Update to 2.34.4: * Fix dire ["Safari Leaks"](https://safarileaks.com/) IndexedDB privacy violation. * Make audio tools (like mixers) display the actual name of the application producing sound, instead of a generic one. * Fix several crashes and rendering issues. * Additional security fixes: CVE-2021-30887, CVE-2021-30890, CVE-2021-30934, CVE-2021-30936, CVE-2021-30951,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-25a98f5d55 2022-01-23 01:41:29.500049 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 35 Version : 2.34.4 Release : 2.fc35 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to 2.34.4: * Fix dire ["Safari Leaks"](https://safarileaks.com/) IndexedDB privacy violation. * Make audio tools (like mixers) display the actual name of the application producing sound, instead of a generic one. * Fix several crashes and rendering issues. * Additional security fixes: CVE-2021-30887, CVE-2021-30890, CVE-2021-30934, CVE-2021-30936, CVE-2021-30951, CVE-2021-30952, CVE-2021-30953, CVE-2021-30954, CVE-2021-30984 --------------------------------------------------------------------------------ChangeLog: * Fri Jan 21 2022 Michael Catanzaro 2.34.4-2 - Add missing BuildRequires for wayland-protocols * Fri Jan 21 2022 Michael Catanzaro 2.34.4-1 - Update to WebKitGTK 2.34.4 * Wed Nov 24 2021 Michael Catanzaro 2.34.2-1 - Upgrade to 2.34.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2034381 - CVE-2021-30887 webkitgtk: Logic issue leading to Content Security Policybypass https://bugzilla.redhat.com/show_bug.cgi?id=2034381 [ 2 ] Bug #2034389 - CVE-2021-30890 webkitgtk: Logic issue leading to universal cross-site scripting https://bugzilla.redhat.com/show_bug.cgi?id=2034389 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-25a98f5d55' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- oggenc: fix large alloca on bad AIFF input (CVE-2015-6749). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14663 2015-09-16 18:49:29.742453 -------------------------------------------------------------------------------- Name : vorbis-tools Product : Fedora 22 Version : 1.4.0 Release : 20.fc22 URL : https://www.xiph.org/ Summary : The Vorbis General Audio Compression Codec tools Description : Ogg Vorbis is a fully open, non-proprietary, patent- and royalty-free, general-purpose compressed audio format for audio and music at fixed and variable bitrates from 16 to 128 kbps/channel. The vorbis package contains an encoder, a decoder, a playback tool, and a comment editor. -------------------------------------------------------------------------------- Update Information: - oggenc: fix large alloca on bad AIFF input (CVE-2015-6749) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1258424 - vorbis-tools: Bufer overflow in aiff_open function https://bugzilla.redhat.com/show_bug.cgi?id=1258424 [ 2 ] Bug #1258443 - CVE-2015-6749 vorbis-tools: invalid AIFF file causes alloca() buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1258443 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update vorbis-tools' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-284 2006-04-06 ---------------------------------------------------------------------Product : Fedora Core 5 Name : alsa-utils Version : 1.0.11 Release : 4.rc2 Summary : Advanced Linux Sound Architecture (ALSA) utilities Description : This package contains command line utilities for the Advanced Linux Sound Architecture (ALSA). ---------------------------------------------------------------------* Thu Apr 6 2006 Martin Stransky 1.0.11-4.rc2 - disabled "Audigy Analog/Digital Output Jack" switch for emu10k1 driver (#187807) ---------------------------------------------------------------------This update can be downloaded from: bcdbc7c978fc03e17c04376d67b81e554314655b SRPMS/alsa-utils-1.0.11-4.rc2.src.rpm ba9f28da4c04efc61d58bb3bbc8230af7a499997 ppc/alsa-utils-1.0.11-4.rc2.ppc.rpm 2093d8d4dd9636105a8ab432449e80951e259c1a ppc/debug/alsa-utils-debuginfo-1.0.11-4.rc2.ppc.rpm d68bc91ceaa6de2fb7a9b44dc90cce40cb984545 x86_64/alsa-utils-1.0.11-4.rc2.x86_64.rpm 935f9d1921c32b22f9d2224118dd1c9dce9e40af x86_64/debug/alsa-utils-debuginfo-1.0.11-4.rc2.x86_64.rpm 709ae2202d79ba316c327b43334d2bce97a78f9c i386/alsa-utils-1.0.11-4.rc2.i386.rpm 1bb2247ea678fdf40bf44df88e0d1b5d3db8139b i386/debug/alsa-utils-debuginfo-1.0.11-4.rc2.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.