Lector de Feeds

MGASA-2026-0328 - Updated openslide packages fix a security vulnerability

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48977 Description
Arbitrary memory write with crafted Ventana BIF file. (CVE-2026-48977) References
SRPMS 10/core
  • openslide-4.0.0-1.1.mga10

MGAA-2026-0085 - Updated rawtherapee package fixes bugs

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
This is rawtherapee version 5.13, the latest from upstream. It is a bugfix and features release. References
SRPMS 10/core
  • rawtherapee-5.13-1.mga10

MGAA-2026-0084 - Updated remotebox package fixes dependency on Gtk3

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Upstream ported RemoteBox to Gtk3 long ago, but we still let the package depend on Gtk2. This update fixes the issue. References
SRPMS 10/core
  • remotebox-3.7-1.1.mga10

MGAA-2026-0083 - Updated mock-core-configs & mock-mageia-configs packages fix bug

Mageia Security - 10 Agosto, 2026 - 20:29
Publication date: 10 Aug 2026
Type: bugfix
Affected Mageia releases : 9
Description
mock chroots for mageia 10 still are using the cauldron configuration and don't produce rpm files for mageia 10. This update fixes the reported issue. References
SRPMS 9/core
  • mock-core-configs-39.1-2.4.mga9
  • mock-mageia-configs-9-1.2.mga9

MGASA-2026-0327 - Updated python-starlette package fixes security vulnerabilities

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2024-28849 , CVE-2025-62727 , CVE-2026-48710 Description
The updated package fixes security vulnerabilities: Proxy-Authorization header kept across hosts. (CVE-2024-28849) Starlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse. (CVE-2025-62727) Security restriction bypass via malformed HTTP Host header. (CVE-2026-48710) References
SRPMS 10/core
  • python-starlette-0.46.0-3.1.mga10

MGAA-2026-0082 - Updated wine and wine-wow64 packages fix a bug

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Fix command line launching for some of the common Wine tools. References
SRPMS 10/core
  • wine-11.0-2.1.mga10
  • wine-wow64-11.0-1.1.mga10

MGAA-2026-0081 - Updated unoconv packages fix bug

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
unoconv can't perform file conversions. This update fixes the reported issue. References
SRPMS 10/core
  • unoconv-0.9.0-4.1.mga10

MGAA-2026-0080 - Updated urpmi packages fix a missing dependency

Mageia Security - 9 Agosto, 2026 - 07:02
Publication date: 09 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
When xz was missing, urpmi and rpmdrake were unable to display information about packages, because they could read neither the description, nor the file list, nor the history. This update fixes the issue by making urpmi depend on xz. References
SRPMS 10/core
  • urpmi-8.136-2.1.mga10

MGASA-2026-0326 - Updated thunderbird packages fix security vulnerabilities

Mageia Security - 7 Agosto, 2026 - 07:29
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-14899 , CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412 , CVE-2026-12289 , CVE-2026-12290 , CVE-2026-12291 , CVE-2026-12292 , CVE-2026-12294 , CVE-2026-12295 , CVE-2026-12296 , CVE-2026-12297 , CVE-2026-12298 , CVE-2026-12299 , CVE-2026-12302 , CVE-2026-12304 , CVE-2026-12305 , CVE-2026-12306 , CVE-2026-12307 , CVE-2026-12308 , CVE-2026-12309 , CVE-2026-12310 , CVE-2026-12311 , CVE-2026-12312 , CVE-2026-12313 , CVE-2026-12314 , CVE-2026-12315 , CVE-2026-12324 , CVE-2026-12325 , CVE-2026-12327 , CVE-2026-12328 , CVE-2026-12329 , CVE-2026-12330 , CVE-2026-57962 , CVE-2026-57963 Description
Updated thunderbird packages fix various security issues. See the links to get complete information of each issue. References
SRPMS 10/core
  • thunderbird-140.13.0-1.mga10
  • thunderbird-l10n-140.13.0-1.mga10
9/core
  • thunderbird-140.13.0-1.mga9
  • thunderbird-l10n-140.13.0-1.mga9

MGASA-2026-0325 - Updated rootcerts, nss & firefox packages fix security vulnerabilities

