Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4381

Опубликовано: 16 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4381: GNOME security, bug fix, and enhancement update (MODERATE)

accountsservice [0.6.55-2]

  • Add support for user templates so user can specify default session Resolves: #1812788

gdm [40.0-14]

  • Fix XDMCP Resolves: #2004170
  • Fix crash at shutdown Related: #2004170

[40.0-13]

  • Disable Wayland on HyperV
  • Fix Xorg fallback Related: #1998989

[40.0-12]

  • Redisable on server chips since rebase Related: #1909300

[40.0-11]

  • Read session settings from users even if theyve never saved before. Needed to support accountsservice templated user defaults. Related: #1812788

[40.0-10]

  • Let customers using vendor nvidia driver choose wayland sessions Resolves: #1962211
  • Drop unused patches

[40.0-3]

  • Disable network items on login screen Resolves: #1935261

[40.0-2]

  • Fix workaround for systemd bug thats breaking X11 fallback Resolves: #1962049

[40.0-1]

  • Rebase to 40.0 Resolves: #1909300

gnome-autoar [0.2.3-2]

  • CVE-2020-36241, CVE-2021-28650: Do not allow symlink in parents (rhbz#1928701)

gnome-calculator [3.28.2-2]

  • Allow disabling downloading by setting refresh interval to 0 Resolves: #1957705

gnome-control-center [3.28.2-28]

  • Update pt_BR translations
  • Resolves: #1978612

gnome-online-accounts [3.28.2-3]

  • Disable the Facebook and Foursquare providers Resolves: #1951086, #1952136

gnome-session [3.28.1-13.0.1]

  • Update kiosk-session subpackage with Oracle references [Orabug: 32095108]

[3.28.1-13]

  • Add patch to tell grub boot was successful when user is able to explicitly request shutdown/reboot. Resolves: #1914925

[3.28.1-12]

  • Introduce gnome-wayland session to allow users that use Xorg on the login screen to try wayland for the user session. Related: #1962211

[3.28.1-11]

  • Exclude kiosk-session from xsession subpackage
  • Disable VT switching when kiosk-session is installed Related: #1955754

gnome-settings-daemon [3.32.0-16]

  • Update pt_BR translations
  • Resolves: #1978612

[3.32.0-15]

  • Keep auto-logout working inside VMs Resolves: #1904139

gnome-shell [3.32.2-40]

  • Add bugs introduced in backport for #1651378 Related: #1999758
  • Tidy up patch list a bit

[3.32.2-39]

  • Allow extensions on the login screen Related: #1651378

[3.32.2-38]

  • Only mask text in password entries Resolves: #1987233

[3.32.2-37]

  • Only warn once when not running under GDM Resolves: #1980661

[3.32.2-36]

  • Add ability to lock down password showing Resolves: #1770302
  • Add requires on newer mutter version Related: #1937866

[3.32.2-35]

  • Improve style of window preview close buttons Resolves: #1981420

[3.32.2-34]

  • Add PolicyKit-authentication-agent virtual provides Resolves: #1978287

[3.32.2-33]

  • Fix warnings on unlock Resolves: #1971534
  • Fix gdm lock screen Resolves: #1971507

[3.32.2-32]

  • Fix network secret requests on login screen Related: #1935261

[3.32.2-31]

  • Backport of touch mode Resolves: #1937866

gnome-shell-extensions [3.32.1-20]

  • Add extension for displaying heads up message Related: #1651378

[3.32.1-19]

  • Dont use status icon wm_class as top bar role Resolves: #1897932

[3.32.1-18]

  • Add gesture-inhibitor extension Resolves: #1854679

[3.32.1-17]

  • Handle touchscreens on Wayland in the desktop-icons extension Resolves: #1924725

[3.32.1-16]

  • Fix opening files with (wrongly) set executable bit Resolves: #1813727

gnome-software [3.36.1-10]

  • Resolves: #1978505 (Development package is missing important header files)

[3.36.1-9]

  • Resolves: #1972545 (flatpak: Prefer runtime from the same origin as the application)

[3.36.1-8]

  • Resolves: #1888404 (Updates page hides ongoing updates on refresh)

[3.36.1-7]

  • Resolves: #1873297 (Crash when run as root)

[3.36.1-6]

  • Resolves: #1791478 (Cannot completely disable ODRS (GNOME Ratings))

gsettings-desktop-schemas [3.32.0-6]

