Update to 2.34.4: * Fix dire ["Safari Leaks"](https://safarileaks.com/) IndexedDB privacy violation. * Make audio tools (like mixers) display the actual name of the application producing sound, instead of a generic one. * Fix several crashes and rendering issues. * Additional security fixes: CVE-2021-30887, CVE-2021-30890, CVE-2021-30934, CVE-2021-30936, CVE-2021-30951,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-25a98f5d55 2022-01-23 01:41:29.500049 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 35 Version : 2.34.4 Release : 2.fc35 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to 2.34.4: * Fix dire ["Safari Leaks"](https://safarileaks.com/) IndexedDB privacy violation. * Make audio tools (like mixers) display the actual name of the application producing sound, instead of a generic one. * Fix several crashes and rendering issues. * Additional security fixes: CVE-2021-30887, CVE-2021-30890, CVE-2021-30934, CVE-2021-30936, CVE-2021-30951, CVE-2021-30952, CVE-2021-30953, CVE-2021-30954, CVE-2021-30984 --------------------------------------------------------------------------------ChangeLog: * Fri Jan 21 2022 Michael Catanzaro 2.34.4-2 - Add missing BuildRequires for wayland-protocols * Fri Jan 21 2022 Michael Catanzaro 2.34.4-1 - Update to WebKitGTK 2.34.4 * Wed Nov 24 2021 Michael Catanzaro 2.34.2-1 - Upgrade to 2.34.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #2034381 - CVE-2021-30887 webkitgtk: Logic issue leading to Content Security Policybypass https://bugzilla.redhat.com/show_bug.cgi?id=2034381 [ 2 ] Bug #2034389 - CVE-2021-30890 webkitgtk: Logic issue leading to universal cross-site scripting https://bugzilla.redhat.com/show_bug.cgi?id=2034389 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-25a98f5d55' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-18a0cf206b 2018-03-12 18:19:23.509144 --------------------------------------------------------------------------------Name : tor Product : Fedora 26 Version : 0.3.1.10 Release : 1.fc26 URL : https://www.torproject.org Summary : Anonymizing overlay network for TCP Description : The Tor network is a group of volunteer-operated servers that allows people to improve their privacy and security on the Internet. Tor's users employ this network by connecting through a series of virtual tunnels rather than making a direct connection, thus allowing both organizations and individuals to share information over public networks without compromising their privacy. Along the same line, Tor is an effective censorship circumvention tool, allowing its users to reach otherwise blocked destinations or content. Tor can also be used as a building block for software developers to create new communication tools with built-in privacy features. This package contains the Tor software that can act as either a server on the Tor network, or as a client to connect to the Tor network. --------------------------------------------------------------------------------Update Information: Update to latest version. Security-Fixes TROVE-2018-001, TROVE-2018-002, --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
update to upstream release 0.2.8.9. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-3b6393acdd 2016-11-01 08:56:12.225163 -------------------------------------------------------------------------------- Name : tor Product : Fedora 23 Version : 0.2.8.9 Release : 1.fc23 URL : https://www.torproject.org Summary : Anonymizing overlay network for TCP Description : The Tor network is a group of volunteer-operated servers that allows people to improve their privacy and security on the Internet. Tor's users employ this network by connecting through a series of virtual tunnels rather than making a direct connection, thus allowing both organizations and individuals to share information over public networks without compromising their privacy. Along the same line, Tor is an effective censorship circumvention tool, allowing its users to reach otherwise blocked destinations or content. Tor can also be used as a building block for software developers to create new communication tools with built-in privacy features. This package contains the Tor software that can act as either a server on the Tor network, or as a client to connect to the Tor network. -------------------------------------------------------------------------------- Update Information: update to upstream release 0.2.8.9 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1386499 - CVE-2016-8860 tor: Version 0.2.8.9 contains security fixes https://bugzilla.redhat.com/show_bug.cgi?id=1386499 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.