Aggregator
freeipmi-1.6.19-1.fc45
- freeipmi-1.6.19-1.fc45
Updates to 1.6.19, also fixes CVE-2026-33554 CVE-2026-50031 CVE-2026-85504 CVE-2026-85505 CVE-2026-85506 CVE-2026-85507 CVE-2026-85508 CVE-2026-85509, and adds tmpfiles configs for image mode
perl-Net-DNS-1.57-1.el10_4
- perl-Net-DNS-1.57-1.el10_4
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
perl-Net-DNS-1.57-1.el10_3
- perl-Net-DNS-1.57-1.el10_3
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
perl-Net-DNS-1.57-1.fc44
- perl-Net-DNS-1.57-1.fc44
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
perl-Net-DNS-1.57-1.fc43
- perl-Net-DNS-1.57-1.fc43
Update to 1.57 to fix CVE-2026-81928 (Net::DNS: Denial of Service via unbounded recursion with misplaced TSIG records)
evolution-3.62.0-1.fc45 evolution-data-server-3.62.0-1.fc45 evolution-ews-3.62.0-1.fc45
- evolution-3.62.0-1.fc45
- evolution-data-server-3.62.0-1.fc45
- evolution-ews-3.62.0-1.fc45
Update to 3.62.0
evolution-data-serverBug Fixes:
- I#660 - GOA EWS: Do not require OABUrl in autodiscover
- I#662 - EBackend: Document how OAuth2 sources should ask to be authenticated (Tobias Mueller)
- I#665 - CalDAV: Ignore Bad Request (400) on overwrite
- M!243 - ESourceRegistry: Name the credentials source in failed-lookup debug message (Tobias Mueller)
Translations:
- Alan Mortensen (da)
- Aurimas Černius (lt)
- Balázs Úr (hu)
- Baurzhan Muftakhidinov (kk)
- Emin Tufan Çetin (tr)
- Juliano de Souza Camargo (pt_BR)
- Kjartan Maraas (nb)
Bug Fixes:
- I#3381 - Composer: De-duplicate inline images before send
- I#3383 - junk-filters: Do not leak the child stdin pipe into concurrent spawns (Benjamin Herrenschmidt)
- I#3386 - Default to not use read-only calendars for reminders and conflict search
- I#3387 - EUIParser: Notify about accelerators moved by an action rename (Martin Monperrus (AI-assisted))
- I#3388 - Mail: Validate clickable preview elements are generated by Evolution
- M!235 - Mail: Remove deprecated SHA1 signature algorithm (Robin Haberkorn)
Miscellaneous:
- docs: Add API index for newly added symbols in 3.62 for e-util
Translations:
- Alan Mortensen (da)
- Aurimas Černius (lt)
- Balázs Úr (hu)
- Baurzhan Muftakhidinov (kk)
- burns (pt_BR)
- Emin Tufan Çetin (tr)
- Guillaume Bernard (fr)
- Jiri Eischmann (cs)
- Kjartan Maraas (nb)
Bug Fixes:
- M!18 - Add a per-folder coalescing gate for sync and refresh (Benjamin Herrenschmidt)
- M!19 - camel: Do not save the folder summary in the subclass dispose (David Woodhouse)
Translations:
- Alan Mortensen (da)
- Balázs Úr (hu)
- Jiri Eischmann (cs)
- Kjartan Maraas (nb)
cyrus-imapd-3.10.4-1.fc43
- cyrus-imapd-3.10.4-1.fc43
- New version 3.10.4 (rhbz#2500822)
cyrus-imapd-3.12.4-1.fc44
- cyrus-imapd-3.12.4-1.fc44
- New version 3.12.4 (rhbz#2500822)
cyrus-imapd-3.12.4-1.fc45
- cyrus-imapd-3.12.4-1.fc45
- New version 3.12.4 (rhbz#2500822)
DSA-6498-1 network-manager-l2tp - security update
USN-8751-1: Urwid vulnerabilities
USN-8750-1: FFmpeg vulnerabilities
USN-8749-1: CivetWeb vulnerabilities
7.3-rc3: mainline
znc-1.10.3-1.fc44 znc-clientbuffer-0-0.33.20190129git9766a4a.fc44
- znc-1.10.3-1.fc44
- znc-clientbuffer-0-0.33.20190129git9766a4a.fc44
Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023
znc-1.10.3-1.fc45 znc-clientbuffer-0-0.34.20190129git9766a4a.fc45
- znc-1.10.3-1.fc45
- znc-clientbuffer-0-0.34.20190129git9766a4a.fc45
Update to 1.10.3 Fix CVE-2026-82373, CVE-2026-82374, CVE-2020-11022, CVE-2020-11023
perl-HTML-FormHandler-0.410002-1.fc44
- perl-HTML-FormHandler-0.410002-1.fc44
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
perl-HTML-FormHandler-0.410002-1.fc43
- perl-HTML-FormHandler-0.410002-1.fc43
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.
perl-HTML-FormHandler-0.410002-1.fc45
- perl-HTML-FormHandler-0.410002-1.fc45
HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method (CVE-2026-85630) . This update fixes that issue.
HTML::FormHandler versions through 0.40068 allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template.
Versions 0.410000+ fix the issue by passing error messages with request data as Locale::Maketext arguments instead of templates.