# New in release OpenJDK 19.0.2 (2023-01-17) ## CVEs Fixed * CVE-2023-21835 * CVE-2023-21843 ## Security Fixes - JDK-8286070: Improve UTF8 representation - JDK-8286496: Improve Thread labels - JDK-8287411: Enhance DTLS performance - JDK-8288516: Enhance font creation - JDK-8293554: Enhanced DH Key Exchanges - JDK-8293598: Enhance InetAddress address handling - JDK-8293717: Objective. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-43bce108c7 2023-02-05 01:52:43.638507 --------------------------------------------------------------------------------Name : java-latest-openjdk Product : Fedora 36 Version : 19.0.2.0.7 Release : 1.rolling.fc36 URL : https://openjdk.org/ Summary : OpenJDK 19 Runtime Environment Description : The OpenJDK 19 runtime environment. --------------------------------------------------------------------------------Update Information: # New in release OpenJDK 19.0.2 (2023-01-17) ## CVEs Fixed * CVE-2023-21835 * CVE-2023-21843 ## Security Fixes - JDK-8286070: Improve UTF8 representation - JDK-8286496: Improve Thread labels - JDK-8287411: Enhance DTLS performance - JDK-8288516: Enhance font creation - JDK-8293554: Enhanced DH Key Exchanges - JDK-8293598: Enhance InetAddress address handling - JDK-8293717: Objective view of ObjectView - JDK-8293734: Improve BMP image handling - JDK-8293742: Better Banking of Sounds - JDK-8295687: Better BMP bounds ## Major Changes ### JDK-8295687: Better BMP bounds Loading a linked ICC profile within a BMP image is now disabled by default. To re-enable it, set the new system property `sun.imageio.bmp.enabledLinkedProfiles` to `true`. This new property replaces the old property, `sun.imageio.plugins.bmp.disableLinkedProfiles`. ### JDK-8293742: Better Banking of Sounds Previously, the SoundbankReader implementation, `com.sun.media.sound.JARSoundbankReader`, would download a JAR soundbank from a URL. Thisbehaviour is now disabled by default. To re-enable it, set the new system property `jdk.sound.jarsoundbank` to `true`. ### JDK-8287411: Enhance DTLS performance The JDK now exchanges DTLS cookies for all handshakes, new and resumed. The previous behaviour can be re-enabled by setting the new system property `jdk.tls.enableDtlsResumeCookie` to `false`. --------------------------------------------------------------------------------ChangeLog: * Thu Jan 26 2023 Andrew Hughes - 1:19.0.2.0.7-1.rolling - Revert "Flip the use of in-tree libraries back on by default" - The transition to bundled libraries is an F37 feature that should not be backported. * Thu Jan 26 2023 Andrew Hughes - 1:19.0.2.0.7-1.rolling - Update to jdk-19.0.2 release - Update release notes to 19.0.2 - Drop JDK-8293834 (CLDR update for Kyiv) which is now upstream - Drop JDK-8294357 (tzdata2022d), JDK-8295173 (tzdata2022e) & JDK-8296108 (tzdata2022f) local patches which are now upstream - Drop JDK-8296715 (CLDR update for 2022f) which is now upstream - Add local patch JDK-8295447 (javac NPE) which was accepted into 19u upstream but not in the GA tag - Add local patches for JDK-8296239 & JDK-8299439 (Croatia Euro update) which are present in 8u, 11u & 17u releases * Thu Jan 19 2023 Fedora Release Engineering - 1:19.0.1.0.10-3.rolling.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Dec 16 2022 Andrew Hughes - 1:19.0.1.0.10-3.rolling - Update in-tree tzdata & CLDR to 2022g with JDK-8296108, JDK-8296715 & JDK-8297804 - Update TestTranslations.java to test the new America/Ciudad_Juarez zone --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-43bce108c7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
firefox bugfix update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:2759', 'synopsis': 'firefox bugfix update', 'severity': 'UnknownSeverity', 'topic': 'An update for firefox is now available for Rocky Linux 8.', 'description': 'Mozilla Firefox is an open-source web browser, designed for standards\ncompliance, performance, and portability.\nThis update upgrades Firefox to version 78.12.0 ESR.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1983018'], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:2759:::RHBA-2021:2759'], 'references': [], 'publishedAt': '2021-07-22T18:28:10.064040Z', 'rpms': ['firefox-78.12.0-2.el8_4.aarch64.rpm', 'firefox-78.12.0-2.el8_4.src.rpm', 'firefox-78.12.0-2.el8_4.x86_64.rpm', 'firefox-debuginfo-78.12.0-2.el8_4.aarch64.rpm', 'firefox-debuginfo-78.12.0-2.el8_4.x86_64.rpm', 'firefox-debugsource-78.12.0-2.el8_4.aarch64.rpm', 'firefox-debugsource-78.12.0-2.el8_4.x86_64.rpm']}\. A recent Rocky Linux 8 patch offers improvements to Firefox, addressing bugs that boost both stability and overall performance.. Rocky Linux, Firefox Update, Software Improvements, Web Browser. . Severity: Critical. LinuxSecurity.com Team
