Update to 1.15.8 Fixes CVE-2024-32462. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-43ea98691e 2024-04-21 01:07:27.497020 -------------------------------------------------------------------------------- Name : flatpak Product : Fedora 40 Version : 1.15.8 Release : 1.fc40 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. -------------------------------------------------------------------------------- Update Information: Update to 1.15.8 Fixes CVE-2024-32462 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 19 2024 David King - 1.15.8-1 - Update to 1.15.8 (#2275983) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2271979 https://bugzilla.redhat.com/show_bug.cgi?id=2271979 [ 2 ] Bug #2275983 https://bugzilla.redhat.com/show_bug.cgi?id=2275983 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-43ea98691e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx) ---- Update to 1.10.6 Fixes these two security issues: * CVE-2021-43860 or *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8c64cb0992 2022-02-03 01:12:09.331919 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 34 Version : 1.10.7 Release : 1.fc34 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx) ---- Update to 1.10.6 Fixes these two security issues: * CVE-2021-43860 or * CVE-2022-21682 or Full release notes: --------------------------------------------------------------------------------ChangeLog: * Tue Jan 18 2022 Debarshi Ray - 1.10.7-1 - Update to 1.10.7 * Fri Jan 14 2022 Debarshi Ray - 1.10.6-1 - Update to 1.10.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1969591 - flatpak-builder-1.2.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1969591 [ 2 ] Bug #2041593 - CVE-2022-21682 flatpak: flatpak-builder --mirror-screenshots-url can access files outside the build directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2041593 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8c64cb0992' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7e328bd66c 2022-01-26 18:39:49.375589 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 35 Version : 1.12.4 Release : 1.fc35 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This is a regression fix update, reverting non-backwards-compatible behaviour changes in the solution previously chosen for [CVE-2022-21682](https://github.com/ m/flatpak/flatpak/security/advisories/GHSA-8ch7-5j3h-g4fx) --------------------------------------------------------------------------------ChangeLog: * Tue Jan 18 2022 Debarshi Ray - 1.12.4-1 - Update to 1.12.4 (#2042071) --------------------------------------------------------------------------------References: [ 1 ] Bug #1969591 - flatpak-builder-1.2.2 is available https://bugzilla.redhat.com/show_bug.cgi?id=1969591 [ 2 ] Bug #2041593 - CVE-2022-21682 flatpak: flatpak-builder --mirror-screenshots-url can access files outside the build directory [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2041593 [ 3 ] Bug #2042071 - flatpak-1.12.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=2042071 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2022-7e328bd66c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Several vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps. CVE-2021-43860 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5049-1
A Flatpak application could access files that it would not normally be permitted to access.. =========================================================================Ubuntu Security Notice USN-4951-1 May 12, 2021 flatpak vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: A Flatpak application could access files that it would not normally be permitted to access. Software Description: - flatpak: Application deployment framework for desktop apps Details: Anton Lydike discovered that Flatpak did not properly handle special tokens in desktop files. An attacker could use this to specially craft a Flatpak application that could escape sandbox confinement. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: flatpak 1.8.2-1ubuntu0.2 libflatpak0 1.8.2-1ubuntu0.2 Ubuntu 20.04 LTS: flatpak 1.6.5-0ubuntu0.3 libflatpak0 1.6.5-0ubuntu0.3 Ubuntu 18.04 LTS: flatpak 1.0.9-0ubuntu0.3 libflatpak0 1.0.9-0ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4951-1 CVE-2021-21381 Package Information: https://launchpad.net/ubuntu/+source/flatpak/1.8.2-1ubuntu0.2 https://launchpad.net/ubuntu/+source/flatpak/1.6.5-0ubuntu0.3 https://launchpad.net/ubuntu/+source/flatpak/1.0.9-0ubuntu0.3 . Security Alert USN-5002-2 addresses a Snap vulnerability permitting unauthorized data exposure on Linux distributions.. Flatpak Issue, Ubuntu Security, Application Access Risk, Update Instructions. . Severity: Critical. LinuxSecurity.com Team
Anton Lydike discovered that sandbox restrictions in Flatpak, an application deployment framework for desktop apps, could by bypassed via a malicious .desktop file. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4868-1
This updates flatpak from 1.8 to new 1.10 stable series. The major new feature in this series compared to 1.8 is the support for the new repo format which should make updates faster and download less data. For details what's new in 1.10, see https://github.com/flatpak/flatpak/releases/tag/1.10.0 This also includes a security update that fixes a sandbox escape where a malicious. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f970ea9d79 2021-01-16 01:32:44.205275 --------------------------------------------------------------------------------Name : flatpak Product : Fedora 33 Version : 1.10.0 Release : 1.fc33 URL : https://flatpak.org/ Summary : Application deployment framework for desktop apps Description : flatpak is a system for building, distributing and running sandboxed desktop applications on Linux. See https://wiki.gnome.org/Projects/SandboxedApps for more information. --------------------------------------------------------------------------------Update Information: This updates flatpak from 1.8 to new 1.10 stable series. The major new feature in this series compared to 1.8 is the support for the new repo format which should make updates faster and download less data. For details what's new in 1.10, see https://github.com/flatpak/flatpak/releases/tag/1.10.0 This also includes a security update that fixes a sandbox escape where a malicious application can execute code outside the sandbox by controlling the environment of the "flatpak run" command when spawning a sub-sandbox. See the advisory for details: https://github.com/flatpak/flatpak/security/advisories/GHSA-4ppf-fxf6-vxg2 --------------------------------------------------------------------------------ChangeLog: * Thu Jan 14 2021 Kalev Lember - 1.10.0-1 - Update to 1.10.0 - Use "Fedora Flatpaks" as the visible repo name --------------------------------------------------------------------------------Thisupdate can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f970ea9d79' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**horde 5.2.22** * [jan] SECURITY: Protect image processing service from rendering active SVG content within the browser. * [jan] SECURITY: Fix XSS vulnerabilities in administration interface. * [jan] Support Redis Sentinel configuration (Michael Menge , Request #14998). * [jan] Use file hashing for detecting outdated configuration files.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-6b8868fad9 2020-05-01 00:35:06.353146 --------------------------------------------------------------------------------Name : php-horde-horde Product : Fedora 32 Version : 5.2.22 Release : 1.fc32 URL : https://www.horde.org/apps/horde Summary : Horde Application Framework Description : The Horde Application Framework is a flexible, modular, general-purpose web application framework written in PHP. It provides an extensive array of components that are targeted at the common problems and tasks involved in developing modern web applications. It is the basis for a large number of production-level web applications, notably the Horde Groupware suites. For more information on Horde or the Horde Groupware suites, visit https://www.horde.org/ --------------------------------------------------------------------------------Update Information: **horde 5.2.22** * [jan] SECURITY: Protect image processing service from rendering active SVG content within the browser. * [jan] SECURITY: Fix XSS vulnerabilities in administration interface. * [jan] Support Redis Sentinel configuration (Michael Menge , Request #14998). * [jan] Use file hashing for detecting outdated configuration files. --------------------------------------------------------------------------------ChangeLog: * Tue Apr 21 2020 Remi Collet - 5.2.22-1 - update to 5.2.22 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2020-6b8868fad9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.