Update of viewvc from 1.1-dev to 1.1.3 to fix security issues?

Bruce Cran bruce at cran.org.uk
Wed Jan 13 15:38:44 UTC 2010


Hi,

Having recently setup a ViewVC server myself, I noticed that
http://svn.freebsd.org/viewvc is still reporting that it's using
version 1.1-dev, which I presume is a version from before 1.1.0?

Version 1.1.3 was released just before Christmas and fixed a couple of
new security issues. I don't know what configuration is being used, but
if you're running a version before 1.1.2 you might want to consider
upgrading since they have an XSS flaw.

Regards,
Bruce Cran

-- 
bruce at cran.org.uk
brucec at freebsd.org


More information about the freebsd-www mailing list