Fedora alert FEDORA-2014-15130 (kwebkitpart)
| From: | updates@fedoraproject.org | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 20 Update: kwebkitpart-1.3.4-5.fc20 | |
| Date: | Sat, 06 Dec 2014 02:31:38 +0000 | |
| Message-ID: | <20141206023155.1980760BC2DC@bastion01.phx2.fedoraproject.org> |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2014-15130 2014-11-15 07:38:24 -------------------------------------------------------------------------------- Name : kwebkitpart Product : Fedora 20 Version : 1.3.4 Release : 5.fc20 URL : https://projects.kde.org/projects/extragear/base/kwebkitpart Summary : A KPart based on QtWebKit Description : KWebKitPart is a web browser component for KDE (KPart) based on (Qt)WebKit. You can use it for example for browsing the web in Konqueror. -------------------------------------------------------------------------------- Update Information: Sanitize input to disallow javascript being executed in the context of the referenced hostname. See also https://www.kde.org/info/security/advisory-20141113-1.txt -------------------------------------------------------------------------------- ChangeLog: * Fri Nov 14 2014 Rex Dieter <rdieter@fedoraproject.org> 1.3.4-5 - CVE-2014-8600 Insufficient Input Validation (#1164293) * Sun Aug 17 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Mon Jul 21 2014 Rex Dieter <rdieter@fedoraproject.org> 1.3.4-3 - keep khtml default on rhel * Thu Jun 19 2014 Rex Dieter <rdieter@fedoraproject.org> 1.3.4-2 - BR: kdelibs4-webkit-devel * Thu Jun 12 2014 Rex Dieter <rdieter@fedoraproject.org> 1.3.4-1 - 1.3.4 * Sun Jun 8 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.3.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Sun Dec 29 2013 Rex Dieter <rdieter@fedoraproject.org> 1.3.3-2 - respin tarball * Wed Dec 4 2013 Rex Dieter <rdieter@fedoraproject.org> 1.3.3-1 - 1.3.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1164293 - CVE-2014-8600 kwebkitpart, kde-runtime: Insufficient Input Validation By IO Slaves and Webkit Part https://bugzilla.redhat.com/show_bug.cgi?id=1164293 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update kwebkitpart' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...
