Qt 6.9.1 bugfix release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-c546fd3f09 2025-06-11 02:45:06.590648+00:00 -------------------------------------------------------------------------------- Name : nheko Product : Fedora 42 Version : 0.12.0 Release : 15.fc42 URL : https://github.com/Nheko-Reborn/nheko Summary : Desktop client for the Matrix protocol Description : The motivation behind the project is to provide a native desktop app for Matrix that feels more like a mainstream chat app. -------------------------------------------------------------------------------- Update Information: Qt 6.9.1 bugfix release. -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 6 2025 Jan Grulich - 0.12.0-15 - Rebuild (qt6) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2369872 - CVE-2025-5455 qt6: QtCore Assertion Failure Denial of Service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2369872 [ 2 ] Bug #2371133 - CVE-2025-5683 qt5: Qt ICNS Image Crash Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2371133 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-c546fd3f09' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 . MGASA-2019-0378 - Updated kdelibs4 packages fix security vulnerability Publication date: 13 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0378.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14744 kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction (CVE-2019-14744). References: - https://bugs.mageia.org/show_bug.cgi?id=25403 - https://kde.org/info/security/advisory-20190807-1.txt - https://access.redhat.com/errata/RHSA-2019:2606 - https://www.cve.org/CVERecord?id=CVE-2019-14744 SRPMS: - 7/core/kdelibs4-4.14.38-7.1.mga7 . Mageia releases kdelibs4 update to address a security vulnerability that permits limited user interaction for executing code. Read on for more information.. kdelibs Security Advisory, Mageia Update, Malicious Files Execution, Desktop Application Vulnerability. . LinuxSecurity.com Team
A vulnerability in Tomboy could result in privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201401-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Tomboy: Privilege escalation Date: January 26, 2014 Bugs: #356583 ID: 201401-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Tomboy could result in privilege escalation. Background ========= Tomboy is a desktop note-taking application. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-misc/tomboy < 1.4.2-r1 > = 1.4.2-r1 Description ========== Tomboy places a zero-length directory name in the LD_LIBRARY_PATH, which might result in the current working directory (.) to be included when searching for dynamically linked libraries. NOTE: This vulnerability exists due to an incomplete fix for CVE-2005-4790 (GLSA 200711-12). Impact ===== A local attacker could gain escalated privileges via a specially crafted shared library. Workaround ========= There is no known workaround at this time. Resolution ========= All Tomboy users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-misc/tomboy-1.4.2-r1" NOTE: This is a legacy GLSA. Updates for all affected architectures are available since March 02, 2011. It is likely that your system is already no longer affected by this issue. References ========= [ 1 ] CVE-2010-4005 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4005 [ 2 ] GLSA 200711-12 https://security.gentoo.org/glsa/200711-12 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201401-28 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
rebuild against pilot-link-0.11.8. