Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-4651

Опубликовано: 11 мар. 2011
Источник: debian
EPSS Низкий

Описание

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
patchunfixedpackage

Примечания

  • Applying a patch blindly opens more severe security issues than only directory traversal...

  • openwall ships a fix

  • See https://bugzilla.redhat.com/show_bug.cgi?id=667529 for details

EPSS

Процентиль: 82%
0.0183
Низкий

Связанные уязвимости

ubuntu
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

redhat
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

nvd
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

github
больше 3 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

suse-cvrf
больше 7 лет назад

Security update for patch

EPSS

Процентиль: 82%
0.0183
Низкий