[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 1348-1] patch security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : patch
Version        : 2.6.1-3+deb7u1
CVE ID         : CVE-2018-1000156
Debian Bug     : #894993

It was discovered that there was an input validation vulnerability in the
patch(1) utility where an ed(1) script embedded in a regular input file
could result in arbitrary code execution. This was reported by Rachel
Kroll [0] et al.

For Debian 7 "Wheezy", this issue has been fixed in patch version
2.6.1-3+deb7u1.

We recommend that you upgrade your patch packages.

  [0] https://rachelbythebay.com/w/2018/04/05/bangpatch/


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAlrUhW0ACgkQHpU+J9Qx
HliTjBAAgoZLoN+0FvkHzq+UqaKYHW+Y1Ybi5cFNC63BZiqn8gXyO3E2NeFiixv2
90J4TsAAmWP+Rm/Y5sxyUwSnpT3MkiJB1/WeAOTyQgIUx0qdchlLGIuqOtj2kAKk
+NHpR+dPaaYRRhDycQlsaXf8lmFqvJec26NbI8GIYSilhv/BNm7thM45s5z78l+U
AL7nt23oOItdO0L3xgYeWIqBhU96OGw7KjK0XgkbKTUh7OGTEMeqXufNlr5wQNgO
zfR+OvRhXJ2oG9Ft1zQlJY7arClk9gW0a1+n7irE+jhRKu4qKR74YevTM6H0PFCv
eCnjSW8cdgXLb8GZKMAUnA0iw0tSbuP6gKIojcdmUhtLOmSmdQx3HMGtMVrE3DaD
+Rk5ocqQjiP+Dm108Gojf9iKSSL9UEoWaVE3haQft2MQBrXs52aerk08/unEntsf
sCKgsh8oqnBtnsWU72pE4Z8ktE6IH6LRCAnoQtkDyG3jpBhXtULD9+qXbR07VR7r
9y4v7lE9VSTiPSiufB7arA5LCnNn/0JeZsmGzYh7CYllfMnJWWZ4oappJrr/MhIx
8YevQA3tZ2sQU2T4+lCmE5nFEEI/B4EVaVjktdm0/B5ke2EkWAotgTO2DLVzk6T6
J40JPr6bgBAgAVP57sx0GtOiSOYosRR5S5tCkDpRUiU7sG+Kc/Q=
=Ave6
-----END PGP SIGNATURE-----


Reply to: