SUSE-SU-2022:1932-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1932-1
SUSE-SU-2022:1932-1
Summary: Security update for patch
Details: This update for patch fixes the following issues: Security fixes: - CVE-2019-13636: Fixed mishandled following of symlinks in certain cases other than input files (bsc#1142041). - CVE-2018-6952: Fixed double free of memory in pch.c:another_hunk() (bsc#1080985). Bugfixes: - Pass the correct stat to backup files (bsc#1198106). - Fix temporary file leak when applying ed-style patches (bsc#1092500).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221932-1/, https://bugzilla.suse.com/1080985, https://bugzilla.suse.com/1092500, https://bugzilla.suse.com/1142041, https://bugzilla.suse.com/1198106, https://www.suse.com/security/cve/CVE-2018-6952, https://www.suse.com/security/cve/CVE-2019-13636
Affected packages
Package
Name: patch
Purl: pkg:rpm/suse/patch&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
