Updated patch package fixes security vulnerabilities: * In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. (CVE-2019-13636). . MGASA-2020-0093 - Updated patch packages fix security vulnerabilities Publication date: 21 Feb 2020 URL: https://advisories.mageia.org/MGASA-2020-0093.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13636, CVE-2019-13638, CVE-2018-20969 Updated patch package fixes security vulnerabilities: * In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. (CVE-2019-13636). * A vulnerability was found in GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters (CVE-2019-13638). * A vulnerability was found in do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter (CVE-2018-20969). References: - https://bugs.mageia.org/show_bug.cgi?id=25279 - https://lists.fedoraproject.org/archives/list/
Update to v1.13.5 (CVE-2019-1002101 - Mishandling of symlinks allows for arbitrary file write via `kubectl cp`). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-bf800b1c04 2019-06-19 22:44:22.998147 --------------------------------------------------------------------------------Name : kubernetes Product : Fedora 30 Version : 1.13.5 Release : 1.fc30 URL : https://kubernetes.io/docs/home/ Summary : Container cluster management Description : Container cluster management --------------------------------------------------------------------------------Update Information: Update to v1.13.5 (CVE-2019-1002101 - Mishandling of symlinks allows for arbitrary file write via `kubectl cp`) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 11 2019 Jan Chaloupka - 1.13.5-1 - Update to v1.13.5 (CVE-2019-1002101 - Mishandling of symlinks allows for arbitrary file write via `kubectl cp`) resolves: #1693884 --------------------------------------------------------------------------------References: [ 1 ] Bug #1693884 - CVE-2019-1002101 kubernetes: Mishandling of symlinks allows for arbitrary file write via `kubectl cp` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1693884 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-bf800b1c04' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailinglist --
Get the latest Linux and open source security news straight to your inbox.