CVE-2015-1196
published 2015-01-21CVE-2015-1196: GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
PriorityP338medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
6.10%
92.6th percentile
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | patch | < patch 2.7.3-1 (bookworm) | patch 2.7.3-1 (bookworm) |
| debian | patch | < patch 2.7.1-7 (bookworm) | patch 2.7.1-7 (bookworm) |
| gnu | patch | < 2.7.4 | 2.7.4 |
| gnu | patch | — | — |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.1-7 | 2.7.1-7 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.1-4ubuntu2.3 | 2.7.1-4ubuntu2.3 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| oracle | solaris | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU patch vulnerabilities
vendor_ubuntu·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] GNU patch vulnerabilities
Title: GNU patch vulnerabilities
Summary: Several security issues were fixed in GNU patch.
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking th
Red Hat
patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
vendor_redhat·2015-01-24·CVSS 4.3
CVE-2015-1396 [MEDIUM] CWE-22 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
Package: patch (Red Hat Enterprise Linux 5) - Not affected
Package: patch (Red Hat Enterprise Linux 6) - Not affected
Package: patch (Red Hat Enterprise Linux 7) - Not affected
Red Hat
patch: directory traversal via symlinks
vendor_redhat·2015-01-12·CVSS 4.3
CVE-2015-1196 [MEDIUM] CWE-22 patch: directory traversal via symlinks
patch: directory traversal via symlinks
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: patch (Red Hat Enterprise Linux 5) - Not affected
Package: patch (Red Hat Enterprise Linux 6) - Not affected
Package: patch (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-1396: patch - A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remo...
vendor_debian·2015·CVSS 4.3
CVE-2015-1396 [MEDIUM] CVE-2015-1396: patch - A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remo...
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
Scope: local
bookworm: resolved (fixed in 2.7.3-1)
bullseye: resolved (fixed in 2.7.3-1)
forky: resolved (fixed in 2.7.3-1)
sid: resolved (fixed in 2.7.3-1)
trixie: resolved (fixed in 2.7.3-1)
Debian
CVE-2015-1196: patch - GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlin...
vendor_debian·2015·CVSS 4.3
CVE-2015-1196 [MEDIUM] CVE-2015-1196: patch - GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlin...
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
Scope: local
bookworm: resolved (fixed in 2.7.1-7)
bullseye: resolved (fixed in 2.7.1-7)
forky: resolved (fixed in 2.7.1-7)
sid: resolved (fixed in 2.7.1-7)
trixie: resolved (fixed in 2.7.1-7)
GHSA
GHSA-37cv-ggjj-37qh: A Directory Traversal vulnerability exists in the GNU patch before 2
ghsa_unreviewed·2022-05-24·CVSS 4.3
CVE-2015-1396 [MEDIUM] GHSA-37cv-ggjj-37qh: A Directory Traversal vulnerability exists in the GNU patch before 2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
GHSA
GHSA-pgg8-q7hj-8mg8: GNU patch 2
ghsa_unreviewed·2022-05-14
CVE-2015-1196 [MEDIUM] CWE-59 GHSA-pgg8-q7hj-8mg8: GNU patch 2
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
OSV
CVE-2015-1396: A Directory Traversal vulnerability exists in the GNU patch before 2
osv·2019-11-25·CVSS 4.3
CVE-2015-1396 [MEDIUM] CVE-2015-1396: A Directory Traversal vulnerability exists in the GNU patch before 2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
OSV
patch vulnerabilities
osv·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] patch vulnerabilities
patch vulnerabilities
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking the
program. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
OSV
CVE-2015-1196: GNU patch 2
osv·2015-01-21·CVSS 4.3
CVE-2015-1196 [MEDIUM] CVE-2015-1196: GNU patch 2
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1396 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
bugzilla·2015-01-28·CVSS 4.3
CVE-2015-1396 [MEDIUM] CVE-2015-1396 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
CVE-2015-1396 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
It was reported [1] that the fix for CVE-2015-1196 [2] was incomplete.
[1] https://bugs.debian.org/775901
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1182154
Discussion:
This was fixed in patch-2.7.3.
---
Sorry, I mean 2.7.4.
---
Given we have not fixed CVE-2015-1196, we're not affected by this issue.
Bugzilla
CVE-2015-1196 patch: directory traversal via symlinks
bugzilla·2015-01-14·CVSS 4.3
CVE-2015-1196 [MEDIUM] CVE-2015-1196 patch: directory traversal via symlinks
CVE-2015-1196 patch: directory traversal via symlinks
It was reported [1] that the versions of the patch utility that support Git-style patches are vulnerable to a directory traversal flaw. This could allow an attacker to overwrite arbitrary files by applying a specially crafted patch, with the privileges of the user running patch. A reproducer for this issue is available in [1].
[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775227
Discussion:
Created patch tracking bugs for this issue:
Affects: fedora-all [bug 1182157]
---
CVE request: http://seclists.org/oss-sec/2015/q1/131
---
Created attachment 981802
Upstream fix
Not sure how the upstream fix applies to the shipped versions. Can anyone help me get this into the packages, and get security updates out?
---
Note that
http://git.savannah.gnu.org/cgit/patch.git/commit/?id=4e9269a5fc1fe80a1095a92593dd85db871e1fd3http://lists.opensuse.org/opensuse-updates/2015-02/msg00013.htmlhttp://seclists.org/oss-sec/2015/q1/173http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/72074https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775227https://bugzilla.redhat.com/show_bug.cgi?id=1182154https://exchange.xforce.ibmcloud.com/vulnerabilities/99967http://git.savannah.gnu.org/cgit/patch.git/commit/?id=4e9269a5fc1fe80a1095a92593dd85db871e1fd3http://lists.opensuse.org/opensuse-updates/2015-02/msg00013.htmlhttp://seclists.org/oss-sec/2015/q1/173http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.htmlhttp://www.securityfocus.com/bid/72074https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775227https://bugzilla.redhat.com/show_bug.cgi?id=1182154https://exchange.xforce.ibmcloud.com/vulnerabilities/99967
2015-01-21
Published