{"id":"openSUSE-SU-2026:20476-1","summary":"Security update for mapserver","details":"This update for mapserver fixes the following issues:\n\nChanges in mapserver:\n\n- Update to release 8.6.1\n  * msSLDParseRasterSymbolizer: fix potential heap buffer overflow\n    [boo#1260869] [CVE-2026-33721]\n  * GetFeatureInfo with IDENTIFY CLASSAUTO: take into account\n    SYMBOL.ANCHORPOINT\n  * WCS 2.0: fix issue when input raster in a rotated pole lon/lat\n    CRS with lon_0�\u003e 180\n  * UVRaster: fix WMS-Time support on layers with TILEINDEX\n    pointing to a shapefile\n  * WMS GetCapabilities response: use group title and abstract when\n    using wms_layer_group instead of GROUP\n\n- Update to release 8.6.0\n  * Add `CONNECTIONTYPE RASTERLABEL`\n  * Set `MS_LEGEND_KEYSIZE_MAX` to 1000\n  * Add 4 new `COMPOSITE.COMPOP` blending operations\n  * Allow encryption key files to use paths relative to a mapfile\n  * Allow `use_default_extent_for_getfeature` to be used for OGC\n    Features API and PostGIS\n  * Allow append of additional query parameters for OGCAPI\n  * New MapServer index page\n  * WMS `GetFeatureInfo`: add options to precisely identify points\n    through their symbols\n  * Add `FALLBACK` parameter for the `CLASS` object, to be applied\n    if none of the previously defined classes has been applied\n","modified":"2026-05-19T06:28:55.293444533Z","published":"2026-04-07T15:33:59Z","related":["CVE-2026-33721"],"upstream":["CVE-2026-33721"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260869"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33721"}],"schema_version":"1.7.5"}