- Security fix for CVE-2019-13636 - Security fix for CVE-2019-13638. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-ac709da87f 2019-08-23 01:26:06.889580 --------------------------------------------------------------------------------Name : patch Product : Fedora 30 Version : 2.7.6 Release : 11.fc30 URL : Summary : Utility for modifying/upgrading files Description : The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Patch should be installed because it is a common way of upgrading applications. --------------------------------------------------------------------------------Update Information: - Security fix for CVE-2019-13636 - Security fix for CVE-2019-13638 --------------------------------------------------------------------------------ChangeLog: * Mon Jul 29 2019 Than Ngo - 2.7.6-11 - fixed #1733917, CVE-2019-13638 patch: OS shell command injection when processing crafted patch files * Wed Jul 24 2019 Than Ngo - 2.7.6-10 - backported patch, abort when cleaning up fails - backported patch, improve support for memory leak detection - backported patch, don't crash when RLIMIT_NOFILE is set to RLIM_INFINITY - backported patch, CVE-2019-13636, don't follow symlinks unless --follow-symlinks is given - backported patch, avoid invalid memory accessin context format diffs - backported patch, fix failed assertion --------------------------------------------------------------------------------References: [ 1 ] Bug #1732781 - CVE-2019-13636 patch: the following of symlinks in inp.c and util.c is mishandled in cases other than input files https://bugzilla.redhat.com/show_bug.cgi?id=1732781 [ 2 ] Bug#1733916 - CVE-2019-13638 patch: OS shell command injection when processing crafted patch files https://bugzilla.redhat.com/show_bug.cgi?id=1733916 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-ac709da87f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Handling of symlinks in patch, a tool to apply a diff file to an original, was wrong in certain cases. . Package : patch Version : 2.7.5-1+deb8u2 CVE ID : CVE-2019-13636 Handling of symlinks in patch, a tool to apply a diff file to an original, was wrong in certain cases. For Debian 8 "Jessie", this problem has been fixed in version 2.7.5-1+deb8u2. We recommend that you upgrade your patch packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your patch packages in response to symlink management concerns on Debian LTS platforms to maintain security.. Debian, patch, symlink, security update, LTS. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in libvirt.. =========================================================================Ubuntu Security Notice USN-2209-1 May 07, 2014 libvirt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 Summary: Several security issues were fixed in libvirt. Software Description: - libvirt: Libvirt virtualization toolkit Details: It was discovered that libvirt incorrectly handled symlinks when using the LXC driver. An attacker could possibly use this issue to delete host devices, create arbitrary nodes, and shutdown or power off the host. (CVE-2013-6456) Marian Krcmarik discovered that libvirt incorrectly handled seamless SPICE migrations. An attacker could possibly use this issue to cause a denial of service. (CVE-2013-7336) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: libvirt-bin 1.1.1-0ubuntu8.11 libvirt0 1.1.1-0ubuntu8.11 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2209-1 CVE-2013-6456, CVE-2013-7336 Package Information: https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.11 . Address vulnerabilities in libvirt by applying recent updates for Ubuntu 13.10 to bolster defenses against potential threats.. Ubuntu Libvirt Fix, Libvirt Security Issues, Ubuntu Vulnerability Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.