Update to 2.34.1: * Update user agent browser versions. * Fix a crash with GTK > = 3.24.30. * Fix a crash when loading videos on reddit. * Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html. * Security fixes: CVE-2021-42762. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-db6ebb2d68 2021-10-29 22:48:33.394808 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 35 Version : 2.34.1 Release : 2.fc35 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to 2.34.1: * Update user agent browser versions. * Fix a crash with GTK > = 3.24.30. * Fix a crash when loading videos on reddit. * Fix file type detection when application calls g_desktop_app_info_set_as_default_for_extension() passing html. * Security fixes: CVE-2021-42762 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 23 2021 Michael Catanzaro 2.34.1-2 - Revert "Remove old obsoletes/provides" * Thu Oct 21 2021 Michael Catanzaro 2.34.1-1 - Update to 2.34.1 * Wed Sep 29 2021 Michael Catanzaro 2.34.0-4 - Improve instructions for generating GPG keyring * Wed Sep 29 2021 Michael Catanzaro 2.34.0-3 - Remove old obsoletes/provides * Thu Sep 23 2021 Michael Catanzaro 2.34.0-2 - Improve BuildRequires --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-db6ebb2d68' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to WebKitGTK 2.32.0: * NPAPI plugins support have been removed. * System font scaling factor is correctly applied now. * New permission request API for MediaKeySystem access. * New API to remove individual scripts/stylesheets using WebKitUserContentManager. * Web inspector now shows detailed information about main loop frames. * The minimum required GStreamer. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-8070916f7a 2021-03-29 00:14:59.219532 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 34 Version : 2.32.0 Release : 1.fc34 URL : https://www.webkitgtk.org/ Summary : GTK Web content engine library Description : WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform. This package contains WebKit2 based WebKitGTK for GTK 3. --------------------------------------------------------------------------------Update Information: Update to WebKitGTK 2.32.0: * NPAPI plugins support have been removed. * System font scaling factor is correctly applied now. * New permission request API for MediaKeySystem access. * New API to remove individual scripts/stylesheets using WebKitUserContentManager. * Web inspector now shows detailed information about main loop frames. * The minimum required GStreamer version is now 1.14. * The GStreamer runtime is now initialized only when required. * Improved platform support for WebAudio (WebAudio-> MediaStream, Worklet, Multi-channel). * Support for hardware-accelerated video rendering on i.MX8 platforms (using the NXP driver). Security fixes: CVE-2020-27918, CVE-2020-29623, CVE-2021-1765, CVE-2021-1788, CVE-2021-1789, CVE-2021-1799, CVE-2021-1801, CVE-2021-1844, CVE-2021-1870, CVE-2021-1871 --------------------------------------------------------------------------------ChangeLog: * Fri Mar 26 2021 Michael Catanzaro - 2.32.0-1 - Updateto 2.32.0 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-8070916f7a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This update addresses the following vulnerability: * [CVE-2018-4345](https://www.cve.org/CVERecord?id=CVE-2018-4345) This update brings the following changes: * Many improvements and fixes for video playback with media source extensions (MSE), which improve the user experience across the board, and in particular for playback of WebM videos. *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a1f37d2f08 2018-11-04 05:49:41.589645 --------------------------------------------------------------------------------Name : webkit2gtk3 Product : Fedora 29 Version : 2.22.3 Release : 1.fc29 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKit2 based WebKitGTK+ for GTK+ 3. --------------------------------------------------------------------------------Update Information: This update addresses the following vulnerability: * [CVE-2018-4345](https://www.cve.org/CVERecord?id=CVE-2018-4345) This update brings the following changes: * Many improvements and fixes for video playback