PT-2019-3242 · Gnu+3 · Gnu Patch+3

Imre Rad

·

Published

2019-07-22

·

Updated

2026-04-01

·

CVE-2019-13638

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU patch versions prior to 2.7.7
Description The issue is related to the do ed script function in the GNU Patch utility, which fails to neutralize special elements used in operating system commands. This can be exploited by opening a crafted patch file containing an ed style diff payload with shell metacharacters, potentially allowing an attacker to access confidential information and execute arbitrary commands.
Recommendations For GNU patch versions prior to 2.7.7, update to version 2.7.7 or later to resolve the issue. As a temporary workaround, consider avoiding the use of crafted patch files that contain ed style diff payloads with shell metacharacters until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-35106
AZL-6790
BDU:2019-03232
CESA-2019_2798
CESA-2019_2964
CLEANSTART-2026-NA21773
CLEANSTART-2026-PM79547
CVE-2019-13638
DLA-1864-1
DSA-4489-1
JLSEC-2026-17
MGASA-2020-0093
RHSA-2019:2798
RHSA-2019:2964
RHSA-2019:3757
RHSA-2019:3758
RHSA-2019:4061
RHSA-2019_2798
RHSA-2019_2964
USN-4071-1
USN-4071-2

Affected Products

Centos
Gnu Patch
Red Hat
Ubuntu