zsh/zsh-5.5.tar.gz.asc
Ismail Dönmez 05394b236c Accepting request 595518 from home:kbabioch:branches:shells
- Update to 5.5
  * The effect of the NO_INTERACTIVE_COMMENTS option extends into $(...)
    and `...` command substitutions when used on the command line.
  * Dropped patches, which are included upstream now:
    - zsh-CVE-2018-1071.patch
    - zsh-CVE-2018-1083.patch
  * Fixes a buffer overflow in utils.c:checkmailpath() that can lead to
    local arbitrary code execution (CVE-2018-1100 bnc#1089030)

- Added zsh-CVE-2018-1071.patch: Fixed a stack-based buffer overflow
  in exec.c:hashcmd() (CVE-2018-1071 bnc#1084656)
- Added zsh-CVE-2018-1083.patch: Fixed a stack-based buffer overflow
  in gen_matches_files() at compctl.c (CVE-2018-1083 bnc#1087026)
- Cleaned up spec file with spec-cleaner

OBS-URL: https://build.opensuse.org/request/show/595518
OBS-URL: https://build.opensuse.org/package/show/shells/zsh?expand=0&rev=186
2018-04-12 07:18:31 +00:00

12 lines
473 B
Plaintext

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQEcBAABCAAGBQJaykAgAAoJEKcdmp1L2yezARAIAKNKQMRNhOHA+Cbqp53mYdNx
VaMl4dNpwB4W+Px2lfHEmdnXGB6MAVrKU5O39VTTdIzi31o2J/4fT1JNrsqtNCZK
ivNYxsqHOfFdO+LfD2mU4xCEBkTVMu3TwZGlhY2dlhhoDf/CvI1gbmLBbpFv619T
ZMzdeDH+iJn2mh+7LJqELEQPEdR1GOA4bLi1FD84vGySmRbHoyas0+8fJ3G6jduR
gDCoBvjcj50QK1dNB06ejqL+79BE0gso2rjt7MDR2yrzDrl5/ifxPxseHj7xvUNN
V9m2sM6JTgLZj2ymgt+LLctvWxBV2HfBmzaL9yg0LHce2hw5vVK18PN7MDjSsf4=
=pDEY
-----END PGP SIGNATURE-----