Lector de Feeds

MGASA-2026-0331 - Updated bind packages fix security vulnerabilities

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10

Updated bind packages fix security vulnerabilities: Incorrect acceptance of NSEC3 records. (CVE-2026-10723) Key Record using PRIVATEDNS algorithm may lead to unexpected exit. (CVE-2026-10822) Potential wildcard CNAME RPZ policy bypass. (CVE-2026-11331) Unnecessary validation of DNSSEC signed records. (CVE-2026-11605) Cache poisoning possible with label count discrepancy, RRSIG, and wildcards. (CVE-2026-11721) Record ordering based unexpected exit with CNAME or DNAME. (CVE-2026-12617) Unexpected exit in certain situations with NSEC and NSEC3 both present. (CVE-2026-13204) DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field. (CVE-2026-13321) References SRPMS 10/core
  • bind-9.20.26-1.mga10

MGASA-2026-0328 - Updated openslide packages fix a security vulnerability

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48977
Arbitrary memory write with crafted Ventana BIF file. (CVE-2026-48977) References SRPMS 10/core
  • openslide-4.0.0-1.1.mga10

MGAA-2026-0085 - Updated rawtherapee package fixes bugs

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10

This is rawtherapee version 5.13, the latest from upstream. It is a bugfix and features release. References SRPMS 10/core
  • rawtherapee-5.13-1.mga10

MGAA-2026-0084 - Updated remotebox package fixes dependency on Gtk3

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10

Upstream ported RemoteBox to Gtk3 long ago, but we still let the package depend on Gtk2. This update fixes the issue. References SRPMS 10/core
  • remotebox-3.7-1.1.mga10

MGAA-2026-0083 - Updated mock-core-configs & mock-mageia-configs packages fix bug

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 9

mock chroots for mageia 10 still are using the cauldron configuration and don't produce rpm files for mageia 10. This update fixes the reported issue. References SRPMS 9/core
  • mock-core-configs-39.1-2.4.mga9
  • mock-mageia-configs-9-1.2.mga9

MGAA-2026-0082 - Updated wine and wine-wow64 packages fix a bug

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10

Fix command line launching for some of the common Wine tools. References SRPMS 10/core
  • wine-11.0-2.1.mga10
  • wine-wow64-11.0-1.1.mga10

MGAA-2026-0081 - Updated unoconv packages fix bug

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10

unoconv can't perform file conversions. This update fixes the reported issue. References SRPMS 10/core
  • unoconv-0.9.0-4.1.mga10

MGAA-2026-0080 - Updated urpmi packages fix a missing dependency

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10

When xz was missing, urpmi and rpmdrake were unable to display information about packages, because they could read neither the description, nor the file list, nor the history. This update fixes the issue by making urpmi depend on xz. References SRPMS 10/core
  • urpmi-8.136-2.1.mga10

MGASA-2026-0326 - Updated thunderbird packages fix security vulnerabilities

Mageia Security - 7 Agosto, 2026 - 07:29
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14899 , CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412 , CVE-2026-12289 , CVE-2026-12290 , CVE-2026-12291 , CVE-2026-12292 , CVE-2026-12294 , CVE-2026-12295 , CVE-2026-12296 , CVE-2026-12297 , CVE-2026-12298 , CVE-2026-12299 , CVE-2026-12302 , CVE-2026-12304 , CVE-2026-12305 , CVE-2026-12306 , CVE-2026-12307 , CVE-2026-12308 , CVE-2026-12309 , CVE-2026-12310 , CVE-2026-12311 , CVE-2026-12312 , CVE-2026-12313 , CVE-2026-12314 , CVE-2026-12315 , CVE-2026-12324 , CVE-2026-12325 , CVE-2026-12327 , CVE-2026-12328 , CVE-2026-12329 , CVE-2026-12330 , CVE-2026-57962 , CVE-2026-57963
Updated thunderbird packages fix various security issues. See the links to get complete information of each issue. References SRPMS 10/core
  • thunderbird-140.13.0-1.mga10
  • thunderbird-l10n-140.13.0-1.mga10
9/core
  • thunderbird-140.13.0-1.mga9
  • thunderbird-l10n-140.13.0-1.mga9

MGASA-2026-0325 - Updated rootcerts, nss & firefox packages fix security vulnerabilities

Mageia Security - 7 Agosto, 2026 - 07:29
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412
Updated rootcerts, nss & firefox packages fixes various vulnerabilities. Please see the links for detailed information of each one. References SRPMS 10/core
  • rootcerts-20260714.00-1.mga10
  • nss-3.126.0-1.mga10
  • firefox-140.13.0-1.mga10
  • firefox-l10n-140.13.0-1.mga10
9/core
  • rootcerts-20260714.00-1.mga9
  • nss-3.126.0-1.mga9
  • firefox-140.13.0-1.mga9
  • firefox-l10n-140.13.0-1.mga9

MGASA-2026-0324 - Updated python-django packages fix security vulnerabilities

Mageia Security - 7 Agosto, 2026 - 07:29
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-6873 , CVE-2026-7666 , CVE-2026-8404 , CVE-2026-35193 , CVE-2026-48587 , CVE-2026-48588 , CVE-2026-53877 , CVE-2026-53878
The updated package fixes security vulnerabilities: Signed cookie salt namespace collision in `django.http.HttpRequest.get_signed_cookie`. (CVE-2026-6873) Potential unencrypted email transmission via `STARTTLS` in the SMTP backend. (CVE-2026-7666) Potential exposure of private data via case-sensitive `Cache-Control` directives in `UpdateCacheMiddleware`. (CVE-2026-8404) Potential exposure of private data via missing `Vary: Authorization` in `UpdateCacheMiddleware`. (CVE-2026-35193) Potential exposure of private data via whitespace padding in `Vary` header. (CVE-2026-48587) Potential exposure of private data via cached `Set-Cookie` response. (CVE-2026-48588) Heap buffer over-read in `GDALRaster`. (CVE-2026-53877) Header injection possibility since `DomainNameValidator` accepted newlines in input. (CVE-2026-53878) References SRPMS 10/core
  • python-django-5.2.16-1.mga10
Feed