7.5
CVSSv3

CVE-2018-6951

Published: 13/02/2018 Updated: 17/04/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in GNU patch up to and including 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu patch

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

Vendor Advisories

Several security issues were fixed in Patch ...
A NULL pointer dereference flaw was found in the way patch processed patch files An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches ...
An issue was discovered in GNU patch through 276 There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pchc, aka a "mangled rename" issue ...