<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for guile1, lilypond</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2023:0137-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2023-06-27T15:41:48Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2023-06-27T15:41:48Z</InitialReleaseDate>
    <CurrentReleaseDate>2023-06-27T15:41:48Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for guile1, lilypond</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for guile1, lilypond fixes the following issues:

guile1:

- Add service file to download release from git excluding the
  directory with commercial non free files.
- Update to version 2.2.6 to enable lilypond to be updated to 
  2.24.1 to fix boo#1210502 and CVE-2020-17354.

lilypond:

- Update to version lilypond-2.24.1 to fix boo#1210502 -
  CVE-2020-17354: lilypond: Lilypond allows attackers to bypass 
  the -dsafe protection mechanism.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2023-137</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ROLJCNPWZ2G4IQWP7NQKXNBT2QR32K2A/</URL>
      <Description>E-Mail link for openSUSE-SU-2023:0137-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1210502</URL>
      <Description>SUSE Bug 1210502</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-8605/</URL>
      <Description>SUSE CVE CVE-2016-8605 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-17354/</URL>
      <Description>SUSE CVE CVE-2020-17354 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP4">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP4">
        <FullProductName ProductID="SUSE Package Hub 15 SP4">SUSE Package Hub 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.4">
      <Branch Type="Product Name" Name="openSUSE Leap 15.4">
        <FullProductName ProductID="openSUSE Leap 15.4" CPE="cpe:/o:opensuse:leap:15.4">openSUSE Leap 15.4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="guile1-2.2.6-bp154.3.3.1">
      <FullProductName ProductID="guile1-2.2.6-bp154.3.3.1">guile1-2.2.6-bp154.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="guile1-modules-2_2-2.2.6-bp154.3.3.1">
      <FullProductName ProductID="guile1-modules-2_2-2.2.6-bp154.3.3.1">guile1-modules-2_2-2.2.6-bp154.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libguile-2_2-1-2.2.6-bp154.3.3.1">
      <FullProductName ProductID="libguile-2_2-1-2.2.6-bp154.3.3.1">libguile-2_2-1-2.2.6-bp154.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libguile1-devel-2.2.6-bp154.3.3.1">
      <FullProductName ProductID="libguile1-devel-2.2.6-bp154.3.3.1">libguile1-devel-2.2.6-bp154.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-2.24.1-bp154.2.3.2">lilypond-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-2.24.1-bp154.2.3.2">lilypond-doc-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-cs-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-cs-2.24.1-bp154.2.3.2">lilypond-doc-cs-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-de-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-de-2.24.1-bp154.2.3.2">lilypond-doc-de-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-es-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-es-2.24.1-bp154.2.3.2">lilypond-doc-es-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-fr-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-fr-2.24.1-bp154.2.3.2">lilypond-doc-fr-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-hu-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-hu-2.24.1-bp154.2.3.2">lilypond-doc-hu-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-it-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-it-2.24.1-bp154.2.3.2">lilypond-doc-it-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-ja-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-ja-2.24.1-bp154.2.3.2">lilypond-doc-ja-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-nl-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-nl-2.24.1-bp154.2.3.2">lilypond-doc-nl-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-doc-zh-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-doc-zh-2.24.1-bp154.2.3.2">lilypond-doc-zh-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2">lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="lilypond-fonts-common-2.24.1-bp154.2.3.2">
      <FullProductName ProductID="lilypond-fonts-common-2.24.1-bp154.2.3.2">lilypond-fonts-common-2.24.1-bp154.2.3.2</FullProductName>
    </Branch>
    <Relationship ProductReference="guile1-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:guile1-2.2.6-bp154.3.3.1">guile1-2.2.6-bp154.3.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="guile1-modules-2_2-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:guile1-modules-2_2-2.2.6-bp154.3.3.1">guile1-modules-2_2-2.2.6-bp154.3.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libguile-2_2-1-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:libguile-2_2-1-2.2.6-bp154.3.3.1">libguile-2_2-1-2.2.6-bp154.3.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libguile1-devel-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:libguile1-devel-2.2.6-bp154.3.3.1">libguile1-devel-2.2.6-bp154.3.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-2.24.1-bp154.2.3.2">lilypond-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-2.24.1-bp154.2.3.2">lilypond-doc-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-cs-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-cs-2.24.1-bp154.2.3.2">lilypond-doc-cs-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-de-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-de-2.24.1-bp154.2.3.2">lilypond-doc-de-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-es-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-es-2.24.1-bp154.2.3.2">lilypond-doc-es-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-fr-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-fr-2.24.1-bp154.2.3.2">lilypond-doc-fr-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-hu-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-hu-2.24.1-bp154.2.3.2">lilypond-doc-hu-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-it-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-it-2.24.1-bp154.2.3.2">lilypond-doc-it-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-ja-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-ja-2.24.1-bp154.2.3.2">lilypond-doc-ja-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-nl-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-nl-2.24.1-bp154.2.3.2">lilypond-doc-nl-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-zh-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-doc-zh-2.24.1-bp154.2.3.2">lilypond-doc-zh-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2">lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-fonts-common-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:lilypond-fonts-common-2.24.1-bp154.2.3.2">lilypond-fonts-common-2.24.1-bp154.2.3.2 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="guile1-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:guile1-2.2.6-bp154.3.3.1">guile1-2.2.6-bp154.3.