openSUSE-SU-2023:0137-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0137-1
openSUSE-SU-2023:0137-1
Summary: Security update for guile1, lilypond
Details: This update for guile1, lilypond fixes the following issues: guile1: - Add service file to download release from git excluding the directory with commercial non free files. - Update to version 2.2.6 to enable lilypond to be updated to 2.24.1 to fix boo#1210502 and CVE-2020-17354. lilypond: - Update to version lilypond-2.24.1 to fix boo#1210502 - CVE-2020-17354: lilypond: Lilypond allows attackers to bypass the -dsafe protection mechanism.
References: https://lists.opensuse.org/archives/list/[email protected]/thread/ROLJCNPWZ2G4IQWP7NQKXNBT2QR32K2A/, https://bugzilla.suse.com/1210502, https://www.suse.com/security/cve/CVE-2016-8605, https://www.suse.com/security/cve/CVE-2020-17354
Affected packages
Package
Name: guile1
Purl: pkg:rpm/suse/guile1&distro=SUSE%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