with media source extensions (MSE), which improve the user experience across the board, and in particular for playback of WebM videos. * Fix a memory leak during media playback when using playbin3. * Fix portions of Web views not being rendered after resizing. * Fix Resource Timing reporting for iframe elements. * Fix the build with the remote Web Inspector disabled. * Fix the build on ARMv7 with NEON extensions. * Fix several crashes and rendering issues. --------------------------------------------------------------------------------ChangeLog: * Mon Oct 29 2018 Tomas Popela - 2.22.3-1 - Update to 2.22.3 * Fri Oct 19 2018 Tomas Popela - 2.22.2-2 - Fix WebProcess crash while printing - Resolves:rhbz#1639754 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a1f37d2f08' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This update addresses the following vulnerabilities: * [CVE-2018-4190](https://www.cve.org/CVERecord?id=CVE-2018-4190), [CVE-2018-4199](https://www.cve.org/CVERecord?id=CVE-2018-4199), [CVE-2018-4218](https://www.cve.org/CVERecord?id=CVE-2018-4218), [CVE-2018-4222](https://www.cve.org/CVERecord?id=CVE-2018-4222), . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2018-118b9abf99 2018-06-16 20:14:44.574740 -------------------------------------------------------------------------------- Name : webkit2gtk3 Product : Fedora 28 Version : 2.20.3 Release : 1.fc28 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKit2 based WebKitGTK+ for GTK+ 3. -------------------------------------------------------------------------------- Update Information: This update addresses the following vulnerabilities: * [CVE-2018-4190](https://www.cve.org/CVERecord?id=CVE-2018-4190), [CVE-2018-4199](https://www.cve.org/CVERecord?id=CVE-2018-4199), [CVE-2018-4218](https://www.cve.org/CVERecord?id=CVE-2018-4218), [CVE-2018-4222](https://www.cve.org/CVERecord?id=CVE-2018-4222), [CVE-2018-4232](https://www.cve.org/CVERecord?id=CVE-2018-4232), [CVE-2018-4233](https://www.cve.org/CVERecord?id=CVE-2018-4233), [CVE-2018-4246](https://www.cve.org/CVERecord?id=CVE-2018-4246), [CVE-2018-11646](https://www.cve.org/CVERecord?id=CVE-2018-11646). Additional fixes: * Fix installation directory of API documentation. * Disable Gigacage if mmap fails to allocate in Linux. * Add user agent quirk for paypal website. * Properly detect compiler flags, needed libs, and fallbacks for usage of 64-bit atomic operations. * Fix a network process crash when trying to get cookies of about:blank page. * Fix UI process crash when closing the window under Wayland. * Fix several crashesand rendering issues. -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 11 2018 Tomas Popela - 2.20.3-1 - Update to 2.20.3 * Wed May 9 2018 Tomas Popela - 2.20.2-1 - Update to 2.20.2 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-118b9abf99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Update WebKitGTK+ package to 2.14.1. Major changes in 2.14.0: * Threaded compositor is enabled by default in both X11 and Wayland. * Accelerated compositing is now supported in Wayland. * Clipboard works in Wayland too. * Memory pressure handler always works even when cgroups is not present or not configured. * The HTTP disk cache implements speculative revalidation of. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f4b5897686 2016-10-18 11:22:09.730738 -------------------------------------------------------------------------------- Name : webkitgtk4 Product : Fedora 24 Version : 2.14.1 Release : 1.fc24 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. This package contains WebKitGTK+ for GTK+ 3. -------------------------------------------------------------------------------- Update Information: Update WebKitGTK+ package to 2.14.1. Major changes in 2.14.0: * Threaded compositor is enabled by default in both X11 and Wayland. * Accelerated compositing is now supported in Wayland. * Clipboard works in Wayland too. * Memory pressure handler always works even when cgroups is not present or not configured. * The HTTP disk cache implements speculative revalidation of resources. * DRI3 is no longer a problem when using the modesetting intel driver. * The amount of file descriptors that are kept open has been drastically reduced. Fixes from 2.14.1: * MiniBrowser and jsc binaries are now installed in pkglibexecdir instead of bindir. * Improve performance when resizing a window with multiple web views in X11. * Check whether GDK can use GL before using gdk_cairo_draw_from_gl() in Wayland. * Updated default UserAgent string or better compatibility. * Fix a crash on github.com in IntlDateTimeFormat::resolvedOptions when using the C locale. * Fix BadDamage X errors when closing the webview in X11. * Fix UIProcess crash when using Japanese input method. * Fix build with clang due to missing header includes. * Fix the build with USE_REDIRECTED_XCOMPOSITE_WINDOW disabled. * Fix several crashes and rendering issues. * Translation updates: German. Update Epiphany to be compatible with the new WebKitGTK+ package. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update webkitgtk4' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
This update addresses the following vulnerabilities: * [CVE-2015-1120](https://www.cve.org/CVERecord?id=CVE-2015-1120) * [CVE-2015-1076](https://www.cve.org/CVERecord?id=CVE-2015-1076) * [CVE-2015-1071](https://www.cve.org/CVERecord?id=CVE-2015-1071) * [CVE-2015-1081](https://www.cve.org/CVERecord?id=CVE-2015-1081) *. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-5d6d75dbea 2016-03-22 15:54:44.506688 -------------------------------------------------------------------------------- Name : webkitgtk Product : Fedora 23 Version : 2.4.10 Release : 1.fc23 URL : https://www.webkitgtk.org/ Summary : GTK+ Web content engine library Description : WebKitGTK+ is the port of the portable web rendering engine WebKit to the GTK+ platform. -------------------------------------------------------------------------------- Update Information: This update addresses the following vulnerabilities: * [CVE-2015-1120](https://www.cve.org/CVERecord?id=CVE-2015-1120) * [CVE-2015-1076](https://www.cve.org/CVERecord?id=CVE-2015-1076) * [CVE-2015-1071](https://www.cve.org/CVERecord?id=CVE-2015-1071) * [CVE-2015-1081](https://www.cve.org/CVERecord?id=CVE-2015-1081) * [CVE-2015-1122](https://www.cve.org/CVERecord?id=CVE-2015-1122) * [CVE-2015-1155](https://www.cve.org/CVERecord?id=CVE-2015-1155) * [CVE-2014-1748](https://www.cve.org/CVERecord?id=CVE-2014-1748) * [CVE-2015-3752](https://www.cve.org/CVERecord?id=CVE-2015-3752) * [CVE-2015-5809](https://www.cve.org/CVERecord?id=CVE-2015-5809) * [CVE-2015-5928](https://www.cve.org/CVERecord?id=CVE-2015-5928) * [CVE-2015-3749](https://www.cve.org/CVERecord?id=CVE-2015-3749) * [CVE-2015-3659](https://www.cve.org/CVERecord?id=CVE-2015-3659) * [CVE-2015-3748](https://www.cve.org/CVERecord?id=CVE-2015-3748) * [CVE-2015-3743](https://www.cve.org/CVERecord?id=CVE-2015-3743) * [CVE-2015-3731](https://www.cve.org/CVERecord?id=CVE-2015-3731) * [CVE-2015-3745](https://www.cve.org/CVERecord?id=CVE-2015-3745) * [CVE-2015-5822](https://www.cve.org/CVERecord?id=CVE-2015-5822) * [CVE-2015-3658](https://www.cve.org/CVERecord?id=CVE-2015-3658) * [CVE-2015-3741](https://www.cve.org/CVERecord?id=CVE-2015-3741) * [CVE-2015-3727](https://www.cve.org/CVERecord?id=CVE-2015-3727) * [CVE-2015-5801](https://www.cve.org/CVERecord?id=CVE-2015-5801) * [CVE-2015-5788](https://www.cve.org/CVERecord?id=CVE-2015-5788) * [CVE-2015-3747](https://www.cve.org/CVERecord?id=CVE-2015-3747) * [CVE-2015-5794](https://www.cve.org/CVERecord?id=CVE-2015-5794) * [CVE-2015-1127](https://www.cve.org/CVERecord?id=CVE-2015-1127) * [CVE-2015-1153](https://www.cve.org/CVERecord?id=CVE-2015-1153) * [CVE-2015-1083](https://www.cve.org/CVERecord?id=CVE-2015-1083) Additional fixes: * Fix crashes on PowerPC 64. * Fix the build on PowerPC 32. * Add ARM64 build support. Translation updates * German * Spanish * French * Italian * Korean * Brazilian Portuguese * Russian * Chinese. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update webkitgtk' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Several vulnerabilities have been discovered in webkit, a Web content engine library for Gtk+. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2188-1
Get the latest Linux and open source security news straight to your inbox.