First published: Mon Jan 12 2015(Updated: )
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE openSUSE | =13.1 | |
openSUSE openSUSE | =13.2 | |
Oracle Solaris | =11.2 | |
GNU patch | =2.7.1 | |
debian/patch | 2.7.6-7 | |
redhat/patch | <2.7.4 | 2.7.4 |
http://git.savannah.gnu.org/cgit/patch.git/commit/?id=4e9269a5fc1fe80a1095a92593dd85db871e1fd3
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.