Update to 2.50.0: Improved rendering performance by recording each layer once and replaying every dirty region in different worker threads. Enable damage propagation to the UI process by default. CSS property font-variant-emoji is now enabled by default.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-fcc043d407 2025-09-25 01:04:37.279331+00:00 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 42 Version : 2.50.0 Release : 1.fc42 URL : https://www.webkitgtk.org/ Summary : GTK web content engine library Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. -------------------------------------------------------------------------------- Update Information: Update to 2.50.0: Improved rendering performance by recording each layer once and replaying every dirty region in different worker threads. Enable damage propagation to the UI process by default. CSS property font-variant-emoji is now enabled by default. Font synthesis properties (bold/italic) are now properly handled. Ensure web view is focused on tap gesture. Added new API to get the theme color of a WebKitWebView. Fix CVE-2025-43272, CVE-2025-43342, CVE-2025-43356, CVE-2025-43368 -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 19 2025 Michael Catanzaro - 2.50.0-1 - Update to 2.50.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2397882 - CVE-2025-43368 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2397882 [ 2 ] Bug #2397887 - CVE-2025-43356 webkitgtk: A website may be able to access sensor information without user consent [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2397887 [ 3 ] Bug #2397892 - CVE-2025-43342 webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2397892 [ 4 ] Bug #2397897 - CVE-2025-43272 webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2397897 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-fcc043d407' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Updated mutt packages fix security vulnerability: Invalid format of RFC parameter passed to atoi() function in rfc2231.c could lead to unexpected behavior (rhbz#1710397, bdo#929017 . MGASA-2020-0086 - Updated mutt packages fix security vulnerability Publication date: 18 Feb 2020 URL: https://advisories.mageia.org/MGASA-2020-0086.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-XXXX Updated mutt packages fix security vulnerability: Invalid format of RFC parameter passed to atoi() function in rfc2231.c could lead to unexpected behavior (rhbz#1710397, bdo#929017 References: - https://bugs.mageia.org/show_bug.cgi?id=25909 - https://bugzilla.redhat.com/show_bug.cgi?id=1710397 - https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929017 - https://www.cve.org/CVERecord?id=CVE-2019-XXXX SRPMS: - 7/core/mutt-1.11.4-1.1.mga7 . Mageia 2020-0086 tackles a vulnerability in mutt associated with an improper RFC parameter format. Dive into the enhancements today.. Mageia Mutt Update, Security Advisory, Software Vulnerability, RFC Parameter Issue. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.