The 4.18.13 update contains a number of important fixes across the tree. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ec3bf1b228 2018-10-30 17:13:37.319202 --------------------------------------------------------------------------------Name : kernel-tools Product : Fedora 29 Version : 4.18.13 Release : 300.fc29 URL : https://www.kernel.org/ Summary : Assortment of tools for the Linux kernel Description : This package contains the tools/ directory from the kernel source and the supporting documentation. --------------------------------------------------------------------------------Update Information: The 4.18.13 update contains a number of important fixes across the tree --------------------------------------------------------------------------------ChangeLog: * Wed Oct 10 2018 Laura Abbott - 4.18.13-300 - Linux v4.18.13 --------------------------------------------------------------------------------References: [ 1 ] Bug #1636349 - CVE-2018-17972 kernel: Unprivileged users able to inspect kernel stacks of arbitrary tasks https://bugzilla.redhat.com/show_bug.cgi?id=1636349 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-ec3bf1b228' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-312 2006-04-17 ---------------------------------------------------------------------Product : Fedora Core 5 Name : gnome-desktop Version : 2.14.1 Release : 1.fc5.1 Summary : Package containing code shared among gnome-panel, gnome-session, nautilus, etc. Description : The gnome-desktop package contains an internal library (libgnomedesktop) used to implement some portions of the GNOME desktop, and also some data files and other shared components of the GNOME user environment. ---------------------------------------------------------------------Update Information: Version 2.14.1 ============= Fixes * Make URI canonical before using them (Vincent) * Remember the added locales in GnomeDitemEdit (Vincent) * Sort locales list in GnomeDitemEdit (Vincent) * Make sure that there is a Name/Comment/etc. for C locale when generating a .desktop file (Vincent) * Use gdk_x11_display_get_user_time() to get the launch time (Vincent) Misc * Generate API documentation (Vincent) * Add GTK to the categories of gnome-about.desktop (Vincent) Documentation * Replace entities with UTF-8 (Shaun McCance) * Updated URLs and emails in the gnome-feedback document (Joachim Noreiko) Doc Translations * Maxim Dziumanenko (uk) Translators * Pema Geyleg (dz) * Ivar Smolin (et) * Ilkka Tuohela (fi) * Luca Ferretti (it) ------------------------------------------------------------------------------------------------------------------------------------------This update can be downloaded from: 82396e8bce839124028e3e4f74ddf56fcb749d8a SRPMS/gnome-desktop-2.14.1-1.fc5.1.src.rpm c3c4020f72b40d5ae4de53aca758fb43c644b504 ppc/gnome-desktop-2.14.1-1.fc5.1.ppc.rpm 9e1a56222bc9a0e05de13a413f073868552c5435 ppc/gnome-desktop-devel-2.14.1-1.fc5.1.ppc.rpm cc21898805fb7a314b41f05c0f552112506bc14a ppc/debug/gnome-desktop-debuginfo-2.14.1-1.fc5.1.ppc.rpm 64819a8d45afe7af22f2ca36958cf9d9dd6edff6 x86_64/gnome-desktop-2.14.1-1.fc5.1.x86_64.rpm e311f1b99804f2898504edbdf74286251709378e x86_64/gnome-desktop-devel-2.14.1-1.fc5.1.x86_64.rpm d033cf0db2f0d4b568ea7e9beba31120107fb1f7 x86_64/debug/gnome-desktop-debuginfo-2.14.1-1.fc5.1.x86_64.rpm 98b8af6b3345bd9d9974a8a85b0699d9e972d065 i386/gnome-desktop-2.14.1-1.fc5.1.i386.rpm 580b975fe3a64b5acb4ac56da069eefb01dce147 i386/gnome-desktop-devel-2.14.1-1.fc5.1.i386.rpm 58ea99b648728c925184d4e9c207fa054e0ba533 i386/debug/gnome-desktop-debuginfo-2.14.1-1.fc5.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.