[ubuntu/bionic-security] cpio 2.12+dfsg-6ubuntu0.18.04.4 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Sep 8 11:11:01 UTC 2021
cpio (2.12+dfsg-6ubuntu0.18.04.4) bionic-security; urgency=medium
* SECURITY UPDATE: arbitrary code execution via crafted pattern file
- debian/patches/CVE-2021-38185.patch: rewrite dynamic string support
in src/copyin.c, src/copyout.c, src/copypass.c, src/dstring.c,
src/dstring.h, src/util.c.
- debian/patches/CVE-2021-38185.2.patch: don't call ds_resize in a loop
in src/dstring.c.
- debian/patches/CVE-2021-38185.3.patch: fix dynamic string
reallocations in src/dstring.c.
- CVE-2021-38185
Date: 2021-08-25 12:04:13.631490+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/cpio/2.12+dfsg-6ubuntu0.18.04.4
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list