Wind River Support Network

HomeDefectsLIN7-11248
Fixed

LIN7-11248 : Security Advisory - patch - CVE-2019-13638

Created: Jul 28, 2019    Updated: Aug 14, 2019
Resolved Date: Aug 14, 2019
Found In Version: 7.0.0.1
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from CVE-2018-1000156.

CREATE(Triage): {Link=https://nvd.nist.gov/vuln/detail/CVE-2019-13638 User=admin}

CVEs


Live chat
Online