CVE-2016-10713: Buffer Overflow
A flaw was found in GNU patch before 2.7.6. An Out-of-bounds access within pchwriteline() function in pch.c file which can lead to a Denial of Service via a crafted input file.
External References:
https://savannah.gnu.org/bugs/index.php?45990
Upstream Patch:
https://git.savannah.gnu.org/cgit/patch.git/commit/src/pch.c?id=a0d7fe4589651c6
Other sources
An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pchwriteline() in pch.c can possibly lead to DoS via a crafted input file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/patchto a version that resolves this vulnerability.Fixed in 2.7.6-7Fixed in 2.8-2 - Upgrade
Upgrade
GNU patchto a version that resolves this vulnerability.Fixed in 2.7.6Patch a0d7fe4589651c6
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10713?
CVE-2016-10713 has a moderate severity level due to its potential to cause Denial of Service through an out-of-bounds access.
How do I fix CVE-2016-10713?
To fix CVE-2016-10713, upgrade your GNU patch to version 2.7.6 or later.
Which versions of GNU patch are affected by CVE-2016-10713?
GNU patch versions prior to 2.7.6 are affected by CVE-2016-10713.
What kind of vulnerability is CVE-2016-10713?
CVE-2016-10713 is an out-of-bounds access vulnerability that can lead to Denial of Service when processing crafted input files.
Where can I find more information about CVE-2016-10713?
Additional information about CVE-2016-10713 can typically be found in security advisories from major distributions.