[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:1925-1 -- SLES patch

ID: oval:org.secpod.oval:def:89047477Date: (C)2022-06-14   (M)2023-12-20
Class: PATCHFamily: unix




This update for patch fixes the following issues: Security issues fixed: - CVE-2019-13636: Fixed follow symlinks unless --follow-symlinks is given. This increases the security against malicious patches . - CVE-2018-6952: Fixed swapping fakelines in pch_swap. This bug was causing a double free leading to a crash . Bugfixes: - Abort when cleaning up fails. This bug could cause an infinite loop when a patch wouldn"t apply, leading to a segmentation fault . - Pass the correct stat to backup files. This bug would occasionally cause backup files to be missing when all hunks failed to apply .

Platform:
SUSE Linux Enterprise Desktop 15 SP4
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Desktop 15 SP3
Product:
patch
Reference:
SUSE-SU-2022:1925-1
CVE-2018-6952
CVE-2019-13636
CVE    2
CVE-2018-6952
CVE-2019-13636
CPE    5
cpe:/a:gnu:patch
cpe:/o:suse:suse_linux_enterprise_server:15:sp4
cpe:/o:suse:suse_linux_enterprise_server:15:sp3
cpe:/o:suse:suse_linux_enterprise_desktop:15:sp4
...

© SecPod Technologies