MGASA-2018-0277

Source
https://advisories.mageia.org/MGASA-2018-0277.html
Import Source
https://advisories.mageia.org/MGASA-2018-0277.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2018-0277
Related
Published
2018-06-14T18:14:36Z
Modified
2018-06-14T17:39:53Z
Summary
Updated patch packages fix security vulnerabilities
Details

Updated patch package fixes security vulnerabilities:

It was discovered that Patch incorrectly handled certain files. An attacker could possibly use this to cause a denial of service (CVE-2016-10713).

It was discovered that Patch incorrectly handled certain inputs. An attacker could possibly use this to cause a denial of service (CVE-2018-6951).

It was discovered that Patch incorrectly handled certain input validation. An attacker could possibly use this to execute arbitrary code (CVE-2018-1000156).

References
Credits

Affected packages

Mageia:5 / patch

Package

Name
patch
Purl
pkg:rpm/mageia/patch?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / patch

Package

Name
patch
Purl
pkg:rpm/mageia/patch?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.6-1.mga6

Ecosystem specific

{
    "section": "core"
}