SUSE-SU-2015:1019-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1019-1
SUSE-SU-2015:1019-1
Summary: Security update for patch
Details: The GNU patch utility was updated to 2.7.5 to fix three security issues and one non-security bug. The following vulnerabilities were fixed: * CVE-2015-1196: directory traversal flaw when handling git-style patches. This could allow an attacker to overwrite arbitrary files by tricking the user into applying a specially crafted patch. (bsc#913678) * CVE-2015-1395: directory traversal flaw when handling patches which rename files. This could allow an attacker to overwrite arbitrary files by tricking the user into applying a specially crafted patch. (bsc#915328) * CVE-2015-1396: directory traversal flaw via symbolic links. This could allow an attacker to overwrite arbitrary files by tricking the user into applying a by applying a specially crafted patch. (bsc#915329) The following bug was fixed: * bsc#904519: Function names in hunks (from diff -p) are now preserved in reject files.
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151019-1/, https://bugzilla.suse.com/904519, https://bugzilla.suse.com/913678, https://bugzilla.suse.com/915328, https://bugzilla.suse.com/915329, https://www.suse.com/security/cve/CVE-2015-1196, https://www.suse.com/security/cve/CVE-2015-1395, https://www.suse.com/security/cve/CVE-2015-1396
Affected packages
Package
Name: patch
Purl: pkg:rpm/suse/patch&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
