One of the reasons why patch.py was started was insecurity of running Unix patch utility on web server. In 2015 the Unix patch still has security issues. So it is important to put them into checklist and cover with tests to ensure that patch.py doesn't have those deficiencies. Here is the starting list that came today with Ubuntu update:
Version 2.7.1-4ubuntu2.3:
- SECURITY UPDATE: Denial of service via crafted patch
- SECURITY UPDATE: Directory traversal via crafted patch
- SECURITY UPDATE: Directory traversal via crafted patch
- SECURITY UPDATE: Directory traversal via crafted patch
One of the reasons why
patch.pywas started was insecurity of running Unixpatchutility on web server. In 2015 the Unix patch still has security issues. So it is important to put them into checklist and cover with tests to ensure thatpatch.pydoesn't have those deficiencies. Here is the starting list that came today with Ubuntu update:Version 2.7.1-4ubuntu2.3:
allocation failures
outside of the current directory
during a rename or copy
outside of the current directory. This patch corrects the incomplete fix
for CVE-2015-1196.