Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2020-4451

Опубликовано: 10 нояб. 2020
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2020-4451: GNOME security, bug fix, and enhancement update (MODERATE)

dleyna-renderer [0.6.0-3]

  • Add a manual Resolves: #1612579

frei0r-plugins [1.6.1-7]

  • Rebuild with newer annobin to fix rpmdiff problems
  • Fix the build with a newer opencv
  • Resolves: rhbz#1703994

gdm [3.28.3-34]

  • Fix file descriptor leak Resolves: #1877853

[3.28.3-33]

  • Fix problem with Xorg fallback Resolves: #1868260

[3.28.3-32]

  • Add dconf db to file manifest Related: #1833158

[3.28.3-31]

  • add back gdm system db to dconf profile Resolves: #1833158

[3.28.3-30]

  • Make sure login screen is killed during login Resolves: #1618481

gnome-control-center [3.28.2-22]

  • Categorize Infiniband devices correctly Resolves: #1826379

[3.28.2-21]

  • Honor sound theme changes when changing from the default theme
  • Resolves: #1706008

[3.28.2-20]

  • Fix 90min automatic sleep option to not last 80min
  • Resolves: #1706076

gnome-photos [3.28.1-3]

  • Disable Python 2 during the build - itstool doesnt need it anymore Resolves: #1597806

[3.28.1-2]

  • rebuild

gnome-remote-desktop [0.1.8-3]

  • Backport cursor only frame fixes Related: #1837406

[0.1.8-2]

  • Dont crash on metadata only buffers Resolves: #1847062

[0.1.8-1]

  • Rebase to 0.1.8 Resolves: #1837406

gnome-session [3.28.1-10.0.1]

  • Update kiosk-session subpackage with Oracle references [Orabug: 32095108]

[3.28.1-10]

  • Show cursor explicitly from session selector Resolves: #1624430

[3.28.1-9]

  • Add kiosk-session subpackage to help users set up RHEL for kiosk/point-of-sale use. Resolves: #1739556

gnome-settings-daemon [3.32.0-11]

  • Remove subman plugin for now Resolves: #1872457

[3.32.0-10]

  • Disable subman plugin on CentOS Resolves: #1827030

gnome-shell [3.32.2-20]

  • Fix popupMenu keynav when NumLock is active Resolves: #1840080

[3.32.2-19]

  • Fix last backport Resolves: #1847051

[3.32.2-18]

  • Fix more spurious allocation warnings Resolves: #1715845

[3.32.2-17]

  • Really allow using perf-tool on wayland Resolves: #1652178
  • Fix timed login without user list Resolves: #1668895
  • Fix HighContrast/symbolic icon mixup Resolves: #1794045
  • Backport introspect API changes Resolves: #1837413

[3.32.2-16]

  • Drop bad upstream patch Resolves: #1820760

[3.32.2-15]

  • Improve performance under load Resolves: #1820760

gnome-shell-extensions [3.32.1-11]

  • Adjust dash-to-dock for classic backports Resolves: #1805929
  • Fix inconsistent state in window-list prefs dialog Resolves: #1824362

gnome-terminal [3.28.3-2]

  • Add a manual
  • Resolves: #1612688

gsettings-desktop-schemas [3.32.0-5]

  • Recommend DejaVu Sans Mono font as the default monospace font Resolves: #1656262

gtk3 [3.22.30-6]

  • Fix reuse of list box header widgets (#rhbz1843486)

gtk-doc [1.28-2]

  • Backport a patch to fix x86_64/i686 differences in generated documentation
  • Resolves: #1634770

gvfs [1.36.2-10]

  • Fix libusb(x) requirements (rhbz#1866332)

[1.36.2-9]

  • Improve enumeration performance of smb backend (rhbz#1569868)

LibRaw [0.19.5-2]

  • Backport fix for CVE-2020-15503 from Fedora Resolves: #1853529

libsoup [2.62.3-2]

