Gnome-Software and Fwupd Security, Bug Fix, and Enhancement Update

Gnome-Software and Fwupd Security, Bug Fix, and Enhancement Update

[RHSA-2020:4436-01] Low: gnome-software and fwupd security, bug fix, and enhancement update http://www.securityhome.eu/mailings/mailing.php?mid=17860 [RHSA-2020:4436-01] Low: gnome-software and fwupd secur... Article URL www.securityhome.eu/mailings/mailing.php?mid=17860 Author SecurityHome.eu Published: 04 November 2020 ===================================================================== Red Hat Security Advisory Synopsis: Low: gnome-software and fwupd security, bug fix, and enhancement update Advisory ID: RHSA-2020:4436-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:4436 Issue date: 2020-11-03 CVE Names: CVE-2020-10759 ===================================================================== 1. Summary: An update for appstream-data, fwupd, gnome-software, and libxmlb is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The gnome-software packages contain an application that makes it easy to add, remove, and update software in the GNOME desktop. The appstream-data package provides the distribution specific AppStream metadata required for the GNOME and KDE software centers. Page 1/4 [RHSA-2020:4436-01] Low: gnome-software and fwupd security, bug fix, and enhancement update http://www.securityhome.eu/mailings/mailing.php?mid=17860 The fwupd packages provide a service that allows session software to update device firmware. The following packages have been upgraded to a later upstream version: gnome-software (3.36.1), fwupd (1.4.2). Security Fix(es): * fwupd: Possible bypass in signature verification (CVE-2020-10759) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1797932 - Rebase gnome-software to 3.36 1815502 - gnome-software support for auth webflow in flatpak remotes 1839774 - missing section for gnome-shell extensions 1844316 - CVE-2020-10759 fwupd: Possible bypass in signature verification 1844488 - request for appstream-data refresh in 8.3 1845714 - Show Details not working for e.g. Firefox installed from rpm 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: appstream-data-8-20200724.el8.src.rpm gnome-software-3.36.1-4.el8.src.rpm aarch64: gnome-software-3.36.1-4.el8.aarch64.rpm gnome-software-debuginfo-3.36.1-4.el8.aarch64.rpm gnome-software-debugsource-3.36.1-4.el8.aarch64.rpm Page 2/4 [RHSA-2020:4436-01] Low: gnome-software and fwupd security, bug fix, and enhancement update http://www.securityhome.eu/mailings/mailing.php?mid=17860 noarch: appstream-data-8-20200724.el8.noarch.rpm ppc64le: gnome-software-3.36.1-4.el8.ppc64le.rpm gnome-software-debuginfo-3.36.1-4.el8.ppc64le.rpm gnome-software-debugsource-3.36.1-4.el8.ppc64le.rpm s390x: gnome-software-3.36.1-4.el8.s390x.rpm gnome-software-debuginfo-3.36.1-4.el8.s390x.rpm gnome-software-debugsource-3.36.1-4.el8.s390x.rpm x86_64: gnome-software-3.36.1-4.el8.x86_64.rpm gnome-software-debuginfo-3.36.1-4.el8.x86_64.rpm gnome-software-debugsource-3.36.1-4.el8.x86_64.rpm Red Hat Enterprise Linux BaseOS (v. 8): Source: fwupd-1.4.2-4.el8.src.rpm libxmlb-0.1.15-1.el8.src.rpm aarch64: fwupd-1.4.2-4.el8.aarch64.rpm fwupd-debuginfo-1.4.2-4.el8.aarch64.rpm fwupd-debugsource-1.4.2-4.el8.aarch64.rpm libxmlb-0.1.15-1.el8.aarch64.rpm libxmlb-debuginfo-0.1.15-1.el8.aarch64.rpm libxmlb-debugsource-0.1.15-1.el8.aarch64.rpm libxmlb-tests-debuginfo-0.1.15-1.el8.aarch64.rpm ppc64le: fwupd-1.4.2-4.el8.ppc64le.rpm fwupd-debuginfo-1.4.2-4.el8.ppc64le.rpm fwupd-debugsource-1.4.2-4.el8.ppc64le.rpm libxmlb-0.1.15-1.el8.ppc64le.rpm libxmlb-debuginfo-0.1.15-1.el8.ppc64le.rpm libxmlb-debugsource-0.1.15-1.el8.ppc64le.rpm libxmlb-tests-debuginfo-0.1.15-1.el8.ppc64le.rpm s390x: fwupd-1.4.2-4.el8.s390x.rpm fwupd-debuginfo-1.4.2-4.el8.s390x.rpm fwupd-debugsource-1.4.2-4.el8.s390x.rpm libxmlb-0.1.15-1.el8.s390x.rpm libxmlb-debuginfo-0.1.15-1.el8.s390x.rpm Page 3/4 [RHSA-2020:4436-01] Low: gnome-software and fwupd security, bug fix, and enhancement update http://www.securityhome.eu/mailings/mailing.php?mid=17860 libxmlb-debugsource-0.1.15-1.el8.s390x.rpm libxmlb-tests-debuginfo-0.1.15-1.el8.s390x.rpm x86_64: fwupd-1.4.2-4.el8.x86_64.rpm fwupd-debuginfo-1.4.2-4.el8.x86_64.rpm fwupd-debugsource-1.4.2-4.el8.x86_64.rpm libxmlb-0.1.15-1.el8.i686.rpm libxmlb-0.1.15-1.el8.x86_64.rpm libxmlb-debuginfo-0.1.15-1.el8.i686.rpm libxmlb-debuginfo-0.1.15-1.el8.x86_64.rpm libxmlb-debugsource-0.1.15-1.el8.i686.rpm libxmlb-debugsource-0.1.15-1.el8.x86_64.rpm libxmlb-tests-debuginfo-0.1.15-1.el8.i686.rpm libxmlb-tests-debuginfo-0.1.15-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-10759 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.3_release_notes/ 8. Contact: The Red Hat security contact is <[email protected]>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. Page 4/4.

View Full Text

Details

  • File Type
    pdf
  • Upload Time
    -
  • Content Languages
    English
  • Upload User
    Anonymous/Not logged-in
  • File Pages
    4 Page
  • File Size
    -

Download

Channel Download Status
Express Download Enable

Copyright

We respect the copyrights and intellectual property rights of all users. All uploaded documents are either original works of the uploader or authorized works of the rightful owners.

  • Not to be reproduced or distributed without explicit permission.
  • Not used for commercial purposes outside of approved use cases.
  • Not used to infringe on the rights of the original creators.
  • If you believe any content infringes your copyright, please contact us immediately.

Support

For help with questions, suggestions, or problems, please contact us