Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21152-1

Опубликовано: 23 июн. 2026
Источник: suse-cvrf

Описание

Security update for atril

This update for atril fixes the following issues:

Changes in atril:

  • Update to version 1.28.4 (bsc#1265880 CVE-2026-46519):

    • Build fixes
    • Fix tests imported from XReader
    • Fix tests with AT-SPI2 >= 2.53
    • Improve search system
    • pdf: Always use poppler_document_save to avoid data loss
    • Use properties for can-zoom-in and -out
    • libview: Allow zooming to the limits of the scale
    • shell: Fix Max zoom in UI
  • Update to version 1.28.2:

    • epub: Disable thumbnailing sidebar
    • Fix .cbr mimetype
    • Wayland: stop segfaults on some systems
    • replace deprecated gtk_menu_tool_button_new_from_stock
    • libview/ev-document-model.c remove one more deprecation warning
    • replace ev_document_model_get_dual_page with
  • Update to version 1.28.1:

    • Update CBR library to libarchive in README.md
    • ci: fix travis build failures caused by recent travis changes
    • Cleanup icons Makefile
    • icons: Include higher resolution icons
    • Updated translations.

Список пакетов

openSUSE Leap 16.0
atril-1.28.4-bp160.1.1
atril-backends-1.28.4-bp160.1.1
atril-devel-1.28.4-bp160.1.1
atril-doc-1.28.4-bp160.1.1
atril-lang-1.28.4-bp160.1.1
atril-thumbnailer-1.28.4-bp160.1.1
caja-extension-atril-1.28.4-bp160.1.1
libatrildocument3-1.28.4-bp160.1.1
libatrilview3-1.28.4-bp160.1.1
typelib-1_0-AtrilDocument-1_5_0-1.28.4-bp160.1.1
typelib-1_0-AtrilView-1_5_0-1.28.4-bp160.1.1

Описание

mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes operations are available. These controls are enforced at the tool discovery layer (tools/list) but not at the execution layer (tools/call). Any client that knows a tool name can invoke it directly regardless of the configured restriction mode. The access control was effectively cosmetic. This issue has been patched in version 3.6.0.


Затронутые продукты
openSUSE Leap 16.0:atril-1.28.4-bp160.1.1
openSUSE Leap 16.0:atril-backends-1.28.4-bp160.1.1
openSUSE Leap 16.0:atril-devel-1.28.4-bp160.1.1
openSUSE Leap 16.0:atril-doc-1.28.4-bp160.1.1

Ссылки