ELA-1294-1 ucf security update

command-injection vulnerability

2025-01-16
Packageucf
Version3.0030+deb8u1 (jessie), 3.0036+deb9u1 (stretch), 3.0038+nmu1+deb10u1 (buster)


A potential command-injection vulnerability was discovered in ucf, a tool to preserve user changes to config files.



For Debian 10 buster, these problems have been fixed in version 3.0038+nmu1+deb10u1.

For Debian 8 jessie, these problems have been fixed in version 3.0030+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 3.0036+deb9u1.

We recommend that you upgrade your ucf packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.