MGASA-2016-0111

Source
https://advisories.mageia.org/MGASA-2016-0111.html
Import Source
https://advisories.mageia.org/MGASA-2016-0111.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2016-0111
Published
2016-03-16T18:07:23Z
Modified
2026-04-16T04:27:50.702867Z
Summary
Updated shotwell packages fix security vulnerabilities
Details

Updated shotwell package fixes security vulnerabilities:

Shotwell is vulnerable to numerous security vulnerabilities, due to its use of the old APIs of the Webkit library which are no longer maintained (the "webkit" package in Mageia).

The shotwell package has been updated to use the current Webkit API, allowing it to benefit from security fixes in the newer Webkit branch (the "webkit2" package in Mageia). Another benefit of switching to the newer Webkit branch is that it allows shotwell to validate TLS certificates when connecting to websites.

References
Credits

Affected packages

Mageia:5 / shotwell

Package

Name
shotwell
Purl
pkg:rpm/mageia/shotwell?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.22.1-0.20160310.1.mga5

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2016-0111.json"