CVE-2014-9637
published 2017-08-25CVE-2014-9637: GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
2.37%
82.0th percentile
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | patch | < patch 2.7.1-7 (bookworm) | patch 2.7.1-7 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | patch | <= 2.7.2 | — |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.1-4ubuntu2.3 | 2.7.1-4ubuntu2.3 |
| mageia | mageia | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpf6-pr9h-p2gj: GNU patch 2
ghsa_unreviewed·2022-05-17
CVE-2014-9637 [HIGH] GHSA-wpf6-pr9h-p2gj: GNU patch 2
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
OSV
CVE-2014-9637: GNU patch 2
osv·2017-08-25·CVSS 5.5
CVE-2014-9637 [MEDIUM] CVE-2014-9637: GNU patch 2
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
OSV
patch vulnerabilities
osv·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] patch vulnerabilities
patch vulnerabilities
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking the
program. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
Ubuntu
GNU patch vulnerabilities
vendor_ubuntu·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] GNU patch vulnerabilities
Title: GNU patch vulnerabilities
Summary: Several security issues were fixed in GNU patch.
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking th
Red Hat
patch: local denial of service with a crafted patch
vendor_redhat·2015-01-20·CVSS 5.5
CVE-2014-9637 [MEDIUM] patch: local denial of service with a crafted patch
patch: local denial of service with a crafted patch
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: patch (Red Hat Enterprise Linux 5) - Affected
Package: patch (Red Hat Enterprise Linux 6) - Affected
Package: patch (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2014-9637: patch - GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service...
vendor_debian·2014·CVSS 5.5
CVE-2014-9637 [MEDIUM] CVE-2014-9637: patch - GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service...
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
Scope: local
bookworm: resolved (fixed in 2.7.1-7)
bullseye: resolved (fixed in 2.7.1-7)
forky: resolved (fixed in 2.7.1-7)
sid: resolved (fixed in 2.7.1-7)
trixie: resolved (fixed in 2.7.1-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9637 patch: local denial of service with a crafted patch
bugzilla·2015-01-23·CVSS 5.5
CVE-2014-9637 [MEDIUM] CVE-2014-9637 patch: local denial of service with a crafted patch
CVE-2014-9637 patch: local denial of service with a crafted patch
It was reported [1] that a crafted diff file (attached) can make patch to eat memory and later segfault.
Upstream commit that fixes this:
http://git.savannah.gnu.org/cgit/patch.git/commit/?id=0c08d7a902c6fdd49b704623a12d8d672ef18944
[1]: https://savannah.gnu.org/bugs/?44051
Discussion:
Created attachment 983284
crash.tar.gz
---
Created patch tracking bugs for this issue:
Affects: fedora-all [bug 1184491]
---
patch-2.7.3-1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
---
patch-2.7.5-1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
---
Statement:
Red Hat
Bugzilla
CVE-2014-9637 patch: various flaws [fedora-all]
bugzilla·2015-01-21·CVSS 5.5
CVE-2014-9637 [MEDIUM] CVE-2014-9637 patch: various flaws [fedora-all]
CVE-2014-9637 patch: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one trackin
http://advisories.mageia.org/MGASA-2015-0068.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154214.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148953.htmlhttp://www.openwall.com/lists/oss-security/2015/01/22/7http://www.securityfocus.com/bid/72286http://www.ubuntu.com/usn/USN-2651-1https://bugzilla.redhat.com/show_bug.cgi?id=1185262https://git.savannah.gnu.org/cgit/patch.git/commit/?id=0c08d7a902c6fdd49b704623a12d8d672ef18944https://savannah.gnu.org/bugs/?44051http://advisories.mageia.org/MGASA-2015-0068.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-April/154214.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148953.htmlhttp://www.openwall.com/lists/oss-security/2015/01/22/7http://www.securityfocus.com/bid/72286http://www.ubuntu.com/usn/USN-2651-1https://bugzilla.redhat.com/show_bug.cgi?id=1185262https://git.savannah.gnu.org/cgit/patch.git/commit/?id=0c08d7a902c6fdd49b704623a12d8d672ef18944https://savannah.gnu.org/bugs/?44051
2017-08-25
Published