A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches (CVE-2018-6951). A double-free flaw was found in the way the patch utility processed . MGASA-2018-0448 - Updated patch packages fix security vulnerabilities Publication date: 15 Nov 2018 URL: https://advisories.mageia.org/MGASA-2018-0448.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-6951, CVE-2018-6952 A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches (CVE-2018-6951). A double-free flaw was found in the way the patch utility processed patch files. An attacker could potentially use this flaw to crash the patch utility by tricking it into processing crafted patches (CVE-2018-6952). References: - https://bugs.mageia.org/show_bug.cgi?id=23704 - https://lists.fedoraproject.org/archives/list/
It was discovered that there was an input validation vulnerability in the patch(1) utility where an ed(1) script embedded in a regular input file could result in arbitrary code execution. This was reported by Rachel Kroll [0] et al. . Package : patch Version : 2.6.1-3+deb7u1 CVE ID : CVE-2018-1000156 Debian Bug : #894993 It was discovered that there was an input validation vulnerability in the patch(1) utility where an ed(1) script embedded in a regular input file could result in arbitrary code execution. This was reported by Rachel Kroll [0] et al. For Debian 7 "Wheezy", this issue has been fixed in patch version 2.6.1-3+deb7u1. We recommend that you upgrade your patch packages. [0] Regards, - -- ,'`. : :' : Chris Lamb `. `'`
New upstream release, including security fixes for CVE-2016-10713, CVE-2018-6951, CVE-2018-6952.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b127e58641 2018-02-20 17:10:59.957351 --------------------------------------------------------------------------------Name : patch Product : Fedora 27 Version : 2.7.6 Release : 3.fc27 URL : Summary : Utility for modifying/upgrading files Description : The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Patch should be installed because it is a common way of upgrading applications. --------------------------------------------------------------------------------Update Information: New upstream release, including security fixes for CVE-2016-10713, CVE-2018-6951, CVE-2018-6952. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade patch' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.