CVE-2015-1396
published 2019-11-25CVE-2015-1396: A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.22%
86.8th percentile
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | patch | < patch 2.7.3-1 (bookworm) | patch 2.7.3-1 (bookworm) |
| gnu | patch | < 2.7.4 | 2.7.4 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.3-1 | 2.7.3-1 |
| gnu | patch | >= 0 < 2.7.1-4ubuntu2.3 | 2.7.1-4ubuntu2.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_ubuntu5.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU patch vulnerabilities
vendor_ubuntu·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] GNU patch vulnerabilities
Title: GNU patch vulnerabilities
Summary: Several security issues were fixed in GNU patch.
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking th
Red Hat
patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
vendor_redhat·2015-01-24·CVSS 4.3
CVE-2015-1396 [MEDIUM] CWE-22 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
Package: patch (Red Hat Enterprise Linux 5) - Not affected
Package: patch (Red Hat Enterprise Linux 6) - Not affected
Package: patch (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2015-1396: patch - A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remo...
vendor_debian·2015·CVSS 4.3
CVE-2015-1396 [MEDIUM] CVE-2015-1396: patch - A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remo...
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
Scope: local
bookworm: resolved (fixed in 2.7.3-1)
bullseye: resolved (fixed in 2.7.3-1)
forky: resolved (fixed in 2.7.3-1)
sid: resolved (fixed in 2.7.3-1)
trixie: resolved (fixed in 2.7.3-1)
GHSA
GHSA-37cv-ggjj-37qh: A Directory Traversal vulnerability exists in the GNU patch before 2
ghsa_unreviewed·2022-05-24·CVSS 4.3
CVE-2015-1396 [MEDIUM] GHSA-37cv-ggjj-37qh: A Directory Traversal vulnerability exists in the GNU patch before 2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
OSV
CVE-2015-1396: A Directory Traversal vulnerability exists in the GNU patch before 2
osv·2019-11-25·CVSS 4.3
CVE-2015-1396 [MEDIUM] CVE-2015-1396: A Directory Traversal vulnerability exists in the GNU patch before 2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
OSV
patch vulnerabilities
osv·2015-06-22·CVSS 5.8
CVE-2010-4651 [MEDIUM] patch vulnerabilities
patch vulnerabilities
Jakub Wilk discovered that GNU patch did not correctly handle file paths in
patch files. An attacker could specially craft a patch file that could
overwrite arbitrary files with the privileges of the user invoking the program.
This issue only affected Ubuntu 12.04 LTS. (CVE-2010-4651)
László Böszörményi discovered that GNU patch did not correctly handle some
patch files. An attacker could specially craft a patch file that could cause a
denial of service. (CVE-2014-9637)
Jakub Wilk discovered that GNU patch did not correctly handle symbolic links in
git style patch files. An attacker could specially craft a patch file that
could overwrite arbitrary files with the privileges of the user invoking the
program. This issue only affected Ubuntu 14.04 LTS and Ubuntu 14.10.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1396 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
bugzilla·2015-01-28·CVSS 4.3
CVE-2015-1396 [MEDIUM] CVE-2015-1396 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
CVE-2015-1396 patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196)
It was reported [1] that the fix for CVE-2015-1196 [2] was incomplete.
[1] https://bugs.debian.org/775901
[2] https://bugzilla.redhat.com/show_bug.cgi?id=1182154
Discussion:
This was fixed in patch-2.7.3.
---
Sorry, I mean 2.7.4.
---
Given we have not fixed CVE-2015-1196, we're not affected by this issue.
Bugzilla
CVE-2015-1196 patch: directory traversal via symlinks
bugzilla·2015-01-14·CVSS 4.3
CVE-2015-1196 [MEDIUM] CVE-2015-1196 patch: directory traversal via symlinks
CVE-2015-1196 patch: directory traversal via symlinks
It was reported [1] that the versions of the patch utility that support Git-style patches are vulnerable to a directory traversal flaw. This could allow an attacker to overwrite arbitrary files by applying a specially crafted patch, with the privileges of the user running patch. A reproducer for this issue is available in [1].
[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775227
Discussion:
Created patch tracking bugs for this issue:
Affects: fedora-all [bug 1182157]
---
CVE request: http://seclists.org/oss-sec/2015/q1/131
---
Created attachment 981802
Upstream fix
Not sure how the upstream fix applies to the shipped versions. Can anyone help me get this into the packages, and get security updates out?
---
Note that
Bugzilla
CVE-2014-3585 redhat-upgrade-tool: does not check GPG signatures on package installation
bugzilla·2014-08-01·CVSS 9.8
CVE-2014-3585 [CRITICAL] CVE-2014-3585 redhat-upgrade-tool: does not check GPG signatures on package installation
CVE-2014-3585 redhat-upgrade-tool: does not check GPG signatures on package installation
Juraj Marko reported [1] that the redhat-upgrade-tool does not implement proper GPG signature checking when upgrading from one version of Red Hat Enterprise Linux to another.
[1] https://bugzilla.redhat.com/show_bug.cgi?id=1123915
Discussion:
This issue was fixed in Red Hat Enterprise Linux 6 with the following errata:
https://rhn.redhat.com/errata/RHBA-2014-1396.html
---
Acknowledgements:
This issue was discovered by Juraj Marko of the Red Hat QE Team.
---
This was fixed in Red Hat Enterprise Linux 7 via:
https://rhn.redhat.com/errata/RHBA-2015-2395.html
http://www.openwall.com/lists/oss-security/2015/01/27/29http://www.openwall.com/lists/oss-security/2015/01/27/29http://www.securityfocus.com/bid/75358http://www.securityfocus.com/bid/75358http://www.ubuntu.com/usn/USN-2651-1https://bugzilla.redhat.com/show_bug.cgi?id=1186764http://www.openwall.com/lists/oss-security/2015/01/27/29http://www.openwall.com/lists/oss-security/2015/01/27/29http://www.securityfocus.com/bid/75358http://www.securityfocus.com/bid/75358http://www.ubuntu.com/usn/USN-2651-1https://bugzilla.redhat.com/show_bug.cgi?id=1186764
2019-11-25
Published