You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa grep

Sigurnosni nedostatak programskog paketa grep

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-1053
2015-01-21 22:11:02
——————————————————————————–

Name : grep
Product : Fedora 21
Version : 2.21
Release : 2.fc21
URL : http://www.gnu.org/software/grep/
Summary : Pattern matching utilities
Description :
The GNU versions of commonly used grep utilities. Grep searches through
textual input for lines which contain a match to a specified pattern and then
prints the matching lines. GNU’s grep utilities include grep, egrep and fgrep.

GNU grep is needed by many scripts, so it shall be installed on every system.

——————————————————————————–
Update Information:

This is an update fixing buffer overflow of grep -F.
——————————————————————————–
ChangeLog:

* Tue Jan 20 2015 Jaroslav Škarvada <jskarvad@redhat.com> – 2.21-2
– Fixed buffer overrun for grep -F
Resolves: rhbz#1183653
* Tue Nov 25 2014 Jaroslav Škarvada <jskarvad@redhat.com> – 2.21-1
– New version
Resolves: rhbz#1167657
– De-fuzzified patches
– Dropped pcre-backported-fixes patch (not needed)
——————————————————————————–
References:

[ 1 ] Bug #1183651 – grep: heap buffer overrun
https://bugzilla.redhat.com/show_bug.cgi?id=1183651
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update grep’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarko Stanec
Cert idNCERT-REF-2015-01-0012-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa jasper

Otkriveni su sigurnosni nedostaci u programskom paketu jasper. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje napada uskraćivanjem usluge ili pokretanje proizvoljnog...

Close