  • Add setting for locking down Show Password in entries Related: #1770302

gtk3 [3.22.30-8]

  • Make reftests work in a vm

[3.22.30-7]

  • Only mention Emoji in context menus when requested (rhbz#1893196)
  • Fix warnings from non-overlay scrollbars (rhbz#1873488)

LibRaw [0.19.5-3]

  • Backport fix for CVE-2020-24870 from upstream Resolves: #1931841

mutter [3.32.2-60]

  • Backport fix avoiding DND regression Resolves: #1999120

[3.32.2-59]

  • Backport fixes avoiding frozen partly off-screen clients Resolves: #1989035

[3.32.2-58]

  • Backport xauth and xhost patches Resolves: #1949176

vino [3.22.0-11]

  • Fix crashes under FIPS
  • Resolves: #1960705

webkit2gtk3 [2.32.3-2]

  • Fix CVE-2021-30858
  • Resolves: #2006428

[2.32.3-1]

  • Update to 2.32.3
  • Related: #1937416

[2.32.2-1]

  • Update to 2.32.2
  • Related: #1937416

[2.32.1-1]

  • Update to 2.32.1
  • Related: #1937416

[2.32.0-1]

  • Update to 2.32.0
  • Related: #1937416

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

LibRaw

0.19.5-3.el8

LibRaw-devel

0.19.5-3.el8

accountsservice

0.6.55-2.el8

accountsservice-devel

0.6.55-2.el8

accountsservice-libs

0.6.55-2.el8

gdm

40.0-15.el8

gnome-autoar

0.2.3-2.el8

gnome-calculator

3.28.2-2.el8

gnome-classic-session

3.32.1-20.el8

gnome-control-center

3.28.2-28.el8

gnome-control-center-filesystem

3.28.2-28.el8

gnome-online-accounts

3.28.2-3.el8

gnome-online-accounts-devel

3.28.2-3.el8

gnome-session

3.28.1-13.0.1.el8

gnome-session-kiosk-session

3.28.1-13.0.1.el8

gnome-session-wayland-session

3.28.1-13.0.1.el8

gnome-session-xsession

3.28.1-13.0.1.el8

gnome-settings-daemon

3.32.0-16.el8

gnome-shell

3.32.2-40.el8

gnome-shell-extension-apps-menu

3.32.1-20.el8

gnome-shell-extension-auto-move-windows

3.32.1-20.el8

gnome-shell-extension-common

3.32.1-20.el8

gnome-shell-extension-dash-to-dock

3.32.1-20.el8

gnome-shell-extension-desktop-icons

3.32.1-20.el8

gnome-shell-extension-disable-screenshield

3.32.1-20.el8

gnome-shell-extension-drive-menu

3.32.1-20.el8

gnome-shell-extension-gesture-inhibitor

3.32.1-20.el8

gnome-shell-extension-horizontal-workspaces

3.32.1-20.el8

gnome-shell-extension-launch-new-instance

3.32.1-20.el8

gnome-shell-extension-native-window-placement

3.32.1-20.el8

gnome-shell-extension-no-hot-corner

3.32.1-20.el8

gnome-shell-extension-panel-favorites

3.32.1-20.el8

gnome-shell-extension-places-menu

3.32.1-20.el8

gnome-shell-extension-screenshot-window-sizer

3.32.1-20.el8

gnome-shell-extension-systemMonitor

3.32.1-20.el8

gnome-shell-extension-top-icons

3.32.1-20.el8

gnome-shell-extension-updates-dialog

3.32.1-20.el8

gnome-shell-extension-user-theme

3.32.1-20.el8

gnome-shell-extension-window-grouper

3.32.1-20.el8

gnome-shell-extension-window-list

3.32.1-20.el8

gnome-shell-extension-windowsNavigator

3.32.1-20.el8

gnome-shell-extension-workspace-indicator

3.32.1-20.el8

gnome-software

3.36.1-10.el8

gnome-software-devel

3.36.1-10.el8

gsettings-desktop-schemas

3.32.0-6.el8

gsettings-desktop-schemas-devel

3.32.0-6.el8

gtk-update-icon-cache

3.22.30-8.el8

gtk3

3.22.30-8.el8

gtk3-devel

3.22.30-8.el8

gtk3-immodule-xim

3.22.30-8.el8

mutter

3.32.2-60.el8

mutter-devel