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="guile1-modules-2_2-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:guile1-modules-2_2-2.2.6-bp154.3.3.1">guile1-modules-2_2-2.2.6-bp154.3.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libguile-2_2-1-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:libguile-2_2-1-2.2.6-bp154.3.3.1">libguile-2_2-1-2.2.6-bp154.3.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libguile1-devel-2.2.6-bp154.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:libguile1-devel-2.2.6-bp154.3.3.1">libguile1-devel-2.2.6-bp154.3.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-2.24.1-bp154.2.3.2">lilypond-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-2.24.1-bp154.2.3.2">lilypond-doc-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-cs-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-cs-2.24.1-bp154.2.3.2">lilypond-doc-cs-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-de-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-de-2.24.1-bp154.2.3.2">lilypond-doc-de-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-es-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-es-2.24.1-bp154.2.3.2">lilypond-doc-es-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-fr-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-fr-2.24.1-bp154.2.3.2">lilypond-doc-fr-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-hu-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-hu-2.24.1-bp154.2.3.2">lilypond-doc-hu-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-it-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-it-2.24.1-bp154.2.3.2">lilypond-doc-it-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-ja-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-ja-2.24.1-bp154.2.3.2">lilypond-doc-ja-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-nl-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-nl-2.24.1-bp154.2.3.2">lilypond-doc-nl-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-doc-zh-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-doc-zh-2.24.1-bp154.2.3.2">lilypond-doc-zh-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2">lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="lilypond-fonts-common-2.24.1-bp154.2.3.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:lilypond-fonts-common-2.24.1-bp154.2.3.2">lilypond-fonts-common-2.24.1-bp154.2.3.2 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.</Note>
    </Notes>
    <CVE>CVE-2016-8605</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP4:guile1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:guile1-modules-2_2-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libguile-2_2-1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libguile1-devel-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-cs-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-de-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-es-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-fr-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-hu-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-it-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-ja-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-nl-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-zh-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-fonts-common-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:guile1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:guile1-modules-2_2-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libguile-2_2-1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libguile1-devel-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-cs-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-de-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-es-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-fr-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-hu-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-it-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-ja-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-nl-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-zh-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-fonts-common-2.24.1-bp154.2.3.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>3.2</BaseScore>
        <Vector>AV:L/AC:L/Au:S/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ROLJCNPWZ2G4IQWP7NQKXNBT2QR32K2A/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-8605.html</URL>
        <Description>CVE-2016-8605</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1004221</URL>
        <Description>SUSE Bug 1004221</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def-lookup or output-def-scope, as demonstrated by dangerous Scheme code in a .ly file that causes arbitrary code execution during conversion to a different file format. NOTE: in 2.24 and later versions, safe mode is removed, and the product no longer tries to block code execution when external files are used.</Note>
    </Notes>
    <CVE>CVE-2020-17354</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP4:guile1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:guile1-modules-2_2-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libguile-2_2-1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libguile1-devel-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-cs-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-de-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-es-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-fr-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-hu-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-it-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-ja-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-nl-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-doc-zh-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:lilypond-fonts-common-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:guile1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:guile1-modules-2_2-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libguile-2_2-1-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libguile1-devel-2.2.6-bp154.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-cs-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-de-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-es-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-fr-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-hu-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-it-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-ja-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-nl-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-doc-zh-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-emmentaler-fonts-2.24.1-bp154.2.3.2</ProductID>
        <ProductID>openSUSE Leap 15.4:lilypond-fonts-common-2.24.1-bp154.2.3.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ROLJCNPWZ2G4IQWP7NQKXNBT2QR32K2A/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-17354.html</URL>
        <Description>CVE-2020-17354</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1210502</URL>
        <Description>SUSE Bug 1210502</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
