PT-2019-3242 · Gnu+3 · Gnu Patch+3
Imre Rad
·
Published
2019-07-22
·
Updated
2026-04-01
·
CVE-2019-13638
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GNU patch versions prior to 2.7.7
Description
The issue is related to the
do ed script function in the GNU Patch utility, which fails to neutralize special elements used in operating system commands. This can be exploited by opening a crafted patch file containing an ed style diff payload with shell metacharacters, potentially allowing an attacker to access confidential information and execute arbitrary commands.Recommendations
For GNU patch versions prior to 2.7.7, update to version 2.7.7 or later to resolve the issue.
As a temporary workaround, consider avoiding the use of crafted patch files that contain ed style diff payloads with shell metacharacters until a patch is available.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Gnu Patch
Red Hat
Ubuntu