[ALSA-2020:4436] Low: gnome-software and fwupd security, bug fix, and enhancement update
Type:
security
Severity:
low
Release date:
2022-07-20
Description:
The gnome-software packages contain an application that makes it easy to add, remove, and update software in the GNOME desktop. The appstream-data package provides the distribution specific AppStream metadata required for the GNOME and KDE software centers. The fwupd packages provide a service that allows session software to update device firmware. The following packages have been upgraded to a later upstream version: gnome-software (3.36.1), fwupd (1.4.2). Security Fix(es): * fwupd: Possible bypass in signature verification (CVE-2020-10759) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libxmlb-0.1.15-1.el8.aarch64.rpm 518628277656002801a17820ab58658af415976f47b534a52eb07c64771e4271
noarch appstream-data-8-20200724.el8.noarch.rpm 1accbb7e4a762fb991df3a47f204bb0c4c77f40e23edca1d4bfa17448c3659f4
ppc64le libxmlb-0.1.15-1.el8.ppc64le.rpm 4ecb5204e65e24fea5a76a851a6fc9ccf124713e2d8fbe8df2390357f1e01806
x86_64 libxmlb-0.1.15-1.el8.x86_64.rpm 0e4835b0e72754669825c84cfd2ec9267eba458270597079a7da855be3d88836
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.