An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for enlightenment ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10153-1 Rating: important References: #1203631 Cross-References: CVE-2022-37706 Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for enlightenment fixes the following issues: Update to 0.25.4 Bugfix release * Fix shape handling in various cases that affected apps with shaped input * Fix procstats popup and dangling icon for fullscreen windows * Fix a vianishing pointer in some cases * Workaround Qt issue where it does not remove WM_STATE on withdraw * Fix fullscreen focus toggle flicker * Fix pointer sticking case * Fix tap-to-click props * Fix gadgcon disabled items * Fix config fallback handling that means no fallback happened * Fix gtk frame prop handling * Fix first map handling that affected energyxt * Fix CVE-2022-37706 (boo#1203631) * Harden enlightenment_sys when mis-packaged without sysactions.conf Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10153=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64): enlightenment-0.25.4-bp154.4.3.1 enlightenment-branding-upstream-0.25.4-bp154.4.3.1 enlightenment-devel-0.25.4-bp154.4.3.1 References: https://www.suse.com/security/cve/CVE-2022-37706.html https://bugzilla.suse.com/1203631 . Update released for openSUSE's Enlightenment, resolving CVE-2022-37706 withcritical patches.. openSUSE Security, Enlightenment Update, Important Patch. . Severity: Important. LinuxSecurity.com Team
Updated enlightenment package to fix the security vulnerability, CVE-2022-37706 that would allow an user to gain root privileges. References: - https://bugs.mageia.org/show_bug.cgi?id=30868 . MGASA-2022-0360 - Updated enlightenment packages fix security vulnerability Publication date: 08 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0360.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-37706 Updated enlightenment package to fix the security vulnerability, CVE-2022-37706 that would allow an user to gain root privileges. References: - https://bugs.mageia.org/show_bug.cgi?id=30868 - https://github.com/MaherAzzouzi/CVE-2022-37706-LPE-exploit - - https://www.cve.org/CVERecord?id=CVE-2022-37706 SRPMS: - 8/core/enlightenment-0.24.2-2.1.mga8 . Revised security bundles tackle CVE-2023-45678, rectifying a privilege escalation flaw in Arch Linux unveiled on 15 Sep 2023.. Mageia Security Advisory, Enlightenment Update, Root Access Fix. . Severity: Important. LinuxSecurity.com Team
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-0cc77b384a 2022-10-03 01:12:44.127165 --------------------------------------------------------------------------------Name : enlightenment Product : Fedora 36 Version : 0.25.4 Release : 1.fc36 URL : https://www.enlightenment.org/ Summary : Enlightenment window manager Description : Enlightenment window manager is a lean, fast, modular and very extensible window manager for X11 and Linux. It is classed as a "desktop shell" providing the things you need to operate your desktop (or laptop), but is not a whole ' application suite. This covered launching applications, managing their windows and doing other system tasks like suspending, reboots, managing files etc. --------------------------------------------------------------------------------Update Information: Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706 --------------------------------------------------------------------------------ChangeLog: * Sat Sep 24 2022 Tom Callaway - 0.25.4-1 - update to 0.25.4 * Thu Jul 21 2022 Fedora Release Engineering - 0.25.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2128741 - CVE-2022-37706 enlightenment: elevate privileges to root. https://bugzilla.redhat.com/show_bug.cgi?id=2128741 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-0cc77b384a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bafb72fdc0 2022-10-03 00:51:18.460384 --------------------------------------------------------------------------------Name : enlightenment Product : Fedora 35 Version : 0.25.4 Release : 1.fc35 URL : https://www.enlightenment.org/ Summary : Enlightenment window manager Description : Enlightenment window manager is a lean, fast, modular and very extensible window manager for X11 and Linux. It is classed as a "desktop shell" providing the things you need to operate your desktop (or laptop), but is not a whole ' application suite. This covered launching applications, managing their windows and doing other system tasks like suspending, reboots, managing files etc. --------------------------------------------------------------------------------Update Information: Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706 --------------------------------------------------------------------------------ChangeLog: * Sat Sep 24 2022 Tom Callaway - 0.25.4-1 - update to 0.25.4 * Thu Jul 21 2022 Fedora Release Engineering - 0.25.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Thu Jan 20 2022 Fedora Release Engineering - 0.25.1-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2128741 - CVE-2022-37706 enlightenment: elevate privileges to root. https://bugzilla.redhat.com/show_bug.cgi?id=2128741 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-bafb72fdc0' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7090749bf4 2022-10-03 00:17:00.182937 --------------------------------------------------------------------------------Name : efl Product : Fedora 37 Version : 1.26.3 Release : 1.fc37 URL : Summary : Collection of Enlightenment libraries Description : EFL is a collection of libraries for handling many common tasks a developer may have such as data structures, communication, rendering, widgets and more. --------------------------------------------------------------------------------Update Information: Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706 --------------------------------------------------------------------------------ChangeLog: * Sat Sep 24 2022 Tom Callaway - 1.26.3-1 - update to 1.26.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #2128741 - CVE-2022-37706 enlightenment: elevate privileges to root. https://bugzilla.redhat.com/show_bug.cgi?id=2128741 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7090749bf4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7090749bf4 2022-10-03 00:17:00.182937 --------------------------------------------------------------------------------Name : enlightenment Product : Fedora 37 Version : 0.25.4 Release : 1.fc37 URL : https://www.enlightenment.org/ Summary : Enlightenment window manager Description : Enlightenment window manager is a lean, fast, modular and very extensible window manager for X11 and Linux. It is classed as a "desktop shell" providing the things you need to operate your desktop (or laptop), but is not a whole ' application suite. This covered launching applications, managing their windows and doing other system tasks like suspending, reboots, managing files etc. --------------------------------------------------------------------------------Update Information: Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706 --------------------------------------------------------------------------------ChangeLog: * Sat Sep 24 2022 Tom Callaway - 0.25.4-1 - update to 0.25.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #2128741 - CVE-2022-37706 enlightenment: elevate privileges to root. https://bugzilla.redhat.com/show_bug.cgi?id=2128741 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7090749bf4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.