freeipmi-1.6.19-1.fc43
- freeipmi-1.6.19-1.fc43
Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode
Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode
Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval.
deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.
Dancer2::Serializer::YAML::deserialize handed request bodies straight to YAML::Load. A body tagged !!perl/hash:Some::Class therefore instantiated an arbitrary blessed object — the entry point for DESTROY/AUTOLOAD/overload gadget chains — and !!perl/code could ask for a string eval.
deserialize now sets $YAML::LoadBlessed = 0 and $YAML::LoadCode = 0 itself (localised) before loading, rather than relying on YAML.pm's ambient defaults, and the minimum YAML is raised to 1.30.
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients.
In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients.
In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
Catalyst::Plugin::Static::Simple for Perl sets the Cache‑Control header to "public" for every static asset served. Consequently, intermediaries such as shared reverse proxies or CDN edge caches may store and later serve content that was intended to be private, thereby exposing sensitive data to unintended recipients.
In this package, the plugin's code is changed to allow the Cache-Control header to be overridden and the Expires header to be set to 0.
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. In this package, a max_counter attribute has been added to Repeatable elements that caps the client-supplied repeat count from the query string. Default is 100, inherited from a new form-level repeatable_max_counter attribute.
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. In this package, a max_counter attribute has been added to Repeatable elements that caps the client-supplied repeat count from the query string. Default is 100, inherited from a new form-level repeatable_max_counter attribute.
HTML::FormFu versions through 2.08 for Perl allow resource exhaustion via an unbounded repeat count from the query string in Repeatable elements. In this package, a max_counter attribute has been added to Repeatable elements that caps the client-supplied repeat count from the query string. Default is 100, inherited from a new form-level repeatable_max_counter attribute.
Fix CVE-2026-91837
Updated to 1.20.26 release Includes fixes for CVE-2026-75131 & CVE-2026-93337
Fix CVE-2026-91837
Updated to 1.52.6 Includes fixes for CVE-2026-75131 & CVE-2026-93337
Updated to 1.52.6 Includes fixes for CVE-2026-75131 & CVE-2026-93337
Fix CVE-2026-91837
Updated to 1.52.6 Includes fixes for CVE-2026-75131 & CVE-2026-93337
Updated to 1.52.6 Includes fixes for CVE-2026-75131 & CVE-2026-93337
Updated to 1.52.6 Includes fixes for CVE-2026-75131 & CVE-2026-93337
upstream security/bugfix release
Latest FFmpeg stable release and rebuilds of dependent packages. Fixes a number of high severity security bugs: CVE-2026-64832 CVE-2026-70628 CVE-2026-70632 CVE-2026-75147 CVE-2026-75146 .
Includes: