SB2019072329 - Improper Link Resolution Before File Access (\'Link Following\') in patch (Alpine package)
Published: July 23, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Link Resolution Before File Access ('Link Following') (CVE-ID: CVE-2019-13636)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=eb88ff152557254bd38fbe358892d73f97a09e6b
- https://git.alpinelinux.org/aports/commit/?id=1d883b90c2617f701a473458f6bea95c5488513b
- https://git.alpinelinux.org/aports/commit/?id=38b6dd1c340446b8eb31aefaf5396ba65ca94369
- https://git.alpinelinux.org/aports/commit/?id=3f413a6b4f89e4d069b26f1e2302a6c914e02b6e
- https://git.alpinelinux.org/aports/commit/?id=858c1e50bc7b69a652bedc684cf06dd025afeeab
- https://git.alpinelinux.org/aports/commit/?id=88e814fbbdb9a9a335964ae6dac9caa730df1cbf