CVE-2015-1396: Path Traversal
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
Other sources
It was reported [1] that the fix for CVE-2015-1196 [2] was incomplete.
[1] https://bugs.debian.org/775901 [2] https://bugzilla.redhat.com/showbug.cgi?id=1182154
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1396?
CVE-2015-1396 has been classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2015-1396?
To fix CVE-2015-1396, update GNU patch to version 2.7.4 or later.
What systems are affected by CVE-2015-1396?
CVE-2015-1396 affects GNU patch versions prior to 2.7.4 and multiple Debian Linux releases.
Can CVE-2015-1396 be exploited remotely?
Yes, CVE-2015-1396 can be exploited remotely through a symlink attack in patch files.
Is there a known workaround for CVE-2015-1396?
Currently, the recommended approach is to apply the patch update rather than relying on a workaround.