Aggregator
flatpak-builder-1.4.12-1.fc44
- flatpak-builder-1.4.12-1.fc44
Update to 1.4.12
USN-8788-1: ClamAV vulnerabilities
perl-Imager-1.036-1.fc45
- perl-Imager-1.036-1.fc45
1.036 bump - Fix CVE-2026-93019 (TGA large color map size interpreted as negative) - Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)
perl-Imager-1.036-1.fc44
- perl-Imager-1.036-1.fc44
1.036 bump - Fix CVE-2026-93019 (TGA large color map size interpreted as negative) - Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)
perl-Imager-1.036-1.fc43
- perl-Imager-1.036-1.fc43
1.036 bump - Fix CVE-2026-93019 (TGA large color map size interpreted as negative) - Fix CVE-2026-93018 (paletted images: out-of-range color index returned uninitialized palette data)
tesseract-5.5.3-2.fc44
- tesseract-5.5.3-2.fc44
Backport fixes for CVE-2026-{88047-88054}
tesseract-5.5.3-2.fc43
- tesseract-5.5.3-2.fc43
Backport fixes for CVE-2026-{88047-88054}
tesseract-5.5.3-2.fc45
- tesseract-5.5.3-2.fc45
Backport fixes for CVE-2026-{88047-88054}
rootlesskit-3.2.0-1.fc44
- rootlesskit-3.2.0-1.fc44
- Update to release v3.2.0
- Resolves: rhbz#2530874
- Resolves CVE-2026-56855: rhbz#2530631
- Resolves CVE-2026-78662: rhbz#2530678
- Upstream enhancements and fixes
rootlesskit-3.2.0-1.fc45
- rootlesskit-3.2.0-1.fc45
- Update to release v3.2.0
- Resolves: rhbz#2530874
- Resolves CVE-2026-56855: rhbz#2530631
- Resolves CVE-2026-78662: rhbz#2530678
- Upstream enhancements and fixes
rootlesskit-3.2.0-1.fc46
- rootlesskit-3.2.0-1.fc46
Automatic update for rootlesskit-3.2.0-1.fc46.
Changelog * Sun Sep 20 2026 Bradley G Smith <bradley.g.smith@gmail.com> - 3.2.0-1 - Update to release v3.2.0 - Resolves: rhbz#2530874 - Resolves CVE-2026-56855: rhbz#2530631 - Resolves CVE-2026-78662: rhbz#2530678 - Upstream enhancements and fixes7.3-rc4: mainline
freeipmi-1.6.19-1.fc43
- freeipmi-1.6.19-1.fc43
Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode
perl-Dancer2-2.2.1-1.fc44
- perl-Dancer2-2.2.1-1.fc44
Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval.
deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.
perl-Dancer2-2.2.1-1.fc45
- perl-Dancer2-2.2.1-1.fc45
Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval.
deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.
perl-Catalyst-Plugin-Static-Simple-0.38-2.fc44
- perl-Catalyst-Plugin-Static-Simple-0.38-2.fc44
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients.
In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
perl-Catalyst-Plugin-Static-Simple-0.38-2.fc45
- perl-Catalyst-Plugin-Static-Simple-0.38-2.fc45
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients.
In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
perl-Catalyst-Plugin-Static-Simple-0.38-2.fc43
- perl-Catalyst-Plugin-Static-Simple-0.38-2.fc43
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients.
In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
perl-HTML-FormFu-2.07-22.fc43
- perl-HTML-FormFu-2.07-22.fc43
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. In this package, a max_counter attribute has been added to Repeatable elements that caps the client-supplied repeat count from the query string. Default is 100, inherited from a new form-level repeatable_max_counter attribute.