CVE-2010-4651
published 2011-03-11CVE-2010-4651: Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a…
PriorityP432medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
4.83%
91.0th percentile
Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | patch | — | — |
| gnu | gnu_patch | <= 2.6.1 | — |
| gnu | gnu_patch | — | — |
| gnu | gnu_patch | — | — |
| gnu | gnu_patch | — | — |
| gnu | gnu_patch | — | — |
| gnu | patch | >= 0 < 2.7.1-4ubuntu2.3 | 2.7.1-4ubuntu2.3 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ghmh-8qx5-2gfp: Directory traversal vulnerability in util
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2010-4651 [MEDIUM] CWE-22 GHSA-ghmh-8qx5-2gfp: Directory traversal vulnerability in util
Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
OSV
patch vulnerabilities
osv·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] patch vulnerabilities
patch vulnerabilities
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking the
program. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
OSV
CVE-2010-4651: Directory traversal vulnerability in util
osv·2011-03-11·CVSS 6.8
CVE-2010-4651 [MEDIUM] CVE-2010-4651: Directory traversal vulnerability in util
Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
Ubuntu
GNU patch vulnerabilities
vendor_ubuntu·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] GNU patch vulnerabilities
Title: GNU patch vulnerabilities
Summary: Several security issues were fixed in GNU patch.
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking th
Red Hat
patch: directory traversal flaw allows for arbitrary file creation
vendor_redhat·2010-12-30·CVSS 6.8
CVE-2010-4651 [MEDIUM] patch: directory traversal flaw allows for arbitrary file creation
patch: directory traversal flaw allows for arbitrary file creation
Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: patch (Red Hat Enterprise Linux 4) - Will not fix
Package: patch (Red Hat Enterprise Linux 5) - Will not fix
Package: patch (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2010-4651: patch - Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allow...
vendor_debian·2010·CVSS 6.8
CVE-2010-4651 [MEDIUM] CVE-2010-4651: patch - Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allow...
Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation [fedora-all]
bugzilla·2011-02-05·CVSS 5.8
CVE-2010-4651 [MEDIUM] CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation [fedora-all]
CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=667529
Please note: this iss
Bugzilla
CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation
bugzilla·2011-01-05·CVSS 5.8
CVE-2010-4651 [MEDIUM] CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation
CVE-2010-4651 patch: directory traversal flaw allows for arbitrary file creation
It was discovered that the patch utility allowed '..' in path names which could allow an attacker to create arbitrary files using a specially-crafted patch file. For instance, the following patch will arbitrarily create the file /tmp/allyourbase.txt:
--- /dev/null
+++ /../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../../tmp/allyourbase.txt
@@ -0,0 +1 @@
+All your base are belong to us.
Discussion:
Forgot to note the original report is here:
http://osdir.com/ml/bug-patch-gnu/2010-12/msg00000.html
---
What command line options/etc. are being used to trigger this? It only creates the file in the local directory for me on Fedora 14:
[kurt@fedora14 ~]$ patch Forgo
http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.htmlhttp://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.htmlhttp://openwall.com/lists/oss-security/2011/01/05/10http://openwall.com/lists/oss-security/2011/01/06/19http://openwall.com/lists/oss-security/2011/01/06/20http://openwall.com/lists/oss-security/2011/01/06/21http://secunia.com/advisories/43663http://secunia.com/advisories/43677http://support.apple.com/kb/HT4723http://www.securityfocus.com/bid/46768http://www.vupen.com/english/advisories/2011/0600https://bugzilla.redhat.com/show_bug.cgi?id=667529http://git.savannah.gnu.org/cgit/patch.git/commit/?id=685a78b6052f4df6eac6d625a545cfb54a6ac0e1http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055241.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055246.htmlhttp://lists.gnu.org/archive/html/bug-patch/2010-12/msg00000.htmlhttp://openwall.com/lists/oss-security/2011/01/05/10http://openwall.com/lists/oss-security/2011/01/06/19http://openwall.com/lists/oss-security/2011/01/06/20http://openwall.com/lists/oss-security/2011/01/06/21http://secunia.com/advisories/43663http://secunia.com/advisories/43677http://support.apple.com/kb/HT4723http://www.securityfocus.com/bid/46768http://www.vupen.com/english/advisories/2011/0600https://bugzilla.redhat.com/show_bug.cgi?id=667529
2011-03-11
Published