Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6951

Опубликовано: 03 фев. 2018
Источник: redhat
CVSS3: 3.3
EPSS Средний

Описание

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5patchNot affected
Red Hat Enterprise Linux 6patchNot affected
Red Hat Enterprise Linux 7patchNot affected
Red Hat Enterprise Linux 8patchNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1545046patch: NULL pointer dereference in pch.c:intuit_diff_type() causes a crash

EPSS

Процентиль: 95%
0.18785
Средний

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

CVSS3: 7.5
nvd
больше 7 лет назад

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

CVSS3: 7.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 7 лет назад

An issue was discovered in GNU patch through 2.7.6. There is a segment ...

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

EPSS

Процентиль: 95%
0.18785
Средний

3.3 Low

CVSS3