CVE-2018-1000156
CVE-2018-1000156
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/154124/GNU-patch-Command-Injection-Directory-Traversal.htmlhttp://rachelbythebay.com/w/2018/04/05/bangpatch/https://access.redhat.com/errata/RHSA-2018:1199https://access.redhat.com/errata/RHSA-2018:1200https://access.redhat.com/errata/RHSA-2018:2091https://access.redhat.com/errata/RHSA-2018:2092https://access.redhat.com/errata/RHSA-2018:2093https://access.redhat.com/errata/RHSA-2018:2094https://access.redhat.com/errata/RHSA-2018:2095https://access.redhat.com/errata/RHSA-2018:2096https://access.redhat.com/errata/RHSA-2018:2097https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=894667#19