[Bug 1047247] chkstat tool can be tricked into trying to interpret the shell environment as a permissions file
http://bugzilla.suse.com/show_bug.cgi?id=1047247 http://bugzilla.suse.com/show_bug.cgi?id=1047247#c10 --- Comment #10 from Swamp Workflow Management <swamp@suse.de> --- SUSE-SU-2019:3183-1: An update that solves two vulnerabilities and has three fixes is now available. Category: security (moderate) Bug References: 1047247,1093414,1097665,1150734,1157198 CVE References: CVE-2019-3688,CVE-2019-3690 Sources used: SUSE Linux Enterprise Server 12-SP5 (src): permissions-20170707-3.14.1 SUSE Linux Enterprise Server 12-SP4 (src): permissions-20170707-3.14.1 SUSE Linux Enterprise Desktop 12-SP4 (src): permissions-20170707-3.14.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com