Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-aa764a8531 2021-02-28 17:25:31.286237 --------------------------------------------------------------------------------Name : chromium Product : Fedora 33 Version : 88.0.4324.182 Release : 1.fc33 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 17 2021 Tom Callaway - 88.0.4234.182-1 - update to 88.0.4234.182 --------------------------------------------------------------------------------References: [ 1 ] Bug #1929523 - CVE-2021-21149 chromium-browser: Stack overflow in Data Transfer https://bugzilla.redhat.com/show_bug.cgi?id=1929523 [ 2 ] Bug #1929524 - CVE-2021-21150 chromium-browser: Use after free in Downloads https://bugzilla.redhat.com/show_bug.cgi?id=1929524 [ 3 ] Bug #1929525 - CVE-2021-21151 chromium-browser: Use after free in Payments https://bugzilla.redhat.com/show_bug.cgi?id=1929525 [ 4 ] Bug #1929526 - CVE-2021-21152 chromium-browser: Heap buffer overflow in Media https://bugzilla.redhat.com/show_bug.cgi?id=1929526 [ 5 ] Bug #1929527 - CVE-2021-21153 chromium-browser: Stack overflow in GPU Process https://bugzilla.redhat.com/show_bug.cgi?id=1929527 [ 6 ] Bug #1929528 - CVE-2021-21154 chromium-browser: Heap bufferoverflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929528 [ 7 ] Bug #1929529 - CVE-2021-21155 chromium-browser: Heap buffer overflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929529 [ 8 ] Bug #1929530 - CVE-2021-21156 chromium-browser: Heap buffer overflow in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1929530 [ 9 ] Bug #1929531 - CVE-2021-21157 chromium-browser: Use after free in Web Sockets https://bugzilla.redhat.com/show_bug.cgi?id=1929531 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-aa764a8531' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
- update to nghttp2-1.6.0 (fixes CVE-2015-8659). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-54f85ec6e8 2016-01-07 16:45:29.292971 -------------------------------------------------------------------------------- Name : nghttp2 Product : Fedora 23 Version : 1.6.0 Release : 1.fc23 URL : https://nghttp2.org/ Summary : Experimental HTTP/2 client, server and proxy Description : This package contains the HTTP/2 client, server and proxy programs. -------------------------------------------------------------------------------- Update Information: - update to nghttp2-1.6.0 (fixes CVE-2015-8659) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1295351 - CVE-2015-8659 nghttp2: heap-use-after-free flaw in idle stream handling code https://bugzilla.redhat.com/show_bug.cgi?id=1295351 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update nghttp2' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Important: netpbm security update. Date: Tue, 13 Dec 2011 08:14:57 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 5x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: acpid-1.0.4-12.el5.i386.rpm gtk2-2.10.4-21.el5_7.7.i386.rpm gtk2-devel-2.10.4-21.el5_7.7.i386.rpm sos-1.7-9.54.el5_7.1.noarch.rpm x86_64: acpid-1.0.4-12.el5.x86_64.rpm gtk2-2.10.4-21.el5_7.7.i386.rpm gtk2-2.10.4-21.el5_7.7.x86_64.rpm gtk2-devel-2.10.4-21.el5_7.7.i386.rpm gtk2-devel-2.10.4-21.el5_7.7.x86_64.rpm sos-1.7-9.54.el5_7.1.noarch.rpm Date: Tue, 13 Dec 2011 11:08:42 -0600 Reply-To:
Get the latest Linux and open source security news straight to your inbox.