Back to search
CVE-2018-1000156
Published: Apr 6, 2018
Modified: Apr 14, 2025
PUBLISHED
Description
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-3624-2
vendor-advisory
USN-3624-1
vendor-advisory
RHSA-2018:2091
vendor-advisory
RHSA-2018:2094
vendor-advisory
RHSA-2018:2093
vendor-advisory
RHSA-2018:1200
vendor-advisory
RHSA-2018:2095
vendor-advisory
RHSA-2018:1199
vendor-advisory
RHSA-2018:2092
vendor-advisory
RHSA-2018:2097
vendor-advisory
RHSA-2018:2096
vendor-advisory
GLSA-201904-17
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now