CVE-2015-1395
published 2017-08-25CVE-2015-1395: Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with…
PriorityP350high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
11.20%
95.5th percentile
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | patch | < patch 2.7.3-1 (bookworm) | patch 2.7.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | patch | <= 2.7.2 | — |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.1-4ubuntu2.3 | 2.7.1-4ubuntu2.3 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:C/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU patch vulnerabilities
vendor_ubuntu·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] GNU patch vulnerabilities
Title: GNU patch vulnerabilities
Summary: Several security issues were fixed in GNU patch.
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking th
Red Hat
patch: directory traversal via file rename
vendor_redhat·2015-01-20·CVSS 7.5
CVE-2015-1395 [HIGH] CWE-22 patch: directory traversal via file rename
patch: directory traversal via file rename
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: patch (Red Hat Enterprise Linux 5) - Not affected
Package: patch (Red Hat Enterprise Linux 6) - Not affected
Package: patch (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-1395: patch - Directory traversal vulnerability in GNU patch versions which support Git-style ...
vendor_debian·2015·CVSS 7.5
CVE-2015-1395 [HIGH] CVE-2015-1395: patch - Directory traversal vulnerability in GNU patch versions which support Git-style ...
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
Scope: local
bookworm: resolved (fixed in 2.7.3-1)
bullseye: resolved (fixed in 2.7.3-1)
forky: resolved (fixed in 2.7.3-1)
sid: resolved (fixed in 2.7.3-1)
trixie: resolved (fixed in 2.7.3-1)
GHSA
GHSA-97xh-wvxp-9m89: Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2
ghsa_unreviewed·2022-05-17
CVE-2015-1395 [HIGH] CWE-22 GHSA-97xh-wvxp-9m89: Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
OSV
CVE-2015-1395: Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2
osv·2017-08-25·CVSS 7.5
CVE-2015-1395 [HIGH] CVE-2015-1395: Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.
OSV
patch vulnerabilities
osv·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] patch vulnerabilities
patch vulnerabilities
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking the
program. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154214.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148953.htmlhttp://www.openwall.com/lists/oss-security/2015/01/27/28http://www.securityfocus.com/bid/72846http://www.ubuntu.com/usn/USN-2651-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775873https://bugzilla.redhat.com/show_bug.cgi?id=1184490https://git.savannah.gnu.org/cgit/patch.git/commit/?id=17953b5893f7c9835f0dd2a704ba04e0371d2cbdhttps://savannah.gnu.org/bugs/?44059http://lists.fedoraproject.org/pipermail/package-announce/2015-April/154214.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148953.htmlhttp://www.openwall.com/lists/oss-security/2015/01/27/28http://www.securityfocus.com/bid/72846http://www.ubuntu.com/usn/USN-2651-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775873https://bugzilla.redhat.com/show_bug.cgi?id=1184490https://git.savannah.gnu.org/cgit/patch.git/commit/?id=17953b5893f7c9835f0dd2a704ba04e0371d2cbdhttps://savannah.gnu.org/bugs/?44059
2017-08-25
Published