Package : patch
Version : 2.6.1-3+deb7u1
CVE ID : CVE-2018-1000156
Debian Bug : #894993
It was discovered that there was an input validation vulnerability in the
patch(1) utility where an ed(1) script embedded in a regular input file
could result in arbitrary code execution. This was reported by Rachel
Kroll [0] et al.
For Debian 7 "Wheezy", this issue has been fixed in patch version
2.6.1-3+deb7u1.
We recommend that you upgrade your patch packages.
[0] https://rachelbythebay.com/w/2018/04/05/bangpatch/
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-