  • Some WebSocket fixes to unbreak cockpit-desktop (rhbz#1872270)

mutter [3.32.2-48]

  • Fix GLX stereo buffer rebase error Resolves: #1880339

[3.32.2-47]

  • Fix screen sharing on wayland Resolves: #1873963

[3.32.2-46]

  • Handle cursor only screen cast frames better Related: #1837381

[3.32.2-45]

  • Handle GPU unplug gracefully Resolves: #1846191

[3.32.2-44]

  • Dont show widow actor until explictly shown Resolves: #1719937

[3.32.2-43]

  • Only treat WM_PROTOCOLS messages as WM_PROTOCOL messages Resolves: #1847203

[3.32.2-42]

  • Dont pass DMA buffers if they cant be mmap():ed Related: #1847062

[3.32.2-41]

  • Backport is_rendering_hardware_acclerated() API Related: #1837381

[3.32.2-40]

  • Fix DMA buffer memory leak Related: #1837381

[3.32.2-39]

  • Fix incorrect pipewire dependency version Related: #1837381

[3.32.2-38]

  • Backport screen cast and remote desktop improvements Resolves: #1837381

[3.32.2-37]

  • Fix corrupted background after suspend Resolves: #1828162

nautilus [3.28.1-14]

  • Fix broken tracker query under certain locales (rhbz#1847061)

[3.28.1-13]

  • Clear selection if any files dont match the pattern (rhbz#1207179)
  • Fix endless content size calculations (rhbz#1566027)
  • Honor umask when creating new files (rhbz#1778579)
  • Close 'There is no application...' dialog after response (rhbz#1816070)

PackageKit [1.1.12-6.0.1]

  • removed rhel-Vendor.conf.patch

[1.1.12-6]

  • Fix documentation links in Vendor.conf
  • Resolves: #1837648

[1.1.12-5]

  • Do not shutdown the daemon on idle
  • Resolves: #1814820

pipewire0.2 [0.2.7-6]

  • Fix Conflicts: line
  • Remove Recommends: line, its wrong
  • Resolves: rhbz#1832347

[0.2.7-5]

  • Fix Conflicts: line
  • Resolves: rhbz#1832347

[0.2.7-4]

  • Add gating file
  • Resolves: rhbz#1832347

[0.2.7-3]

  • Change source URL
  • Resolves: rhbz#1832347

[0.2.7-2]

  • Add compat -devel package

[0.2.7-1]

  • First version
  • Fix bluez5 plugins build

pipewire [0.3.6-1]

  • Update to 0.3.6
  • Resolves: rhbz#1832347

[0.3.5-3]

  • Rebuild
  • Resolves: rhbz#1832347

[0.3.5-2]

  • Disable vulkan
  • Resolves: rhbz#1832347

[0.3.5-1]

  • Update to 0.3.5
  • Disable pulse and jack
  • Add patch to work with meson 0.49
  • Add patch to fix neon compilation
  • Resolves: rhbz#1832347

potrace [1.15-3]

  • Fixing build for flatpak (rhbz#1840788)

pygobject3 [3.28.3-2]

  • Add lock to avoid two type object wrappers getting generated at the same time in multi-threaded programs. Resolves: #1844578

tracker [2.1.5-2]

  • Rebuild to include tracker-devel in CRB
  • Resolves: #1758891

vte291 [0.52.4-2]

  • Avoid overriding -fno-exceptions Resolves: #1804719

[0.52.4-1]

  • Update to 0.52.4 Resolves: #1804719

webkit2gtk3 [2.28.4-1]

  • Update to 2.28.4
  • Related: #1817143

[2.28.2-2]

  • Related: rhbz#1817143 Properly remove webkit2gtk3-plugin-process-gtk2 package

[2.28.2-1]

  • Resolves: rhbz#1817143 Update to 2.28.2

webrtc-audio-processing [0.3-9]