Mageia Security - 7 Agosto, 2026 - 07:29
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-15718 , CVE-2026-15719 , CVE-2026-16349 , CVE-2026-16350 , CVE-2026-16351 , CVE-2026-16352 , CVE-2026-16353 , CVE-2026-16354 , CVE-2026-16355 , CVE-2026-16356 , CVE-2026-16357 , CVE-2026-16358 , CVE-2026-16359 , CVE-2026-16360 , CVE-2026-16361 , CVE-2026-16362 , CVE-2026-16363 , CVE-2026-16368 , CVE-2026-16369 , CVE-2026-16371 , CVE-2026-16374 , CVE-2026-16375 , CVE-2026-16377 , CVE-2026-16379 , CVE-2026-16381 , CVE-2026-16383 , CVE-2026-16387 , CVE-2026-16390 , CVE-2026-16391 , CVE-2026-16396 , CVE-2026-16405 , CVE-2026-16412 Description
Updated rootcerts, nss & firefox packages fixes various vulnerabilities. Please see the links for detailed information of each one. References
SRPMS 10/core
  • rootcerts-20260714.00-1.mga10
  • nss-3.126.0-1.mga10
  • firefox-140.13.0-1.mga10
  • firefox-l10n-140.13.0-1.mga10
9/core
  • rootcerts-20260714.00-1.mga9
  • nss-3.126.0-1.mga9
  • firefox-140.13.0-1.mga9
  • firefox-l10n-140.13.0-1.mga9

MGASA-2026-0324 - Updated python-django packages fix security vulnerabilities

Mageia Security - 7 Agosto, 2026 - 07:29
Publication date: 07 Aug 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-6873 , CVE-2026-7666 , CVE-2026-8404 , CVE-2026-35193 , CVE-2026-48587 , CVE-2026-48588 , CVE-2026-53877 , CVE-2026-53878 Description
The updated package fixes security vulnerabilities: Signed cookie salt namespace collision in `django.http.HttpRequest.get_signed_cookie`. (CVE-2026-6873) Potential unencrypted email transmission via `STARTTLS` in the SMTP backend. (CVE-2026-7666) Potential exposure of private data via case-sensitive `Cache-Control` directives in `UpdateCacheMiddleware`. (CVE-2026-8404) Potential exposure of private data via missing `Vary: Authorization` in `UpdateCacheMiddleware`. (CVE-2026-35193) Potential exposure of private data via whitespace padding in `Vary` header. (CVE-2026-48587) Potential exposure of private data via cached `Set-Cookie` response. (CVE-2026-48588) Heap buffer over-read in `GDALRaster`. (CVE-2026-53877) Header injection possibility since `DomainNameValidator` accepted newlines in input. (CVE-2026-53878) References
SRPMS 10/core
  • python-django-5.2.16-1.mga10

MGAA-2026-0079 - Updated purple-telegram-tdlib packages fix bugs

Mageia Security - 6 Agosto, 2026 - 20:41
Publication date: 06 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
In telegram groups with topics, the conversations from all the topics end in the Unique chat tab in pidgin and messages from pidgin end in the General topic, making it hard to follow the conversations. If the session for the plugin is closed from the phone client, in the next pidgin start you can't login. This update fixes the reported issues. Please note that the icon for the protocol has changed and is now listed as Unofficial Telegram. References
SRPMS 10/core
  • purple-telegram-tdlib-2.0.2-1.mga10
9/core
  • purple-telegram-tdlib-2.0.2-1.mga9

MGAA-2026-0078 - Updated font-tools packages fix two bugs

Mageia Security - 6 Agosto, 2026 - 20:41
Publication date: 06 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
pfm2afm crashed on 64-bit machines and did not accept absolute path names to files. Both these issues have been fixed. References
SRPMS 10/core
  • font-tools-0.1-34.mga10
9/core
  • font-tools-0.1-34.mga9

MGAA-2026-0077 - Updated steam, steam-udevrules packages add requires

Mageia Security - 6 Agosto, 2026 - 15:44
Publication date: 06 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Steam is updated to 1.0.0.87 and Requires: are added for libmesavulkan-drivers and libvulkan-loader1, needed for some games on Intel and AMD gpus. Note that steam-udevrules is required by steam and will be automatically pulled in by steam. However, it is available as a separate package so it can be used by folks with the libre steamcontroller without having to install all of steam to get it. References
SRPMS 10/core
  • steam-udevrules-1.0.0.87-1.mga10
10/nonfree
  • steam-1.0.0.87-1.mga10.nonfree

