[ubuntu/trusty-updates] zsh 5.0.2-3ubuntu6.1 (Accepted)
Ubuntu Archive Robot
cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Thu Mar 8 15:28:08 UTC 2018
zsh (5.0.2-3ubuntu6.1) trusty-security; urgency=medium
* SECURITY UPDATE: possibly privilege escalation
- debian/patches/CVE-2014-10070.patch: safer import of
numerical variables from environment in Src/params.c,
Src/zsh.h.
- CVE-2014-10070
* SECURITY UPDATE: buffer overflow
- debian/patches/CVE-2014-10071.patch: avoid buffer overflow
for very long fds in Src/exec.c.
- CVE-2014-10071
* SECURITY UPDATE: buffer overflow
- debian/patches/CVE-2014-10072.patch: fix buffer overflow in
Src/utils.c.
- CVE-2014-10072
* SECURITY UPDATE: undersized buffer
- debian/patches/CVE-2016-10714.patch: Add extra byte to PATH_MAX
in Src/Zle/compctl.c, Src/builtin.c, Src/compat.c, Src/exec.c,
Src/glob.c, Src/hist.c, Src/utils.c.
- CVE-2016-10714
* SECURITY UPDATE: NULL dereference
- debian/patches/CVE-2017-18205.patch: fix in Src/builtin.c,
Test/B01cd.ztst.
- CVE-2017-18205
* SECURITY UPDATE: Crash while copy an empty hash table
- debian/patches/CVE-2018-7549.patch: avoid crash empty
hash table in Src/params.c.
- CVE-2018-7549
Date: 2018-03-07 12:44:11.697876+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/zsh/5.0.2-3ubuntu6.1
-------------- next part --------------
Sorry, changesfile not available.
More information about the Trusty-changes
mailing list