Bugzilla – Bug 915329
VUL-1: CVE-2015-1396: patch: directory traversal via symlinks
Last modified: 2016-10-05 06:38:01 UTC
rh#1186764 It was reported [1] that the fix for CVE-2015-1196 [2] was incomplete. [1] https://bugs.debian.org/775901 [2] https://bugzilla.redhat.com/show_bug.cgi?id=1182154 References: https://bugzilla.redhat.com/show_bug.cgi?id=1186764 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1396 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-1396.html
bugbot adjusting priority
As far as I can see this is fixed since GNU patch version 2.7.3, by commit "Fix the fix for CVE-2015-1196": http://git.savannah.gnu.org/cgit/patch.git/commit/?id=41688ad8ef88bc296f3bed30b171ec73e5876b88
This is an autogenerated message for OBS integration: This bug (915329) was mentioned in https://build.opensuse.org/request/show/309612 13.2+13.1 / patch
SUSE-SU-2015:1019-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 904519,913678,915328,915329 CVE References: CVE-2015-1196,CVE-2015-1395,CVE-2015-1396 Sources used: SUSE Linux Enterprise Server 12 (src): patch-2.7.5-7.1 SUSE Linux Enterprise Desktop 12 (src): patch-2.7.5-7.1
Fixed long ago, closing.