GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    Tom Sellers (tomsellers@infosec.exchange)'s status on Tuesday, 26-Sep-2023 23:55:12 JSTTom SellersTom Sellers
    in reply to
    • Jason Levine

    The patched (fixed) versions of Electron are

    Electron v22.3.24, v24.8.3, v25.8.1 - released September 13 and fixes CVE-2023-4863 as well as CVE-2023-4763, CVE-2023-4762, and CVE-2023-4761

    Electron v26.2.1 - released September 13 and updates Chrome. Fixes the CVEs but does not call them out

    Here are the fixed versions of some other common software:

    GitHub Desktop v3.3.3 - bumps Electron to v24.8.3 which fixes CVE-2023-4863

    VS Code 1.82.2 - bumps Electron to v25.8.1 which fixes CVE-2023-4863

    Signal Desktop v6.30.2 - bumps Electron to v25.8.1 which fixes CVE-2023-4863

    Slack v4.34.119 - bumps Electron to v26.2.1, indicates a security fix but doesn't label it with its highest risk label

    Apple iOS 16.7, 17.0.1
    Apple iPadOS 16.7, 17.0.1
    Apple macOS Ventura 13.6
    Apple macOS Monterey 12.7
    Apple watchOS 9.6.3, 10.0.1
    Apple Safari 16.6.1

    Google Chrome 116.0.5845.187 for Mac and Linux and 116.0.5845.187/.188 for Windows

    Mozilla Firefox 117.0.1, ESR 102.15.1, ESR 115.2.1
    Mozilla Thunderbird 102.15.1, 115.2.2

    Edit: Added Electron v22.3.24 to the patched list. Thanks @delfuego

    In conversationTuesday, 26-Sep-2023 23:55:12 JST from infosec.exchangepermalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.