First published: Tue Feb 13 2018(Updated: )
A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU patch | <=2.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6952 is classified as a high severity vulnerability due to the potential for crash and denial of service.
To fix CVE-2018-6952, upgrade GNU patch to version 2.7.7 or later.
Exploitation of CVE-2018-6952 involves supplying a crafted patch file that triggers the double free condition.
CVE-2018-6952 can lead to unpredictable application behavior, including crashes, impacting overall system stability.
All versions of GNU patch up to and including 2.7.6 are affected by CVE-2018-6952.