| Newsgroups |
gmane.linux.lfs.beyond.devel,gmane.linux.lfs.beyond.support |
| Message-ID |
<[email protected]> |
Good evening folks,
I know it's been less than a week since I've written the last one of
these, but some major security issues came in for the gstreamer stack
and QtWebEngine since the last email.
The first update I'd like to talk about is QtWebEngine. It had 17
security flaws fixed, fixing all of the vulnerabilities found in recent
Chromium releases. Most of these are remote code execution issues, but
some can also allow for UI spoofing, remotely exploitable crashes, and
unauthorized access to data on the filesystem. Some of the
vulnerabilities have received attention by the press, and if you have
QtWebEngine installed you should update to Qt 6.8.1 (and QtWebEngine
6.8.1) immediately to protect your system, especially if you use Falkon.
The vulnerabilities were found in the Mojo, Dawn, V8, Extensions,
DevTools, Navigation, Web Authentication, Paint, Filesystem, Blink,
Media, Views, and Serial components.
The other update I'd like to talk about is the gstreamer stack. There
were over **40** security vulnerabilities fixed in the 1.24.10 update,
from a security audit performed by GitHub Security Labs. The issues
range from crashes to arbitrary (and in some contexts, remote) code
execution, and they occur in a variety of plugins - including MOV/MP4
playback support, the ID3v2 tag parser, the JPEG decoder, the WebM
demuxer, the Vorbis decoder, the SSA subtitle parser, the Opus decoder,
the gdk-pixbuf decoder, the WAV parser, the AVI subtitle parser, and the
LRC subtitle parser. In addition, a vulnerability was found in the
gst-discoverer-1.0 tool. Most of the issues can be exploited by
attempting to parse malicious files, and in some cases (such as playback
of WebM/MP4/MOV/AVI videos and WAV audio), these can be exploitable via
a web browser. If you have the gstreamer stack installed on your system,
you should update the entire stack to 1.24.10 ASAP to protect your
system from these critical vulnerabilities.
For more information, please visit
https://linuxfromscratch.org/blfs/advisories/consolidated.html and
https://linuxfromscratch.org/blfs/advisories/12.2.html.
Thank you,
- Doug
--
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page