Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-4651

Опубликовано: 30 дек. 2010
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3patchWill not fix
Red Hat Enterprise Linux 4patchWill not fix
Red Hat Enterprise Linux 5patchWill not fix
Red Hat Enterprise Linux 6patchWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=667529patch: directory traversal flaw allows for arbitrary file creation

EPSS

Процентиль: 82%
0.0183
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

nvd
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

debian
почти 15 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and ear ...

github
больше 3 лет назад

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

suse-cvrf
больше 7 лет назад

Security update for patch

EPSS

Процентиль: 82%
0.0183
Низкий

2.1 Low

CVSS2