Version update + security fix
Archive for May 15th, 2020
Debian: DSA-4686-1: apache-log4j1.2 security update
It was discovered that the SocketServer class included in apache-log4j1.2, a logging library for java, is vulnerable to deserialization of untrusted data. An attacker can take advantage of this flaw to execute arbitrary code in the context of the logger
USN-4360-1 introduced a regression in json-c.
USN-4360-1 introduced a regression in json-c.
Fix for CVE-2020-5283. ViewVC 1.1.28 ChangeLog – security fix: escape subdir lastmod file name (#211) – fix standalone.py first request failure (#195) ViewVC 1.1.27 ChangeLog: – suppress stack traces (with option to show) (#140) – distinguish text/binary/image files by icons (#166, #175) – colorize alternating file content lines (#167) – link to the instance root from the