{
  "cves": [
    "CVE-2021-30682",
    "CVE-2021-1871",
    "CVE-2020-24870",
    "CVE-2021-1765",
    "CVE-2021-1789",
    "CVE-2021-30744",
    "CVE-2020-27918",
    "CVE-2021-1799",
    "CVE-2021-1801",
    "CVE-2020-36241",
    "CVE-2021-30663",
    "CVE-2020-29623",
    "CVE-2021-30720",
    "CVE-2020-13558",
    "CVE-2021-21779",
    "CVE-2021-21806",
    "CVE-2021-28650",
    "CVE-2021-30758",
    "CVE-2021-1788",
    "CVE-2021-1844",
    "CVE-2021-1870",
    "CVE-2021-21775",
    "CVE-2021-30734",
    "CVE-2021-30749",
    "CVE-2021-30689",
    "CVE-2021-30795",
    "CVE-2021-30665",
    "CVE-2021-30799",
    "CVE-2021-30797"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "MODERATE"
  },
  "description": "accountsservice\n[0.6.55-2]\n- Add support for user templates so user can specify default session\n  Resolves: #1812788\n\ngdm\n[40.0-14]\n- Fix XDMCP\n  Resolves: #2004170\n- Fix crash at shutdown\n  Related: #2004170\n\n[40.0-13]\n- Disable Wayland on HyperV\n- Fix Xorg fallback\n  Related: #1998989\n\n[40.0-12]\n- Redisable on server chips since rebase\n  Related: #1909300\n\n[40.0-11]\n- Read session settings from users even if theyve never saved\n  before. Needed to support accountsservice templated user\n  defaults.\n  Related: #1812788\n\n[40.0-10]\n- Let customers using vendor nvidia driver choose wayland sessions\n  Resolves: #1962211\n- Drop unused patches\n\n[40.0-3]\n- Disable network items on login screen\n  Resolves: #1935261\n\n[40.0-2]\n- Fix workaround for systemd bug thats breaking X11 fallback\n  Resolves: #1962049\n\n[40.0-1]\n- Rebase to 40.0\n  Resolves: #1909300\n\ngnome-autoar\n[0.2.3-2]\n- CVE-2020-36241, CVE-2021-28650: Do not allow symlink in parents (rhbz#1928701)\n\ngnome-calculator\n[3.28.2-2]\n- Allow disabling downloading by setting refresh interval to 0\n  Resolves: #1957705\n\ngnome-control-center\n[3.28.2-28]\n- Update pt_BR translations\n- Resolves: #1978612\n\ngnome-online-accounts\n[3.28.2-3]\n- Disable the Facebook and Foursquare providers\nResolves: #1951086, #1952136\n\ngnome-session\n[3.28.1-13.0.1]\n- Update kiosk-session subpackage with Oracle references [Orabug: 32095108]\n\n[3.28.1-13]\n- Add patch to tell grub boot was successful when user is\n  able to explicitly request shutdown/reboot.\n  Resolves: #1914925\n\n[3.28.1-12]\n- Introduce gnome-wayland session to allow users that use\n  Xorg on the login screen to try wayland for the user session.\n  Related: #1962211\n\n[3.28.1-11]\n- Exclude kiosk-session from xsession subpackage\n- Disable VT switching when kiosk-session is installed\n  Related: #1955754\n\ngnome-settings-daemon\n[3.32.0-16]\n- Update pt_BR translations\n- Resolves: #1978612\n\n[3.32.0-15]\n- Keep auto-logout working inside VMs\n  Resolves: #1904139\n\ngnome-shell\n[3.32.2-40]\n- Add bugs introduced in backport for #1651378\n  Related: #1999758\n- Tidy up patch list a bit\n\n[3.32.2-39]\n- Allow extensions on the login screen\n  Related: #1651378\n\n[3.32.2-38]\n- Only mask text in password entries\n  Resolves: #1987233\n\n[3.32.2-37]\n- Only warn once when not running under GDM\n  Resolves: #1980661\n\n[3.32.2-36]\n- Add ability to lock down password showing\n  Resolves: #1770302\n- Add requires on newer mutter version\n  Related: #1937866\n\n[3.32.2-35]\n- Improve style of window preview close buttons\n  Resolves: #1981420\n\n[3.32.2-34]\n- Add PolicyKit-authentication-agent virtual provides\n  Resolves: #1978287\n\n[3.32.2-33]\n- Fix warnings on unlock\n  Resolves: #1971534\n- Fix gdm lock screen\n  Resolves: #1971507\n\n[3.32.2-32]\n- Fix network secret requests on login screen\n  Related: #1935261\n\n[3.32.2-31]\n- Backport of touch mode\n  Resolves: #1937866\n\ngnome-shell-extensions\n[3.32.1-20]\n- Add extension for displaying heads up message\n  Related: #1651378\n\n[3.32.1-19]\n- Dont use status icon wm_class as top bar role\n  Resolves: #1897932\n\n[3.32.1-18]\n- Add gesture-inhibitor extension\n  Resolves: #1854679\n\n[3.32.1-17]\n- Handle touchscreens on Wayland in the desktop-icons extension\n  Resolves: #1924725\n\n[3.32.1-16]\n- Fix opening files with (wrongly) set executable bit\n  Resolves: #1813727\n\ngnome-software\n[3.36.1-10]\n- Resolves: #1978505 (Development package is missing important header files)\n\n[3.36.1-9]\n- Resolves: #1972545 (flatpak: Prefer runtime from the same origin as the application)\n\n[3.36.1-8]\n- Resolves: #1888404 (Updates page hides ongoing updates on refresh)\n\n[3.36.1-7]\n- Resolves: #1873297 (Crash when run as root)\n\n[3.36.1-6]\n- Resolves: #1791478 (Cannot completely disable ODRS (GNOME Ratings))\n\ngsettings-desktop-schemas\n[3.32.0-6]\n- Add setting for locking down Show Password in entries\n  Related: #1770302\n\ngtk3\n[3.22.30-8]\n- Make reftests work in a vm\n\n[3.22.30-7]\n- Only mention Emoji in context menus when requested (rhbz#1893196)\n- Fix warnings from non-overlay scrollbars (rhbz#1873488)\n\nLibRaw\n[0.19.5-3]\n- Backport fix for CVE-2020-24870 from upstream\nResolves: #1931841\n\nmutter\n[3.32.2-60]\n- Backport fix avoiding DND regression\n  Resolves: #1999120\n\n[3.32.2-59]\n- Backport fixes avoiding frozen partly off-screen clients\n  Resolves: #1989035\n\n[3.32.2-58]\n- Backport xauth and xhost patches\n  Resolves: #1949176\n\nvino\n[3.22.0-11]\n- Fix crashes under FIPS\n- Resolves: #1960705\n\nwebkit2gtk3\n[2.32.3-2]\n- Fix CVE-2021-30858\n- Resolves: #2006428\n\n[2.32.3-1]\n- Update to 2.32.3\n- Related: #1937416\n\n[2.32.2-1]\n- Update to 2.32.2\n- Related: #1937416\n\n[2.32.1-1]\n- Update to 2.32.1\n- Related: #1937416\n\n[2.32.0-1]\n- Update to 2.32.0\n- Related: #1937416",
  "id": "ELSA-2021-4381",
  "ovalId": "oval:com.oracle.elsa:def:20214381",
  "source": "oracle_linux",
  "title": "ELSA-2021-4381:  GNOME security, bug fix, and enhancement update (MODERATE)",
  "url": "https://linux.oracle.com/errata/ELSA-2021-4381.html"
}