[ubuntu/xenial-updates] zsh 5.1.1-1ubuntu2.1 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Thu Mar 8 15:28:08 UTC 2018


zsh (5.1.1-1ubuntu2.1) xenial-security; urgency=medium

  * SECURITY UPDATE: undersized buffer
    - debian/patches/CVE-2016-10714.patch: Add extra byte to PATH_MAX
      in Src/Zle/compctl.c, Src/builtin.c, Src/compat.c, Src/exec.c,
      Src/glob.c, Src/hist.c, Src/utils.c.
    - CVE-2016-10714
  * SECURITY UPDATE: NULL dereference
    - debian/patches/CVE-2017-18205.patch: fix in Src/builtin.c,
      Test/B01cd.ztst.
    - CVE-2017-18205
  * SECURITY UPATE: buffer overflow
    - debian/patches/CVE-2017-18206.patch: fix buffer overrun in xsymlinks
      in Src/utils.c.
    - CVE-2017-18206
  * SECURITY UPDATE: Crash while copy an empty hash table
    - debian/patches/CVE-2018-7549.patch: avoid crash empty
      hash table in Src/params.c.
    - CVE-2018-7549

Date: 2018-03-07 14:40:18.423398+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/zsh/5.1.1-1ubuntu2.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Xenial-changes mailing list