{"id":"openSUSE-SU-2021:0119-1","summary":"Security update for viewvc","details":"This update for viewvc fixes the following issues:\n\n- update to 1.1.28 (boo#1167974, CVE-2020-5283):\n  * security fix: escape subdir lastmod file name (#211)\n  * fix standalone.py first request failure (#195)\n  * suppress stack traces (with option to show) (#140)\n  * distinguish text/binary/image files by icons (#166, #175)\n  * colorize alternating file content lines (#167)\n  * link to the instance root from the ViewVC logo (#168)\n  * display directory and root counts, too (#169)\n  * fix double fault error in standalone.py (#157)\n  * support timezone offsets with minutes piece (#176)\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","modified":"2026-03-11T07:32:53.546696Z","published":"2021-01-19T15:26:25Z","related":["CVE-2020-5283"],"upstream":["CVE-2020-5283"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/KGEO74AOMRFBUZ5VL2QLLN3TAWYC7ZKW/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-5283"}],"affected":[{"package":{"name":"viewvc","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/viewvc&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.28-bp151.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"viewvc":"1.1.28-bp151.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0119-1.json"}}],"schema_version":"1.7.5"}