  • Rebuild to address Annobin coverage issues Resolves: #1704148

xdg-desktop-portal [1.6.0-2]

  • Require pipewire0.2-libs for legacy application support. Resolves: #1854734

[1.6.0-1]

  • Rebase to 1.6.0 (#1775345)
  • Backport PipeWire 0.3 support (#1775345)
  • Backport fixes (#1775345)

xdg-desktop-portal-gtk [1.6.0-1]

  • Rebase to 1.6.0 (#1837413)
  • Bump supported Mutter screen cast API version (#1837413)
  • Backport bugfix (#1837413)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

PackageKit

1.1.12-6.0.1.el8

PackageKit-command-not-found

1.1.12-6.0.1.el8

PackageKit-cron

1.1.12-6.0.1.el8

PackageKit-glib

1.1.12-6.0.1.el8

PackageKit-glib-devel

1.1.12-6.0.1.el8

PackageKit-gstreamer-plugin

1.1.12-6.0.1.el8

PackageKit-gtk3-module

1.1.12-6.0.1.el8

frei0r-devel

1.6.1-7.el8

frei0r-plugins

1.6.1-7.el8

frei0r-plugins-opencv

1.6.1-7.el8

gdm

3.28.3-34.el8

gnome-classic-session

3.32.1-11.el8

gnome-control-center

3.28.2-22.el8

gnome-control-center-filesystem

3.28.2-22.el8

gnome-remote-desktop

0.1.8-3.el8

gnome-session

3.28.1-10.0.1.el8

gnome-session-wayland-session

3.28.1-10.0.1.el8

gnome-session-xsession

3.28.1-10.0.1.el8

gnome-settings-daemon

3.32.0-11.el8

gnome-shell

3.32.2-20.el8

gnome-shell-extension-apps-menu

3.32.1-11.el8

gnome-shell-extension-auto-move-windows

3.32.1-11.el8

gnome-shell-extension-common

3.32.1-11.el8

gnome-shell-extension-dash-to-dock

3.32.1-11.el8

gnome-shell-extension-desktop-icons

3.32.1-11.el8

gnome-shell-extension-disable-screenshield

3.32.1-11.el8

gnome-shell-extension-drive-menu

3.32.1-11.el8

gnome-shell-extension-horizontal-workspaces

3.32.1-11.el8

gnome-shell-extension-launch-new-instance

3.32.1-11.el8

gnome-shell-extension-native-window-placement

3.32.1-11.el8

gnome-shell-extension-no-hot-corner

3.32.1-11.el8

gnome-shell-extension-panel-favorites

3.32.1-11.el8

gnome-shell-extension-places-menu

3.32.1-11.el8

gnome-shell-extension-screenshot-window-sizer

3.32.1-11.el8

gnome-shell-extension-systemMonitor

3.32.1-11.el8

gnome-shell-extension-top-icons

3.32.1-11.el8

gnome-shell-extension-updates-dialog

3.32.1-11.el8

gnome-shell-extension-user-theme

3.32.1-11.el8

gnome-shell-extension-window-grouper

3.32.1-11.el8

gnome-shell-extension-window-list

3.32.1-11.el8

gnome-shell-extension-windowsNavigator

3.32.1-11.el8

gnome-shell-extension-workspace-indicator

3.32.1-11.el8

gnome-terminal

3.28.3-2.el8

gnome-terminal-nautilus

3.28.3-2.el8

gsettings-desktop-schemas

3.32.0-5.el8

gsettings-desktop-schemas-devel

3.32.0-5.el8

gtk-doc

1.28-2.el8

gtk-update-icon-cache

3.22.30-6.el8

