Описание
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | released | 2.7.3-1 |
| esm-infra-legacy/trusty | released | 2.7.1-4ubuntu2.3 |
| lucid | not-affected | 2.6-2ubuntu1 |
| precise | not-affected | 2.6.1-3 |
| trusty | released | 2.7.1-4ubuntu2.3 |
| trusty/esm | released | 2.7.1-4ubuntu2.3 |
| upstream | released | 2.7.3-1 |
| utopic | released | 2.7.1-5ubuntu0.3 |
| vivid | released | 2.7.3-1 |
Показывать по
EPSS
6.4 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
A Directory Traversal vulnerability exists in the GNU patch before 2.7 ...
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
EPSS
6.4 Medium
CVSS2
7.5 High
CVSS3