Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-9114

Опубликовано: 14 нояб. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-9114: gnome-shell and gnome-shell-extensions security update (MODERATE)

gnome-shell [40.10-21]

  • Only open portal login in response to user action Resolves: RHEL-39098

[40.10-20]

  • Fix inhibit-shortcut permissions Resolves: #RHEL-2031

[40.10-19]

  • Use correct bus name for screencast service Related: RHEL-35775

gnome-shell-extensions [40.7-19]

  • Extend workspace buttons to screen edge Resolves: RHEL-43545

[40.7-18]

  • Add 'move-clock' extension Resolves: RHEL-33429

[40.7-17]

  • Fix downstream stylesheets Resolves: RHEL-25016

[40.7-16]

  • Improve workspace previews Resolves: RHEL-25016

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gnome-classic-session

40.7-19.el9

gnome-shell

40.10-21.el9

gnome-shell-extension-apps-menu

40.7-19.el9

gnome-shell-extension-auto-move-windows

40.7-19.el9

gnome-shell-extension-classification-banner

40.7-19.el9

gnome-shell-extension-common

40.7-19.el9

gnome-shell-extension-custom-menu

40.7-19.el9

gnome-shell-extension-dash-to-dock

40.7-19.el9

gnome-shell-extension-dash-to-panel

40.7-19.el9

gnome-shell-extension-desktop-icons

40.7-19.el9

gnome-shell-extension-drive-menu

40.7-19.el9

gnome-shell-extension-gesture-inhibitor

40.7-19.el9

gnome-shell-extension-heads-up-display

40.7-19.el9

gnome-shell-extension-launch-new-instance

40.7-19.el9

gnome-shell-extension-native-window-placement

40.7-19.el9

gnome-shell-extension-panel-favorites

40.7-19.el9

gnome-shell-extension-places-menu

40.7-19.el9

gnome-shell-extension-screenshot-window-sizer

40.7-19.el9

gnome-shell-extension-systemMonitor

40.7-19.el9

gnome-shell-extension-top-icons

40.7-19.el9

gnome-shell-extension-updates-dialog

40.7-19.el9

gnome-shell-extension-user-theme

40.7-19.el9

gnome-shell-extension-window-list

40.7-19.el9

gnome-shell-extension-windowsNavigator

40.7-19.el9

gnome-shell-extension-workspace-indicator

40.7-19.el9

Oracle Linux x86_64

gnome-classic-session

40.7-19.el9

gnome-shell

40.10-21.el9

gnome-shell-extension-apps-menu

40.7-19.el9

gnome-shell-extension-auto-move-windows

40.7-19.el9

gnome-shell-extension-classification-banner

40.7-19.el9

gnome-shell-extension-common

40.7-19.el9

gnome-shell-extension-custom-menu

40.7-19.el9

gnome-shell-extension-dash-to-dock

40.7-19.el9

gnome-shell-extension-dash-to-panel

40.7-19.el9

gnome-shell-extension-desktop-icons

40.7-19.el9

gnome-shell-extension-drive-menu

40.7-19.el9

gnome-shell-extension-gesture-inhibitor

40.7-19.el9

gnome-shell-extension-heads-up-display

40.7-19.el9

gnome-shell-extension-launch-new-instance

40.7-19.el9

gnome-shell-extension-native-window-placement

40.7-19.el9

gnome-shell-extension-panel-favorites

40.7-19.el9

gnome-shell-extension-places-menu

40.7-19.el9

gnome-shell-extension-screenshot-window-sizer

40.7-19.el9

gnome-shell-extension-systemMonitor

40.7-19.el9

gnome-shell-extension-top-icons

40.7-19.el9

gnome-shell-extension-updates-dialog

40.7-19.el9

gnome-shell-extension-user-theme

40.7-19.el9

gnome-shell-extension-window-list

40.7-19.el9

gnome-shell-extension-windowsNavigator

40.7-19.el9

gnome-shell-extension-workspace-indicator

40.7-19.el9

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

CVSS3: 7.5
redhat
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

CVSS3: 6.5
nvd
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior.

CVSS3: 6.5
debian
около 1 года назад

In GNOME Shell through 45.7, a portal helper can be launched automatic ...

suse-cvrf
11 месяцев назад

Security update for gnome-shell