VulnerabilityModified
CVE-2019-13636
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files.
MEDIUM 5.9EPSS 3.90%
Does this matter?
Lower severity and a low EPSS score (3.90%). Track it; it rarely justifies an emergency change on its own.
Description
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 3.90% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- gnu/patch
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71aMailing List, Patch, Vendor Advisory
- https://github.com/irsl/gnu-patch-vulnerabilities
- https://lists.debian.org/debian-lts-announce/2019/07/msg00016.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVWWGISFWACROJJPVJJL4UBLVZ7LPOLT/
- https://seclists.org/bugtraq/2019/Aug/29
- https://seclists.org/bugtraq/2019/Jul/54
- https://security.gentoo.org/glsa/201908-22
- https://security.netapp.com/advisory/ntap-20190828-0001/
- https://usn.ubuntu.com/4071-1/
- https://usn.ubuntu.com/4071-2/
- https://www.debian.org/security/2019/dsa-4489
- http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.html
- https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71aMailing List, Patch, Vendor Advisory
- https://github.com/irsl/gnu-patch-vulnerabilities
- https://lists.debian.org/debian-lts-announce/2019/07/msg00016.htmlThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVWWGISFWACROJJPVJJL4UBLVZ7LPOLT/
- https://seclists.org/bugtraq/2019/Aug/29
- https://seclists.org/bugtraq/2019/Jul/54
- https://security.gentoo.org/glsa/201908-22
- https://security.netapp.com/advisory/ntap-20190828-0001/
- https://usn.ubuntu.com/4071-1/
- https://usn.ubuntu.com/4071-2/
- https://www.debian.org/security/2019/dsa-4489
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.