{"id":"MGASA-2016-0111","summary":"Updated shotwell packages fix security vulnerabilities","details":"Updated shotwell package fixes security vulnerabilities:\n\nShotwell is vulnerable to numerous security vulnerabilities, due to its use\nof the old APIs of the Webkit library which are no longer maintained (the\n\"webkit\" package in Mageia).\n\nThe shotwell package has been updated to use the current Webkit API, allowing\nit to benefit from security fixes in the newer Webkit branch (the \"webkit2\"\npackage in Mageia).  Another benefit of switching to the newer Webkit branch\nis that it allows shotwell to validate TLS certificates when connecting to\nwebsites.\n","modified":"2026-04-16T04:27:50.702867Z","published":"2016-03-16T18:07:23Z","references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0111.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17491"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2016-January/175443.html"}],"affected":[{"package":{"name":"shotwell","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/shotwell?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.22.1-0.20160310.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0111.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}