Oval Definition:oval:com.redhat.rhsa:def:20204451
Revision Date:2020-11-04Version:640
Title:RHSA-2020:4451: GNOME security, bug fix, and enhancement update (Moderate)
Description:GNOME is the default desktop environment of Red Hat Enterprise Linux.

  • The following packages have been upgraded to a later upstream version: gnome-remote-desktop (0.1.8), pipewire (0.3.6), vte291 (0.52.4), webkit2gtk3 (2.28.4), xdg-desktop-portal (1.6.0), xdg-desktop-portal-gtk (1.6.0). (BZ#1775345, BZ#1779691, BZ#1817143, BZ#1832347, BZ#1837406)

    Security Fix(es):

  • webkitgtk: Multiple security issues (CVE-2019-8625, CVE-2019-8710, CVE-2019-8720, CVE-2019-8743, CVE-2019-8764, CVE-2019-8766, CVE-2019-8769, CVE-2019-8771, CVE-2019-8782, CVE-2019-8783, CVE-2019-8808, CVE-2019-8811, CVE-2019-8812, CVE-2019-8813, CVE-2019-8814, CVE-2019-8815, CVE-2019-8816, CVE-2019-8819, CVE-2019-8820, CVE-2019-8823, CVE-2019-8835, CVE-2019-8844, CVE-2019-8846, CVE-2020-3862, CVE-2020-3864, CVE-2020-3865, CVE-2020-3867, CVE-2020-3868, CVE-2020-3885, CVE-2020-3894, CVE-2020-3895, CVE-2020-3897, CVE-2020-3899, CVE-2020-3900, CVE-2020-3901, CVE-2020-3902, CVE-2020-9802, CVE-2020-9803, CVE-2020-9805, CVE-2020-9806, CVE-2020-9807, CVE-2020-9843, CVE-2020-9850, CVE-2020-9862, CVE-2020-9893, CVE-2020-9894, CVE-2020-9895, CVE-2020-9915, CVE-2020-9925, CVE-2020-10018, CVE-2020-11793)

  • gnome-settings-daemon: Red Hat Customer Portal password logged and passed as command line argument when user registers through GNOME control center (CVE-2020-14391)

  • LibRaw: lack of thumbnail size range check can lead to buffer overflow (CVE-2020-15503)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2019-8625
    CVE-2019-8710
    CVE-2019-8720
    CVE-2019-8743
    CVE-2019-8764
    CVE-2019-8766
    CVE-2019-8769
    CVE-2019-8771
    CVE-2019-8782
    CVE-2019-8783
    CVE-2019-8808
    CVE-2019-8811
    CVE-2019-8812
    CVE-2019-8813
    CVE-2019-8814
    CVE-2019-8815
    CVE-2019-8816
    CVE-2019-8819
    CVE-2019-8820
    CVE-2019-8823
    CVE-2019-8835
    CVE-2019-8844
    CVE-2019-8846
    CVE-2020-10018
    CVE-2020-11793
    CVE-2020-14391
    CVE-2020-15503
    CVE-2020-3862
    CVE-2020-3864
    CVE-2020-3865
    CVE-2020-3867
    CVE-2020-3868
    CVE-2020-3885
    CVE-2020-3894
    CVE-2020-3895
    CVE-2020-3897
    CVE-2020-3899
    CVE-2020-3900
    CVE-2020-3901
    CVE-2020-3902
    CVE-2020-9802
    CVE-2020-9803
    CVE-2020-9805
    CVE-2020-9806
    CVE-2020-9807
    CVE-2020-9843
    CVE-2020-9850
    CVE-2020-9862
    CVE-2020-9893
    CVE-2020-9894
    CVE-2020-9895
    CVE-2020-9915
    CVE-2020-9925
    CVE-2020-9952
    CVE-2021-30666
    CVE-2021-30761
    CVE-2021-30762
    RHSA-2020:4451
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • webkit2gtk3 is earlier than 0:2.28.4-1.el8
  • AND webkit2gtk3 is signed with Red Hat redhatrelease2 key
  • webkit2gtk3-devel is earlier than 0:2.28.4-1.el8
  • AND webkit2gtk3-devel is signed with Red Hat redhatrelease2 key
  • webkit2gtk3-jsc is earlier than 0:2.28.4-1.el8
  • AND webkit2gtk3-jsc is signed with Red Hat redhatrelease2 key
  • webkit2gtk3-jsc-devel is earlier than 0:2.28.4-1.el8
  • AND webkit2gtk3-jsc-devel is signed with Red Hat redhatrelease2 key
  • LibRaw is earlier than 0:0.19.5-2.el8
  • AND LibRaw is signed with Red Hat redhatrelease2 key
  • LibRaw-devel is earlier than 0:0.19.5-2.el8
  • AND LibRaw-devel is signed with Red Hat redhatrelease2 key
  • gnome-settings-daemon is earlier than 0:3.32.0-11.el8
  • AND gnome-settings-daemon is signed with Red Hat redhatrelease2 key
  • BACK