Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1395

Опубликовано: 20 янв. 2015
Источник: redhat
CVSS2: 3.6
EPSS Низкий

Описание

Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5patchNot affected
Red Hat Enterprise Linux 6patchNot affected
Red Hat Enterprise Linux 7patchWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1184490patch: directory traversal via file rename

EPSS

Процентиль: 80%
0.01329
Низкий

3.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

CVSS3: 7.5
nvd
больше 8 лет назад

Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

CVSS3: 7.5
debian
больше 8 лет назад

Directory traversal vulnerability in GNU patch versions which support ...

CVSS3: 7.5
github
больше 3 лет назад

Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.

fstec
около 11 лет назад

Уязвимость компонента, поддерживаемого Git-style, программной Unix-утилиты GNU Patch операционных систем Ubuntu, Fedora, позволяющая нарушителю изменять произвольные файлы

EPSS

Процентиль: 80%
0.01329
Низкий

3.6 Low

CVSS2