[ubuntu/bionic-security] patch 2.7.6-2ubuntu1.1 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Wed Jul 24 13:36:57 UTC 2019
patch (2.7.6-2ubuntu1.1) bionic-security; urgency=medium
* SECURITY UPDATE: Directory traversal
- debian/patches/CVE-2019-13636.patch: Don't follow symlinks unless
--follow-symlinks is given in src/inp.c, src/util.c.
- CVE-2019-13636
* SECURITY UPDATE: Shell command injection
- debian/patches/CVE-2019-13638.patch: Invoke ed directly instead of
using the shell in src/pch.c.
- CVE-2019-13638
Date: 2019-07-23 16:31:16.411751+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/patch/2.7.6-2ubuntu1.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list