ALSA-2021:1586

Source
https://errata.almalinux.org/8/ALSA-2021-1586.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2021:1586.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2021:1586
Related
Published
2021-05-18T05:35:26Z
Modified
2021-11-12T10:20:56Z
Summary
Moderate: GNOME security, bug fix, and enhancement update
Details

GNOME is the default desktop environment of AlmaLinux.

The following packages have been upgraded to a later upstream version: accountsservice (0.6.55), webkit2gtk3 (2.30.4). (BZ#1846376, BZ#1883304)

Security Fix(es):

  • webkitgtk: type confusion may lead to arbitrary code execution (CVE-2020-9948)

  • webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-9951)

  • webkitgtk: out-of-bounds write may lead to code execution (CVE-2020-9983)

  • webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13543)

  • webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13584)

  • glib2: insecure permissions for files and directories (CVE-2019-13012)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

References

Affected packages

AlmaLinux:8 / OpenEXR-devel

Package

Name
OpenEXR-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.0-12.el8

AlmaLinux:8 / OpenEXR-libs

Package

Name
OpenEXR-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.0-12.el8

AlmaLinux:8 / accountsservice-devel

Package

Name
accountsservice-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.55-1.el8

AlmaLinux:8 / atkmm

Package

Name
atkmm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.2-7.el8

AlmaLinux:8 / atkmm-devel

Package

Name
atkmm-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.2-7.el8

AlmaLinux:8 / atkmm-doc

Package

Name
atkmm-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.2-7.el8

AlmaLinux:8 / cairomm

Package

Name
cairomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.0-8.el8

AlmaLinux:8 / cairomm-devel

Package

Name
cairomm-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.0-8.el8

AlmaLinux:8 / cairomm-doc

Package

Name
cairomm-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.12.0-8.el8

AlmaLinux:8 / chrome-gnome-shell

Package

Name
chrome-gnome-shell

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.1-7.el8

AlmaLinux:8 / dleyna-core

Package

Name
dleyna-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0-3.el8

AlmaLinux:8 / dleyna-server

Package

Name
dleyna-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.6.0-3.el8

AlmaLinux:8 / enchant2

Package

Name
enchant2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.3-3.el8

AlmaLinux:8 / enchant2-devel

Package

Name
enchant2-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.3-3.el8

AlmaLinux:8 / gamin

Package

Name
gamin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.10-32.el8

AlmaLinux:8 / gamin-devel

Package

Name
gamin-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.10-32.el8

AlmaLinux:8 / geoclue2

Package

Name
geoclue2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.5-2.el8

AlmaLinux:8 / geoclue2-demos

Package

Name
geoclue2-demos

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.5-2.el8

AlmaLinux:8 / geoclue2-devel

Package

Name
geoclue2-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.5-2.el8

AlmaLinux:8 / geoclue2-libs

Package

Name
geoclue2-libs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.5.5-2.el8

AlmaLinux:8 / geocode-glib

Package

Name
geocode-glib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.26.0-3.el8

AlmaLinux:8 / geocode-glib-devel

Package

Name
geocode-glib-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.26.0-3.el8

AlmaLinux:8 / gjs

Package

Name
gjs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.56.2-5.el8

AlmaLinux:8 / gjs-devel

Package

Name
gjs-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.56.2-5.el8

AlmaLinux:8 / glib2-doc

Package

Name
glib2-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.56.4-9.el8

AlmaLinux:8 / glib2-static

Package

Name
glib2-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.56.4-9.el8

AlmaLinux:8 / glibmm24

Package

Name
glibmm24

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.56.0-2.el8

AlmaLinux:8 / glibmm24-devel

Package

Name
glibmm24-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.56.0-2.el8

AlmaLinux:8 / glibmm24-doc

Package

Name
glibmm24-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.56.0-2.el8

AlmaLinux:8 / gnome-boxes

Package

Name
gnome-boxes

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.36.5-8.el8

AlmaLinux:8 / gnome-photos

Package

Name
gnome-photos

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.1-4.el8

AlmaLinux:8 / gnome-photos-tests

Package

Name
gnome-photos-tests

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.1-4.el8

AlmaLinux:8 / gnome-terminal

Package

Name
gnome-terminal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.3-3.el8

AlmaLinux:8 / gnome-terminal-nautilus

Package

Name
gnome-terminal-nautilus

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.3-3.el8

AlmaLinux:8 / gtk-doc

Package

Name
gtk-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.28-3.el8

AlmaLinux:8 / gtk2

Package

Name
gtk2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.32-5.el8

AlmaLinux:8 / gtk2-devel

Package

Name
gtk2-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.32-5.el8

AlmaLinux:8 / gtk2-devel-docs

Package

Name
gtk2-devel-docs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.32-5.el8

