Описание
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
A vulnerability was found in GNU Patch due to a double-free issue in the another_hunk function within pch.c, where an attacker could exploit this flaw to cause memory corruption, leading the application to crash and resulting in a denial of service.
Отчет
This vulnerability was rated as LOW severity because it causes the application to crash, it doesn’t compromise system security, it can disrupt the application's normal function.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | patch | Out of support scope | ||
| Red Hat Enterprise Linux 6 | patch | Out of support scope | ||
| Red Hat Enterprise Linux 7 | patch | Fix deferred | ||
| Red Hat Enterprise Linux 8 | patch | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file. NOTE: this issue exists because of an incomplete fix for CVE-2018-6952.
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vul ...
EPSS
3.3 Low
CVSS3