{"id":"openSUSE-SU-2021:0145-1","summary":"Security update for viewvc","details":"This update for viewvc fixes the following issues:\n\n- update to 1.1.28 (boo#1167974, CVE-2020-5283):\n  * security fix: escape subdir lastmod file name (#211)\n  * fix standalone.py first request failure (#195)\n  * suppress stack traces (with option to show) (#140)\n  * distinguish text/binary/image files by icons (#166, #175)\n  * colorize alternating file content lines (#167)\n  * link to the instance root from the ViewVC logo (#168)\n  * display directory and root counts, too (#169)\n  * fix double fault error in standalone.py (#157)\n  * support timezone offsets with minutes piece (#176)\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.\nThis update was imported from the openSUSE:Leap:15.2:Update update project.","modified":"2026-03-11T07:32:53.875744Z","published":"2021-01-23T11:22:34Z","related":["CVE-2020-5283"],"upstream":["CVE-2020-5283"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/E2A7TO5T4QEJHRLA7YZBTOPVCY4745TO/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-5283"}],"affected":[{"package":{"name":"viewvc","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/viewvc&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.28-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"viewvc":"1.1.28-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0145-1.json"}}],"schema_version":"1.7.5"}