Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12865
HistoryJan 15, 2019 - 9:22 a.m.

Arbitrary Code Execution

2019-01-1509:22:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.016 Low

EPSS

Percentile

87.6%

patch is vulnerable to arbitrary code execution attacks. The vulnerability exists as GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility.

CPENameOperatorVersion
patcheq2.6__6.el6