A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.openwall.com/lists/oss-security/2015/01/27/29 | |
| http://www.securityfocus.com/bid/75358 | Third Party Advisory VDB Entry | 
| http://www.ubuntu.com/usn/USN-2651-1 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1186764 | 
Configurations
                    History
                    No history.
Information
                Published : 2019-11-25 16:15
Updated : 2020-02-17 18:15
NVD link : CVE-2015-1396
Mitre link : CVE-2015-1396
CVE.ORG link : CVE-2015-1396
JSON object : View
Products Affected
                debian
- debian_linux
gnu
- patch
CWE
                
                    
                        
                        CWE-22
                        
            Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
