Bug 915329 (CVE-2015-1396) - VUL-1: CVE-2015-1396: patch: directory traversal via symlinks
Summary: VUL-1: CVE-2015-1396: patch: directory traversal via symlinks
Status: RESOLVED FIXED
Alias: CVE-2015-1396
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Jean Delvare
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/113242/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-01-29 09:32 UTC by Victor Pereira
Modified: 2016-10-05 06:38 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Swamp Workflow Management 2015-01-29 23:01:04 UTC
bugbot adjusting priority
Comment 2 Jean Delvare 2015-02-16 14:01:51 UTC
As far as I can see this is fixed since GNU patch version 2.7.3, by commit "Fix the fix for CVE-2015-1196":

http://git.savannah.gnu.org/cgit/patch.git/commit/?id=41688ad8ef88bc296f3bed30b171ec73e5876b88
Comment 3 Bernhard Wiedemann 2015-06-01 12:00:11 UTC
This is an autogenerated message for OBS integration:
This bug (915329) was mentioned in
https://build.opensuse.org/request/show/309612 13.2+13.1 / patch
Comment 5 Swamp Workflow Management 2015-06-09 14:05:45 UTC
SUSE-SU-2015:1019-1: An update that solves three vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 904519,913678,915328,915329
CVE References: CVE-2015-1196,CVE-2015-1395,CVE-2015-1396
Sources used:
SUSE Linux Enterprise Server 12 (src):    patch-2.7.5-7.1
SUSE Linux Enterprise Desktop 12 (src):    patch-2.7.5-7.1
Comment 6 Jean Delvare 2016-10-05 06:38:01 UTC
Fixed long ago, closing.