gtk3

3.22.30-6.el8

gtk3-devel

3.22.30-6.el8

gtk3-immodule-xim

3.22.30-6.el8

gvfs

1.36.2-10.el8

gvfs-afc

1.36.2-10.el8

gvfs-afp

1.36.2-10.el8

gvfs-archive

1.36.2-10.el8

gvfs-client

1.36.2-10.el8

gvfs-devel

1.36.2-10.el8

gvfs-fuse

1.36.2-10.el8

gvfs-goa

1.36.2-10.el8

gvfs-gphoto2

1.36.2-10.el8

gvfs-mtp

1.36.2-10.el8

gvfs-smb

1.36.2-10.el8

libsoup

2.62.3-2.el8

libsoup-devel

2.62.3-2.el8

mutter

3.32.2-48.el8

mutter-devel

3.32.2-48.el8

nautilus

3.28.1-14.el8

nautilus-devel

3.28.1-14.el8

nautilus-extensions

3.28.1-14.el8

pipewire

0.3.6-1.el8

pipewire-devel

0.3.6-1.el8

pipewire-doc

0.3.6-1.el8

pipewire-libs

0.3.6-1.el8

pipewire-utils

0.3.6-1.el8

pipewire0.2-devel

0.2.7-6.el8

pipewire0.2-libs

0.2.7-6.el8

potrace

1.15-3.el8

pygobject3-devel

3.28.3-2.el8

python3-gobject

3.28.3-2.el8

python3-gobject-base

3.28.3-2.el8

tracker

2.1.5-2.el8

tracker-devel

2.1.5-2.el8

vte-profile

0.52.4-2.el8

vte291

0.52.4-2.el8

vte291-devel

0.52.4-2.el8

webkit2gtk3

2.28.4-1.el8

webkit2gtk3-devel

2.28.4-1.el8

webkit2gtk3-jsc

2.28.4-1.el8

webkit2gtk3-jsc-devel

2.28.4-1.el8

webrtc-audio-processing

0.3-9.el8

xdg-desktop-portal

1.6.0-2.el8

xdg-desktop-portal-gtk

1.6.0-1.el8

Oracle Linux x86_64

LibRaw

0.19.5-2.el8

LibRaw-devel

0.19.5-2.el8

PackageKit

1.1.12-6.0.1.el8

PackageKit-command-not-found

1.1.12-6.0.1.el8

PackageKit-cron

1.1.12-6.0.1.el8

PackageKit-glib

1.1.12-6.0.1.el8

PackageKit-glib-devel

1.1.12-6.0.1.el8

PackageKit-gstreamer-plugin

1.1.12-6.0.1.el8

PackageKit-gtk3-module

1.1.12-6.0.1.el8

dleyna-renderer

0.6.0-3.el8

frei0r-devel

1.6.1-7.el8

frei0r-plugins

1.6.1-7.el8

frei0r-plugins-opencv

1.6.1-7.el8

gdm

3.28.3-34.el8

gnome-classic-session

3.32.1-11.el8

gnome-control-center

3.28.2-22.el8

gnome-control-center-filesystem

3.28.2-22.el8

gnome-photos

3.28.1-3.el8

gnome-photos-tests

3.28.1-3.el8

gnome-remote-desktop

0.1.8-3.el8

gnome-session

3.28.1-10.0.1.el8

gnome-session-wayland-session

3.28.1-10.0.1.el8

gnome-session-xsession

3.28.1-10.0.1.el8

gnome-settings-daemon

3.32.0-11.el8

gnome-shell

3.32.2-20.el8

gnome-shell-extension-apps-menu

3.32.1-11.el8

gnome-shell-extension-auto-move-windows

3.32.1-11.el8

gnome-shell-extension-common

3.32.1-11.el8

gnome-shell-extension-dash-to-dock

3.32.1-11.el8

gnome-shell-extension-desktop-icons

3.32.1-11.el8

gnome-shell-extension-disable-screenshield

3.32.1-11.el8

gnome-shell-extension-drive-menu

3.32.1-11.el8

gnome-shell-extension-horizontal-workspaces

3.32.1-11.el8

gnome-shell-extension-launch-new-instance

3.32.1-11.el8

