AZL-35101
Dashboard / Vulnerabilities / AZL-35101
Summary: CVE-2018-1000156 affecting package patch for versions less than 2.7.6-9
Details: GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
Affected packages
Package
Name: patch
Purl: pkg:rpm/azure-linux/patch
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.7.6-9
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
