perl-Dancer2-1.1.2-4.fc43
- perl-Dancer2-1.1.2-4.fc43
Dancer2 générates sessions id from low-entropy sources if Crypt::URandom and Math::Random::ISAAC::XS are not present. With this update, they are always there.
Dancer2 générates sessions id from low-entropy sources if Crypt::URandom and Math::Random::ISAAC::XS are not present. With this update, they are always there.
Dancer2 générates sessions id from low-entropy sources if Crypt::URandom and Math::Random::ISAAC::XS are not present. With this update, they are always there.
Dancer2 générates sessions id from low-entropy sources if Crypt::URandom and Math::Random::ISAAC::XS are not present. With this update, they are always there.
Update to 1.7.6
Security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.
Update to 1.7.6
Security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.
Update to 1.7.6
Security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.
Update to 1.7.6
Security fix for GHSA-6m27-337c-jcgf. Config file or environment variable can trigger writing out a config file, overwriting an arbitrary file and disclosing configuration values.
Update lru crate to version 0.18.4 and add a compat package for version 0.16.
This fixes an obscure potential use-after-free issue: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Rebuild tracker: https://forge.fedoraproject.org/rust/backlog/issues/39
Update lru crate to version 0.18.4 and add a compat package for version 0.16.
This fixes an obscure potential use-after-free issue: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Rebuild tracker: https://forge.fedoraproject.org/rust/backlog/issues/39
Update lru crate to version 0.18.4 and add a compat package for version 0.16.
This fixes an obscure potential use-after-free issue: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Rebuild tracker: https://forge.fedoraproject.org/rust/backlog/issues/39
Update lru crate to version 0.18.4 and add a compat package for version 0.16.
This fixes an obscure potential use-after-free issue: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Rebuild tracker: https://forge.fedoraproject.org/rust/backlog/issues/39
Update lru crate to version 0.18.4 and add a compat package for version 0.16.
This fixes an obscure potential use-after-free issue: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Rebuild tracker: https://forge.fedoraproject.org/rust/backlog/issues/39
Update lru crate to version 0.18.4 and add a compat package for version 0.16.
This fixes an obscure potential use-after-free issue: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
Rebuild tracker: https://forge.fedoraproject.org/rust/backlog/issues/39
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. This update fixes that issue (CVE-2026-18536).
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. This update fixes that issue (CVE-2026-18536).
Data::Entropy versions before 0.010 for Perl read remote entropy sources over plain HTTP. This update fixes that issue (CVE-2026-18536).
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.