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-375 2006-04-18 ---------------------------------------------------------------------Product : Fedora Core 4 Name : jpilot Version : 0.99.8 Release : 0.pre10.fc4.2 Summary : Jpilot pilot desktop software Description : J-Pilot is a desktop organizer application for the palm pilot that runs under Linux. It is similar in functionality to the one that 3com distributes for a well known rampant legacy operating system. ---------------------------------------------------------------------Update Information: rebuild against pilot-link-0.11.8 ---------------------------------------------------------------------* Mon Apr 3 2006 Ivana Varekova 0.99.8-0.pre10.fc4.2 - rebuild against pilot-link-0.11.8 ---------------------------------------------------------------------This update can be downloaded from: 6725ec4bb0fed74f3785a51443e8ab8355cf8b23 SRPMS/jpilot-0.99.8-0.pre10.fc4.2.src.rpm 92077c236a1c859b73adedfa7757edc23118e507 ppc/jpilot-0.99.8-0.pre10.fc4.2.ppc.rpm 1958ffff23215bd74933fd86eb8ccd26ea763516 ppc/debug/jpilot-debuginfo-0.99.8-0.pre10.fc4.2.ppc.rpm 7ec578b841af4bf93bbf76a8b29a7ebab9fedef1 x86_64/jpilot-0.99.8-0.pre10.fc4.2.x86_64.rpm d4d4f5159311277cff0065a66d1a9e2d37f33d91 x86_64/debug/jpilot-debuginfo-0.99.8-0.pre10.fc4.2.x86_64.rpm e070937141b87fcdb7bd98654f9636dd186f6588 i386/jpilot-0.99.8-0.pre10.fc4.2.i386.rpm 85dfa1567e0a5cf810a6c25b1c9c6cc1c08e3373 i386/debug/jpilot-debuginfo-0.99.8-0.pre10.fc4.2.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
This is new upstream version which is compatible with new fc4 pilot-link version.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-422 2005-06-21 ---------------------------------------------------------------------Product : Fedora Core 4 Name : jpilot Version : 0.99.8 Release : 0.pre9.fc4.1 Summary : Jpilot pilot desktop software Description : J-Pilot is a desktop organizer application for the palm pilot that runs under Linux. It is similar in functionality to the one that 3com distributes for a well known rampant legacy operating system. ---------------------------------------------------------------------Update Information: This is new upstream version which is compatible with new fc4 pilot-link version. ---------------------------------------------------------------------* Thu Jun 9 2005 Ivana Varekova 0.99.8-0.pre9.1 - rebuilt new version * Fri May 6 2005 Ivana Varekova 0.99.8-0.pre8.5 - fix typo (bug 157007) ---------------------------------------------------------------------This update can be downloaded from: e2e47c58cf772eca73ac9b2fc6e49ec9 SRPMS/jpilot-0.99.8-0.pre9.fc4.1.src.rpm 7321e1bf3d0235258120b340d6cd24c0 ppc/jpilot-0.99.8-0.pre9.fc4.1.ppc.rpm 8b1c1fefb0fbc289bb0d3eaf3a8b79d8 ppc/debug/jpilot-debuginfo-0.99.8-0.pre9.fc4.1.ppc.rpm a11a4053ff81f90a2b979506f2eb7e33 x86_64/jpilot-0.99.8-0.pre9.fc4.1.x86_64.rpm eb8f678e258649e2eb3ce09431ff35c9 x86_64/debug/jpilot-debuginfo-0.99.8-0.pre9.fc4.1.x86_64.rpm 743522ae429bc22d7ad68d521a760de6 i386/jpilot-0.99.8-0.pre9.fc4.1.i386.rpm 1609e9ba387a1f5e4d3d11424da9a373 i386/debug/jpilot-debuginfo-0.99.8-0.pre9.fc4.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list
KDE 3.3.1 update. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-384 2004-11-08 --------------------------------------------------------------------- Product : Fedora Core 3 Name : kdetoys Version : 3.3.1 Release : 1 Summary : K Desktop Environment - Toys and Amusements Description : Toys for the K Desktop Environment. Includes: kmoon (displays various phases of the moon); kworldwatch (displays where in the world it is light and dark depending on time), and kodo (a mouse odometer which shows how far your mouse has traveled). --------------------------------------------------------------------- Update Information: KDE 3.3.1 update --------------------------------------------------------------------- * Wed Oct 13 2004 Than Ngo 7:3.3.1-1 - update to 3.3.1 --------------------------------------------------------------------- This update can be downloaded from: f02ad0fd1faea60863f9b7679ae306d8 SRPMS/kdetoys-3.3.1-1.src.rpm 374524a68d342ddb383e2d8af8896591 x86_64/kdetoys-3.3.1-1.x86_64.rpm 62b9d7363446dd787362f242db14d200 x86_64/debug/kdetoys-debuginfo-3.3.1-1.x86_64.rpm c8519c29135232d7fb6d01dbea89ddf7 i386/kdetoys-3.3.1-1.i386.rpm b755b9cea84c2936d6f88cd7a9483e5c i386/debug/kdetoys-debuginfo-3.3.1-1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . The KDE 3.3.1 enhancement for Fedora Core 3 offers playful and entertainment features to enhance the user interface.. kdetoys update,Fedora Core 3,KDE 3.3.1,desktop environment,software installation. . Severity: Informational. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.