Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Mageia 7: MGASA-2020-0093 Moderate Update for GNU Patch Vulnerabilities

mageia
Calendar Grey February 21, 2020
Dist Mageia Esm H88
The latest Mageia update addresses vulnerabilities linked to improper symlink management and potential command injection exploits.
Updated patch package fixes security vulnerabilities: * In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files

Summary

Updated patch package fixes security vulnerabilities:
* In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. (CVE-2019-13636).
* A vulnerability was found in GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters (CVE-2019-13638).
* A vulnerability was found in do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter (CVE-2018-20969).

References

- https://bugs.mageia.org/show_bug.cgi?id=25279

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SVWWGISFWACROJJPVJJL4UBLVZ7LPOLT/

- https://access.redhat.com/errata/RHSA-2019:2798

- https://www.cve.org/CVERecord?id=CVE-2019-13636

- https://www.cve.org/CVERecord?id=CVE-2019-13638

- https://www.cve.org/CVERecord?id=CVE-2018-20969

Resolution

SRPMS

- 7/core/patch-2.7.6-4.1.mga7

Publication date: 21 Feb 2020
URL: https://advisories.mageia.org/MGASA-2020-0093.html
Type: security
CVE: CVE-2019-13636, CVE-2019-13638, CVE-2018-20969

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here