-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-731133ab8e 2023-10-01 03:37:03.210259 -------------------------------------------------------------------------------- Name : plantuml Product : Fedora 39 Version : 1.2023.11 Release : 1.fc39 URL : https://plantuml.com/ Summary : Program to generate UML diagram from a text description Description : PlantUML is a program allowing to draw UML diagrams, using a simple and human readable text description. It is extremely useful for code documenting, sketching project architecture during team conversations and so on. PlantUML supports the following diagram types - sequence diagram - use case diagram - class diagram - activity diagram - component diagram - state diagram -------------------------------------------------------------------------------- Update Information: Update plantuml to the latest version v1.2023.11. This update also includes fixes for CVE-2023-3431 and CVE-2023-3432. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 23 2023 blinxen- 1:1.2023.11-1 - Update to version 1.2023.11 (rhbz#2232105) * Fri Sep 22 2023 blinxen - 1:1.2023.7-4 - Migrate license specification to SPDX -------------------------------------------------------------------------------- References: [ 1 ] Bug #2218063 - CVE-2023-3432 plantuml: URL Restriction Bypass in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218063 [ 2 ] Bug #2218066 - CVE-2023-3431 plantuml: Local file read through %load_json in plantuml/plantuml https://bugzilla.redhat.com/show_bug.cgi?id=2218066 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-731133ab8e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue