The following Fedora EPEL 6 Security updates need testing: Age URL 12 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-aa01e58571 openvpn-2.4.9-1.el6 6 https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2020-c8a92d6324 wordpress-5.1.5-1.el6 The following builds have been pushed to Fedora EPEL 6 updates-testing viewvc-1.1.28-1.el6 Details about builds: ================================================================================ viewvc-1.1.28-1.el6 (FEDORA-EPEL-2020-1be509a6b3) Browser interface for CVS and SVN version control repositories -------------------------------------------------------------------------------- Update Information: Fix for CVE-2020-5283. ViewVC 1.1.28 ChangeLog - security fix: escape subdir lastmod file name (#211) - fix standalone.py first request failure (#195) ViewVC 1.1.27 ChangeLog: - suppress stack traces (with option to show) (#140) - distinguish text/binary/image files by icons (#166, #175) - colorize alternating file content lines (#167) - link to the instance root from the ViewVC logo (#168) - display directory and root counts, too (#169) - fix double fault error in standalone.py (#157) - support timezone offsets with minutes piece (#176) -------------------------------------------------------------------------------- ChangeLog: * Wed May 6 2020 Bojan Smojver <bojan@xxxxxxxxxxxxx> - 1.1.28-1 - bump up to 1.1.26 - CVE-2020-5283 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1831804 - CVE-2020-5283 viewvc: XSS vulnerability in CVS show_subdir_lastmod support [fedora-30] https://bugzilla.redhat.com/show_bug.cgi?id=1831804 [ 2 ] Bug #1831805 - CVE-2020-5283 viewvc: XSS vulnerability in CVS show_subdir_lastmod support [epel-6] https://bugzilla.redhat.com/show_bug.cgi?id=1831805 [ 3 ] Bug #1831806 - CVE-2020-5283 viewvc: XSS vulnerability in CVS show_subdir_lastmod support [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1831806 -------------------------------------------------------------------------------- _______________________________________________ epel-devel mailing list -- epel-devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to epel-devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/epel-devel@xxxxxxxxxxxxxxxxxxxxxxx