[ubuntu/bionic-updates] busybox 1:1.27.2-2ubuntu3.1 (Accepted)

Robie Basak robie.basak at canonical.com
Wed Mar 6 11:43:04 UTC 2019


busybox (1:1.27.2-2ubuntu3.1) bionic; urgency=medium

  * Fix symlink handling (LP: #1753572)
    - debian/patches/CVE-2011-5325-2.patch: re-enable patch.
    - debian/patches/CVE-2011-5325-3.patch:postpone creation of symlinks
      with "suspicious" targets in archival/libarchive/data_extract_all.c,
      archival/libarchive/unsafe_symlink_target.c, archival/tar.c,
      include/bb_archive.h, testsuite/tar.tests.
    - debian/patches/CVE-2011-5325-4.patch: extract "unsafe" symlinks
      the same way tar/unzip does in archival/cpio.c.
    - debian/patches/CVE-2011-5325-5.patch: fix symlink creation in
      archival/libarchive/get_header_ar.c.

Date: 2019-01-17 18:28:09.641020+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Robie Basak <robie.basak at canonical.com>
https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Bionic-changes mailing list