MGAA-2026-0075 - Updated woeusb-ng packages fix bug

Mageia Security - 5 Agosto, 2026 - 19:27
Publication date: 05 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
woeusb-ng did not mark the 7zip package as a required dependency. This update fixes the reported issue. References
SRPMS 10/core
  • woeusb-ng-0.2.12-4.1.mga10

MGASA-2026-0323 - Updated tomcat packages fix security vulnerabilities

Mageia Security - 5 Agosto, 2026 - 18:22
Publication date: 05 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-50229 , CVE-2026-53404 , CVE-2026-53434 , CVE-2026-55276 , CVE-2026-55955 , CVE-2026-55956 , CVE-2026-55957 Description
The updated packages fix security vulnerabilities: XSS in number guess example. (CVE-2026-50229) Bad ornext processing in RewriteValve. (CVE-2026-53404) Invalid CRL configuration doesn't trigger failure for FFM Connector. (CVE-2026-53434) Logged effective web.xml is incomplete. (CVE-2026-55276) EncryptInterceptor not protected against replay attacks. (CVE-2026-55955) Security constraints for default servlet ignored method. (CVE-2026-55956) Authentication bypass with JNDIRealm and GSSAPI authenticated bind. (CVE-2026-55957) References
SRPMS 10/core
  • tomcat-9.0.119-1.mga10
9/core
  • tomcat-9.0.119-1.mga9

MGAA-2026-0076 - Updated php-fpdf package fixes two issues.

Mageia Security - 5 Agosto, 2026 - 18:22
Publication date: 05 Aug 2026
Type: bugfix
Affected Mageia releases : 10
Description
Updating php-fpdf to version 1.9.0 suppresses deprecated warnings in php 8.5. This update also fixes a bug related to the PDF creation date. References
SRPMS 10/core
  • php-fpdf-1.9.0-1.mga10

MGAA-2026-0074 - Updated netprofile packages fix a bug

Mageia Security - 5 Agosto, 2026 - 18:22
Publication date: 05 Aug 2026
Type: bugfix
Affected Mageia releases : 10 , 9
Description
netprofile sent messages to com.mandriva.user instead of org.mageia.user. This update fixes the issue. References
SRPMS 10/core
  • netprofile-0.29.1-1.mga10
9/core
  • netprofile-0.29.1-1.mga9

Potions in Mageia. 01 – Pidgin and its accessories

Blog de Mageia (English) - 5 Agosto, 2026 - 14:35

We started a series of blog posts. Ideas, applications, processes, customizations, contributions about our distribution that are relevant to our users, bringing the use of Mageia closer to everyone. We certainly hope that these new publications are of interest to you, you can share them on social networks, your personal blog, website, news sites or any other place that serves to show the qualities of Mageia!

Prologue

Today we’re going to talk about this application which, although somewhat forgotten by many, is a great low-resource alternative for managing multiple messaging protocols simultaneously. In Mageia, it’s very well packaged with many plugins that you won’t find in other distributions and that complement Pidgin very well, allowing you to use it like modern messaging apps.

Pidgin is cross-platform and multi-protocol, which means that if you add what you need, you’ll have a multitude of messaging applications in one.

On the other hand, resource optimization is such that the impact on the system is truly minimal. Just look at some data from two of the most requested applications by the average user: WhatsApp and Telegram, for example.

    • Opening Telegram will consume 300 to 400MB of your computer’s RAM.

    • Opening WhatsApp will consume 700 to 900MB of your computer’s RAM—a truly outrageous amount for a messaging app… Of course, most of these versions are built on Electron, and their optimization is about as good as Mageia is for Windows…

Opening Pidgin with both accounts configured consumes 90 to 150 MB of your computer’s RAM, at most, so as you can see, in terms of performance and resource optimization, it’s highly recommended…

After this, Pidgin has its plugins. It’s highly recommended to leave the “History” plugin activated, which allows you to save conversations in the log. Note that it’s advisable not to delete conversations from the conversation window, which you can find in the “View History” option in each conversation’s menu.

