FlawAtlas
Search the atlas
ALSA-2021:1586 Not scored

Moderate: GNOME security, bug fix, and enhancement update

GNOME is the default desktop environment of AlmaLinux. The following packages have been upgraded to a later upstream version: accountsservice (0.6.55), webkit2gtk3 (2.30.4). (BZ#1846376, BZ#1883304) Security Fix(es): * webkitgtk: type confusion may lead to arbitrary code execution (CVE-2020-9948) * webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-9951) * webkitgtk: out-of-bounds write may lead to code execution (CVE-2020-9983) * webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13543) * webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13584) * glib2: insecure permissions for files and directories (CVE-2019-13012) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

Exploit probability Not scored
Published May 18, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:8 cairomm-doc
AlmaLinux:8 vala-devel
AlmaLinux:8 nautilus-extensions
AlmaLinux:8 pangomm
AlmaLinux:8 gtkmm24
AlmaLinux:8 gvfs-goa
AlmaLinux:8 gtk2-devel-docs
AlmaLinux:8 gtk2
AlmaLinux:8 gtkmm24-docs
AlmaLinux:8 nautilus
AlmaLinux:8 woff2
AlmaLinux:8 glib2-doc
AlmaLinux:8 geocode-glib-devel
AlmaLinux:8 geoclue2-libs
AlmaLinux:8 dleyna-core
AlmaLinux:8 vala
AlmaLinux:8 gnome-photos-tests
AlmaLinux:8 atkmm
AlmaLinux:8 cairomm-devel
AlmaLinux:8 gtk2-devel
AlmaLinux:8 nautilus-devel
AlmaLinux:8 gtkmm24-devel
AlmaLinux:8 enchant2
AlmaLinux:8 gvfs-devel
AlmaLinux:8 libvisual
AlmaLinux:8 glibmm24
AlmaLinux:8 dleyna-server
AlmaLinux:8 glibmm24-doc
AlmaLinux:8 gvfs-afc
AlmaLinux:8 gjs-devel
AlmaLinux:8 libepubgen
AlmaLinux:8 pangomm-devel
AlmaLinux:8 libsass
AlmaLinux:8 libsass-devel
AlmaLinux:8 libvisual-devel
AlmaLinux:8 gvfs-archive
AlmaLinux:8 gtkmm30
AlmaLinux:8 soundtouch
AlmaLinux:8 gvfs-fuse
AlmaLinux:8 gvfs-smb
AlmaLinux:8 gnome-boxes
AlmaLinux:8 gamin
AlmaLinux:8 glibmm24-devel
AlmaLinux:8 gtk2-immodule-xim
AlmaLinux:8 libdazzle-devel
AlmaLinux:8 gvfs-client
AlmaLinux:8 gtkmm30-doc
AlmaLinux:8 enchant2-devel
AlmaLinux:8 gtk-doc
AlmaLinux:8 chrome-gnome-shell
AlmaLinux:8 geoclue2-demos
AlmaLinux:8 gnome-photos
AlmaLinux:8 OpenEXR-libs
AlmaLinux:8 geocode-glib
AlmaLinux:8 libsigc++20-devel
AlmaLinux:8 gvfs-gphoto2
AlmaLinux:8 atkmm-doc
AlmaLinux:8 geoclue2-devel
AlmaLinux:8 mutter-devel
AlmaLinux:8 pangomm-doc
AlmaLinux:8 gjs
AlmaLinux:8 geoclue2
AlmaLinux:8 libdazzle
AlmaLinux:8 gtkmm30-devel
AlmaLinux:8 gamin-devel
AlmaLinux:8 gnome-terminal-nautilus
AlmaLinux:8 libsigc++20-doc
AlmaLinux:8 gvfs-mtp
AlmaLinux:8 gtk2-immodules
AlmaLinux:8 gvfs
AlmaLinux:8 OpenEXR-devel
AlmaLinux:8 gvfs-afp
AlmaLinux:8 soundtouch-devel
AlmaLinux:8 glib2-static
AlmaLinux:8 woff2-devel
AlmaLinux:8 libepubgen-devel
AlmaLinux:8 atkmm-devel
AlmaLinux:8 cairomm
AlmaLinux:8 accountsservice-devel
AlmaLinux:8 gnome-terminal
AlmaLinux:8 libsigc++20

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2021:1586

GNOME is the default desktop environment of AlmaLinux. The following packages have been upgraded to a later upstream version: accountsservice (0.6.55), webkit2gtk3 (2.30.4). (BZ#1846376, BZ#1883304) Security Fix(es): * webkitgtk: type confusion may lead to arbitrary code execution (CVE-2020-9948) * webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-9951) * webkitgtk: out-of-bounds write may lead to code execution (CVE-2020-9983) * webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13543) * webkitgtk: use-after-free may lead to arbitrary code execution (CVE-2020-13584) * glib2: insecure permissions for files and directories (CVE-2019-13012) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

View original source

05 / REFERENCES

Further evidence