CVE-2015-1196: Medium severity suse linux vulnerability
GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
Other sources
It was reported [1] that the versions of the patch utility that support Git-style patches are vulnerable to a directory traversal flaw. This could allow an attacker to overwrite arbitrary files by applying a specially crafted patch, with the privileges of the user running patch. A reproducer for this issue is available in [1].
[1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775227
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1196?
CVE-2015-1196 is considered a medium severity vulnerability due to its potential to allow unauthorized file write access.
How do I fix CVE-2015-1196?
To fix CVE-2015-1196, upgrade the GNU patch utility to version 2.7.4 or later, or apply the necessary patches provided by your distribution.
What types of software are affected by CVE-2015-1196?
CVE-2015-1196 affects versions of GNU patch up to 2.7.4, including distributions like Red Hat, Debian, openSUSE, and Oracle Solaris.
What attack vector is associated with CVE-2015-1196?
CVE-2015-1196 is exploited through a symlink attack, allowing remote attackers to overwrite arbitrary files.
Is CVE-2015-1196 a local or remote vulnerability?
CVE-2015-1196 is classified as a remote vulnerability, enabling attackers to exploit it without physical access to the affected system.