CVE-2019-14868: Fixed code injection due to environment variables on startup interpreted as arithmetic expression (bsc#1160796)
Other fixes:
do not use posix_spawn as it lacks proper job handling (bsc#1224057)
fix segfault in variable substitution (bsc#1129288)
Affected Packages
ksh
SUSE Linux Enterprise High Performance Computing 12SUSE Linux Enterprise Module for Legacy 12SUSE Linux Enterprise Server 12SUSE Linux Enterprise Server 12 SP3SUSE Linux Enterprise Server 12 SP4
Fixed in:
93vu-19.3.2
ksh-devel
SUSE Linux Enterprise Software Development Kit 12 SP5