Release date:
2026-08-18 14:47:57 UTC
Description:
* Non-maintainer upload by the TuxCare ELS team.
* CVE-2026-40261: Prevent a command injection vulnerability in
Perforce::syncCodeBase(), which appended the source reference to the
'p4 sync -f' command without escaping. Package metadata served by a
malicious or compromised Composer repository could inject shell
metacharacters, leading to command execution even when Perforce is not
installed.
- debian/patches/0018-CVE-2026-40261.patch
* CVE-2026-40176: Prevent a command injection vulnerability in
Perforce::generateP4Command(), which interpolated the Perforce
connection parameters (user, client, port) into the 'p4' command line
without escaping. A malicious composer.json declaring a Perforce VCS
repository could inject shell metacharacters, leading to command
execution even when Perforce is not installed. Also backport the
prerequisite upstream fix for Perforce::connectClient(), which passed
the client spec path through the shell redirection of the same command
line with only spaces escaped.
- debian/patches/0019-CVE-2026-40176.patch
Updated packages:
-
composer_1.8.4-1+deb10u4+tuxcare.els1_all.deb
sha:8a4cc08e4fa3b5b6b4284a4fd2a9183b375028f0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.