CVE-2014-9637: High severity Fedoraproject Fedora vulnerability
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
Other sources
It was reported [1] that a crafted diff file (attached) can make patch to eat memory and later segfault. Upstream commit that fixes this: http://git.savannah.gnu.org/cgit/patch.git/commit/?id=0c08d7a902c6fdd49b704623a12d8d672ef18944
[1]: https://savannah.gnu.org/bugs/?44051
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9637?
CVE-2014-9637 has been classified as a denial of service vulnerability, which can lead to memory consumption and segmentation faults.
How do I fix CVE-2014-9637?
To fix CVE-2014-9637, upgrade GNU patch to version 2.7.6-7 or later.
What versions are affected by CVE-2014-9637?
CVE-2014-9637 affects GNU patch versions up to and including 2.7.2.
Can CVE-2014-9637 be exploited remotely?
Yes, CVE-2014-9637 can be exploited by remote attackers using a crafted diff file.
What systems are vulnerable to CVE-2014-9637?
Systems using affected versions of GNU patch, such as certain versions of Debian, Fedora, Mageia, and Ubuntu, are vulnerable to CVE-2014-9637.