Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-20633

Опубликовано: 28 июл. 2019
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.

A vulnerability was found in GNU Patch due to a double-free issue in the another_hunk function within pch.c, where an attacker could exploit this flaw to cause memory corruption, leading the application to crash and resulting in a denial of service.

Отчет

This vulnerability was rated as LOW severity because it causes the application to crash, it doesn’t compromise system security, it can disrupt the application's normal function.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5patchOut of support scope
Red Hat Enterprise Linux 6patchOut of support scope
Red Hat Enterprise Linux 7patchFix deferred
Red Hat Enterprise Linux 8patchFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1818934patch: double free in another_hunk function in pch.c

EPSS

Процентиль: 59%
0.00998
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.

CVSS3: 5.5
nvd
больше 6 лет назад

GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.

CVSS3: 5.5
msrc
11 месяцев назад

GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.

CVSS3: 5.5
debian
больше 6 лет назад

GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vul ...

suse-cvrf
почти 2 года назад

Security update for patch

EPSS

Процентиль: 59%
0.00998
Низкий

3.3 Low

CVSS3