REDHAT-BUG-1545405: Low severity gnu patch vulnerability
Published Feb 14, 2018
·Updated
A flaw was found in GNU patch before 2.7.6. An Out-of-bounds access within pchwriteline() function in pch.c file which can lead to a Denial of Service via a crafted input file.
External References:
https://savannah.gnu.org/bugs/index.php?45990
Upstream Patch:
https://git.savannah.gnu.org/cgit/patch.git/commit/src/pch.c?id=a0d7fe4589651c6
Affected Software
1 affected component
GNU patch<2.7.6
Event History
Feb 14, 2018
Data Sourced
via Red Hat·08:48 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-1545405?
The severity of REDHAT-BUG-1545405 is high due to the potential for Denial of Service exploitation.
2
How do I fix REDHAT-BUG-1545405?
To fix REDHAT-BUG-1545405, update GNU patch to version 2.7.6 or later.
3
What software is affected by REDHAT-BUG-1545405?
GNU patch versions prior to 2.7.6 are affected by REDHAT-BUG-1545405.
4
What vulnerability type is REDHAT-BUG-1545405?
REDHAT-BUG-1545405 is classified as an out-of-bounds access vulnerability.
5
Is REDHAT-BUG-1545405 under active exploitation?
As of now, there are no known active exploits for REDHAT-BUG-1545405.