Fedora 32 : kf5-messagelib / qt5-qtwebengine (2021-bdaf015218)

high Nessus Plugin ID 146054

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 32 host has packages installed that are affected by a vulnerability as referenced in the FEDORA-2021-bdaf015218 advisory.

- This update rebases QtWebEngine to the latest Qt 5 release, 5.15.2, fixing dozens of security issues. (The same version is already shipped on Fedora 33 and Rawhide.) The included kf5-messagelib update backports a fix for compatibility with QtWebEngine 5.15.x. The Chromium version has been updated to 83.0.4103.122, with backported security fixes from Chromium up to version 86.0.4240.183. That fixes dozens of security issues compared to 5.14.2. This version also adds the Qt PDF module, a Qt wrapper around PDFium. This is a separate library and cannot cause backwards compatibility issues. In addition, several bugs have been fixed, see the Changes files: * https://code.qt.io/cgit/qt/qtwebengine.git/tree/dist/changes-5.15.0?h=5.15 * https://code.qt.io/cgit/qt/qtwebengine.git/tree/dist/changes-5.15.1?h=5.15 * https://code.qt.io/cgit/qt/qtwebengine.git/tree/dist/changes-5.15.2?h=5.15 Behavior Changes since 5.14.2:
* XSS Auditing has been removed, and the XSSAuditingEnabled setting no longer has any effect. * [QTBUG-79864] The viz display compositor is now used by default on all platforms, but can be disabled with
--disable-viz-display-compositor. * The network layer integration has been rewritten to use Chromium's network service, and now runs in a separate sandboxed process by default. * [QTBUG-83656] CTRL+mouse wheel page zoom fixed, and now works by default. (FEDORA-2021-bdaf015218)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected kf5-messagelib and / or qt5-qtwebengine packages.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2021-bdaf015218

Plugin Details

Severity: High

ID: 146054

File Name: fedora_2021-bdaf015218.nasl

Version: 1.2

Type: local

Agent: unix

Published: 2/2/2021

Updated: 4/12/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:32, p-cpe:/a:fedoraproject:fedora:kf5-messagelib, p-cpe:/a:fedoraproject:fedora:qt5-qtwebengine

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 1/26/2021

Vulnerability Publication Date: 1/26/2021

Reference Information