Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20969

Опубликовано: 16 авг. 2019
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

A flaw was found in GNU patch through version 2.7.6. Strings beginning with a exclamation mark are not blocked by default. When ed receives an exclamation mark-prefixed command line argument, the argument is executed as a shell command. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5patchOut of support scope
Red Hat Enterprise Linux 6patchNot affected
Red Hat Enterprise Linux 7patchFixedRHSA-2019:296403.10.2019
Red Hat Enterprise Linux 7.4 Advanced Update SupportpatchFixedRHSA-2019:406103.12.2019
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportpatchFixedRHSA-2019:406103.12.2019
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionspatchFixedRHSA-2019:406103.12.2019
Red Hat Enterprise Linux 7.5 Extended Update SupportpatchFixedRHSA-2019:375706.11.2019
Red Hat Enterprise Linux 7.6 Extended Update SupportpatchFixedRHSA-2019:375806.11.2019
Red Hat Enterprise Linux 8patchFixedRHSA-2019:279819.09.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1746672patch: do_ed_script in pch.c does not block strings beginning with a ! character

EPSS

Процентиль: 73%
0.00784
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

CVSS3: 7.8
nvd
около 6 лет назад

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

CVSS3: 7.8
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.8
debian
около 6 лет назад

do_ed_script in pch.c in GNU patch through 2.7.6 does not block string ...

CVSS3: 7.8
github
больше 3 лет назад

do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.

EPSS

Процентиль: 73%
0.00784
Низкий

7.8 High

CVSS3