetype 2.10.4 which fixes security flaw CVE-2020-15999.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-768b1690f8 2020-10-25 01:01:06.523422 --------------------------------------------------------------------------------Name : freetype Product : Fedora 33 Version : 2.10.4 Release : 1.fc33 URL : https://freetype.org/ Summary : A free and portable font rendering engine Description : The FreeType engine is a free and portable font rendering engine, developed to provide advanced font support for a variety of platforms and environments. FreeType is a library which can open and manages font files as well as efficiently load, hint and render individual glyphs. FreeType is not a font server or a complete text-rendering library. --------------------------------------------------------------------------------Update Information: Update to freetype 2.10.4 which fixes security flaw CVE-2020-15999. --------------------------------------------------------------------------------ChangeLog: * Fri Oct 23 2020 Marek Kasik - 2.10.4-1 - Update to 2.10.4 - Test bitmap size earlier for PNGs - Fix memory leak in pngshim.c - Enable man pages for demos - Resolves: #1887084, #1890211 --------------------------------------------------------------------------------References: [ 1 ] Bug #1890210 - CVE-2020-15999 freetype: heap-based buffer overflow via malformed ttf files https://bugzilla.redhat.com/show_bug.cgi?id=1890210 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-768b1690f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project canbe found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The 5.7.15 stable kernel release contains a number of important fixes across the tree. ---- The 5.7.14 stable kernel update contains a number of important fixes across the tree. ---- The 5.7.12 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-2cd6393548 2020-08-18 01:22:46.800855 --------------------------------------------------------------------------------Name : kernel Product : Fedora 31 Version : 5.7.15 Release : 100.fc31 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: The 5.7.15 stable kernel release contains a number of important fixes across the tree. ---- The 5.7.14 stable kernel update contains a number of important fixes across the tree. ---- The 5.7.12 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Tue Aug 11 2020 Justin M. Forbes - 5.7.15-100 - Linux v5.7.15 * Fri Aug 7 2020 Justin M. Forbes - 5.7.14-100 - Linux v5.7.14 * Wed Aug 5 2020 Justin M. Forbes - 5.7.13-100 - Linux v5.7.13 - Fix CVE-2020-16166 (rhbz 1865751 1865752) * Sat Aug 1 2020 Justin M. Forbes - 5.7.12-100 - Linux v5.7.12 --------------------------------------------------------------------------------References: [ 1 ] Bug #1865751 - CVE-2020-16166 kernel: information exposure in drivers/char/random.c and kernel/time/timer.c https://bugzilla.redhat.com/show_bug.cgi?id=1865751 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-2cd6393548' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2015-9541. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-ca02c529f8 2020-04-25 02:14:03.394166 --------------------------------------------------------------------------------Name : qt5-qtbase Product : Fedora 32 Version : 5.13.2 Release : 5.fc32 URL : https://contribute.qt-project.org/ Summary : Qt5 - QtBase components Description : Qt is a software toolkit for developing applications. This package contains base tools, like string, xml, and network handling. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-9541 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 8 2020 Than Ngo - 5.13.2-5 - Fixed bz#1801370 - CVE-2015-9541 XML entity expansion vulnerability via a crafted SVG document --------------------------------------------------------------------------------References: [ 1 ] Bug #1801369 - CVE-2015-9541 qt: XML entity expansion vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1801369 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-ca02c529f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.