CVE-2015-1416
published 2018-02-05CVE-2015-1416: Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5…
PriorityP344high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
3.47%
87.8th percentile
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | patch | < patch 2.5-1 (bookworm) | patch 2.5-1 (bookworm) |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| gnu | patch | >= 0 < 2.5-1 | 2.5-1 |
| gnu | patch | >= 0 < 2.5-1 | 2.5-1 |
| gnu | patch | >= 0 < 2.5-1 | 2.5-1 |
| gnu | patch | >= 0 < 2.5-1 | 2.5-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hgf9-q4jg-3xqq: Larry Wall's patch; patch in FreeBSD 10
ghsa_unreviewed·2022-05-14
CVE-2015-1416 [HIGH] GHSA-hgf9-q4jg-3xqq: Larry Wall's patch; patch in FreeBSD 10
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.
OSV
CVE-2015-1416: Larry Wall's patch; patch in FreeBSD 10
osv·2018-02-05·CVSS 7.8
CVE-2015-1416 [HIGH] CVE-2015-1416: Larry Wall's patch; patch in FreeBSD 10
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.
BSD
FreeBSD-SA-15:14.bsdpatch: shell injection vulnerability in patch(1)
bsd_advisories·2015-07-28·CVSS 7.8
CVE-2015-1416 [HIGH] FreeBSD-SA-15:14.bsdpatch: shell injection vulnerability in patch(1)
FreeBSD-SA-15:14.bsdpatch Security Advisory
The FreeBSD Project
Topic: shell injection vulnerability in patch(1)
Category: contrib
Module: patch
Announced: 2015-07-28
Credits: Martin Natano
Affects: FreeBSD 10.x.
Corrected: 2015-07-28 19:58:44 UTC (stable/10, 10.2-PRERELEASE)
2015-07-28 19:58:44 UTC (stable/10, 10.2-BETA2-p2)
2015-07-28 19:59:04 UTC (releng/10.2, 10.2-RC1-p1)
2015-07-28 19:59:11 UTC (releng/10.1, 10.1-RELEASE-p16)
CVE Name: CVE-2015-1416
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
The patch(1) utility takes a patch file produced by the diff(1) program and
apply the differences to an original file, producing a patched version.
The
Debian
CVE-2015-1416: patch - Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10...
vendor_debian·2015·CVSS 7.8
CVE-2015-1416 [HIGH] CVE-2015-1416: patch - Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10...
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary shell commands via a crafted patch file.
Scope: local
bookworm: resolved (fixed in 2.5-1)
bullseye: resolved (fixed in 2.5-1)
forky: resolved (fixed in 2.5-1)
sid: resolved (fixed in 2.5-1)
trixie: resolved (fixed in 2.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2015/07/30/9http://www.openwall.com/lists/oss-security/2015/08/01/4http://www.openwall.com/lists/oss-security/2015/08/02/1http://www.openwall.com/lists/oss-security/2015/08/02/6http://www.securityfocus.com/bid/76116http://www.securitytracker.com/id/1033110https://www.freebsd.org/security/advisories/FreeBSD-SA-15:14.bsdpatch.aschttp://www.openwall.com/lists/oss-security/2015/07/30/9http://www.openwall.com/lists/oss-security/2015/08/01/4http://www.openwall.com/lists/oss-security/2015/08/02/1http://www.openwall.com/lists/oss-security/2015/08/02/6http://www.securityfocus.com/bid/76116http://www.securitytracker.com/id/1033110https://www.freebsd.org/security/advisories/FreeBSD-SA-15:14.bsdpatch.asc
2018-02-05
Published