Bug 1746672 (CVE-2018-20969) - CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning with a ! character
Summary: CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-20969
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1746673 1747863 1747864 1747865 1747866 1759538 1759539 1759548 1764222
Blocks: 1746675
TreeView+ depends on / blocked
 
Reported: 2019-08-29 05:53 UTC by Dhananjay Arunesh
Modified: 2021-02-16 21:27 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-09-19 06:45:36 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2019:2883 0 None None None 2019-09-23 20:06:10 UTC
Red Hat Product Errata RHBA-2019:2984 0 None None None 2019-10-09 05:22:06 UTC
Red Hat Product Errata RHBA-2019:3129 0 None None None 2019-10-16 13:38:46 UTC
Red Hat Product Errata RHBA-2019:3137 0 None None None 2019-10-17 13:58:38 UTC
Red Hat Product Errata RHBA-2019:3279 0 None None None 2019-10-31 11:56:37 UTC
Red Hat Product Errata RHBA-2019:3290 0 None None None 2019-10-31 17:03:24 UTC
Red Hat Product Errata RHSA-2019:2798 0 None None None 2019-09-19 04:08:10 UTC
Red Hat Product Errata RHSA-2019:2964 0 None None None 2019-10-03 14:04:11 UTC
Red Hat Product Errata RHSA-2019:3757 0 None None None 2019-11-06 16:57:27 UTC
Red Hat Product Errata RHSA-2019:3758 0 None None None 2019-11-06 17:05:37 UTC
Red Hat Product Errata RHSA-2019:4061 0 None None None 2019-12-03 11:00:59 UTC

Description Dhananjay Arunesh 2019-08-29 05:53:34 UTC
A vulnerability was found in do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

Reference:
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=3fcd042d26d70856e826a42b5f93dc4854d80bf0
https://seclists.org/bugtraq/2019/Aug/29

Comment 1 Dhananjay Arunesh 2019-08-29 05:53:59 UTC
Created patch tracking bugs for this issue:

Affects: fedora-all [bug 1746673]

Comment 3 errata-xmlrpc 2019-09-19 04:08:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:2798 https://access.redhat.com/errata/RHSA-2019:2798

Comment 4 Product Security DevOps Team 2019-09-19 06:45:36 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-20969

Comment 9 errata-xmlrpc 2019-10-03 14:04:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2964 https://access.redhat.com/errata/RHSA-2019:2964

Comment 15 errata-xmlrpc 2019-11-06 16:57:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.5 Extended Update Support

Via RHSA-2019:3757 https://access.redhat.com/errata/RHSA-2019:3757

Comment 16 errata-xmlrpc 2019-11-06 17:05:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.6 Extended Update Support

Via RHSA-2019:3758 https://access.redhat.com/errata/RHSA-2019:3758

Comment 18 Marco Benatto 2019-11-20 12:56:19 UTC
The version of patch shipped with Red Hat Enterprise Linux 6 is not affected. The vulnerability was introduced on upstream's patch version 2.7 while RHEL6 ships version 2.6.x from patch.

Comment 21 errata-xmlrpc 2019-12-03 11:00:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.4 Advanced Update Support
  Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
  Red Hat Enterprise Linux 7.4 Telco Extended Update Support

Via RHSA-2019:4061 https://access.redhat.com/errata/RHSA-2019:4061

Comment 23 Eric Christensen 2020-05-04 15:43:55 UTC
External References:

https://seclists.org/bugtraq/2019/Aug/29


Note You need to log in before you can comment on or make changes to this bug.