Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
202

openSUSE Tumbleweed: viewvc Moderate Security Update 2025:15374-1

An update that solves one vulnerability can now be installed.. # viewvc-1.3.0~dev20250722-1.1 on GA media Announcement ID: openSUSE-SU-2025:15374-1 Rating: moderate Cross-References: * CVE-2025-54141 CVSS scores: * CVE-2025-54141 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-54141 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the viewvc-1.3.0~dev20250722-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * viewvc 1.3.0~dev20250722-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54141.html . # viewvc-1.3.0~dev20250722-1.1 on GA media Announcement ID: openSUSE-SU-2025:15374-1 Rating: moderat. update, solves, vulnerability, installed, viewvc-1, 0~dev20250722-1. . LinuxSecurity.com Team

Calendar%202 Jul 25, 2025 OpenSUSE
202

openSUSE: 2021:0145-1 Moderate Update for ViewVC Security Issues

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for viewvc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0145-1 Rating: moderate References: #1167974 Cross-References: CVE-2020-5283 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for viewvc fixes the following issues: - update to 1.1.28 (boo#1167974, CVE-2020-5283): * security fix: escape subdir lastmod file name (#211) * fix standalone.py first request failure (#195) * suppress stack traces (with option to show) (#140) * distinguish text/binary/image files by icons (#166, #175) * colorize alternating file content lines (#167) * link to the instance root from the ViewVC logo (#168) * display directory and root counts, too (#169) * fix double fault error in standalone.py (#157) * support timezone offsets with minutes piece (#176) This update was imported from the openSUSE:Leap:15.1:Update update project. This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-145=1 Package List: - openSUSE Backports SLE-15-SP2 (noarch): viewvc-1.1.28-bp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-5283.html https://bugzilla.suse.com/1167974 . A Fedora security patch for gnome-shell addresses a significant vulnerability, improving security and functionality, warranting immediate attention.. openSUSE Security Fix, ViewVCUpdate, Moderate Issue, Software Patch. . LinuxSecurity.com Team

Calendar%202 Jan 23, 2021 OpenSUSE
202

openSUSE Leap 15.2: openSUSE-SU-2021:0123-1 Moderate ViewVC Security Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for viewvc ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0123-1 Rating: moderate References: #1167974 Cross-References: CVE-2020-5283 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for viewvc fixes the following issues: - update to 1.1.28 (boo#1167974, CVE-2020-5283): * security fix: escape subdir lastmod file name (#211) * fix standalone.py first request failure (#195) * suppress stack traces (with option to show) (#140) * distinguish text/binary/image files by icons (#166, #175) * colorize alternating file content lines (#167) * link to the instance root from the ViewVC logo (#168) * display directory and root counts, too (#169) * fix double fault error in standalone.py (#157) * support timezone offsets with minutes piece (#176) This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-123=1 Package List: - openSUSE Leap 15.2 (noarch): viewvc-1.1.28-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-5283.html https://bugzilla.suse.com/1167974 . The latest release for openSUSE addresses a significant security vulnerability in viewvc, ensuring improved system reliability and enhanced protection.. openSUSE Update, ViewVC Security Patch, Software Security Fix. . LinuxSecurity.com Team

Calendar%202 Jan 20, 2021 OpenSUSE
203

Mageia: 2020-0221 Moderate: Fix for ViewVC Cross-Site Scripting Issue

Updated viewvc package fixes security vulnerability: ViewVC before versions 1.1.28 has an XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository . MGASA-2020-0221 - Updated viewvc packages fix security vulnerability Publication date: 24 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0221.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-5283 Updated viewvc package fixes security vulnerability: ViewVC before versions 1.1.28 has an XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create (CVE-2020-5283). The viewvc package has been updated to version 1.1.28, fixing this issue and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=26628 - https://github.com/viewvc/viewvc/security/advisories/GHSA-xpxf-fvqv-7mfg - https://github.com/viewvc/viewvc/releases/tag/1.1.27 - https://github.com/viewvc/viewvc/releases/tag/1.1.28 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/2Q2STF2MKT24HXZ3YZIU7CN6F6QM67I5/ - https://www.cve.org/CVERecord?id=CVE-2020-5283 SRPMS: - 7/core/viewvc-1.1.28-1.mga7 . Revised viewvc distributions fix a cross-site scripting vulnerability impacting Mageia 7 versions. Release date: May 24, 2020.. ViewVC Update, Mageia Security, XSS Fix, Security Advisory. . LinuxSecurity.com Team

