First published: Wed Jul 17 2019(Updated: )
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/patch | <=2.7.6-4<=2.7.6-3 | 2.7.6-5 2.7.6-3+deb10u1 2.7.5-1+deb9u2 |
GNU patch | <=2.7.6 | |
debian/patch | 2.7.6-7 |
https://git.savannah.gnu.org/cgit/patch.git/commit/?id=dce4683cbbe107a95f1f0d45fabc304acfb5d71a
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.