Important: thunderbird security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:0476", "synopsis": "Important: thunderbird security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for thunderbird.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Mozilla Thunderbird is a standalone mail and newsgroup client.\n\nThis update upgrades Thunderbird to version 102.7.1.\n\nSecurity Fix(es):\n\n* Mozilla: libusrsctp library out of date (CVE-2022-46871)\n\n* Mozilla: Arbitrary file read from GTK drag and drop on Linux (CVE-2023-23598)\n\n* Mozilla: Memory safety bugs fixed in Firefox 109 and Firefox ESR 102.7 (CVE-2023-23605)\n\n* Mozilla: Malicious command could be hidden in devtools output (CVE-2023-23599)\n\n* Mozilla: URL being dragged from cross-origin iframe into same tab triggers navigation (CVE-2023-23601)\n\n* Mozilla: Content Security Policy wasn't being correctly applied to WebSockets in WebWorkers (CVE-2023-23602)\n\n* Mozilla: Fullscreen notification bypass (CVE-2022-46877)\n\n* Mozilla: Calls to console.log allowed bypasing Content Security Policy via format directive (CVE-2023-23603)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2162336", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162336", "description": ""}, {"ticket": "2162338", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162338", "description": ""}, {"ticket": "2162339", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162339", "description": ""}, {"ticket": "2162340", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2162340", "description": ""}, {"ticket": "2162341", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162341", "description": ""}, {"ticket": "2162342", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162342", "description": ""}, {"ticket": "2162343", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162343", "description": ""}, {"ticket": "2162344", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2162344", "description": ""}], "cves": [{"name": "CVE-2022-46871", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-46871", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-1104"}, {"name": "CVE-2022-46877", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-46877", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "cvss3BaseScore": "4.3", "cwe": "CWE-357"}, {"name": "CVE-2023-23598", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23598", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-450"}, {"name": "CVE-2023-23599", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23599", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-77"}, {"name": "CVE-2023-23601", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23601", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-829"}, {"name": "CVE-2023-23602", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23602", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-1385"}, {"name": "CVE-2023-23603", "sourceBy": "MITRE", "sourceLink":"https://www.cve.org/CVERecord?id=CVE-2023-23603", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N", "cvss3BaseScore": "6.5", "cwe": "CWE-185"}, {"name": "CVE-2023-23605", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-23605", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-120"}], "references": [], "publishedAt": "2023-01-26T17:04:32Z", "rpms": {"Rocky Linux 9": {"nvras": ["thunderbird-0:102.7.1-1.el9_1.aarch64.rpm", "thunderbird-0:102.7.1-1.el9_1.ppc64le.rpm", "thunderbird-0:102.7.1-1.el9_1.s390x.rpm", "thunderbird-0:102.7.1-1.el9_1.src.rpm", "thunderbird-0:102.7.1-1.el9_1.x86_64.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.aarch64.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.ppc64le.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.s390x.rpm", "thunderbird-debuginfo-0:102.7.1-1.el9_1.x86_64.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.aarch64.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.ppc64le.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.s390x.rpm", "thunderbird-debugsource-0:102.7.1-1.el9_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The latest Thunderbird patch for Rocky Linux enhances its security measures, effectively bolstering the email client's protection against various cyber threats.. Thunderbird Security, Rocky Linux Update, Security Fixes, Open Source Email, Linux Client Protection. . Severity: Important. LinuxSecurity.com Team
update to latest upstream release -fixes CVE-2021-38385. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-847ca2749a 2021-08-24 03:32:16.467222 --------------------------------------------------------------------------------Name : tor Product : Fedora 34 Version : 0.4.5.10 Release : 1.fc34 URL : https://www.torproject.org Summary : Anonymizing overlay network for TCP Description : The Tor network is a group of volunteer-operated servers that allows people to improve their privacy and security on the Internet. Tor's users employ this network by connecting through a series of virtual tunnels rather than making a direct connection, thus allowing both organizations and individuals to share information over public networks without compromising their privacy. Along the same line, Tor is an effective censorship circumvention tool, allowing its users to reach otherwise blocked destinations or content. Tor can also be used as a building block for software developers to create new communication tools with built-in privacy features. This package contains the Tor software that can act as either a server on the Tor network, or as a client to connect to the Tor network. --------------------------------------------------------------------------------Update