PT-2019-10405 · Gnu+3 · Gnu Patch+3

Imre Rad

·

Published

2018-06-08

·

Updated

2026-04-01

·

CVE-2018-20969

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU patch versions through 2.7.6
Description The issue is related to the do ed script function in pch.c, which fails to block strings starting with a ! character. This syntax is specific to ed and is unrelated to shell metacharacters.
Recommendations For GNU patch versions through 2.7.6, update to a version that contains a fix for this issue.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1872
AZL-35102
AZL-6786
CESA-2019_2798
CESA-2019_2964
CLEANSTART-2026-PM79547
CVE-2018-20969
DLA-1864-1
DSA-4489-1
MGASA-2020-0093
RHSA-2019:2798
RHSA-2019:2964
RHSA-2019:3757
RHSA-2019:3758
RHSA-2019:4061
RHSA-2019_2798
RHSA-2019_2964
ROSA-SA-2024-2468
USN-4071-1
USN-4071-2

Affected Products

Alt Linux
Centos
Gnu Patch
Red Hat