Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

openSUSE Leap 15.2: openSUSE-SU-2021:0123-1 Moderate ViewVC Security Fix

opensuse
Calendar Grey January 20, 2021
Dist Opensuse Esm H88
The latest release for openSUSE addresses a significant security vulnerability in viewvc, ensuring improved system reliability and enhanced protection.
An update that fixes one vulnerability is now available

Description

This update for viewvc fixes the following issues:

- update to 1.1.28 (boo#1167974, CVE-2020-5283):

* security fix: escape subdir lastmod file name (#211)

* fix standalone.py first request failure (#195)

* suppress stack traces (with option to show) (#140)

* distinguish text/binary/image files by icons (#166, #175)

* colorize alternating file content lines (#167)

* link to the instance root from the ViewVC logo (#168)

* display directory and root counts, too (#169)

* fix double fault error in standalone.py (#157)

* support timezone offsets with minutes piece (#176)

This update was imported from the openSUSE:Leap:15.1:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-123=1

Package List

- openSUSE Leap 15.2 (noarch):

viewvc-1.1.28-lp152.4.3.1

References

https://www.suse.com/security/cve/CVE-2020-5283.html

https://bugzilla.suse.com/1167974

Announcement ID: openSUSE-SU-2021:0123-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here