GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade patch | Nov 8, 2019 | Jul 26, 2019 |
| Amazon Linux Ami 2 | — | Upgrade patch-debuginfoUpgrade patch | Apr 27, 2020 | Jul 26, 2019 |
| Amazon_linux | — | Upgrade patch | Oct 26, 2019 | Jul 24, 2019 |
| Centos_linux | — | Upgrade patch-debugsourceUpgrade patch-debuginfoUpgrade patch | Sep 20, 2019 | Jul 26, 2019 |
| Debian | — | Upgrade patch | Jul 29, 2019 | Jul 26, 2019 |
| Gentoo Linux | — | Upgrade sys-devel/patch. | Aug 19, 2019 | Jul 26, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade patch | Dec 18, 2019 | Jul 26, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade patch | Nov 19, 2019 | Jul 26, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade patch | Jan 3, 2020 | Jul 26, 2019 |
| Oracle Solaris | — | Upgrade text/gnu-patch to version 2.7.6.1-11.4.15.0.1.2.0 on Solaris 11.4 | Nov 20, 2019 | Jul 26, 2019 |
| Oracle_linux | — | Upgrade patch | Oct 5, 2022 | Jul 29, 2019 |
| Redhat_linux | — | Upgrade patch-debugsourceUpgrade patch-debuginfoUpgrade patchNo solution exists | Sep 20, 2019 | Jul 26, 2019 |
| Ubuntu | — | Upgrade patchUpgrade patch (Ubuntu Pro) | Jul 25, 2019 | Jul 24, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 26, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub