Bug 29447 - qtwebengine5 new security issues fixed upstream in 5.15.6
Summary: qtwebengine5 new security issues fixed upstream in 5.15.6
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2021-09-08 22:19 CEST by David Walser
Modified: 2021-09-29 19:23 CEST (History)
3 users (show)

See Also:
Source RPM: qtwebengine5-5.15.5-1.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2021-09-08 22:19:29 CEST
Fedora has issued an advisory on September 7:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LMVCTGROJF6NNTYL2FOLPBBG6DMG6K45/

It updates the bundled Chromium code to a newer version with more security fixes.

Advisory:
========================

Updated qtwebengine5 packages fix security vulnerabilities:

The qtwebengine5 package has been updated to version 5.15.6, fixing several
security issues in the bundled chromium code.

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/LMVCTGROJF6NNTYL2FOLPBBG6DMG6K45/
========================

Updated packages in core/updates_testing:
========================
qtwebengine5-5.15.6-1.mga8
qtwebengine5-doc-5.15.6-1.mga8
libqt5pdf5-5.15.6-1.mga8
libqt5webengine-devel-5.15.6-1.mga8
libqt5webengine5-5.15.6-1.mga8
libqt5webenginewidgets5-5.15.6-1.mga8
libqt5pdfwidgets5-5.15.6-1.mga8
libqt5webenginecore5-5.15.6-1.mga8

from qtwebengine5-5.15.6-1.mga8.src.rpm
Comment 1 Herman Viaene 2021-09-15 15:17:49 CEST
MGA8-64 Plasma on Lenovo B50
No installation issues.
Ref bug 29249 for tests.
Tried different sites with konqueror. All display text and images OK, but on none do videos play,and at the CLI I see many of those:

[17816:13:0915/150026.298277:ERROR:batching_media_log.cc(38)] MediaEvent: {"error":"FFmpegDemuxer: no supported streams"}
[17816:1:0915/150026.300199:ERROR:batching_media_log.cc(35)] MediaEvent: {"pipeline_error":14}

Testing the previous update on the same laptop with the same sites did not bring this problem forward. I don't know what to make of it.

CC: (none) => herman.viaene

Comment 2 Thomas Andrews 2021-09-23 23:26:46 CEST
No installation issues here, either.

I see similar messages when playing a Transformers clip on Youtube. There were two ad clips before getting to the actual clip, and each generated something:

js: Refused to display 'https://accounts.google.com/' in a frame because it set 'X-Frame-Options' to 'deny'.
js: The resource https://i.ytimg.com/generate_204 was preloaded using link preload but not used within a few seconds from the window's load event. Please make sure it has an appropriate `as` value and it is preloaded intentionally.
js: Not allowed to load local resource: about:blank
js: Not allowed to load local resource: about:blank
[3518:3538:0923/170621.914870:ERROR:context_group.cc(146)] ContextResult::kFatalFailure: WebGL1 blocklisted
js: Not allowed to load local resource: about:blank
[3518:3538:0923/170628.186456:ERROR:context_group.cc(146)] ContextResult::kFatalFailure: WebGL1 blocklisted
libpng warning: iCCP: known incorrect sRGB profile
libpng warning: iCCP: known incorrect sRGB profile
js: Not allowed to load local resource: about:blank

However, this may indicate a bugfix. I noticed that when I ran konqueror from the command line, while it ran Konsole went right to the command prompt. If there had been messages, they would not have been reported before the update. After the update, the command prompt doesn't appear until after the window is closed.

The video is played to the conclusion, and if konqueror is run from the menu, no errors appear. 

I believe this is OK, Validating. Advisory in Comment 0.

CC: (none) => andrewsfarm, sysadmin-bugs
Whiteboard: (none) => MGA8-64-OK
Keywords: (none) => validated_update

Thomas Backlund 2021-09-29 18:06:32 CEST

Keywords: (none) => advisory

Comment 3 Mageia Robot 2021-09-29 19:23:58 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0443.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.