Dennis Dast discovered that the Konsole terminal emulator insecurely handled the telnet URI scheme, which could result in the execution of arbitrary code in some configurations. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5945-1
Update to 0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-756c627691 2025-03-17 01:37:24.408041+00:00 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 41 Version : 0.40.0 Release : 2.fc41 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: Update to0.40.0 https://sw.kovidgoyal.net/kitty/changelog/#detailed-list-of-changes -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 8 2025 Pavel Solovev - 0.40.0-1 - Update to 0.40.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2350858 - kitty-0.40.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2350858 [ 2 ] Bug #2352305 - CVE-2025-22870 kitty: HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2352305 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-756c627691' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
rebuild for rhbz#2292712. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c7b79bc227 2024-06-29 01:41:49.506039 -------------------------------------------------------------------------------- Name : kitty Product : Fedora 39 Version : 0.31.0 Release : 3.fc39 URL : https://sw.kovidgoyal.net/kitty Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. -------------------------------------------------------------------------------- Update Information: rebuild for rhbz#2292712 -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 20 2024 Pavel Solovev -0.31.0-3 - rebuild for rhbz#2292712 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c7b79bc227' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
version 0.28.1, backport security fix.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0418511dfe 2023-05-19 01:14:41.265566 --------------------------------------------------------------------------------Name : kitty Product : Fedora 38 Version : 0.28.1 Release : 4.fc38 URL : https://sw.kovidgoyal.net/kitty/ Summary : Cross-platform, fast, feature full, GPU based terminal emulator Description : - Offloads rendering to the GPU for lower system load and buttery smooth scrolling. Uses threaded rendering to minimize input latency. - Supports all modern terminal features: graphics (images), unicode, true-color, OpenType ligatures, mouse protocol, focus tracking, bracketed paste and several new terminal protocol extensions. - Supports tiling multiple terminal windows side by side in different layouts without needing to use an extra program like tmux. - Can be controlled from scripts or the shell prompt, even over SSH. - Has a framework for Kittens, small terminal programs that can be used to extend kitty's functionality. For example, they are used for Unicode input, Hints and Side-by-side diff. - Supports startup sessions which allow you to specify the window/tab layout, working directories and programs to run on startup. - Cross-platform: kitty works on Linux and macOS, but because it uses only OpenGL for rendering, it should be trivial to port to other Unix-like platforms. - Allows you to open the scrollback buffer in a separate window using arbitrary programs of your choice. This is useful for browsing the history comfortably in a pager or editor. - Has multiple copy/paste buffers, like vim. --------------------------------------------------------------------------------Update Information: version 0.28.1, backport security fix. --------------------------------------------------------------------------------ChangeLog: * Wed May 10 2023Pavel Solovev - 0.28.1-4 - Ask for permission before executing script files * Mon May 8 2023 Pavel Solovev - 0.28.1-3 - enable shell integration by default - remove unneeded weak dep, add ripgrep as a weak dep * Sat Apr 29 2023 Pavel Solovev - 0.28.1-2 - reenable s390x * Tue Apr 25 2023 Pavel Solovev - 0.28.1-1 - version 0.28.1 (rhbz#2188669) --------------------------------------------------------------------------------References: [ 1 ] Bug #2196802 - kitty: should not handle application/x-sh mime type by executing the script https://bugzilla.redhat.com/show_bug.cgi?id=2196802 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0418511dfe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-965978ed67 2022-02-16 01:12:44.297197 --------------------------------------------------------------------------------Name : xterm Product : Fedora 34 Version : 370 Release : 3.fc34 URL : https://invisible-island.net/xterm/ Summary : Terminal emulator for the X Window System Description : The xterm program is a terminal emulator for the X Window System. It provides DEC VT102 and Tektronix 4014 compatible terminals for programs that can't use the window system directly. --------------------------------------------------------------------------------Update Information: Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------ChangeLog: * Sat Jan 22 2022 Fedora Release Engineering - 370-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Fri Jan 7 2022 Thomas E. Dickey - 370-2 - Trim configure options which are no longer necessary. - Resolves: rhbz#2038247 * Tue Nov 30 2021 Tomas Korbar - 370-1 - Rebase to version 370 - Resolves: rhbz#2023017 * Wed Sep 22 2021 Tomas Korbar - 369-1 - Rebase to version 369 - Resolves: rhbz#2006589 * Fri Jul 23 2021 Fedora Release Engineering - 368-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild * Wed Jul 14 2021 Petr Pisar - 368-2 - Rebuild against pcre2-10.37 (bug #1965025) * Tue Jun 8 2021 Tomas Korbar - 368-1 - Rebase to version 368 - Resolves: rhbz#1969214 * Fri May 21 2021 Joe Orton - 367-3 - drop luit support * Mon May 17 2021 Peter Hutterer 367-2 - Add luit to Requires - Resolves: rhbz#1959210 * Mon Apr 12 2021 Tomas Korbar - 367-1 - Rebase to version 367 - Resolves:rhbz#1943741 --------------------------------------------------------------------------------References: [ 1 ] Bug #2048677 - CVE-2022-24130 xterm: Buffer overflow in set_sixel in graphics_sixel.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2048677 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-965978ed67' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0642394b5a 2017-07-27 14:26:19.255151 --------------------------------------------------------------------------------Name : minicom Product : Fedora 26 Version : 2.7.1 Release : 1.fc26 URL : Summary : A text-based modem control and terminal emulation program Description : Minicom is a simple text-based modem control and terminal emulation program somewhat similar to MSDOS Telix. Minicom includes a dialing directory, full ANSI and VT100 emulation, an (external) scripting language, and other features. --------------------------------------------------------------------------------Update Information: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade minicom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Nicolas Braud-Santoni discovered that incorrect sanitising of character escape sequences in the Terminology terminal emulator may result in the execution of arbitrary commands. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3712-1
* Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-463143720f 2016-01-07 23:40:26.816421 -------------------------------------------------------------------------------- Name : shellinabox Product : Fedora 22 Version : 2.19 Release : 1.fc22 URL : https://github.com/shellinabox/shellinabox Summary : Web based AJAX terminal emulator Description : Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator. This emulator is accessible to any JavaScript and CSS enabled web browser and does not require any additional browser plugins. -------------------------------------------------------------------------------- Update Information: * Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1287579 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287579 [ 2 ] Bug #1287578 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287578 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shellinabox' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.