Ublock-origin is a lightweight and efficient ads, malware and trackers blocker. The new upstream version improves the user experience and ad / malware filter capabilities of this popular browser addon. It also fixes a bug in the Filter lists page which prevented it from rendering normal. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4356-1
GNOME 40.rc. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-303f6623fa 2021-03-20 00:16:30.596999 --------------------------------------------------------------------------------Name : gnome-online-miners Product : Fedora 34 Version : 3.34.0 Release : 8.fc34 URL : https://wiki.gnome.org/Projects/GnomeOnlineMiners Summary : Crawls through your online content Description : GNOME Online Miners provides a set of crawlers that go through your online content and index them locally in Tracker. It has miners for Facebook, Flickr, Google, OneDrive and Nextcloud. --------------------------------------------------------------------------------Update Information: GNOME 40.rc --------------------------------------------------------------------------------ChangeLog: * Tue Mar 16 2021 Debarshi Ray - 3.34.0-8 - Disable unused gnome-documents-specific miners * Mon Mar 15 2021 Kalev Lember - 3.34.0-7 - Backport patches for Tracker 3 support --------------------------------------------------------------------------------References: [ 1 ] Bug #1925640 - CVE-2020-36241 gnome-autoar: directory traversal via a malicious archive that contains a file whose parent is a symbolic link which points outside of the destination directory https://bugzilla.redhat.com/show_bug.cgi?id=1925640 [ 2 ] Bug #1940026 - CVE-2021-28650 gnome-autoar: directory traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations https://bugzilla.redhat.com/show_bug.cgi?id=1940026 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-303f6623fa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Tracker could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-3101-1 October 12, 2016 tracker vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Tracker could be made to crash if it opened a specially crafted file. Software Description: - tracker: metadata database, indexer and search tool Details: It was discovered that Tracker incorrectly handled certain malformed GIF images. If a user or automated system were tricked into downloading a specially-crafted GIF image, Tracker could crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: tracker-extract 1.6.2-0ubuntu1.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://bugs.launchpad.net/ubuntu-gnome/+bug/1178402 Package Information: https://launchpad.net/ubuntu/+source/tracker/1.6.2-0ubuntu1.1 . Upgrade your Ubuntu 16.04 LTS to resolve the Tracker failure triggered by corrupted GIF files alongside essential software patches.. Tracker Vulnerability, Ubuntu Update, Denial of Service, Software Fix, Image Handling. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.