{"id":43774,"date":"2023-03-15T16:03:57","date_gmt":"2023-03-15T16:03:57","guid":{"rendered":"https:\/\/ubuntuhandbook.org\/?p=43774"},"modified":"2023-03-15T16:03:57","modified_gmt":"2023-03-15T16:03:57","slug":"liferea-1-14-1-critical-security-fix","status":"publish","type":"post","link":"https:\/\/ubuntuhandbook.org\/index.php\/2023\/03\/liferea-1-14-1-critical-security-fix\/","title":{"rendered":"Liferea News Reader 1.14.1 Released with A Critical Security Fix"},"content":{"rendered":"<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature.webp\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-thumbnail wp-image-36141\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature-250x250.webp\" alt=\"\" width=\"250\" height=\"250\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature-250x250.webp 250w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature-300x300.webp 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature-600x600.webp 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature-768x768.webp 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2021\/12\/liferea-feature.webp 1200w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><\/a><\/p>\n<p>For users of Liferea feed reader, new version 1.14.1 and 1.12.10 were released few days ago. All users are urged to upgrade due to an important security fix.<\/p>\n<p>Liferea is a free open-source GTK3 feed reader that brings together all of the content from your favorite subscriptions into a simple interface. It can synchronizes with Reedah, TinyTinyRSS, and Google Reader API.<\/p>\n<p>Just few days ago, it release new point releases for its 1.14 and 1.12 release series with an important security fix.<\/p>\n<p>It&#8217;s <a href=\"https:\/\/github.com\/advisories\/GHSA-9q9p-r5vc-g557\" target=\"_blank\" rel=\"noopener\">CVE-2023-1350<\/a> Remote code execution on feed enrichment.<\/p>\n<blockquote><p>If you have enabled &#8220;Extract full content from HTML5 and Google AMP&#8221; for one or more of your feed subscriptions it is possible for a an attacker to inject a script command that would run any command on your system.<\/p><\/blockquote>\n<p>All users are recommended to upgrade to the new release with this bug-fix.<\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/03\/liferea1141.webp\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-43776\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/03\/liferea1141-600x485.webp\" alt=\"\" width=\"600\" height=\"485\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/03\/liferea1141-600x485.webp 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/03\/liferea1141-300x243.webp 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/03\/liferea1141-768x621.webp 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/03\/liferea1141.webp 859w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p>Without the upgrade, user can alternatively disable &#8220;<i>Extract full content from HTML5 and Google AMP<\/i>&#8221; for all the feeds via following steps:<\/p>\n<ol>\n<li>Close Liferea<\/li>\n<li>Open <code>~\/.config\/liferea\/feedlist.opml<\/code> in an editor<\/li>\n<li>Replace all occurences of <code>html5Extract=\"true\"<\/code> with an empty string<\/li>\n<\/ol>\n<h3>How to Install Liferea 1.14.1 in Ubuntu:<\/h3>\n<p>For most Linux, Liferea is available to install as <a href=\"https:\/\/flathub.org\/apps\/details\/net.sourceforge.liferea\" target=\"_blank\" rel=\"noopener\">Flatpak package<\/a>, that runs in sandbox.<\/p>\n<p>Ubuntu users can also use the <a href=\"https:\/\/launchpad.net\/~ubuntuhandbook1\/+archive\/ubuntu\/apps\" target=\"_blank\" rel=\"noopener\">unofficial PPA<\/a>, which so far supports for <b>Ubuntu 20.04<\/b>, <b>Ubuntu 22.04<\/b>, <b>Ubuntu 22.10<\/b>, <b>Linux Mint 20\/21<\/b>, and their based systems.<\/p>\n<p><b>1.<\/b> First, press <b>Ctrl+Alt+T<\/b> on keyboard to open terminal. When it opens, run command to add the PPA:<\/p>\n<pre>sudo add-apt-repository ppa:ubuntuhandbook1\/apps<\/pre>\n<p><i>Type user password (no asterisk feedback) and hit Enter to continue.<\/i><\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/handbook-apps-jammy.webp\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-43564\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/handbook-apps-jammy-600x402.webp\" alt=\"\" width=\"600\" height=\"402\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/handbook-apps-jammy-600x402.webp 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/handbook-apps-jammy-300x201.webp 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/handbook-apps-jammy-768x515.webp 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/handbook-apps-jammy.webp 849w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<p><b>2.<\/b> Then, install the Liferea package by running command:<\/p>\n<pre>sudo apt install liferea<\/pre>\n<p><i>Linux Mint user may have to run <code>sudo apt update<\/code> first to update cache.<\/i><\/p>\n<p><a href=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/apt-liferea-jammy.webp\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-large wp-image-43565\" src=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/apt-liferea-jammy-600x268.webp\" alt=\"\" width=\"600\" height=\"268\" srcset=\"https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/apt-liferea-jammy-600x268.webp 600w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/apt-liferea-jammy-300x134.webp 300w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/apt-liferea-jammy-768x344.webp 768w, https:\/\/ubuntuhandbook.org\/wp-content\/uploads\/2023\/01\/apt-liferea-jammy.webp 778w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/a><\/p>\n<h3>Uninstall:<\/h3>\n<p>The PPA also contains some other software packages, so you may remove it immediately after installed Liferea.<\/p>\n<p>To do so, either run the command below in terminal, or remove the source line under <b>&#8220;Other Software&#8221;<\/b> tab in <b>Software &amp; Updates<\/b> tool.<\/p>\n<pre>sudo add-apt-repository --remove ppa:ubuntuhandbook1\/apps<\/pre>\n<p>To remove the feed reader package, simply run command:<\/p>\n<pre>sudo apt remove --autoremove liferea-data liferea<\/pre>\n<p>That&#8217;s all. Enjoy!<\/p>","protected":false},"excerpt":{"rendered":"<p>For users of Liferea feed reader, new version 1.14.1 and 1.12.10 were released few days ago. All users are urged to upgrade due to an important security fix. Liferea is a free open-source GTK3 feed reader that brings together all of the content from your favorite subscriptions into a simple interface. It can synchronizes with [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":36141,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[45],"class_list":["post-43774","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-howtos","tag-feed-reader"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/posts\/43774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/comments?post=43774"}],"version-history":[{"count":0,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/posts\/43774\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/media\/36141"}],"wp:attachment":[{"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/media?parent=43774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/categories?post=43774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ubuntuhandbook.org\/index.php\/wp-json\/wp\/v2\/tags?post=43774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}