AlmaLinux:8 / gtk2-immodule-xim

Package

Name
gtk2-immodule-xim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.32-5.el8

AlmaLinux:8 / gtk2-immodules

Package

Name
gtk2-immodules

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.32-5.el8

AlmaLinux:8 / gtkmm24

Package

Name
gtkmm24

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.5-6.el8

AlmaLinux:8 / gtkmm24-devel

Package

Name
gtkmm24-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.5-6.el8

AlmaLinux:8 / gtkmm24-docs

Package

Name
gtkmm24-docs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.24.5-6.el8

AlmaLinux:8 / gtkmm30

Package

Name
gtkmm30

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.2-3.el8

AlmaLinux:8 / gtkmm30-devel

Package

Name
gtkmm30-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.2-3.el8

AlmaLinux:8 / gtkmm30-doc

Package

Name
gtkmm30-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.22.2-3.el8

AlmaLinux:8 / gvfs

Package

Name
gvfs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-afc

Package

Name
gvfs-afc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-afp

Package

Name
gvfs-afp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-archive

Package

Name
gvfs-archive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-client

Package

Name
gvfs-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-devel

Package

Name
gvfs-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-fuse

Package

Name
gvfs-fuse

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-goa

Package

Name
gvfs-goa

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-gphoto2

Package

Name
gvfs-gphoto2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-mtp

Package

Name
gvfs-mtp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / gvfs-smb

Package

Name
gvfs-smb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.36.2-11.el8

AlmaLinux:8 / libdazzle

Package

Name
libdazzle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.5-2.el8

AlmaLinux:8 / libdazzle-devel

Package

Name
libdazzle-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.5-2.el8

AlmaLinux:8 / libepubgen

Package

Name
libepubgen

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.0-3.el8

AlmaLinux:8 / libepubgen-devel

Package

Name
libepubgen-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.1.0-3.el8

AlmaLinux:8 / libsass

Package

Name
libsass

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.5-6.el8

AlmaLinux:8 / libsass-devel

Package

Name
libsass-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.5-6.el8

AlmaLinux:8 / libsigc++20

Package

Name
libsigc++20

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.0-6.el8

AlmaLinux:8 / libsigc++20-devel

Package

Name
libsigc++20-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.0-6.el8

AlmaLinux:8 / libsigc++20-doc

Package

Name
libsigc++20-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.10.0-6.el8

AlmaLinux:8 / libvisual

Package

Name
libvisual

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:0.4.0-25.el8

AlmaLinux:8 / libvisual-devel

Package

Name
libvisual-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:0.4.0-25.el8

AlmaLinux:8 / mutter-devel

Package

Name
mutter-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.32.2-57.el8

AlmaLinux:8 / nautilus

Package

Name
nautilus

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.1-15.el8

AlmaLinux:8 / nautilus-devel

Package

Name
nautilus-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.1-15.el8

AlmaLinux:8 / nautilus-extensions

Package

Name
nautilus-extensions

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.28.1-15.el8

AlmaLinux:8 / pangomm

Package

Name
pangomm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.40.1-6.el8

AlmaLinux:8 / pangomm-devel

Package

Name
pangomm-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.40.1-6.el8

AlmaLinux:8 / pangomm-doc

Package

Name
pangomm-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.40.1-6.el8

AlmaLinux:8 / soundtouch

Package

Name
soundtouch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.0-3.el8

AlmaLinux:8 / soundtouch-devel

Package

Name
soundtouch-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.0-3.el8

AlmaLinux:8 / vala

Package

Name
vala

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.40.19-2.el8

AlmaLinux:8 / vala-devel

Package

Name
vala-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.40.19-2.el8

AlmaLinux:8 / woff2

Package

Name
woff2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2-5.el8

AlmaLinux:8 / woff2-devel

Package

Name
woff2-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.2-5.el8