Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-4651

Опубликовано: 11 мар. 2011
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:gnu:gnu_patch:*:*:*:*:*:*:*:*
Версия до 2.6.1 (включая)
cpe:2.3:a:gnu:gnu_patch:2.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnu_patch:2.5.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnu_patch:2.5.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:gnu_patch:2.6:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.0183
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

redhat
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

debian
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and ear ...

github
больше 3 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

suse-cvrf
больше 7 лет назад

Security update for patch

EPSS

Процентиль: 82%
0.0183
Низкий

5.8 Medium

CVSS2

Дефекты

CWE-22