Описание
Security update for atril
This update for atril fixes the following issues:
Changes in atril:
-
Update to version 1.28.4 (bsc#1265880 CVE-2026-46519):
- Build fixes
- Fix tests imported from XReader
- Fix tests with AT-SPI2 >= 2.53
- Improve search system
- pdf: Always use poppler_document_save to avoid data loss
- Use properties for can-zoom-in and -out
- libview: Allow zooming to the limits of the scale
- shell: Fix Max zoom in UI
-
Update to version 1.28.2:
- epub: Disable thumbnailing sidebar
- Fix .cbr mimetype
- Wayland: stop segfaults on some systems
- replace deprecated gtk_menu_tool_button_new_from_stock
- libview/ev-document-model.c remove one more deprecation warning
- replace ev_document_model_get_dual_page with
-
Update to version 1.28.1:
- Update CBR library to libarchive in README.md
- ci: fix travis build failures caused by recent travis changes
- Cleanup icons Makefile
- icons: Include higher resolution icons
- Updated translations.
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1265880
- SUSE CVE CVE-2026-46519 page
Описание
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (tools/list) but not at the execution layer (tools/call). Any client that knows a tool name can invoke it directly regardless of the configured restriction mode. The access control was effectively cosmetic. This issue has been patched in version 3.6.0.
Затронутые продукты
Ссылки
- CVE-2026-46519