Security Fixes 11.05.100
Citrix
- Fixed file properties for
/var/log/.ctxlogconf
adjusted, so no code can be executed by the user.
Firefox
- Added
view-source:file:///
to the blocklist in case the browser should not have random access to the local file system.
Base system
- Fixed bluez security issue CVE-2020-0556.
- Fixed librsvg security issue CVE-2019-20446.
- Fixed ppp security issue CVE-2020-15704.
Fixed chromium-browser security issues:
- Fixed ffmpeg security issues CVE-2020-14212, CVE-2020-13904, CVE-2020-35965, and CVE-2020-35964.
- Fixed pulseaudio security issues CVE-2020-11931 and CVE-2020-16123.
- Fixed nss security issues CVE-2020-6829, CVE-2020-12401, CVE-2020-12400, and CVE-2020-12403.
- Fixed libvirt security issues CVE-2020-14301, CVE-2020-12430, CVE-2020-10701, and CVE-2020-14339.
- Fixed libslirp security issues CVE-2020-10756, CVE-2020-29130, and CVE-2020-29129.
Fixed samba security issues:
Fixed qemu security issues:
- Fixed bind9 security issues CVE-2020-8624, CVE-2020-8623, and CVE-2020-8622.
Fixed grub2 security issues:
Fixed sane-backends security issues:
Fixed ghostscript security issues:
- Fixed net-snmp security issues CVE-2020-15862 and CVE-2020-15861.
Fixed curl security issues:
- Fixed chrony security issue CVE-2020-14367.
- Fixed libx11 security issue CVE-2020-14344.
Fixed xorg-server security issues:
- Fixed cairo security issues CVE-2018-19876 and CVE-2020-35492.
Fixed openssl1.0 security issues:
- Fixed libproxy security issues CVE-2020-25219 and CVE-2020-26154.
- Fixed gnupg2 security issue CVE-2019-14855.
- Fixed util-linux security issue CVE-2018-7738.
- Fixed ntp security issue CVE-2019-8936.
- Fixed tigervnc security issue CVE-2020-26117.
- Fixed brotli security issue CVE-2020-8927.
- Fixed vim security issue CVE-2019-20807.
- Fixed python2.7 security issue CVE-2020-26116.
- Fixed python3.6 security issue CVE-2020-26116.
- Fixed freetype security issue CVE-2020-15999.
- Fixed perl security issues CVE-2020-12723, CVE-2020-10878 and CVE-2020-10543.
- Fixed spice security issue CVE-2020-14355.
- Fixed glibc security issue CVE-2017-18269.
- Fixed python-cryptography security issue CVE-2020-25659.
- Fixed openldap security issues CVE-2020-25692, CVE-2020-25710, and CVE-2020-25709.
- Fixed libexif security issue CVE-2020-0452.
- Fixed krb5 security issue CVE-2020-28196.
- Fixed libvncserver security issues CVE-2018-21247, and CVE-2020-14396.
- Fixed poppler security issues CVE-2020-27778, CVE-2019-9959, CVE-2019-10871, and CVE-2018-21009.
- Fixed xdg-utils security issue CVE-2020-27748.
- Fixed wpa security issue CVE-2020-12695.
- Fixed x11vnc security issue CVE-2020-29074.
- Fixed spice-gtk security issue CVE-2020-14355.
- Fixed libssh2 security issues CVE-2019-17498 and CVE-2019-13115.
Fixed spice-vdagent security issues:
- Fixed openssl security issue CVE-2020-1971.
- Fixed libxml2 security issue CVE-2020-24977.
Fixed webkit2gtk security issues:
- Fixed lxml security issue CVE-2020-27783.
- Fixed p11-kit security issues CVE-2020-29363, CVE-2020-29362, and CVE-2020-29361.
- Fixed wavpack security issue CVE-2020-35738.
- Fixed nvidia-graphics-drivers-450 security issues CVE-2021-1053 and CVE-2021-1052.
- Fixed tar security issues CVE-2019-9923 and CVE-2018-20482.
- Fixed pillow security issues CVE-2020-35655 and CVE-2020-35653.
Fixed dnsmasq security issues:
- Fixed sudo security issues CVE-2021-3156 and CVE-2021-23239.
- Fixed privilege escalation via environment variable
PATH
in/bin/usershell
binary. - Fixed privilege escalation via environment variables in the
/bin/update
binary. - Fixed BleedingTooth security issue which means CVE-2020-12351, CVE-2020-12352 and CVE-2020-24490.
- Fixed kernel security issues named Platypus (CVE-2020-8694 and CVE-2020-8695).
- Fixed possible security issue
- Fixed a local command injection with SSH session.
Remote Management
- Added secure channel for following commands
show_message
,get_file_from_url
,write_file_to_url
andupload_tc_support_information
sends all relevant data in a secured way.
VNC
- Fixed a secure terminal and secure VNC shadowing remote code execution vulnerability.