Fixed #1554752 - Double free of memory, CVE-2018-6952
This commit is contained in:
parent
6cc9c0f08c
commit
677e72bdb1
10
patch.spec
10
patch.spec
@ -1,16 +1,17 @@
|
|||||||
Summary: Utility for modifying/upgrading files
|
Summary: Utility for modifying/upgrading files
|
||||||
Name: patch
|
Name: patch
|
||||||
Version: 2.7.6
|
Version: 2.7.6
|
||||||
Release: 5%{?dist}
|
Release: 6%{?dist}
|
||||||
License: GPLv3+
|
License: GPLv3+
|
||||||
URL: http://www.gnu.org/software/patch/patch.html
|
URL: http://www.gnu.org/software/patch/patch.html
|
||||||
Group: Development/Tools
|
Group: Development/Tools
|
||||||
Source: ftp://ftp.gnu.org/gnu/patch/patch-%{version}.tar.xz
|
Source: ftp://ftp.gnu.org/gnu/patch/patch-%{version}.tar.xz
|
||||||
Patch1: patch-CVE-2018-1000156.patch
|
Patch1: patch-CVE-2018-1000156.patch
|
||||||
|
Patch2: patch-2.7.6-CVE-2018-6952.patch
|
||||||
Patch100: patch-selinux.patch
|
Patch100: patch-selinux.patch
|
||||||
Buildroot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
Buildroot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
||||||
|
|
||||||
BuildRequires: gcc
|
BuildRequires: gcc
|
||||||
BuildRequires: libselinux-devel
|
BuildRequires: libselinux-devel
|
||||||
BuildRequires: libattr-devel
|
BuildRequires: libattr-devel
|
||||||
BuildRequires: ed
|
BuildRequires: ed
|
||||||
@ -30,6 +31,8 @@ applications.
|
|||||||
|
|
||||||
# CVE-2018-1000156, Malicious patch files cause ed to execute arbitrary commands
|
# CVE-2018-1000156, Malicious patch files cause ed to execute arbitrary commands
|
||||||
%patch1 -p1 -b .CVE-2018-1000156
|
%patch1 -p1 -b .CVE-2018-1000156
|
||||||
|
# CVE-2018-6952
|
||||||
|
%patch2 -p1 -b .CVE-2018-6952
|
||||||
|
|
||||||
# SELinux support.
|
# SELinux support.
|
||||||
%patch100 -p1 -b .selinux
|
%patch100 -p1 -b .selinux
|
||||||
@ -56,6 +59,9 @@ rm -rf $RPM_BUILD_ROOT
|
|||||||
%{_mandir}/*/*
|
%{_mandir}/*/*
|
||||||
|
|
||||||
%changelog
|
%changelog
|
||||||
|
* Wed Aug 15 2018 Than Ngo <than@redhat.com> - 2.7.6-6
|
||||||
|
- Fixed #1554752 - Double free of memory, CVE-2018-6952
|
||||||
|
|
||||||
* Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 2.7.6-5
|
* Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 2.7.6-5
|
||||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user