3.32.2-60.el8

vino

3.22.0-11.el8

webkit2gtk3

2.32.3-2.el8

webkit2gtk3-devel

2.32.3-2.el8

webkit2gtk3-jsc

2.32.3-2.el8

webkit2gtk3-jsc-devel

2.32.3-2.el8

Oracle Linux x86_64

LibRaw

0.19.5-3.el8

LibRaw-devel

0.19.5-3.el8

accountsservice

0.6.55-2.el8

accountsservice-devel

0.6.55-2.el8

accountsservice-libs

0.6.55-2.el8

gdm

40.0-15.el8

gnome-autoar

0.2.3-2.el8

gnome-calculator

3.28.2-2.el8

gnome-classic-session

3.32.1-20.el8

gnome-control-center

3.28.2-28.el8

gnome-control-center-filesystem

3.28.2-28.el8

gnome-online-accounts

3.28.2-3.el8

gnome-online-accounts-devel

3.28.2-3.el8

gnome-session

3.28.1-13.0.1.el8

gnome-session-kiosk-session

3.28.1-13.0.1.el8

gnome-session-wayland-session

3.28.1-13.0.1.el8

gnome-session-xsession

3.28.1-13.0.1.el8

gnome-settings-daemon

3.32.0-16.el8

gnome-shell

3.32.2-40.el8

gnome-shell-extension-apps-menu

3.32.1-20.el8

gnome-shell-extension-auto-move-windows

3.32.1-20.el8

gnome-shell-extension-common

3.32.1-20.el8

gnome-shell-extension-dash-to-dock

3.32.1-20.el8

gnome-shell-extension-desktop-icons

3.32.1-20.el8

gnome-shell-extension-disable-screenshield

3.32.1-20.el8

gnome-shell-extension-drive-menu

3.32.1-20.el8

gnome-shell-extension-gesture-inhibitor

3.32.1-20.el8

gnome-shell-extension-horizontal-workspaces

3.32.1-20.el8

gnome-shell-extension-launch-new-instance

3.32.1-20.el8

gnome-shell-extension-native-window-placement

3.32.1-20.el8

gnome-shell-extension-no-hot-corner

3.32.1-20.el8

gnome-shell-extension-panel-favorites

3.32.1-20.el8

gnome-shell-extension-places-menu

3.32.1-20.el8

gnome-shell-extension-screenshot-window-sizer

3.32.1-20.el8

gnome-shell-extension-systemMonitor

3.32.1-20.el8

gnome-shell-extension-top-icons

3.32.1-20.el8

gnome-shell-extension-updates-dialog

3.32.1-20.el8

gnome-shell-extension-user-theme

3.32.1-20.el8

gnome-shell-extension-window-grouper

3.32.1-20.el8

gnome-shell-extension-window-list

3.32.1-20.el8

gnome-shell-extension-windowsNavigator

3.32.1-20.el8

gnome-shell-extension-workspace-indicator

3.32.1-20.el8

gnome-software

3.36.1-10.el8

gnome-software-devel

3.36.1-10.el8

gsettings-desktop-schemas

3.32.0-6.el8

gsettings-desktop-schemas-devel

3.32.0-6.el8

gtk-update-icon-cache

3.22.30-8.el8

gtk3

3.22.30-8.el8

gtk3-devel

3.22.30-8.el8

gtk3-immodule-xim

3.22.30-8.el8

mutter

3.32.2-60.el8

mutter-devel

3.32.2-60.el8

vino

3.22.0-11.el8

webkit2gtk3

2.32.3-2.el8

webkit2gtk3-devel

2.32.3-2.el8

webkit2gtk3-jsc

2.32.3-2.el8

webkit2gtk3-jsc-devel

2.32.3-2.el8

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 4 года назад

A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.

CVSS3: 6.5
redhat
около 4 лет назад

A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.

CVSS3: 5.5
nvd
почти 4 года назад

A logic issue was addressed with improved restrictions. This issue is fixed in tvOS 14.6, iOS 14.6 and iPadOS 14.6, Safari 14.1.1, macOS Big Sur 11.4, watchOS 7.5. A malicious application may be able to leak sensitive user information.

CVSS3: 5.5
debian
почти 4 года назад

A logic issue was addressed with improved restrictions. This issue is ...

suse-cvrf
больше 4 лет назад

Security update for webkit2gtk3