Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2020:4436

Опубликовано: 03 нояб. 2020
Источник: rocky
Оценка: Low

Описание

Low: gnome-software and fwupd security, bug fix, and enhancement update

The gnome-software packages contain an application that makes it easy to add, remove, and update software in the GNOME desktop.

The appstream-data package provides the distribution specific AppStream metadata required for the GNOME and KDE software centers.

The fwupd packages provide a service that allows session software to update device firmware.

The following packages have been upgraded to a later upstream version: gnome-software (3.36.1), fwupd (1.4.2).

Security Fix(es):

  • fwupd: Possible bypass in signature verification (CVE-2020-10759)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.3 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libxmlbx86_641.el8libxmlb-0.1.15-1.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 6
ubuntu
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 5.7
redhat
около 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
nvd
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signature bypass is theoretically possible, but not practical because the Linux Vendor Firmware Service (LVFS) is either not implemented or enabled in versions of fwupd shipped with Red Hat Enterprise Linux 7 and 8. The highest threat from this vulnerability is to confidentiality and integrity.

CVSS3: 6
debian
почти 5 лет назад

A PGP signature bypass flaw was found in fwupd (all versions), which c ...

suse-cvrf
около 4 лет назад

Security update for fwupd