Installation

Installation in Mageia is very simple, although some accounts may require the installation of a few extra packages. There are two ways to do it: through the software manager or via the terminal. Let’s get started:

    • Terminal: It is recommended to have the Blogdrake community repositories enabled for some packages. Enter the terminal as root and write: “urpmi pidgin pidgin-telegram-tdlib purple-gowhatsapp purple-telegram-tdlib pidgin-libnotify pidgin-indicator pidgin-window_merge pidgin-wemoji-theme”. With this command, pidgin and plugins for telegram, whatsapp and a complete emoji theme will be installed.



    • Software Manager: Go to the Start menu and search for “Install or Remove Apps.” Once there, make sure both search filters are set to “All.” Next, we install the following packages: “pidgin pidgin-telegram-tdlib” “pidgin-wemoji-theme” “purple-gowhatsapp” “purple-telegram-tdlib” “pidgin-libnotify” “pidgin-indicator” “pidgin-window_merge”. As before, this will install plugins and the emoji theme.



Configure Pidgin to manage these two messages It’s relatively simple. As soon as you launch the application, a greeting and a window to start configuring the accounts will appear. Note that Pidgin supports many other communication protocols, such as Gadu-Gadu, Google Talk, IRC, XMPP, etc. For more information about them and how to install them, you can visit the “official Pidgin website. Let’s get started:

Telegram

In the accounts section, tap “Add.” In the next window, choose the “Telegram (tdlib)” protocol. Then, in the “Username” field, enter your phone number with the international code. For example, in my case, from Spain, it would be 34669543111, and tap “Accept” or “Add.” After this, a pop-up window will appear to add the code that Telegram sends to the mobile application. The Telegram account is now set up.


Whatsapp

In the accounts section, tap “Add”, and in the next window choose the “Whatsapp” protocol. Next, in the “Username” field, enter your phone number in international code, and now comes the important part followed by “@s.whatsapp.net”, for example, 34669543111@s.whatsapp.net. After this, a window will appear with a QR code to add the session from the mobile app.



Extra configuration for GTK themes, dark mode in Pidgin

For desktop environments other than Plasma, if Pidgin doesn’t pick up the default dark theme from the desktop environment preferences, you can try closing Pidgin after configuring the accounts and installing the packages:

    • “gtk-chtheme”. This is an application that will allow you to change the themes of GTK applications.

    • “gtk2-theme-engines”. Installs various GTK themes for GTK applications.

    • Open the GTK themes application and select the “Nodoka-Midnight” theme.

This seems to be the theme that best integrates dark mode into Pidgin.

    • Go to your home folder and find the file “.gtkrc-2.0” (you will need to show hidden files to find it). Remember to remove the period from the name once copied so that the theme applies correctly to Pidgin, leaving the name as “gtkrc-2.0”.

    • Copy that file to the “.purple” folder, which is where everything related to Pidgin is located.

    • Restart, and then open Pidgin normally. It should now display the dark theme.

    • Some screenshots:

We previously installed an expanded emoji theme. To activate it, go to Preferences, then to “Themes > Emoji Theme,” and select the theme. It will appear as WhatsApp/iOS Emojis.



Extra access, shortcuts, and other features.

    • From the main window, you can search for a chat using “Ctrl+f”. If, for example, we have the same name on two different accounts (WhatsApp and Telegram), Pidgin will tell us which account we want the chat from.

      From a chat window, use “Ctrl+F” to search within the current chat.

      From the chats window, use “Ctrl+M” to open a new chat or search for one to open a conversation.

      From the “Conversation > View History” menu, you can view the history of the current chat (remember to enable the “History” plugin in the plugins section first). –>

    • From the main “Friends List” window, press “Ctrl-p” to open preferences.

Add-ons

    • History: Shows previous chat conversations. Enter the last conversation before starting the new one.

    • Libnotify Popus (not to be confused with Libnotify+): Displays notifications using libnotify

    • Message notification: Allows notification of unread messages.

    • New line: Adds a horizontal line to separate old and new conversations.

    • Window-merge: This plugin allows you to merge the “friends” and “chats” windows.

You can configure these plugins from the “Configure Plugin” option just below the window.



We hope you found this tutorial interesting. It shows you how to configure and use an application that, while not very well-known, is a gem for managing messaging from your PC with minimal resources. Best of all, it’s available from the Mageia and BlogDrake!!!.

repositories.

Categorías: Blogs Oficiales
Feed