MGASA-2017-0048

Source
https://advisories.mageia.org/MGASA-2017-0048.html
Import Source
https://advisories.mageia.org/MGASA-2017-0048.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0048
Related
Published
2017-02-18T16:29:09Z
Modified
2017-02-18T15:40:54Z
Summary
Updated viewvc packages fix security vulnerability
Details

Thomas Gerbet discovered that viewvc, a web interface for CVS and Subversion repositories, did not properly sanitize user input. This problem resulted in a potential Cross-Site Scripting vulnerability (CVE-2017-5938).

The viewvc package has been updated to version 1.1.26 which fixes this issue.

References
Credits

Affected packages

Mageia:5 / viewvc

Package

Name
viewvc
Purl
pkg:rpm/mageia/viewvc?arch=source&distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.26-1.mga5

Ecosystem specific

{
    "section": "core"
}