Summary: | <www-apps/tt-rss-20200922: Multiple vulnerabilities (CVE-2020-{25787,25788,25789}) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | ajak, chewi |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://community.tt-rss.org/t/heads-up-several-vulnerabilities-fixed/3799 | ||
Whiteboard: | ~4 [gnoglsa cve] | ||
Package list: | Runtime testing required: | --- |
Description
Sam James
2020-09-22 20:31:52 UTC
Please bump when you can! Thanks :) * CVE-2020-25789 Description: "An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. The cached_url feature mishandles JavaScript inside an SVG document." Bump on the way. (In reply to James Le Cuirot from comment #3) > Bump on the way. Thanks! The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=25bbfeb39f123d840b57975e6f71c76666c73a9e commit 25bbfeb39f123d840b57975e6f71c76666c73a9e Author: James Le Cuirot <chewi@gentoo.org> AuthorDate: 2020-09-23 21:41:53 +0000 Commit: James Le Cuirot <chewi@gentoo.org> CommitDate: 2020-09-23 21:41:53 +0000 www-apps/tt-rss: Drop old vulnerable versions Bug: https://bugs.gentoo.org/744157 Package-Manager: Portage-3.0.6, Repoman-3.0.1 Signed-off-by: James Le Cuirot <chewi@gentoo.org> www-apps/tt-rss/Manifest | 2 - www-apps/tt-rss/tt-rss-20180105.ebuild | 84 ---------------------------------- www-apps/tt-rss/tt-rss-20190523.ebuild | 84 ---------------------------------- 3 files changed, 170 deletions(-) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5ef6ecc9f0d8c046fd0b66f6e371400f251ac17a commit 5ef6ecc9f0d8c046fd0b66f6e371400f251ac17a Author: James Le Cuirot <chewi@gentoo.org> AuthorDate: 2020-09-23 21:39:41 +0000 Commit: James Le Cuirot <chewi@gentoo.org> CommitDate: 2020-09-23 21:40:58 +0000 www-apps/tt-rss: Bump snapshot to 20200922, GLEP 81 Bug: https://bugs.gentoo.org/744157 Package-Manager: Portage-3.0.6, Repoman-3.0.1 Signed-off-by: James Le Cuirot <chewi@gentoo.org> www-apps/tt-rss/Manifest | 1 + www-apps/tt-rss/tt-rss-20200922.ebuild | 87 ++++++++++++++++++++++++++++++++++ www-apps/tt-rss/tt-rss-99999999.ebuild | 48 ++++++++++--------- 3 files changed, 114 insertions(+), 22 deletions(-) Thanks Chewi. Tree clean, no stable -> noglsa, all done. |