6.4
CVSSv2

CVE-2015-1396

Published: 25/11/2019 Updated: 17/02/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

A Directory Traversal vulnerability exists in the GNU patch prior to 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu patch

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

debian debian linux 11.0

Vendor Advisories

Debian Bug report logs - #775901 patch: CVE-2015-1396: another directory traversal via symlinks Package: patch; Maintainer for patch is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for patch is src:patch (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date: Wed, 21 Jan 2015 10:42:06 UTC Severit ...
Several security issues were fixed in GNU patch ...