Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE (security issues) of Linux patch utility #31

Open
techtonik opened this issue Jun 24, 2015 · 1 comment
Open

CVE (security issues) of Linux patch utility #31

techtonik opened this issue Jun 24, 2015 · 1 comment

Comments

@techtonik
Copy link
Owner

One of the reasons why patch.py was started was insecurity of running Unix patch utility on web server. In 2015 the Unix patch still has security issues. So it is important to put them into checklist and cover with tests to ensure that patch.py doesn't have those deficiencies. Here is the starting list that came today with Ubuntu update:

Version 2.7.1-4ubuntu2.3:

  • SECURITY UPDATE: Denial of service via crafted patch
  • SECURITY UPDATE: Directory traversal via crafted patch
  • SECURITY UPDATE: Directory traversal via crafted patch
  • SECURITY UPDATE: Directory traversal via crafted patch
@techtonik
Copy link
Owner Author

There are still problems 4 years after - #65

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant