cbcvebase.
CVE-2019-13636
published 2019-07-17

CVE-2019-13636: In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
debianpatch< patch 2.7.6-5 (bookworm)patch 2.7.6-5 (bookworm)
gnupatch<= 2.7.6
gnupatch>= 0 < 2.7.6-52.7.6-5
gnupatch>= 0 < 2.7.6-52.7.6-5
gnupatch>= 0 < 2.7.6-52.7.6-5
gnupatch>= 0 < 2.7.6-52.7.6-5
gnupatch>= 0 < 2.7.5-1ubuntu0.16.04.22.7.5-1ubuntu0.16.04.2
gnupatch>= 0 < 2.7.6-2ubuntu1.12.7.6-2ubuntu1.1
gnupatch>= 0 < 2.7.1-4ubuntu2.4+esm12.7.1-4ubuntu2.4+esm1
msrcazl3_patch_2.7.6-9_on_azure_linux_3.0
msrccbl2_patch_2.7.6-7_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_patch_2.7.6-7_on_cbl_mariner_1.0
msrcpatch-2.7.6-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcpatch-2.7.6-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcpatch-2.7.6-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcpatch-2.7.6-7.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
msrcpatch-2.7.6-9.azl3.aarch64.rpm_on_azure_linux_3.0_arm
msrcpatch-2.7.6-9.azl3.x86_64.rpm_on_azure_linux_3.0_x64
msrcpatch-debuginfo-2.7.6-7.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcpatch-debuginfo-2.7.6-7.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcpatch-debuginfo-2.7.6-7.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm

CVSS provenance

nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
osv5.9MEDIUM