Update NEWS

Signed-off-by: Simon McVittie <smcv@collabora.com>
This commit is contained in:
Simon McVittie
2024-04-17 18:16:44 +01:00
parent 25ef001b1e
commit 381bc1a06b

10
NEWS
View File

@@ -1,3 +1,13 @@
Changes in 1.10.9
~~~~~~~~~~~~~~~~~
Security fixes:
* Don't allow an executable name to be misinterpreted as a command-line
option for bwrap(1). This prevents a sandbox escape where a malicious
or compromised app could ask xdg-desktop-portal to generate a .desktop
file with access to files outside the sandbox. (CVE-2024-32462)
Changes in 1.10.8
~~~~~~~~~~~~~~~~~
Released: 2023-03-16