openSUSE-SU-2026:20476-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20476-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20476-1
Upstream
Related
Published
2026-04-07T15:33:59Z
Modified
2026-05-19T06:28:55Z
Summary
Security update for mapserver
Details

This update for mapserver fixes the following issues:

Changes in mapserver:

  • Update to release 8.6.1

    • msSLDParseRasterSymbolizer: fix potential heap buffer overflow [boo#1260869] [CVE-2026-33721]
    • GetFeatureInfo with IDENTIFY CLASSAUTO: take into account SYMBOL.ANCHORPOINT
    • WCS 2.0: fix issue when input raster in a rotated pole lon/lat CRS with lon_0�> 180
    • UVRaster: fix WMS-Time support on layers with TILEINDEX pointing to a shapefile
    • WMS GetCapabilities response: use group title and abstract when using wms_layer_group instead of GROUP
  • Update to release 8.6.0

    • Add CONNECTIONTYPE RASTERLABEL
    • Set MS_LEGEND_KEYSIZE_MAX to 1000
    • Add 4 new COMPOSITE.COMPOP blending operations
    • Allow encryption key files to use paths relative to a mapfile
    • Allow use_default_extent_for_getfeature to be used for OGC Features API and PostGIS
    • Allow append of additional query parameters for OGCAPI
    • New MapServer index page
    • WMS GetFeatureInfo: add options to precisely identify points through their symbols
    • Add FALLBACK parameter for the CLASS object, to be applied if none of the previously defined classes has been applied
References

Affected packages