[SECURITY] [DLA 3753-1] yard security update
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-3753-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Adrian Bunk
March 06, 2024 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : yard
Version : 0.9.16-1+deb10u1
CVE ID : CVE-2019-1020001 CVE-2024-27285
Debian Bug : 945369 1065118
Two vulnerabilities were fixed in YARD, a documentation tool for the
Ruby programming laguage.
CVE-2019-1020001
Arbitrary path traversal and file access in yard server
CVE-2024-27285
Cross-Site Scripting in generated frames.html
For Debian 10 buster, these problems have been fixed in version
0.9.16-1+deb10u1.
We recommend that you upgrade your yard packages.
For the detailed security status of yard please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/yard
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmXo49MACgkQiNJCh6LY
mLEyTg/+PNYSVvH+2sniZv0cTA8bCYdKZ4esv21v3LjfoXkV8eQUzsGFxj/wCRfs
MG/roq1v+VV9eFrnEZXFZbQUloECK1TgSGL3z7uHBzgVIyKaE2Mcwm4HeoALG+03
9A5ZkRG7OsCpVHL6RB2bGQsHfZYS4n8CEYGIfGXHA2jLEsYwMNMKyMlkVENLH9f3
YMfodhZZVG4sv2CrxFBEUHC5SOhoKYaascYC8BI3gwoQZIHTwLkBA+c8ml3Fh39p
i+cppcug1BdacJJUO7Jn0TxXn9gz1u4/6C7LAxKEADiLpMGB9AfDMO4ggSBLWr2U
n6A8EnGiXm8OOVR+0XIO18QcgQIZrFS/GBzJtE5bGXAlmtTuBRxlOqliJo7aSCVl
BgGVg/CdfpEgjVqemCSPArUPQQ05jxfyaZk2YMIwb24DSMrx+83faezsktIRh0pj
zdeM+VejGGVLt+Z+u0Bdj7K4crGIJlVIHxFLDSmxPsIhlxix4xpTna8TyXb77k/X
72/AmXTtXp4lBoGuPQOMYvAYYuxXyowhxs3rnz8KmKxiL/U0el/pJQ64rfe6TGEz
nLa3Np6V46OaI6n1Um1QB66IU2rdM0XRO/yLP1RvaEEynlTBFxEyPEc6fVFok5FA
eyuARTCam9EnaFD1oHY4HmwYiORO99POnA0WTZzWtTaTYb6Bf00=
=CRhG
-----END PGP SIGNATURE-----
Reply to: