File _patchinfo of Package patchinfo
<patchinfo incident="18508"> <issue tracker="bnc" id="1129288"></issue> <issue tracker="bnc" id="1160796">VUL-0: CVE-2019-14868: ksh: environment variables on startup are interpreted as arithmetic expression leading to code injection</issue> <issue tracker="cve" id="2019-14868"/> <packager>mlschroe</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for ksh</summary> <description>This update for ksh fixes the following issues: - fix segfault in variable substitution [boo#1129288] - fix untrusted environment execution [boo#1160796] [CVE-2019-14868] </description> </patchinfo>