[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 3753-1] yard security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3753-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                          Adrian Bunk
March 06, 2024                                https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : yard
Version        : 0.9.16-1+deb10u1
CVE ID         : CVE-2019-1020001 CVE-2024-27285
Debian Bug     : 945369 1065118

Two vulnerabilities were fixed in YARD, a documentation tool for the 
Ruby programming laguage.

CVE-2019-1020001

    Arbitrary path traversal and file access in yard server

CVE-2024-27285

    Cross-Site Scripting in generated frames.html

For Debian 10 buster, these problems have been fixed in version
0.9.16-1+deb10u1.

We recommend that you upgrade your yard packages.

For the detailed security status of yard please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/yard

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmXo49MACgkQiNJCh6LY
mLEyTg/+PNYSVvH+2sniZv0cTA8bCYdKZ4esv21v3LjfoXkV8eQUzsGFxj/wCRfs
MG/roq1v+VV9eFrnEZXFZbQUloECK1TgSGL3z7uHBzgVIyKaE2Mcwm4HeoALG+03
9A5ZkRG7OsCpVHL6RB2bGQsHfZYS4n8CEYGIfGXHA2jLEsYwMNMKyMlkVENLH9f3
YMfodhZZVG4sv2CrxFBEUHC5SOhoKYaascYC8BI3gwoQZIHTwLkBA+c8ml3Fh39p
i+cppcug1BdacJJUO7Jn0TxXn9gz1u4/6C7LAxKEADiLpMGB9AfDMO4ggSBLWr2U
n6A8EnGiXm8OOVR+0XIO18QcgQIZrFS/GBzJtE5bGXAlmtTuBRxlOqliJo7aSCVl
BgGVg/CdfpEgjVqemCSPArUPQQ05jxfyaZk2YMIwb24DSMrx+83faezsktIRh0pj
zdeM+VejGGVLt+Z+u0Bdj7K4crGIJlVIHxFLDSmxPsIhlxix4xpTna8TyXb77k/X
72/AmXTtXp4lBoGuPQOMYvAYYuxXyowhxs3rnz8KmKxiL/U0el/pJQ64rfe6TGEz
nLa3Np6V46OaI6n1Um1QB66IU2rdM0XRO/yLP1RvaEEynlTBFxEyPEc6fVFok5FA
eyuARTCam9EnaFD1oHY4HmwYiORO99POnA0WTZzWtTaTYb6Bf00=
=CRhG
-----END PGP SIGNATURE-----


Reply to: