Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

openSUSE Leap 15.1: 2021:0084-1 Moderate: ViewVC Security Fix

opensuse
Calendar Grey January 16, 2021
Dist Opensuse Esm H88
The recent update for ViewVC in openSUSE introduces a significant security patch that mitigates issues related to CVE-2020-5283 along with additional improvements.
An update that fixes one vulnerability is now available

Description

This update for viewvc fixes the following issues:

- update to 1.1.28 (boo#1167974, CVE-2020-5283):

* security fix: escape subdir lastmod file name (#211)

* fix standalone.py first request failure (#195)

* suppress stack traces (with option to show) (#140)

* distinguish text/binary/image files by icons (#166, #175)

* colorize alternating file content lines (#167)

* link to the instance root from the ViewVC logo (#168)

* display directory and root counts, too (#169)

* fix double fault error in standalone.py (#157)

* support timezone offsets with minutes piece (#176)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2021-84=1

Package List

- openSUSE Leap 15.1 (noarch):

viewvc-1.1.28-lp151.3.3.1

References

https://www.suse.com/security/cve/CVE-2020-5283.html

https://bugzilla.suse.com/1167974

Announcement ID: openSUSE-SU-2021:0084-1
Rating: moderate
Affected Products: openSUSE Leap 15.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here