gnome-shell-extension-native-window-placement

3.32.1-11.el8

gnome-shell-extension-no-hot-corner

3.32.1-11.el8

gnome-shell-extension-panel-favorites

3.32.1-11.el8

gnome-shell-extension-places-menu

3.32.1-11.el8

gnome-shell-extension-screenshot-window-sizer

3.32.1-11.el8

gnome-shell-extension-systemMonitor

3.32.1-11.el8

gnome-shell-extension-top-icons

3.32.1-11.el8

gnome-shell-extension-updates-dialog

3.32.1-11.el8

gnome-shell-extension-user-theme

3.32.1-11.el8

gnome-shell-extension-window-grouper

3.32.1-11.el8

gnome-shell-extension-window-list

3.32.1-11.el8

gnome-shell-extension-windowsNavigator

3.32.1-11.el8

gnome-shell-extension-workspace-indicator

3.32.1-11.el8

gnome-terminal

3.28.3-2.el8

gnome-terminal-nautilus

3.28.3-2.el8

gsettings-desktop-schemas

3.32.0-5.el8

gsettings-desktop-schemas-devel

3.32.0-5.el8

gtk-doc

1.28-2.el8

gtk-update-icon-cache

3.22.30-6.el8

gtk3

3.22.30-6.el8

gtk3-devel

3.22.30-6.el8

gtk3-immodule-xim

3.22.30-6.el8

gvfs

1.36.2-10.el8

gvfs-afc

1.36.2-10.el8

gvfs-afp

1.36.2-10.el8

gvfs-archive

1.36.2-10.el8

gvfs-client

1.36.2-10.el8

gvfs-devel

1.36.2-10.el8

gvfs-fuse

1.36.2-10.el8

gvfs-goa

1.36.2-10.el8

gvfs-gphoto2

1.36.2-10.el8

gvfs-mtp

1.36.2-10.el8

gvfs-smb

1.36.2-10.el8

libsoup

2.62.3-2.el8

libsoup-devel

2.62.3-2.el8

mutter

3.32.2-48.el8

mutter-devel

3.32.2-48.el8

nautilus

3.28.1-14.el8

nautilus-devel

3.28.1-14.el8

nautilus-extensions

3.28.1-14.el8

pipewire

0.3.6-1.el8

pipewire-devel

0.3.6-1.el8

pipewire-doc

0.3.6-1.el8

pipewire-libs

0.3.6-1.el8

pipewire-utils

0.3.6-1.el8

pipewire0.2-devel

0.2.7-6.el8

pipewire0.2-libs

0.2.7-6.el8

potrace

1.15-3.el8

pygobject3-devel

3.28.3-2.el8

python3-gobject

3.28.3-2.el8

python3-gobject-base

3.28.3-2.el8

tracker

2.1.5-2.el8

tracker-devel

2.1.5-2.el8

vte-profile

0.52.4-2.el8

vte291

0.52.4-2.el8

vte291-devel

0.52.4-2.el8

webkit2gtk3

2.28.4-1.el8

webkit2gtk3-devel

2.28.4-1.el8

webkit2gtk3-jsc

2.28.4-1.el8

webkit2gtk3-jsc-devel

2.28.4-1.el8

webrtc-audio-processing

0.3-9.el8

xdg-desktop-portal

1.6.0-2.el8

xdg-desktop-portal-gtk

1.6.0-1.el8

Связанные уязвимости

rocky
больше 4 лет назад

Moderate: GNOME security, bug fix, and enhancement update

CVSS3: 8.8
ubuntu
больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS3: 8.1
redhat
больше 5 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS3: 8.8
nvd
больше 4 лет назад

A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.

CVSS3: 8.8
debian
больше 4 лет назад

A use after free issue was addressed with improved memory management. ...

Уязвимость ELSA-2020-4451