Updated viewvc packages fix security vulnerability
Publication date: 18 Feb 2017Modification date: 18 Feb 2017
Type: security
Affected Mageia releases : 5
CVE: CVE-2017-5938
Description
Thomas Gerbet discovered that viewvc, a web interface for CVS and Subversion repositories, did not properly sanitize user input. This problem resulted in a potential Cross-Site Scripting vulnerability (CVE-2017-5938). The viewvc package has been updated to version 1.1.26 which fixes this issue.
References
SRPMS
5/core
- viewvc-1.1.26-1.mga5