Security fix for CVE-2018-6951 and CVE-2018-6952. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c255f16bfe 2018-10-15 10:46:15.107498 --------------------------------------------------------------------------------Name : patch Product : Fedora 28 Version : 2.7.6 Release : 5.fc28 URL : Summary : Utility for modifying/upgrading files Description : The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Patch should be installed because it is a common way of upgrading applications. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-6951 and CVE-2018-6952 --------------------------------------------------------------------------------ChangeLog: * Thu Oct 11 2018 Than Ngo - 2.7.6-5 - Fixed CVE-2018-6952 - Double free of memory * Thu May 3 2018 Tim Waugh - 2.7.6-4 - Fixed CVE-2018-1000156 - Malicious patch files cause ed to execute arbitrary commands. --------------------------------------------------------------------------------References: [ 1 ] Bug #1545053 - CVE-2018-6952 patch: Double free of memory in pch.c:another_hunk() causes a crash https://bugzilla.redhat.com/show_bug.cgi?id=1545053 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c255f16bfe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2018-1000156. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ed8d7c62c9 2018-05-09 21:21:50.032869 --------------------------------------------------------------------------------Name : patch Product : Fedora 28 Version : 2.7.6 Release : 4.fc28 URL : Summary : Utility for modifying/upgrading files Description : The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Patch should be installed because it is a common way of upgrading applications. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-1000156 --------------------------------------------------------------------------------ChangeLog: * Thu May 3 2018 Tim Waugh - 2.7.6-4 - Fixed CVE-2018-1000156 - Malicious patch files cause ed to execute arbitrary commands. --------------------------------------------------------------------------------References: [ 1 ] Bug #1564326 - CVE-2018-1000156 patch: Malicious patch files cause ed to execute arbitrary commands https://bugzilla.redhat.com/show_bug.cgi?id=1564326 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-ed8d7c62c9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.