File _patchinfo of Package patchinfo.29453

<patchinfo incident="29453">
  <issue tracker="cve" id="2023-2976"/>
  <issue tracker="cve" id="2020-8908"/>
  <issue tracker="bnc" id="1212401">VUL-0: CVE-2023-2976: guava: Predictable temporary files and directories used in FileBackedOutputStream</issue>
  <issue tracker="bnc" id="1179926">VUL-1: CVE-2020-8908: guava,guava20: A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.</issue>
  <packager>fstrba</packager>
  <rating>moderate</rating>
  <category>security</category>
  <summary>Security update for guava</summary>
  <description>This update for guava fixes the following issues:

Upgrade to guava 32.0.1:

- CVE-2020-8908: Fixed predictable temporary files and directories used in FileBackedOutputStream (bsc#1179926).
- CVE-2023-2976: Fixed a temp directory creation vulnerability (bsc#1212401).
</description>
</patchinfo>
openSUSE Build Service is sponsored by