do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade patch | Mar 26, 2024 | Aug 16, 2019 |
| Amazon Linux Ami 2 | — | Upgrade patchUpgrade patch-debuginfo | Apr 27, 2020 | Aug 16, 2019 |
| Amazon_linux | — | Upgrade patch | Oct 26, 2019 | Aug 16, 2019 |
| Centos_linux | — | Upgrade patch-debugsourceUpgrade patchUpgrade patch-debuginfo | Sep 20, 2019 | Aug 16, 2019 |
| Debian | — | Upgrade patch | Aug 19, 2019 | Aug 16, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade patch | Dec 18, 2019 | Aug 16, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade patch | Nov 19, 2019 | Aug 16, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade patch | Jan 3, 2020 | Aug 16, 2019 |
| Oracle_linux | — | Upgrade patch | Oct 5, 2022 | Aug 16, 2019 |
| Redhat_linux | — | No solution existsUpgrade patch-debugsourceUpgrade patch-debuginfoUpgrade patch | Sep 20, 2019 | Aug 16, 2019 |
| Ubuntu | — | Upgrade patch (Ubuntu Pro)Upgrade patch | Nov 19, 2024 | Aug 16, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 16, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub