Mageia 2023-0019: viewvc security update
Summary
ViewVC is vulnerable to cross-site scripting. The impact of these
vulnerabilities is mitigated by the need for an attacker to have commit
privileges to a Subversion repository exposed by an otherwise trusted
ViewVC instance. The attack vector involves files with unsafe names (names
that, when embedded into an HTML stream, would cause the browser to run
unwanted code), which themselves can be challenging to create.
(CVE-2023-22456, CVE-2023-22464)
References
- https://bugs.mageia.org/show_bug.cgi?id=31417
- https://www.debian.org/lts/security/2023/dla-3266
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22456
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-22464
Resolution
MGASA-2023-0019 - Updated viewvc packages fix security vulnerability
SRPMS
- 8/core/viewvc-1.3.0-0.dev20200516.1.1.mga8