CVE Database
/

CVE-2019-13638

Back to search

CVE-2019-13638

Published: Jul 26, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-4489
vendor-advisory
x_refsource_DEBIAN
GLSA-201908-22
vendor-advisory
x_refsource_GENTOO
FEDORA-2019-ac709da87f
vendor-advisory
x_refsource_FEDORA
RHSA-2019:2798
vendor-advisory
x_refsource_REDHAT
RHSA-2019:2964
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3757
vendor-advisory
x_refsource_REDHAT
RHSA-2019:3758
vendor-advisory
x_refsource_REDHAT
RHSA-2019:4061
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now