SUSE-SU-2018:1128-1
Dashboard / Vulnerabilities / SUSE-SU-2018:1128-1
SUSE-SU-2018:1128-1
Summary: Security update for patch
Details: This update for patch fixes the following issues: Security issues fixed: - CVE-2018-1000156: Malicious patch files cause ed to execute arbitrary commands (bsc#1088420). - CVE-2018-6951: Fixed NULL pointer dereference in the intuit_diff_type function in pch.c (bsc#1080918). - CVE-2016-10713: Fixed out-of-bounds access within pch_write_line() in pch.c (bsc#1080918).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20181128-1/, https://bugzilla.suse.com/1080918, https://bugzilla.suse.com/1080951, https://bugzilla.suse.com/1088420, https://www.suse.com/security/cve/CVE-2016-10713, https://www.suse.com/security/cve/CVE-2018-1000156, https://www.suse.com/security/cve/CVE-2018-6951
Affected packages
Package
Name: patch
Purl: pkg:rpm/suse/patch&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
