More critical information about recent security updates in BLFS

"\"Douglas R. Reno\"" ([email protected] via blfs-dev Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.devel,gmane.linux.lfs.beyond.support
Message-ID <[email protected]>
Good evening folks,

I know it's been less than a week since I've written the last one of 
these, but some major security issues came in for the gstreamer stack 
and QtWebEngine since the last email.

The first update I'd like to talk about is QtWebEngine. It had 17 
security flaws fixed, fixing all of the vulnerabilities found in recent 
Chromium releases. Most of these are remote code execution issues, but 
some can also allow for UI spoofing, remotely exploitable crashes, and 
unauthorized access to data on the filesystem. Some of the 
vulnerabilities have received attention by the press, and if you have 
QtWebEngine installed you should update to Qt 6.8.1 (and QtWebEngine 
6.8.1) immediately to protect your system, especially if you use Falkon. 
The vulnerabilities were found in the Mojo, Dawn, V8, Extensions, 
DevTools, Navigation, Web Authentication, Paint, Filesystem, Blink, 
Media, Views, and Serial components.

The other update I'd like to talk about is the gstreamer stack. There 
were over **40** security vulnerabilities fixed in the 1.24.10 update, 
from a security audit performed by GitHub Security Labs. The issues 
range from crashes to arbitrary (and in some contexts, remote) code 
execution, and they occur in a variety of plugins - including MOV/MP4 
playback support, the ID3v2 tag parser, the JPEG decoder, the WebM 
demuxer, the Vorbis decoder, the SSA subtitle parser, the Opus decoder, 
the gdk-pixbuf decoder, the WAV parser, the AVI subtitle parser, and the 
LRC subtitle parser. In addition, a vulnerability was found in the 
gst-discoverer-1.0 tool. Most of the issues can be exploited by 
attempting to parse malicious files, and in some cases (such as playback 
of WebM/MP4/MOV/AVI videos and WAV audio), these can be exploitable via 
a web browser. If you have the gstreamer stack installed on your system, 
you should update the entire stack to 1.24.10 ASAP to protect your 
system from these critical vulnerabilities.

For more information, please visit 
https://linuxfromscratch.org/blfs/advisories/consolidated.html and 
https://linuxfromscratch.org/blfs/advisories/12.2.html.

Thank you,

- Doug

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-dev
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.