Calendar%202 May 24, 2020 Mageia
89

Fedora 24: FEDORA-2017-2bce6ed778 Moderate: ViewVC XSS Issue

Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-2bce6ed778 2017-02-09 16:28:05.010316 -------------------------------------------------------------------------------- Name : viewvc Product : Fedora 24 Version : 1.1.26 Release : 1.fc24 URL : https://www.viewvc.org/ Summary : Browser interface for CVS and SVN version control repositories Description : ViewVC is a browser interface for CVS and Subversion version control repositories. It generates templatized HTML to present navigable directory, revision, and change log listings. It can display specific versions of files as well as diffs between those versions. Basically, ViewVC provides the bulk of the report-like functionality you expect out of your version control tool, but much more prettily than the average textual command-line program output. -------------------------------------------------------------------------------- Update Information: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade viewvc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent ViewVC 1.1.26 release for Fedora 24 addresses critical XSS issues by sanitizing nav_data, thus bolstering the overall security of the application.. Fedora ViewVC Security Fix, XSS Attack Mitigation, Software Update Notification. . LinuxSecurity.com Team

Calendar%202 Feb 09, 2017 Fedora
87

Debian: DSA-3784-1 Critical: Viewvc Cross-Site Scripting Threat

Thomas Gerbet discovered that viewvc, a web interface for CVS and Subversion repositories, did not properly sanitize user input. This problem resulted in a potential Cross-Site Scripting vulnerability. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3784-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 09, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : viewvc CVE ID : CVE-2017-5938 Debian Bug : 854681 Thomas Gerbet discovered that viewvc, a web interface for CVS and Subversion repositories, did not properly sanitize user input. This problem resulted in a potential Cross-Site Scripting vulnerability. For the stable distribution (jessie), this problem has been fixed in version 1.1.22-1+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 1.1.26-1. We recommend that you upgrade your viewvc packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-3785-1: drupal update addresses Multiple Vulnerabilities. Immediate upgrade advised for safety.. Debian Security, Viewvc Update, Cross-Site Scripting Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 09, 2017 Critical Debian
89

Fedora 25 ViewVC Update: XSS Attack Prevention in Version 1.1.26

Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-bd3c3c957f 2017-02-09 01:14:52.524823 -------------------------------------------------------------------------------- Name : viewvc Product : Fedora 25 Version : 1.1.26 Release : 1.fc25 URL : https://www.viewvc.org/ Summary : Browser interface for CVS and SVN version control repositories Description : ViewVC is a browser interface for CVS and Subversion version control repositories. It generates templatized HTML to present navigable directory, revision, and change log listings. It can display specific versions of files as well as diffs between those versions. Basically, ViewVC provides the bulk of the report-like functionality you expect out of your version control tool, but much more prettily than the average textual command-line program output. -------------------------------------------------------------------------------- Update Information: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name to avoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrev assertion on long input -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade viewvc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an emailto This email address is being protected from spambots. You need JavaScript enabled to view it. . A vital update for Fedora 25 is here to fix a critical XSS vulnerability in viewvc version 1.1.26, ensuring your system's security against threats. Fedora Updates, ViewVC Security, XSS Protection, Software Updates, Version Control. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 09, 2017 Critical Fedora
87

Debian: DSA-2563-1 Critical: ViewVC Remote Attack Mitigations

Several vulnerabilities were found in ViewVC, a web interface for CVS and Subversion repositories. CVE-2009-5024: remote attackers can bypass the cvsdb row_limit . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2563-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst October 23, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : viewvc Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2009-5024 CVE-2012-3356 CVE-2012-3357 CVE-2012-4533 Several vulnerabilities were found in ViewVC, a web interface for CVS and Subversion repositories. CVE-2009-5024: remote attackers can bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks via the limit parameter. CVE-2012-3356: the remote SVN views functionality does not properly perform authorization, which allows remote attackers to bypass intended access restrictions. CVE-2012-3357: the SVN revision view does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information. CVE-2012-4533: "function name" lines returned by diff are not properly escaped, allowing attackers with commit access to perform cross site scripting. For the stable distribution (squeeze), these problems have been fixed in version 1.1.5-1.1+squeeze2. For the testing distribution (wheezy), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 1.1.5-1.4. We recommend that you upgrade your viewvc packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. .Tackling significant ViewVC vulnerabilities in Debian: update immediately to prevent potential threats and security incidents.. Debian Security Advisory, ViewVC Update, Remote Attack Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 23, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200