MGASA-2023-0019 - Updated viewvc packages fix security vulnerability

Publication date: 24 Jan 2023
URL: https://advisories.mageia.org/MGASA-2023-0019.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2023-22456,
     CVE-2023-22464

ViewVC is vulnerable to cross-site scripting. The impact of these
vulnerabilities is mitigated by the need for an attacker to have commit
privileges to a Subversion repository exposed by an otherwise trusted
ViewVC instance. The attack vector involves files with unsafe names (names
that, when embedded into an HTML stream, would cause the browser to run
unwanted code), which themselves can be challenging to create.
(CVE-2023-22456, CVE-2023-22464)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31417
- https://www.debian.org/lts/security/2023/dla-3266
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22456
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22464

SRPMS:
- 8/core/viewvc-1.3.0-0.dev20200516.1.1.mga8

Mageia 2023-0019: viewvc security update

ViewVC is vulnerable to cross-site scripting

Summary

ViewVC is vulnerable to cross-site scripting. The impact of these vulnerabilities is mitigated by the need for an attacker to have commit privileges to a Subversion repository exposed by an otherwise trusted ViewVC instance. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. (CVE-2023-22456, CVE-2023-22464)

References

- https://bugs.mageia.org/show_bug.cgi?id=31417

- https://www.debian.org/lts/security/2023/dla-3266

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22456

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22464

Resolution

MGASA-2023-0019 - Updated viewvc packages fix security vulnerability

SRPMS

- 8/core/viewvc-1.3.0-0.dev20200516.1.1.mga8

Severity
Publication date: 24 Jan 2023
URL: https://advisories.mageia.org/MGASA-2023-0019.html
Type: security
CVE: CVE-2023-22456, CVE-2023-22464

Related News