Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0123-1

Опубликовано: 19 янв. 2021
Источник: suse-cvrf

Описание

Security update for viewvc

This update for viewvc fixes the following issues:

  • update to 1.1.28 (boo#1167974, CVE-2020-5283):
    • security fix: escape subdir lastmod file name (#211)
    • fix standalone.py first request failure (#195)
    • suppress stack traces (with option to show) (#140)
    • distinguish text/binary/image files by icons (#166, #175)
    • colorize alternating file content lines (#167)
    • link to the instance root from the ViewVC logo (#168)
    • display directory and root counts, too (#169)
    • fix double fault error in standalone.py (#157)
    • support timezone offsets with minutes piece (#176)

This update was imported from the openSUSE:Leap:15.1:Update update project.

Список пакетов

openSUSE Leap 15.2
viewvc-1.1.28-lp152.4.3.1

Описание

ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. This vulnerability is patched in versions 1.2.1 and 1.1.28.


Затронутые продукты
openSUSE Leap 15.2:viewvc-1.1.28-lp152.4.3.1

Ссылки
Уязвимость openSUSE-SU-2021:0123-1