Information: update to latest upstream release -fixes CVE-2021-38385 --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1995254 - CVE-2021-38385 tor: assertion failure in signature verification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1995254 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-847ca2749a' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8b33bd7abf 2018-03-12 19:02:51.236775 --------------------------------------------------------------------------------Name : tor Product : Fedora 27 Version : 0.3.1.10 Release : 1.fc27 URL : https://www.torproject.org Summary : Anonymizing overlay network for TCP Description : The Tor network is a group of volunteer-operated servers that allows people to improve their privacy and security on the Internet. Tor's users employ this network by connecting through a series of virtual tunnels rather than making a direct connection, thus allowing both organizations and individuals to share information over public networks without compromising their privacy. Along the same line, Tor is an effective censorship circumvention tool, allowing its users to reach otherwise blocked destinations or content. Tor can also be used as a building block for software developers to create new communication tools with built-in privacy features. This package contains the Tor software that can act as either a server on the Tor network, or as a client to connect to the Tor network. --------------------------------------------------------------------------------Update Information: Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002, --------------------------------------------------------------------------------References: [ 1 ] Bug #1532909 - tor-0.3.2.10 is available https://bugzilla.redhat.com/show_bug.cgi?id=1532909 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed withthe Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- Update to 52.0.1 - All patches synchronized with firefox. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-8c567ee528 2017-04-04 16:01:42.501284 -------------------------------------------------------------------------------- Name : icecat Product : Fedora 26 Version : 52.0.1 Release : 5.fc26 URL : http://www.gnu.org/software/gnuzilla/ Summary : GNU version of Firefox browser Description : GNUZilla Icecat is a fully-free fork of Mozilla Firefox ESR. Extensions included to this version of IceCat: * LibreJS GNU LibreJS aims to address the JavaScript problem described in Richard Stallman's article The JavaScript Trap. * SpyBlock Blocks privacy trackers while in normal browsing mode, and all third party requests when in private browsing mode. Based on Adblock Plus. * AboutIceCat Adds a custom "about:icecat" homepage with links to information about the free software and privacy features in IceCat, and check-boxes to enable and disable the ones more prone to break websites. * HTML5-video-everywhere Uses the native video player to play embedded videos from different sources * Fingerprinting countermeasures: Fingerprinting is a series of techniques allowing to uniquely identify a browser based on specific characterisics of that particular instance (like what fonts are available in that machine). Unlike cookies the user cannot opt-out of being tracked this way, so the browser has to avoid giving away that kind of hints. -------------------------------------------------------------------------------- Update Information: - Update to 52.0.1 - All patches synchronized with firefox -------------------------------------------------------------------------------- References: [ 1 ] Bug #1429252 - icecat does not compile on aarch64 https://bugzilla.redhat.com/show_bug.cgi?id=1429252 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade icecat' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
telegram-cli-1.3.1-7.20150730git2052f4.fc22 - Hardened builds on
icecat-38.3.0-10.fc23 - Rebuild with RPM_LD_FLAGS - Activated hardened_build icecat-38.3.0-10.fc22 - Rebuild with RPM_LD_FLAGS - Activated hardened_build icecat-38.3.0-10.fc21 - Rebuild with RPM_LD_FLAGS - Activated hardened_build. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-bbb6a72996 2015-11-09 20:15:33.214131 -------------------------------------------------------------------------------- Name : icecat Product : Fedora 22 Version : 38.3.0 Release : 10.fc22 URL : Summary : GNU version of Firefox browser Description : GNUZilla Icecat is a fully-free fork of Mozilla Firefox. Four extensions are included to this version of IceCat: * LibreJS 6.0.10.20150620 GNU LibreJS aims to address the JavaScript problem described in Richard Stallman's article The JavaScript Trap. * SpyBlock 2.6.9.0 Blocks privacy trackers while in normal browsing mode, and all third party requests when in private browsing mode. Based on Adblock Plus. * AboutIceCat 1.0 Adds a custom "about:icecat" homepage with links to information about the free software and privacy features in IceCat, and check-boxes to enable and disable the ones more prone to break websites. * HTML5-video-everywhere 0.3.3 Uses the native video player to play embedded videos from different sources -------------------------------------------------------------------------------- Update Information: icecat-38.3.0-10.fc23 - Rebuild with RPM_LD_FLAGS - Activated hardened_build icecat-38.3.0-10.fc22 - Rebuild with RPM_LD_FLAGS - Activated hardened_build icecat-38.3.0-10.fc21 - Rebuild with RPM_LD_FLAGS - Activated hardened_build -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update icecat' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.