Aggregator

roundcubemail-1.6.18-1.el10_2

2 hours 57 minutes ago
FEDORA-EPEL-2026-4e7b9eeb2b Packages in this update:
  • roundcubemail-1.6.18-1.el10_2
Update description: Release 1.6.18
  • Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

roundcubemail-1.6.18-1.el10_3

2 hours 57 minutes ago
FEDORA-EPEL-2026-c09c342945 Packages in this update:
  • roundcubemail-1.6.18-1.el10_3
Update description: Release 1.6.18
  • Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

roundcubemail-1.6.18-1.fc43

2 hours 57 minutes ago
FEDORA-2026-914a40b4fd Packages in this update:
  • roundcubemail-1.6.18-1.fc43
Update description: Release 1.6.18
  • Password: Fix fatal error "Class 'Zxcvbn' not found" (#10274)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

roundcubemail-1.7.3-1.fc44

3 hours 10 minutes ago
FEDORA-2026-2aa96a9ce5 Packages in this update:
  • roundcubemail-1.7.3-1.fc44
Update description: Release 1.7.3
  • OAuth: Don't log an error when a refreshed token's TTL is below refresh_interval (#10213)
  • Fix out-of-bounds string reads on truncated compressed-RTF in the TNEF decoder (#10269)
  • Fix bug where searching in example_addressbook plugin was reporting zero results despite matches (#9022)
  • Fix vCard import mis-detecting folded continuation lines as BEGIN/END:VCARD (#9593)
  • Fix bug where the php session driver practically disabled session.lazy_write optimization (#9885, #10248)
  • Fix bug where dates could get displayed shifted back one day in some places (#9403)
  • Fix regression where it wasn't possible to hide a skin logo image anymore (#10254)
  • Fix decoding of multi-segment RFC2231 extended attachment filenames (#10268)
  • Fix vCard import silently dropping properties with a non-item group prefix (#10271)
  • Fix so REQUEST_URI is used as a fallback if PATH_INFO is empty in static.php (#10181)
  • Security: Add basic validation for content proxied by the css proxy
  • Security: Fix SSRF bypass via specific local address URLs using 100.64.0.0/10 and fe80::/10 nets
  • Security: Fix SSRF filter bypass via various forms of nip.io/sslip.io hostnames evading is_local_url() check
  • Security: Fix remote content blocking bypass via unclosed url() in a FuncIRI attribute
  • Security: Fix LDAP filter injection via unescaped %u/%fu/%d substitution into the search_filter
  • Security: Fix arbitrary Sieve script injection via a filter rule name bypassing managesieve_disabled_actions
  • Security: Fix RCE via cmd_learn driver of markasjunk plugin
  • Security: Fix IMAP command injection via mail search and LITERAL+ byte-count desynchronization
  • Security: Fix password's modoboa driver leak of an authentication token to a user-controlled host
  • Security: Fix stored XSS in "Add to address book" action
  • Security: Fix HTML/CSS sanitization bypass via SVG animate by attribute

USN-8592-1: ImageMagick vulnerabilities

11 hours 8 minutes ago
Hao Ren discovered that ImageMagick incorrectly handled certain images when using the wavelet-denoise operation. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-30936) It was discovered that ImageMagick incorrectly handled extremely large XWD images. An attacker could possibly use this issue to trigger an out-of-bounds heap write, resulting in arbitrary code execution. (CVE-2026-30937) It was discovered that ImageMagick incorrectly handled extremely large SFW images on 32-bit systems. An attacker could possibly use this issue to trigger an integer overflow, resulting in a denial of service. (CVE-2026-31853) It was discovered that ImageMagick incorrectly handled memory allocation failures in the sixel encoder. An attacker could possibly use this issue to trigger a stack buffer overflow, resulting in arbitrary code execution. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-32259)

GraphicsMagick-1.3.45-10.fc45 ImageMagick-7.1.2.29-2.fc45 OpenImageIO-3.1.15.0-4.fc45 OpenImageIO2.5-2.5.19.1-17.fc45 darktable-5.4.1-12.fc45 digikam-9.1.0-3.fc45 ffmpeg-8.1.2-10.fc45 geeqie-2.7-6.fc45 gimp-3.2.4-4.fc45 gthumb-4.0~beta-4.fc45 imlib2-1.12…

13 hours 52 minutes ago
FEDORA-2026-26ae66c60f Packages in this update:
  • darktable-5.4.1-12.fc45
  • digikam-9.1.0-3.fc45
  • ffmpeg-8.1.2-10.fc45
  • geeqie-2.7-6.fc45
  • gimp-3.2.4-4.fc45
  • GraphicsMagick-1.3.45-10.fc45
  • gthumb-4.0~beta-4.fc45
  • ImageMagick-7.1.2.29-2.fc45
  • imlib2-1.12.5-4.fc45
  • imv-5.0.1-4.fc45
  • kf5-kimageformats-5.116.0-12.fc45
  • kf6-kimageformats-6.29.0-2.fc45
  • libheif-1.23.1-9.fc45
  • mingw-openexr-3.4.13-3.fc45
  • mpv-0.41.0-8.fc45
  • openapv-0.3.0.0-1.fc45
  • OpenImageIO2.5-2.5.19.1-17.fc45
  • OpenImageIO-3.1.15.0-4.fc45
  • openjph-0.31.0-1.fc45
  • perl-Prima-1.77-6.fc45
  • python-imagecodecs-2025.8.2-7.fc45
  • siril-1.4.4-3.fc45
  • swayimg-5.5-2.fc45
  • vapoursynth-79-3.fc45
  • vips-8.18.3-4.fc45
  • xevd-0.7.0-2.fc45
  • xeve-0.7.0-2.fc45
Update description:

Updated xeve/xevd, updated openapv and updated vapoursynth.