Mageia alert MGASA-2018-0210 (freeplane)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2018-0210: Updated freeplane packages fix security vulnerability | |
| Date: | Sun, 22 Apr 2018 21:59:46 +0200 | |
| Message-ID: | <20180422195946.EF1B29FCEF@duvel.mageia.org> |
MGASA-2018-0210 - Updated freeplane packages fix security vulnerability Publication date: 22 Apr 2018 URL: https://advisories.mageia.org/MGASA-2018-0210.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-1000069 Description: Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened (CVE-2018-1000069). References: - https://bugs.mageia.org/show_bug.cgi?id=22925 - https://www.debian.org/security/2018/dsa-4175 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1... SRPMS: - 6/core/freeplane-1.3.15-3.1.mga6
