Fedora Linux 8567 Published by

A js-jquery-ui security update has been released for Fedora 34.



SECURITY: Fedora 34 Update: js-jquery-ui-1.13.0-1.fc34


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2021-ab38307fc3
2021-11-20 01:11:01.223658
--------------------------------------------------------------------------------

Name : js-jquery-ui
Product : Fedora 34
Version : 1.13.0
Release : 1.fc34
URL :   https://jqueryui.com/
Summary : jQuery user interface
Description :
A curated set of user interface interactions, effects, widgets, and
themes built on top of the jQuery JavaScript Library.

--------------------------------------------------------------------------------
Update Information:

jQuery UI 1.13.0
--------------------------------------------------------------------------------
ChangeLog:

* Thu Nov 11 2021 Mattias Ellert - 1.13.0-1
- Update to version 1.13.0
* Thu Jul 22 2021 Fedora Release Engineering - 1.12.1-3
- Rebuilt for   https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #2019145 - CVE-2021-41182 js-jquery-ui: jquery-ui: XSS in the altField option of the datepicker widget [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2019145
[ 2 ] Bug #2019149 - CVE-2021-41183 js-jquery-ui: jquery-ui: XSS in *Text options of the datepicker widget [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2019149
[ 3 ] Bug #2019154 - CVE-2021-41184 js-jquery-ui: jquery-ui: XSS in the 'of' option of the .position() util [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=2019154
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2021-ab38307fc3' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________