<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="3e98780dca4b5d3f502d07c3558db551"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="48">
  <id>viewvc</id>
  <title>viewvc: multiple vulnerabilities fixed</title>
  <release>openSUSE 11.0</release>
  <issued date="1213627561"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=370197" id="370197" title="bug number 370197" type="bugzilla"/>
  </references>
  <description>This update of viewvc fixes multiple vulnerabilities.
- CVE-2008-1290: list CVS or SVN commits on &quot;all-forbidden&quot;
  files
- CVE-2008-1291: directly access hidden CVSROOT folders
- CVE-2008-1292: expose restricted content via the revision
  view, the log history, or the diff view
</description>
  <pkglist>
    <collection>
        <package name="viewvc" arch="i586" version="1.0.5" release="29.1">
          <filename>viewvc-1.0.5-29.1.i586.rpm</filename>
        </package>
        <package name="viewvc" arch="ppc" version="1.0.5" release="29.1">
          <filename>viewvc-1.0.5-29.1.ppc.rpm</filename>
        </package>
        <package name="viewvc" arch="x86_64" version="1.0.5" release="29.1">
          <filename>viewvc-1.0.5-29.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
