~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Service Pack 10 for ThinPro 8.0 10.1 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 1. Service Pack 10 for ThinPro 8.0 ============================================================================ HP announces the service pack 'Service Pack 10 for ThinPro 8.0'. 2. Support Matrix ============================================================================ Package Platform Image ---------------------------------------------------------------------------- ThinPro8.0_SP-10.1-signed.xar PC 8.0 ThinPro8.0_SP-10.1-signed.xar mt21 8.0 ThinPro8.0_SP-10.1-signed.xar mt22 8.0 ThinPro8.0_SP-10.1-signed.xar mt32 8.0 ThinPro8.0_SP-10.1-signed.xar mt440 8.0 ThinPro8.0_SP-10.1-signed.xar mt45 8.0 ThinPro8.0_SP-10.1-signed.xar mt46 8.0 ThinPro8.0_SP-10.1-signed.xar mt645 8.0 ThinPro8.0_SP-10.1-signed.xar t430 8.0 ThinPro8.0_SP-10.1-signed.xar t530 8.0 ThinPro8.0_SP-10.1-signed.xar t540 8.0 ThinPro8.0_SP-10.1-signed.xar t550 8.0 ThinPro8.0_SP-10.1-signed.xar t630 8.0 ThinPro8.0_SP-10.1-signed.xar t638 8.0 ThinPro8.0_SP-10.1-signed.xar t640 8.0 ThinPro8.0_SP-10.1-signed.xar t655 8.0 ThinPro8.0_SP-10.1-signed.xar t730 8.0 ThinPro8.0_SP-10.1-signed.xar t740 8.0 3. What's New ============================================================================ SP10 (v10.1) - Fixed an issue where audio input and output functionality was lost in the system tray. - Resolved incorrect "Disabled" status in Network Information when LAN Dash is enabled. - Fixed an issue preventing LAN Dash activation. - Addressed network and wireless icons not updating to "Connected" status after connecting to certain access points. - Resolved connectivity issues preventing switching between access points. - Fixed an issue preventing ThinState USB from restoring images to thin clients. - Resolved errors when running hptc-bios-cfg and hptc-bios-flash in XTerm. - Fixed network reconnection failure after sleep and wake-up cycles. - Addressed an issue where only one 4K monitor lights up when connecting two via DP port. - Fixed installation hang issues when using Easy Update for SP10.1 package. - Resolved errors when installing the ThinPro 8.0 SP10.1 signed package. - Fixed issues preventing package installation via Easy Update and USB Update. - Addressed a storage resizing issue where storage could not expand to maximum capacity after an aborted FTP image capture. - Fixed a system crash issue when updating Citrix to version 24.2 and capturing an image using HPDM or ThinState. - Resolved a service pack installation failure when updating from TP8.0-SP7.3/8.3/9.1. - Fixed an issue preventing partial profile imports without registry settings. - Bind :: CVE-2024-1737, CVE-2024-0760, CVE-2024-4076, CVE-2024-1975 - BlueZ :: CVE-2022-3563, CVE-2023-27349 - BusyBox :: CVE-2023-42363, CVE-2023-42364, CVE-2023-42365, CVE-2022-48174 - curl :: CVE-2024-7264 - FFmpeg :: CVE-2024-31578, CVE-2023-49502, CVE-2023-51796, CVE-2023-51798, CVE-2023-51795, CVE-2024-31582, CVE-2023-51793, CVE-2023-49528, CVE-2023-50007, CVE-2023-51794, CVE-2023-50008, CVE-2024-31585, CVE-2023-49501, CVE-2023-50010, CVE-2023-50009 - GDK-PixBuf :: CVE-2022-48622 - Ghostscript :: CVE-2024-33869, CVE-2024-33870, CVE-2024-29511, CVE-2024-29507, CVE-2024-29508, CVE-2024-29510, CVE-2024-29506, CVE-2024-33871, CVE-2023-52722, CVE-2024-29509 - GIFLIB :: CVE-2021-40633, CVE-2022-28506, CVE-2023-39742 - GLib :: CVE-2024-34397 - GNU C Library :: CVE-2024-33600, CVE-2024-33599, CVE-2024-33602, CVE-2024-33601 - GStreamer Base Plugins :: CVE-2024-4453 - GTK :: CVE-2024-6655 - idna :: CVE-2024-3651 - Kerberos :: CVE-2024-37371, CVE-2024-37370 - Libcroco :: CVE-2020-12825, CVE-2017-7960, CVE-2017-8871, CVE-2017-8834 - LibTIFF :: CVE-2023-3164 - libvpx :: CVE-2024-5197 - MySQL :: CVE-2024-21096, CVE-2024-20996, CVE-2024-20998, CVE-2024-21171, CVE-2024-21000, CVE-2024-21009, CVE-2024-21102, CVE-2024-21060, CVE-2024-21047, CVE-2024-21127, CVE-2024-21129, CVE-2024-21054, CVE-2024-21185, CVE-2024-20994, CVE-2024-21069, CVE-2024-21173, CVE-2024-21013, CVE-2024-21087, CVE-2024-21062, CVE-2024-21130, CVE-2024-21142, CVE-2024-21162, CVE-2024-21125, CVE-2024-21134, CVE-2024-21177, CVE-2024-21179, CVE-2024-21008, CVE-2024-21163, CVE-2024-21165 - NSS :: CVE-2023-6135, CVE-2023-5388, CVE-2023-4421 - OpenSSL :: CVE-2024-4741, CVE-2024-4603, CVE-2024-5535, CVE-2024-2511 - ORC :: CVE-2024-40897 - Python :: CVE-2019-20907, CVE-2020-14422, CVE-2020-8492, CVE-2018-1061, CVE-2023-41105, CVE-2019-9948, CVE-2022-48560, CVE-2019-5010, CVE-2020-27619, CVE-2019-16056, CVE-2018-20852, CVE-2022-45061, CVE-2021-3177, CVE-2023-6597, CVE-2021-3426, CVE-2022-42919, CVE-2022-48564, CVE-2024-4032, CVE-2022-0391, CVE-2022-48565, CVE-2019-16935, CVE-2018-1060, CVE-2019-9740, CVE-2020-26116, CVE-2021-29921, CVE-2021-3733, CVE-2019-10160, CVE-2022-48566, CVE-2024-0450, CVE-2019-18348, CVE-2023-6507, CVE-2019-9947, CVE-2019-17514, CVE-2015-20107, CVE-2021-3737, CVE-2018-20406, CVE-2023-24329, CVE-2024-0397, CVE-2021-4189, CVE-2018-14647, CVE-2019-9636, CVE-2019-9674, CVE-2023-40217 - TPM2 Software Stack :: CVE-2023-22745, CVE-2024-29040 - Wget :: CVE-2024-38428 - wpa_supplicant and hostapd :: CVE-2024-5290 4. Documentation Set ============================================================================ There is no additional documentation associated with this softpaq. 5. Installation ============================================================================ 5.1 Installing update for ThinPro To install this addon: 1. Use the installer to deploy files to the server. 2. Copy the add-on from the appropriate directory to the "/tmp" directory. 3. On the device, run the command as follows: "xarinstall /tmp/ThinPro8.0_SP-10.1-signed.xar" 4. Reboot the affected devices. Tip: This section describes the manual process of installing packages. To perform the recommended update method, use "Easy Update" in the ThinPro Control Panel. For detailed information see the "HP ThinPro Administrator's Guide". 6. Known Issues ============================================================================ There are no known issues. 7. Additional Notes ============================================================================ There are no additional notes. 8. Release History ============================================================================ 2024-09-11 Package version 10.1 - First official installer release SP9 (v9.1) - Fixed Set Timezone via DHCP Options Fail - Fixed Time is not updated automatically after applying Mutiple time server addresses in 'Use these time Server' option. - Fixed hptc-bios-cfg commands not working - Fixed SNMP packets are sent at startup - SQLite vulnerabilities - CVE-2022-46908, CVE-2023 7104 - OpenSSH vulnerabilities - CVE-20221-41617, CVE-2012-51384, CVE-2023-51385 - TeX Live vulnerability - CVE-2023-32700 - Xerces-C++ vulnerability - CVE-2018-1311 - Bind vulnerabilities - CVE-2023-50868, CVE-2023-6516, CVE-2023-5517, CVE-2023-50387, CVE-2023-4408 - curl Vulnerabilities - CVE-2023-2398, CVE-2024-2004 - GnuTLS vulnerabilities - CVE-2024-0567, CVE-2024-0553 - GNU C Library vulnerability - CVE-2024-2961 - libxml2 vulnerability - CVE-2024-25062 - less vulnerability - CVE-2022-48624 - libuv vulnerability - CVE-2024-24806 - PAM vulnerability - CVE-2024-22365 - OpenLDAP vulnerability - CVE-2023-2953 - Vim vulnerability - CVE-2024-22667 - util-linux vulnerability - CVE-2024-28085 - Pillow vulnerabilities - CVE-2023-50447, CVE-44271 - GNU cpio vulnerabilities - CVE-2023-7207 - GLib vulnerability - CVE-2024-34397 - idna vulnerability - CVE-2024-3651 - GStreamer Base Plugins vulnerability - CVE-2024-4453 - util-linux vulnerability - CVE-2024-28085 - GnuTLS vulnerabilities - CVE-2024-0567, CVE-2024-0553 - shadow vulnerability - CVE-2023-4641 - klibc vulnerabilities - CVE-2022-37434, CVE-2016-9841, CVE-2016-9840, CVE-2018-25032 - libssh vulnerabilities - CVE2023-6918, CVE-2023-6004 - LibTIFF vulnerabilities - CVE-2023-52356, CVE-2023-6277, CVE-2023-6228 - NSS regression - CVE-2023-5388, CVE-2023-4421, CVE-2023-6135 - MySQL vulnerabilities - CVE-2024-20962, CVE-2024-20973, CVE-2024-20961, CVE-2024-20985, CVE-2024-20963, CVE-2024-20977, CVE-2024-20960, CVE-2024-20969, CVE-2024-20967, CVE-2024-20964, CVE-2024-20970, CVE-2024-20965, CVE-2024-20971, CVE-2024-20976, CVE-2024-20966, CVE-2024-20978, CVE-2024-20981, CVE-2024-20983, CVE-2024-20972, CVE-2024-20982, CVE-2024-20974, CVE-2024-20984 - nghttp2 vulnerabilities - CVE-2023-44487, CVE-2019-9513, CVE-2019-9511, CVE-2024-28182 - GNU binutils vulnerabilities - CVE-2022-45703, CVE-2022-44840, CVE-2022-47010, CVE-2022-47008, CVE-2022-47011, CVE-2022-47007 - OpenSSL vulnerabilities - CVE-2023-6237, CVE-2023-6129, CVE-2024-0727, CVE-2023-5678 - python-cryptography vulnerabilities - CVE-2024-26130, CVE-2023-50782 - X.Org X Server vulnerabilities - CVE-2023-6816, CVE-2024-21886, CVE-2024-0229, CVE-2024-21885, CVE-2024-0409, CVE-2024-0408 9. Contact Information ============================================================================ For contact and support information, refer to: http://www.hp.com/go/thinclient