From 6966718bf08a312b2c1f9fb83d3655e5dfc22539e2ddaf04f537b8b62a17e9e0 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Bj=C3=B8rn=20Lie?= Date: Fri, 17 Mar 2023 15:42:54 +0000 Subject: [PATCH] Accepting request 1072671 from home:AndreasStieger:branches:GNOME:Factory bugzilla references OBS-URL: https://build.opensuse.org/request/show/1072671 OBS-URL: https://build.opensuse.org/package/show/GNOME:Factory/flatpak?expand=0&rev=183 --- flatpak.changes | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/flatpak.changes b/flatpak.changes index 45aff4e..4cc42b3 100644 --- a/flatpak.changes +++ b/flatpak.changes @@ -5,13 +5,13 @@ Thu Mar 16 16:15:42 UTC 2023 - Bjørn Lie + Escape special characters when displaying permissions and metadata, preventing malicious apps from manipulating the appearance of the permissions list using crafted metadata - (CVE-2023-28101). + (CVE-2023-28101, boo#1209410). + If a Flatpak app is run on a Linux virtual console (tty1, tty2, etc.), don't allow copy/paste via the TIOCLINUX ioctl (CVE-2023-28100). Note that this is specific to virtual consoles: Flatpak is not vulnerable to this if run from a graphical terminal emulator such as xterm, gnome-terminal or - Konsole. + Konsole. (boo#1209411) + Updated translations. -------------------------------------------------------------------