Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # viewvc-1.3.0~dev20250722-1.1 on GA media Announcement ID: openSUSE-SU-2025:15374-1 Rating: moderate Cross-References: * CVE-2025-54141 CVSS scores: * CVE-2025-54141 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-54141 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the viewvc-1.3.0~dev20250722-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * viewvc 1.3.0~dev20250722-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54141.html . # viewvc-1.3.0~dev20250722-1.1 on GA media Announcement ID: openSUSE-SU-2025:15374-1 Rating: moderat. update, solves, vulnerability, installed, viewvc-1, 0~dev20250722-1. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for viewvc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0145-1 Rating: moderate References: #1167974 Cross-References: CVE-2020-5283 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for viewvc fixes the following issues: - update to 1.1.28 (boo#1167974, CVE-2020-5283): * security fix: escape subdir lastmod file name (#211) * fix standalone.py first request failure (#195) * suppress stack traces (with option to show) (#140) * distinguish text/binary/image files by icons (#166, #175) * colorize alternating file content lines (#167) * link to the instance root from the ViewVC logo (#168) * display directory and root counts, too (#169) * fix double fault error in standalone.py (#157) * support timezone offsets with minutes piece (#176) This update was imported from the openSUSE:Leap:15.1:Update update project. This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-145=1 Package List: - openSUSE Backports SLE-15-SP2 (noarch): viewvc-1.1.28-bp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-5283.html https://bugzilla.suse.com/1167974 . A Fedora security patch for gnome-shell addresses a significant vulnerability, improving security and functionality, warranting immediate attention.. openSUSE Security Fix, ViewVCUpdate, Moderate Issue, Software Patch. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for viewvc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0123-1 Rating: moderate References: #1167974 Cross-References: CVE-2020-5283 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for viewvc fixes the following issues: - update to 1.1.28 (boo#1167974, CVE-2020-5283): * security fix: escape subdir lastmod file name (#211) * fix standalone.py first request failure (#195) * suppress stack traces (with option to show) (#140) * distinguish text/binary/image files by icons (#166, #175) * colorize alternating file content lines (#167) * link to the instance root from the ViewVC logo (#168) * display directory and root counts, too (#169) * fix double fault error in standalone.py (#157) * support timezone offsets with minutes piece (#176) This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-123=1 Package List: - openSUSE Leap 15.2 (noarch): viewvc-1.1.28-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-5283.html https://bugzilla.suse.com/1167974 . The latest release for openSUSE addresses a significant security vulnerability in viewvc, ensuring improved system reliability and enhanced protection.. openSUSE Update, ViewVC Security Patch, Software Security Fix. . LinuxSecurity.com Team
Updated viewvc package fixes security vulnerability: ViewVC before versions 1.1.28 has an XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository . MGASA-2020-0221 - Updated viewvc packages fix security vulnerability Publication date: 24 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0221.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-5283 Updated viewvc package fixes security vulnerability: ViewVC before versions 1.1.28 has an XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create (CVE-2020-5283). The viewvc package has been updated to version 1.1.28, fixing this issue and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=26628 - https://github.com/viewvc/viewvc/security/advisories/GHSA-xpxf-fvqv-7mfg - https://github.com/viewvc/viewvc/releases/tag/1.1.27 - https://github.com/viewvc/viewvc/releases/tag/1.1.28 - https://lists.fedoraproject.org/archives/list/
Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-2bce6ed778 2017-02-09 16:28:05.010316 -------------------------------------------------------------------------------- Name : viewvc Product : Fedora 24 Version : 1.1.26 Release : 1.fc24 URL : https://www.viewvc.org/ Summary : Browser interface for CVS and SVN version control repositories Description : ViewVC is a browser interface for CVS and Subversion version control repositories. It generates templatized HTML to present navigable directory, revision, and change log listings. It can display specific versions of files as well as diffs between those versions. Basically, ViewVC provides the bulk of the report-like functionality you expect out of your version control tool, but much more prettily than the average textual command-line program output. -------------------------------------------------------------------------------- Update Information: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade viewvc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Thomas Gerbet discovered that viewvc, a web interface for CVS and Subversion repositories, did not properly sanitize user input. This problem resulted in a potential Cross-Site Scripting vulnerability. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3784-1
Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-bd3c3c957f 2017-02-09 01:14:52.524823 -------------------------------------------------------------------------------- Name : viewvc Product : Fedora 25 Version : 1.1.26 Release : 1.fc25 URL : https://www.viewvc.org/ Summary : Browser interface for CVS and SVN version control repositories Description : ViewVC is a browser interface for CVS and Subversion version control repositories. It generates templatized HTML to present navigable directory, revision, and change log listings. It can display specific versions of files as well as diffs between those versions. Basically, ViewVC provides the bulk of the report-like functionality you expect out of your version control tool, but much more prettily than the average textual command-line program output. -------------------------------------------------------------------------------- Update Information: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade viewvc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several vulnerabilities were found in ViewVC, a web interface for CVS and Subversion repositories. CVE-2009-5024: remote attackers can bypass the cvsdb row_limit . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2563-1
Get the latest Linux and open source security news straight to your inbox.